As AI governance has matured, a set of credentials and standards has grown up around it: some for individuals, some for organisations, from different bodies and with different scopes. This page sets them side by side, factually and neutrally: what each one is, who issues it, who it is for, and how they relate, with links to the primary source for each.
Last reviewed: 21 July 2026 · AIRiskAware is an independent reference and does not issue or endorse any certification; confirm details and fees with each provider
The single most useful distinction is between a credential for a person and a certification for an organisation. An individual credential, such as the IAPP AIGP, certifies that someone has passed an exam demonstrating defined knowledge. An organisation certification, above all ISO/IEC 42001, certifies that an organisation has an AI management system that meets a standard, confirmed by an external audit. People hold credentials; organisations hold certifications, and the two work together.
A second distinction is who stands behind the certificate. Some credentials are accredited: ISO/IEC 42001 is certified by accredited certification bodies whose own requirements are set in ISO/IEC 42006, and personnel credentials such as the ISO/IEC 42001 lead auditor are issued under ISO/IEC 17024. Others are professional-body or vendor credentials that carry the issuer’s reputation rather than a formal accreditation. Neither is inherently better; what matters is that the certificate says what you think it says. Note too that frameworks like the NIST AI Risk Management Framework and Singapore’s Model AI Governance Framework are voluntary guidance, not certifications you can hold.
Who it is for: Governance, privacy, legal, risk and compliance professionals who need a broad grounding in AI governance
Format: Three-hour, 100-question exam; no formal prerequisites; two-year term with continuing-education credits
The most widely held general AI governance credential. The exam launched in 2024, following the training programme in 2023. Exam fees are published by the IAPP and vary with membership; confirm current pricing directly with the IAPP.
Who it is for: Experienced auditors (eligibility requires an active CISA, CIA or CPA)
Format: Advanced credential launched May 2025; exam based on AI governance, risk, operations and tools
Described by ISACA as the first advanced, audit-specific AI credential. It builds on an existing audit certification rather than standing alone.
Who it is for: Security leaders who hold a CISM or CISSP
Format: Advanced credential launched August 2025; covers identifying, assessing, monitoring and mitigating AI security risk
Positioned by ISACA as the first AI-centric security management credential, aimed at technology and information-security leaders.
Who it is for: People implementing or auditing an organisation’s AI management system
Format: Typically a multi-day course plus exam; Lead Implementer and Lead Auditor are separate credentials
These are personnel credentials that sit alongside the ISO/IEC 42001 standard below. They certify a person to implement or audit an AI management system; they are distinct from an organisation being certified to the standard itself. Fees vary by provider and region.
Who it is for: A foundation and awareness level credential for anyone building or governing AI
Format: Five online modules and a one-hour exam
An entry point that covers the need for ethical and regulatory standards, lawful and ethical data use, and ethical considerations across the AI lifecycle.
Who it is for: Organisations that provide or use AI and want independent assurance of their AI management system
Format: A management system standard (an AI management system, or AIMS), certified through an external audit; certification is voluntary
The world’s first AI management system standard, built on a Plan-Do-Check-Act cycle. An organisation is certified against it by an accredited certification body; the requirements for those bodies are set out in ISO/IEC 42006. This is the closest thing to a recognised organisation-level AI certification.
Who it is for: Organisations wanting to demonstrate ethics governance in a specific autonomous or intelligent system
Format: A product and system ethics certification assessing transparency, accountability, algorithmic bias and privacy
Assesses ethics governance during the design and implementation of an autonomous intelligent system, so an organisation can demonstrate accountability and strengthen trust in that product.
No single certification is mandated. For individuals, the IAPP AIGP is the most widely held general credential; specialist credentials exist for auditors (ISACA AAIA), security leaders (ISACA AAISM) and management-system practitioners (ISO/IEC 42001 lead implementer and auditor). For organisations, ISO/IEC 42001 is the recognised AI management system standard, certified by accredited bodies.
An individual credential certifies that a person has demonstrated defined knowledge, usually by passing an exam. An organisation certification, such as ISO/IEC 42001, certifies that an organisation has an AI management system meeting a standard, confirmed by an external audit. The two are complementary: people hold credentials, organisations hold certifications.
Not for the organisation certification. ISO/IEC 42001 is a standard that an organisation is audited and certified against by an accredited certification body. The exams people take are the separate Lead Implementer and Lead Auditor personnel credentials offered by training providers, which certify an individual to implement or audit an AI management system.
No. These credentials and certifications are voluntary. They demonstrate competence or provide independent assurance, but they are not a legal requirement. Legal obligations come from laws and regulators, such as the EU AI Act, the Australian Privacy Act, or Singapore’s Personal Data Protection Act, not from holding a certification.
No. AIRiskAware is an independent reference. It does not issue, accredit or endorse any certification, and it is not affiliated with any of the bodies listed on this page. This comparison is factual information to help you choose, not a recommendation of one credential over another.
Most of these credentials, and an ISO/IEC 42001 certification in particular, rest on the same foundations: a clear AI inventory, defined ownership, risk assessment and documented controls. A short, free assessment shows where an organisation stands against a structured governance model before it commits to a certification path.
This page is general, factual information as at 21 July 2026, not career, legal or compliance advice, and not a recommendation of one certification over another. AIRiskAware is an independent reference and is not affiliated with, accredited by, or endorsed by any of the bodies named here. Certifications, eligibility and fees change; confirm the current details with each provider through the primary sources linked above.