Corporate Business Alliance

CBA Standard · Technology

AI Governance Professional

The CBA Standard for AI Governance Professional states what competent practice in the discipline consists of: the domains of the work, their relative weight, and the learning objectives a competent practitioner meets in each.

Version
6.1
Domains
6weighted
Learning objectives
31
Published
2026
AI Governance Professional: weighting by domain
  1. 1Foundations of AI Governance

    15%
  2. 2Risk Classification and the Regulatory Landscape

    25%
  3. 3Governance Frameworks and Management Systems

    20%
  4. 4Documentation, Transparency and Accountability

    15%
  5. 5Bias, Robustness and Testing Concepts

    15%
  6. 6Incident Handling and Organisational Structures

    10%
Show as a table
AI Governance Professional: weighting by domain
DomainObjectivesWeighting
1. Foundations of AI Governance515%
2. Risk Classification and the Regulatory Landscape625%
3. Governance Frameworks and Management Systems520%
4. Documentation, Transparency and Accountability515%
5. Bias, Robustness and Testing Concepts515%
6. Incident Handling and Organisational Structures510%

Domains and learning objectives

A domain’s weighting is its share of the discipline, and the share of the examination paper drawn from that domain. The study material and the examination questions are written to the objectives.

  1. Domain 1

    Foundations of AI Governance

    15%

    • 1.1Distinguish AI governance from adjacent disciplines such as data protection, information security and model development quality assurance
    • 1.2Identify the characteristics of AI systems that create distinct governance needs, including opacity, drift, scale of automated decisions and probabilistic outputs
    • 1.3Classify organisational AI activity into common categories such as procured AI features, in-house models, general-purpose model use and shadow AI
    • 1.4Select appropriate first steps for establishing governance in an organisation with no existing AI oversight, such as inventory building and use-case intake
    • 1.5Interpret the roles of provider, deployer, and affected person as they recur across regulatory and framework language
  2. Domain 2

    Risk Classification and the Regulatory Landscape

    25%

    • 2.1Classify described AI use cases into the EU AI Act's tiers of prohibited practice, high risk, transparency risk and minimal risk
    • 2.2Distinguish the obligations that fall on providers from those that fall on deployers of high-risk AI systems
    • 2.3Interpret the treatment of general-purpose AI models, including when additional obligations attach to models presenting systemic risk
    • 2.4Evaluate the extraterritorial reach of AI regulation and its practical effect on organisations in the Middle East, Asia and other regions outside the EU
    • 2.5Select the correct regulatory response to borderline cases, such as emotion recognition at work, biometric identification and credit scoring
    • 2.6Identify the broad direction of AI rules in other jurisdictions, including sectoral approaches, national strategies and voluntary codes
  3. Domain 3

    Governance Frameworks and Management Systems

    20%

    • 3.1Interpret the purpose and structure of the NIST AI Risk Management Framework, including its four functions and its trustworthiness characteristics
    • 3.2Distinguish a certifiable management system standard such as ISO/IEC 42001 from a voluntary risk framework such as the NIST AI RMF
    • 3.3Select framework elements appropriate to a given organisational need, such as risk identification, policy setting or supplier assurance
    • 3.4Evaluate an organisation's AI policy against the elements a recognised framework would expect it to contain
    • 3.5Interpret how the plan-do-check-act cycle applies to an AI management system, including internal audit and management review
  4. Domain 4

    Documentation, Transparency and Accountability

    15%

    • 4.1Select the appropriate documentation artefact for a given purpose, such as a model card, data sheet, AI inventory entry or impact assessment
    • 4.2Evaluate the completeness of a model card or system documentation against the questions a deployer or regulator would ask
    • 4.3Interpret transparency obligations owed to end users and affected persons, including disclosure of AI interaction and synthetic content labelling
    • 4.4Distinguish explainability of individual decisions from transparency about a system's existence, purpose and limits
    • 4.5Calculate simple documentation coverage measures from an AI inventory, such as the proportion of high-risk systems with a completed impact assessment
  5. Domain 5

    Bias, Robustness and Testing Concepts

    15%

    • 5.1Distinguish sources of bias across the lifecycle, including historical data bias, sampling bias, label bias and deployment drift
    • 5.2Interpret basic fairness measures conceptually, such as comparing selection or error rates across groups, and recognise that fairness definitions can conflict
    • 5.3Calculate simple disparity measures from a small results table, such as a selection-rate ratio between two groups
    • 5.4Evaluate the design of a testing plan for an AI system, including test data independence, edge cases and human review checkpoints
    • 5.5Select appropriate ongoing monitoring practices for a deployed system, including drift indicators, performance thresholds and re-validation triggers
  6. Domain 6

    Incident Handling and Organisational Structures

    10%

    • 6.1Classify AI-related events by severity and type, distinguishing incidents, near misses and complaints
    • 6.2Select the correct sequence of actions when a serious AI incident occurs, including containment, escalation, communication and regulator notification concepts
    • 6.3Evaluate the design of an AI governance operating model, including board oversight, an AI governance committee and operational ownership
    • 6.4Distinguish the responsibilities of first-line operators, second-line risk and compliance functions and third-line internal audit for AI systems
    • 6.5Interpret post-incident review findings and select corrective actions that address root causes rather than symptoms

Competence at award

What a holder of the CBA-AIG credential has demonstrated, at Professional level.

  • Classify AI systems and use cases by risk level using criteria drawn from the EU AI Act and comparable regulatory regimes, and assign provider and deployer responsibilities correctly
  • Apply the core structures of the NIST AI Risk Management Framework and ISO/IEC 42001 to design an organisational AI governance programme at a conceptual level
  • Produce and evaluate AI governance documentation, including AI inventories, use-case risk registers, model cards, data sheets and transparency notices
  • Interpret the purpose, methods and limits of bias, fairness and robustness testing, and select appropriate metrics and review checkpoints for a given deployment
  • Design AI incident handling, escalation and post-incident review routines, and allocate governance roles across boards, committees and operational teams
  • Evaluate third-party and procured AI systems using contractual, documentation and assurance evidence available to a deploying organisation
The Competency Framework

Study material

CBA publishes study material written objective by objective to this standard. Its contents are open to read, and one lesson is published in full.