RSS Amplifier

Joe’s Substack · Jun 28, 2026

I Used AI to Study for an AI Governance Exam. Then I Passed It on My Own.

0
Sign in to vote or save

Joe Sabado · Joe’s Substack

If you’re preparing for IAPP’s Artificial Intelligence Governance Professional (AIGP) exam, here’s the method that worked for me: what I read, what I built, how I tested myself, and what I’d prioritize. Take it as one path, not the only one. I’ll explain each choice so you can adapt it to how you learn.

A bit of context, because it shaped my approach. I came to the AIGP already working in the field. I chair the Innovation and Impact Committee of the UC AI Council, co-lead the EDUCAUSE AI Community Group, and sit on UCSB’s Senate-Administration Committee on AI in Academic Contexts. For three years I’ve also been researching AI in higher education and governance, much of it in public at CampusAIExchange. So I studied less to learn the field than to validate what I knew and fill the gaps. If you’re newer to AI governance, you’ll lean harder on the foundational material than I did, but the method works either way.

On timeline

For a sense of pace: I decided to take the exam on May 31, 2026, booked the appointment, and passed on June 25. About three and a half weeks of focused preparation. That worked because I came in with years of practice and research behind me, so most of my time went to organizing what I knew rather than learning it cold. If you’re newer to the field, give yourself more runway. The honest measure isn’t the calendar. It’s whether you can explain every sub-topic in the Body of Knowledge without reaching for the book. Set your date once you feel that coming into range.

A note on what I won’t share

Before the exam, you sign a confidentiality agreement. So this guide contains no exam questions, no scenarios, and nothing I saw on the test. Only public materials and my own study process. Anyone promising you the “actual questions” is breaking that agreement and setting you up to fail, because the exam rewards understanding you can’t fake.

While I’m drawing lines: skip the brain dumps. Beyond trading in leaked content, which is exactly what the agreement exists to prevent, I don’t trust their accuracy and see no value in them. You can’t tell whether a stranger’s recalled “answer” is even right, and the exam doesn’t reward the rote memorization they encourage. Studying the real material is the path and the one that works.

Start with the Body of Knowledge, and never leave it

The most important thing I did was treat the AIGP Body of Knowledge and exam blueprint as the spine of everything. The BoK (I studied version 2.1) lists every domain and sub-topic the exam can draw from. It’s the table of contents for the test.

My rule was simple: study nothing that doesn’t map back to it. For each sub-topic, I’d find the material that covered it, work through it, and move on only once I could explain it plainly to someone outside the field. If I couldn’t say it simply, I didn’t know it yet. That one discipline did more for me than any single resource.

The resources, and what each is good for

I used several, and they aren’t interchangeable.

The Sybex IAPP AIGP Study Guide was my core reading: thorough, well organized, and close enough to the BoK that I could read it domain by domain. If you buy one book, buy this one. It also has a companion site that includes mock exams.

IAPP’s own AIGP study guide is worth having as the authoritative companion. It comes from the body that writes the exam.

The AIGP Certification Masterclass on Udemy by Dr. Kyle David gave me the same material in a different format, which helps more than it sounds. Hearing a concept after reading it is a cheap way to find out whether you actually understood it.

Around all of this, study the public frameworks the field rests on: the EU AI Act, the NIST AI Risk Management Framework, and the working vocabulary of impact assessments and risk tiering. The exam assumes familiarity with these, and they tie the domains together.

One caveat. I used other materials too, but left them off this list on purpose. A couple of sites I leaned on were excellent but too deep for the task, built for applying AI governance in an organization rather than passing a 100-question exam. They pulled toward depth the test doesn’t reward and away from the breadth it does. Studying for the exam and learning to govern AI at work overlap, but they aren’t the same project, and a resource that’s perfect for one can be a poor fit for the other.

What I invested

Since this was self-funded, I watched the total closely. Here’s the budget, so you can plan yours.

The exam is $649 at the member rate, plus $295 for the IAPP membership that unlocks it, so the exam alone runs about $944. The official IAPP practice exam was $60. The Sybex guide was $50 on Kindle. The Udemy Masterclass was $189. The Body of Knowledge, the blueprint, and the public frameworks are all free. That puts my direct out-of-pocket total around $1,243, on top of the AI subscriptions for Claude, Grok, and Perplexity that I was already paying for.

The biggest line item I chose not to spend was IAPP’s own AIGP online training, at $1,195. Reading the course description, I wasn’t convinced it would add enough beyond what the Body of Knowledge, the Sybex guide, and my own study site already gave me. That’s not a knock on the training. If your employer is paying, or you prefer a structured course with instruction built in, it may be exactly right. But self-funding forces the question of what each dollar actually does, and for me the answer was clear: I learn by building, not by sitting through a course. You’ll have to weigh that for your own budget and learning style.

Use AI as a preparation partner, if it works for you

Here’s an angle that worked for me, with the caveat that it may not suit you. I used AI as a study partner throughout: to research, to build my study site, and to draft practice questions. It was a collaborator in how I prepared, never a stand-in for the work itself.

How you use it is everything, especially for an AI governance exam. The center of my preparation was something I made: an interactive self-study site structured around version 2.1 of the Body of Knowledge, so its architecture mirrors the BoK itself. I built it with Claude’s design tool and used Perplexity and Grok to pull and check information. But I didn’t outsource my understanding. I used my own knowledge to judge whether what they returned was accurate, and I treated anything I couldn’t verify as a flag rather than a fact.

That discipline, letting AI accelerate the work while the judgment stays human, is the whole point of AI governance. It’s also the only way these tools help rather than hurt. Lean on them to think for you and you’ll walk in with the illusion of understanding. Use them to research faster, organize better, and pressure-test what you know, and they become a real advantage.

Here’s what matters most, though. In the end, I had to pass the test. AI didn’t pass it for me. I sat in that chair alone, no tools and no assistant, and answered every question out of what I understood. That’s the whole case for using AI the way I did: not to carry the knowledge for me, but to help me build knowledge I could carry in on my own.

What I built, and what’s actually in it

Since the self-study site was the center of my preparation, here’s what’s in it. The architecture mirrors version 2.1 of the Body of Knowledge: four domains, thirteen competencies, and all fifty-eight performance indicators, each with its own page. Nothing on the site exists that doesn’t map back to an indicator, so the discipline I described above is built into the structure rather than left to willpower.

Every indicator page follows the same shape: the core concepts and key definitions, two worked examples (one from industry, one from higher education, since that’s my field), the learning objective in plain terms, the patterns that signal a wrong answer, the governance controls that apply, and a few self-test questions. Reading one should feel like working through the indicator, not skimming past it.

On top of the indicators, I built reference pages for the frameworks the exam leans on hardest: the EU AI Act with its risk pyramid, prohibitions, GPAI rules, and timeline; the NIST AI RMF as Govern, Map, Measure, and Manage; plus OECD, ISO, and the US federal and state picture. Where the exam makes you tell similar things apart, I added comparison tables and a few small interactive tools, like a risk-tier classifier and an assessment picker. Around all of it sits the testing layer: flashcards, a glossary, a full mock exam, decision drills, teach-back prompts, and a readiness check.

What’s true about the site is that it goes deepest where I once struggled. The topics I couldn’t explain without the book became the longest pages. If you’re studying the same material, that’s a map of my weak spots, and you’re welcome to start where I had to.

Test yourself daily, and chase your weak spots

I tested myself every day, pulling practice questions from several sources: the ones bundled with the Sybex guide, the official IAPP practice exam, and the Udemy assessments. Use more than one. Each has its own style, and you want to be ready for all of them.

I also generated my own, and I’d recommend it. I didn’t write them from scratch. I had Claude draft questions based on the format and focus described in the Body of Knowledge and IAPP’s materials, then revised them as I saw fit. The revision is where the learning happened. You can’t tell whether a generated question is fair, well aimed, or even correct unless you understand the topic well enough to fix it, so editing them exposed my thin spots fast. The questions came from public material, never from anything I saw on the test, and I treated every one as a draft to verify rather than an answer to trust.

When a topic showed me I didn’t really understand it, I didn’t just reread and move on. I built detailed material on it and added it to my site. Let your weak spots drive what you study next. Over time my guide became a map of my own learning: it goes deepest exactly where I once struggled, which is probably where you will too.

AI is good at the pattern, not the specifics

After doing this for a while, I started to see where these tools help and where they don’t. AI is good at pattern. It reproduces the shape of the exam well: the kinds of questions IAPP asks, the format each one takes, the way a scenario is framed and the choices laid out. Ask it to draft questions in that mold and what comes back feels close to the real thing, which is what you want from a practice set. But the pattern is where its reliability ends. The specifics, meaning the content of the answer and the fact a question turns on, are where it gets things wrong, sometimes confidently. So I learned to trust the form and check the substance. It gave me a fair model of the exam’s format and a draft of every answer I still had to verify.

Verifying the answers is where I actually learned

That verifying turned out to be the real studying. Some answers were quick to confirm because they were plainly factual and I already knew them. The four levels of harm, say: individual, group, organizational, societal. Those I could check at a glance. Others I couldn’t, either because the answer wasn’t obvious or because I didn’t know the material yet. Early on I couldn’t have told you the obligations and penalties tied to each risk tier under the EU AI Act. Those were the questions worth having. When I hit one I couldn’t verify on sight, I researched it, on the web and through Perplexity and Grok, until I understood it well enough to judge whether the answer was right. Those topics were usually the ones I then built into new study material. The questions I couldn’t immediately check were a map of what I didn’t yet know, drawn for free. You can’t verify an answer you don’t understand, so verifying is learning.

What the exam actually asks of you

Without disclosing anything specific, here’s what to prepare for, all consistent with the format IAPP publishes openly.

Know the Body of Knowledge cold. Many questions are factual, and there’s no substitute for having truly absorbed the material. Breadth is real, and confidence is not recall.

Get the fundamentals solid. You need real command of AI terminology and definitions: how systems are classified, how they function, how they’re trained, and the vocabulary around all of it. This is the layer everything else sits on, and it’s easy to underestimate if you work around AI without having built it. Familiarity isn’t fluency.

Understand risks and harms in detail. The exam expects you to distinguish types of risk, the groups they fall on, and the levels of harm. Risk classification is central to how the field thinks, so it’s central to the test. Knowing something is “risky” isn’t enough. You need to know what kind, to whom, and how severe.

Understand the AI lifecycle, its stages in sequence and the roles and responsibilities attached to each. This matters as much as any test-taking technique. Governance lives in who is accountable for what, and when. Hold the lifecycle in your head as a structure and much of the material organizes itself around it.

Be ready to interpret, not just recall. Some questions are scenario-based and ask you to read closely, both the situation and the answer choices. The options aren’t always easy to tell apart, and the right one often turns on a distinction you’ll catch only if you understand the concept rather than recognize the words.

Watch the formats. You’ll be asked for the best response, or to select three of five, or to identify what’s most likely. These are formats where more than one answer looks defensible and the task is judgment rather than knowledge. Read slowly and be sure you know exactly what’s being asked.

None of this is a shortcut, which is the whole point. The exam rewards structured, applied understanding, exactly what the credential is meant to certify.

Answer to the exam’s frame, not your own

One thing to keep in mind, something I read while preparing and found true. You have to think about what IAPP wants you to know, based on the Body of Knowledge, and answer from that frame rather than your own.

This mattered more than I expected. With years of governance work behind me, my instinct was to answer from experience: what I’d actually do, how my institution would handle it, what I’ve seen work. But the exam isn’t testing your practice. It’s testing your command of the knowledge IAPP has defined, and sometimes the answer that fits the BoK isn’t the one experience reaches for first.

So I studied and tested differently. Not “what would I do here?” but “what does IAPP expect me to know, and what does the framework say?” If you come in with real-world experience, especially if you’re confident in it, make this adjustment consciously. Your experience is an asset for understanding the material. It becomes a liability if you let it answer the questions for you.

Last thing

Study to understand, not to pass, and passing takes care of itself. The candidates who struggle are usually the ones hunting for shortcuts. The ones who do well used the preparation to actually learn AI governance. That’s the better goal anyway: the certification lasts two years, but the understanding is yours to keep.

If it helps, my self-study site is open to anyone walking the same path. I built it to learn, and left it up to share.

Have thoughts or want to collaborate? Email me at joepsabado@gmail.com, connect with me on LinkedIn, or visitCampusAIExchange.com for more resources on responsible AI adoption in higher education.

Note: The perspectives shared are personal and do not reflect official positions of my employer.

Read the original on joesabado.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.