Topic module

AI Standards, Frameworks and Tools

AIGP candidates should understand major trustworthy AI principles and frameworks such as OECD AI principles, NIST AI RMF, and core ISO AI standards.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for IAPP AIGP

Treat each question as a governance decision: identify the AI role and life-cycle stage, classify the legal or risk issue, then choose the control, evidence, and accountability path.

Core concepts

Concept 1

Standards and frameworks help organizations translate responsible AI principles into governance practices, risk management activities, and evidence.

Exam cue: Use frameworks when the scenario asks for structured risk management rather than a single legal rule.

Concept 2

NIST AI RMF organizes AI risk work through core functions, categories, and practical playbook activities.

Exam cue: Use standards to support repeatable, auditable management practices.

Concept 3

ISO AI standards can support terminology, AI management systems, and impact assessment practices.

Exam cue: Treat frameworks as guidance that must be tailored to the organization's context.

Risk pitfalls and guardrails

Assuming a framework replaces legal analysis.

Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.

Selecting a standard without mapping it to actual controls.

Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.

Treating AI principles as complete governance evidence by themselves.

Guardrail: Avoid treating vendor tools as risk-free, relying on aggregate accuracy alone, or stopping governance after deployment approval.

Memory anchors

OECD AI Principles

OECD AI principles describe widely used expectations for trustworthy and human-centered AI.

NIST AI RMF

NIST AI RMF provides a structured approach to managing AI risks.

NIST Playbook

The NIST playbook helps organizations operationalize AI risk management activities.

ISO 22989

ISO 22989 supports AI terminology and concepts.

ISO 42001

ISO 42001 addresses AI management systems.

ISO 42005

ISO 42005 addresses AI system impact assessment.

Framework Mapping

Framework mapping links principles, requirements, controls, owners, and evidence.

Trustworthy AI

Trustworthy AI is AI governed for reliability, safety, fairness, transparency, accountability, privacy, and security.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

What are the core functions of the NIST AI Risk Management Framework?

What does ISO/IEC 42001 provide?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.