Corporate Business Alliance

CBA-AIG · Technology · Professional level

CBA Certified AI Governance Professional

Award requires3 years' relevant professional experience (2 with a relevant degree), confirmed by a named referee

A professional certification in organisational AI governance covering risk classification, the EU AI Act landscape, NIST AI RMF and ISO/IEC 42001 concepts, documentation and transparency, bias and robustness testing, and incident response structures.

Level
Professional
Domains
6weighted
Questions
80
Time limit
120minutes

The CBA Certified AI Governance Professional (CBA-AIG) certifies the knowledge needed to govern AI in an organisation: how to classify AI systems by risk, what the EU AI Act and comparable regimes require of providers and deployers, how frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 structure an AI management programme, and how to document, test and monitor AI systems.

Candidates learn to draft AI inventories and use-case risk registers, interpret transparency and human oversight obligations, read a model card or data sheet critically, understand what bias and robustness testing can and cannot prove, and design incident handling and escalation routines that fit ordinary organisational structures. The syllabus is vendor neutral: worked examples use spreadsheets and shared document templates.

The syllabus teaches the reasoning behind the rules rather than a single statute's text, including for jurisdictions without AI-specific legislation. The examination is taken online.

The path to the credential

Awarded on the examination, 6 assessed workbooks of applied work and 3 years' relevant professional experience (2 with a relevant degree), confirmed by a named referee, with a signed undertaking to the Code of Professional Conduct.

  1. 01Prepare

    Study to the published standard with CBA’s study material, or prepare in your own way. The examination is the same whichever route you take. Routes to preparation

  2. 02Enrol

    Enrolling for the examination gives a voucher for one sitting, valid for 12 months.

  3. 03Sit the examination

    80 questions in 120 minutes, taken online and drawn to the published domain weightings. The specimen paper

  4. 04Complete the applied work

    6 assessed workbooks, marked against a published tolerance.

  5. 05Evidence your experience

    Declare 3 years' relevant professional experience (2 with a relevant degree), confirmed by a named referee, and sign the undertaking to the Code of Professional Conduct. The Code

  6. 06Award

    The credential is awarded at Professional level and entered in the public register, and the holder may use the CBA-AIG designation.

  7. 07Maintain

    Renew every 3 years against evidenced continuing professional development. CPD and renewal

Exam blueprint

Every paper is assembled to these weightings, which are published in full and fixed for the life of the scheme version.

Assessment domains and their percentage weighting of the CBA-AIG exam
Domain

Foundations of AI Governance15%

  • Distinguish AI governance from adjacent disciplines such as data protection, information security and model development quality assurance
  • Identify the characteristics of AI systems that create distinct governance needs, including opacity, drift, scale of automated decisions and probabilistic outputs
  • Classify organisational AI activity into common categories such as procured AI features, in-house models, general-purpose model use and shadow AI
  • Select appropriate first steps for establishing governance in an organisation with no existing AI oversight, such as inventory building and use-case intake
  • Interpret the roles of provider, deployer, and affected person as they recur across regulatory and framework language

Risk Classification and the Regulatory Landscape25%

  • Classify described AI use cases into the EU AI Act's tiers of prohibited practice, high risk, transparency risk and minimal risk
  • Distinguish the obligations that fall on providers from those that fall on deployers of high-risk AI systems
  • Interpret the treatment of general-purpose AI models, including when additional obligations attach to models presenting systemic risk
  • Evaluate the extraterritorial reach of AI regulation and its practical effect on organisations in the Middle East, Asia and other regions outside the EU
  • Select the correct regulatory response to borderline cases, such as emotion recognition at work, biometric identification and credit scoring
  • Identify the broad direction of AI rules in other jurisdictions, including sectoral approaches, national strategies and voluntary codes

Governance Frameworks and Management Systems20%

  • Interpret the purpose and structure of the NIST AI Risk Management Framework, including its four functions and its trustworthiness characteristics
  • Distinguish a certifiable management system standard such as ISO/IEC 42001 from a voluntary risk framework such as the NIST AI RMF
  • Select framework elements appropriate to a given organisational need, such as risk identification, policy setting or supplier assurance
  • Evaluate an organisation's AI policy against the elements a recognised framework would expect it to contain
  • Interpret how the plan-do-check-act cycle applies to an AI management system, including internal audit and management review

Documentation, Transparency and Accountability15%

  • Select the appropriate documentation artefact for a given purpose, such as a model card, data sheet, AI inventory entry or impact assessment
  • Evaluate the completeness of a model card or system documentation against the questions a deployer or regulator would ask
  • Interpret transparency obligations owed to end users and affected persons, including disclosure of AI interaction and synthetic content labelling
  • Distinguish explainability of individual decisions from transparency about a system's existence, purpose and limits
  • Calculate simple documentation coverage measures from an AI inventory, such as the proportion of high-risk systems with a completed impact assessment

Bias, Robustness and Testing Concepts15%

  • Distinguish sources of bias across the lifecycle, including historical data bias, sampling bias, label bias and deployment drift
  • Interpret basic fairness measures conceptually, such as comparing selection or error rates across groups, and recognise that fairness definitions can conflict
  • Calculate simple disparity measures from a small results table, such as a selection-rate ratio between two groups
  • Evaluate the design of a testing plan for an AI system, including test data independence, edge cases and human review checkpoints
  • Select appropriate ongoing monitoring practices for a deployed system, including drift indicators, performance thresholds and re-validation triggers

Incident Handling and Organisational Structures10%

  • Classify AI-related events by severity and type, distinguishing incidents, near misses and complaints
  • Select the correct sequence of actions when a serious AI incident occurs, including containment, escalation, communication and regulator notification concepts
  • Evaluate the design of an AI governance operating model, including board oversight, an AI governance committee and operational ownership
  • Distinguish the responsibilities of first-line operators, second-line risk and compliance functions and third-line internal audit for AI systems
  • Interpret post-incident review findings and select corrective actions that address root causes rather than symptoms
Total100%

Specimen examination paper

Twelve examination items, with the answer and a rationale for every option. None of them will appear on a live paper.

Open the specimen paper

The study material

The full contents of the study material: every chapter and lesson, how long each takes, and where the assessed workbooks fall. One complete lesson is free to read, with no account.

Contents of the study material

What you will be able to do

  • Classify AI systems and use cases by risk level using criteria drawn from the EU AI Act and comparable regulatory regimes, and assign provider and deployer responsibilities correctly
  • Apply the core structures of the NIST AI Risk Management Framework and ISO/IEC 42001 to design an organisational AI governance programme at a conceptual level
  • Produce and evaluate AI governance documentation, including AI inventories, use-case risk registers, model cards, data sheets and transparency notices
  • Interpret the purpose, methods and limits of bias, fairness and robustness testing, and select appropriate metrics and review checkpoints for a given deployment
  • Design AI incident handling, escalation and post-incident review routines, and allocate governance roles across boards, committees and operational teams
  • Evaluate third-party and procured AI systems using contractual, documentation and assurance evidence available to a deploying organisation

Who this is for

Compliance and risk professionals
Officers in compliance, data protection, internal audit or enterprise risk who are being handed responsibility for AI oversight and need a structured, defensible approach to classifying and controlling AI use across the business.
IT and data leaders
IT managers, data managers and solution architects who select, integrate or operate AI-enabled systems and must translate governance requirements into inventories, documentation, testing routines and monitoring practices.
Consultants and project professionals
Advisers, analysts and project or programme managers who guide clients or internal stakeholders through AI adoption and want recognised evidence that they can assess regulatory exposure and stand up governance structures.

Other certifications

CBA-AIP

CBA Certified Artificial Intelligence Professional

A broad professional certification in applied artificial intelligence covering machine learning and deep learning concepts, data foundations, the full model lifecycle, application patterns including generative AI, and responsible AI practice. Conceptual and applied; no coding required.

View certification
CBA-DAP

CBA Certified Data Analytics Professional

A professional certification covering the full analytics workflow: statistical reasoning, data preparation, spreadsheet and SQL analysis, visualisation and dashboards, insight communication, and an introduction to predictive methods.

View certification
CBA-GAI

CBA Certified Generative AI Practitioner

A professional certification in practical generative AI: how large language and diffusion models behave, prompt design, retrieval-grounded and multimodal workflows, output evaluation, and safe, well-governed use of AI in everyday work.

View certification