CBA Standard · Technology
AI Governance Professional
The CBA Standard for AI Governance Professional states what competent practice in the discipline consists of: the domains of the work, their relative weight, and the learning objectives a competent practitioner meets in each.
- Version
- 6.1
- Domains
- 6weighted
- Learning objectives
- 31
- Published
- 2026
1Foundations of AI Governance
15%2Risk Classification and the Regulatory Landscape
25%3Governance Frameworks and Management Systems
20%4Documentation, Transparency and Accountability
15%5Bias, Robustness and Testing Concepts
15%6Incident Handling and Organisational Structures
10%
Show as a table
| Domain | Objectives | Weighting |
|---|---|---|
| 1. Foundations of AI Governance | 5 | 15% |
| 2. Risk Classification and the Regulatory Landscape | 6 | 25% |
| 3. Governance Frameworks and Management Systems | 5 | 20% |
| 4. Documentation, Transparency and Accountability | 5 | 15% |
| 5. Bias, Robustness and Testing Concepts | 5 | 15% |
| 6. Incident Handling and Organisational Structures | 5 | 10% |
Domains and learning objectives
A domain’s weighting is its share of the discipline, and the share of the examination paper drawn from that domain. The study material and the examination questions are written to the objectives.
Domain 1
Foundations of AI Governance
15%
- 1.1Distinguish AI governance from adjacent disciplines such as data protection, information security and model development quality assurance
- 1.2Identify the characteristics of AI systems that create distinct governance needs, including opacity, drift, scale of automated decisions and probabilistic outputs
- 1.3Classify organisational AI activity into common categories such as procured AI features, in-house models, general-purpose model use and shadow AI
- 1.4Select appropriate first steps for establishing governance in an organisation with no existing AI oversight, such as inventory building and use-case intake
- 1.5Interpret the roles of provider, deployer, and affected person as they recur across regulatory and framework language
Domain 2
Risk Classification and the Regulatory Landscape
25%
- 2.1Classify described AI use cases into the EU AI Act's tiers of prohibited practice, high risk, transparency risk and minimal risk
- 2.2Distinguish the obligations that fall on providers from those that fall on deployers of high-risk AI systems
- 2.3Interpret the treatment of general-purpose AI models, including when additional obligations attach to models presenting systemic risk
- 2.4Evaluate the extraterritorial reach of AI regulation and its practical effect on organisations in the Middle East, Asia and other regions outside the EU
- 2.5Select the correct regulatory response to borderline cases, such as emotion recognition at work, biometric identification and credit scoring
- 2.6Identify the broad direction of AI rules in other jurisdictions, including sectoral approaches, national strategies and voluntary codes
Domain 3
Governance Frameworks and Management Systems
20%
- 3.1Interpret the purpose and structure of the NIST AI Risk Management Framework, including its four functions and its trustworthiness characteristics
- 3.2Distinguish a certifiable management system standard such as ISO/IEC 42001 from a voluntary risk framework such as the NIST AI RMF
- 3.3Select framework elements appropriate to a given organisational need, such as risk identification, policy setting or supplier assurance
- 3.4Evaluate an organisation's AI policy against the elements a recognised framework would expect it to contain
- 3.5Interpret how the plan-do-check-act cycle applies to an AI management system, including internal audit and management review
Domain 4
Documentation, Transparency and Accountability
15%
- 4.1Select the appropriate documentation artefact for a given purpose, such as a model card, data sheet, AI inventory entry or impact assessment
- 4.2Evaluate the completeness of a model card or system documentation against the questions a deployer or regulator would ask
- 4.3Interpret transparency obligations owed to end users and affected persons, including disclosure of AI interaction and synthetic content labelling
- 4.4Distinguish explainability of individual decisions from transparency about a system's existence, purpose and limits
- 4.5Calculate simple documentation coverage measures from an AI inventory, such as the proportion of high-risk systems with a completed impact assessment
Domain 5
Bias, Robustness and Testing Concepts
15%
- 5.1Distinguish sources of bias across the lifecycle, including historical data bias, sampling bias, label bias and deployment drift
- 5.2Interpret basic fairness measures conceptually, such as comparing selection or error rates across groups, and recognise that fairness definitions can conflict
- 5.3Calculate simple disparity measures from a small results table, such as a selection-rate ratio between two groups
- 5.4Evaluate the design of a testing plan for an AI system, including test data independence, edge cases and human review checkpoints
- 5.5Select appropriate ongoing monitoring practices for a deployed system, including drift indicators, performance thresholds and re-validation triggers
Domain 6
Incident Handling and Organisational Structures
10%
- 6.1Classify AI-related events by severity and type, distinguishing incidents, near misses and complaints
- 6.2Select the correct sequence of actions when a serious AI incident occurs, including containment, escalation, communication and regulator notification concepts
- 6.3Evaluate the design of an AI governance operating model, including board oversight, an AI governance committee and operational ownership
- 6.4Distinguish the responsibilities of first-line operators, second-line risk and compliance functions and third-line internal audit for AI systems
- 6.5Interpret post-incident review findings and select corrective actions that address root causes rather than symptoms
Competence at award
What a holder of the CBA-AIG credential has demonstrated, at Professional level.
- Classify AI systems and use cases by risk level using criteria drawn from the EU AI Act and comparable regulatory regimes, and assign provider and deployer responsibilities correctly
- Apply the core structures of the NIST AI Risk Management Framework and ISO/IEC 42001 to design an organisational AI governance programme at a conceptual level
- Produce and evaluate AI governance documentation, including AI inventories, use-case risk registers, model cards, data sheets and transparency notices
- Interpret the purpose, methods and limits of bias, fairness and robustness testing, and select appropriate metrics and review checkpoints for a given deployment
- Design AI incident handling, escalation and post-incident review routines, and allocate governance roles across boards, committees and operational teams
- Evaluate third-party and procured AI systems using contractual, documentation and assurance evidence available to a deploying organisation
Study material
CBA publishes study material written objective by objective to this standard. Its contents are open to read, and one lesson is published in full.
