← Back to all articles
Insights

AI Governance Certifications in 2026: What AIGP, ISO/IEC 42001 and ISACA's Credentials Are Actually Worth

Before you spend anything on an AI governance certification, read one sentence from the European Commission's own AI Literacy questions and answers: "There is no need for a certificate." That is the Commission answering, in writing, whether staff need certificates to satisfy the AI Act's literacy obligation. It adds that "no specific governance structure is mandated to comply with article 4" and that "no strict requirements or mandatory trainings are imposed" (EC AI Literacy Q&A). The legal question is settled. The commercial one is not: which credential actually buys you something in the job market, in a procurement questionnaire, or in an audit room? Here is the buyer-side answer, with published prices, published accreditation status, and an honest admission of where the answer is "none of them".

What the EU AI Act actually requires of people

Most certification marketing is still selling against law that no longer exists. The Digital Omnibus on AI, Regulation (EU) 2026/1744 - dated 8 July 2026, in the Official Journal on 24 July 2026, in force 27 July 2026 - replaced Article 4 in full. Providers and deployers must now "take measures to support the development of AI literacy of their staff", and, decisively, "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual" (Article 4). That converts an obligation of result into an obligation of means. The old "ensure, to their best extent, a sufficient level of AI literacy" wording is not current law, so a vendor page still quoting it tells you how recently its legal content was reviewed.

Copying someone else's programme does not protect you either. The Living Repository of AI Literacy Practices collects 40-plus initiatives and states that replicating them "does not automatically grant presumption of compliance with Article 4".

Enforcement is live. Article 4 has been enforceable since 2 August 2026, and supervision sits "not with the AI Office, but it is under the remit of national market surveillance authorities". Sanctions are national and proportionate, and the Q&A notes they are "more likely if there is proof of an incident due to lack of appropriate training and guidance of employees". That tells you what to build: an evidence trail, not a wall of certificates.

Where competence requirements do bite

Two places. The first is notified bodies, and it is Article 31, not Annex VII - an error repeated constantly in vendor material. Annex VII contains no personnel competence or qualification provisions at all. Article 31(11) requires "sufficient internal competences" and the "permanent availability of sufficient administrative, technical, legal and scientific personnel who possess experience and knowledge relating to the relevant types of AI systems"; Article 31(10) requires "the requisite competence in the specific field" (Article 31). The duty attaches to the organisation, never to an individual credential.

The second is human oversight: deployers of high-risk systems must still ensure staff assigned oversight duties are trained, under Articles 26 and 14. That survived the Omnibus intact, and still specifies no certification.

The ISO/IEC 42001 presumption-of-conformity myth

ISO/IEC 42001 certification does not buy AI Act conformity. Article 40(1) grants presumption only for harmonised standards "the references of which have been published in the Official Journal" (Article 40). Article 42 grants it only for representative training data under Article 10(4) and for cybersecurity certification under Regulation (EU) 2019/881 or the Cyber Resilience Act (EU) 2024/2847. ISO/IEC 42001 is in neither route.

Name the category error: 42001 certifies an organisation's management system, while the AI Act regulates each individual high-risk AI system as a product. A provider relying solely on 42001 keeps the full evidentiary burden if challenged. One 2026 wrinkle will be mis-sold: 42001 was adopted in Europe as EN ISO/IEC 42001:2026, published 18 March 2026 and approved by CEN-CENELEC/JTC 21 without modification. European adoption alone does not make a standard harmonised, and without an OJ citation there is no presumption of conformity.

The costed comparison: what an AI governance certification really costs

Vendors' own published figures, unrounded and unconverted. Where nothing is published, the table says so rather than guessing.

Credential Published price Prerequisite Format Accreditation
IAPP AIGP USD 649 member / USD 799 non-member None 100 questions, 2.75 hours plus 15-minute break; Pearson VUE or OnVUE Not ANAB/ISO 17024
PECB 42001 Lead Auditor / Implementer No list price; partner-sold. Schellman USD 1,000 each; Mastermind USD 99 self-paced Experience gates for the full title 5 days, 31 CPD credits, exam and certification fees included, one free retake in 12 months No CQI/IRCA scheme exists
BSI UK 42001 Lead Auditor GBP 2,585 ex-VAT (Implementer GBP 2,600; Conversion 3 days GBP 1,965) None published 4 days No Exemplar Global claim on the UK page
BSI US 42001 Lead Auditor (TPECS) USD 2,730 (USD 2,630 early bird) None published 4 days Exemplar Global, units AI, AU, TL
TÜV SÜD 42001 Lead Auditor USD 2,950 net (Implementer 4 days, USD 2,350 net) None published 5 days, virtual classroom Exemplar Global
TÜV Rheinland ISO 42001 Auditor (TÜV) From EUR 4,440 net ISO 42001 Professional (3 days, EUR 2,555 net) is mandatory 5 days plus exam PersCert TÜV under ISO/IEC 17024
ISACA AAIA USD 459 member / USD 599 non-member, plus USD 50 application fee Active CISA, or CIA/CPA in IT-audit or advisory role Exam via PSI Not stated
ISACA AAISM USD 459 / USD 599, plus USD 50 Active CISM or CISSP 90 questions, three domains Not stated
ISACA AAIR USD 459 / USD 599, plus USD 50 One of roughly 25 designations 90 questions; 10 AI CPE hours a year Not stated
CertNexus CAIP (AIP-210) USD 367.50 voucher None 80 items, 120 minutes ANAB under ISO/IEC 17024
CertNexus CEET (CET-110) USD 367.50 None 80 items, 120 minutes No ANAB/17024 claim
BCS AI certificates Essentials GBP 125.00 ex-VAT; Foundation GBP 165.00; each Pathway award GBP 75.00; remote proctoring adds GBP 35 None Modular; 4 awards make a Foundation Certificate, 8 a Diploma Not applicable
GARP Risk and AI (RAI) USD 625 FRM/SCR/ERP holders, USD 650 members, USD 750 non-members (October 2026) None Certificate programme Not applicable
CompTIA SecAI+ (CY0-001) Not published on the vendor page None published 19% AI governance, risk and compliance 17024 applied for, pending
EC-Council CRAGE No voucher price; USD 100 non-refundable application fee Not published Still "Beta" as of 4 September 2026 Not stated
BABL AI Business Professionals USD 899; Legal USD 1,199; AI and Algorithm Auditor USD 2,999; EU AI Act QMS USD 2,399 None Online Vendor credential
IEEE CertifAIEd USD 499 for IEEE members, certification plus exam None Course plus exam Vendor credential

Two caveats. The CertNexus AIP-210 product page returned a server error on 10 September 2026, and the USD 367.50 comes from CertNexus's own store cross-sell block. And there is no "CertNexus CAIEP" - the ethics credential is CEET, launched October 2020. Note the irony that CAIP claims ISO 17024 and the ethics credential does not.

True total cost, not sticker price

Two routes cost far more than their headline. AIGP certification: the exam is USD 649 for members, membership is USD 295, official training USD 1,195 and the practice exam USD 60, so a fully-equipped first attempt is USD 2,199, not USD 649. The term is two years; maintenance needs 20 continuing education credits plus a fee, covered by membership for members, while for non-members the initial maintenance fee is bundled into the exam fee and USD 250 falls due at recertification. Most third-party "AIGP cost" articles get this wrong. TÜV Rheinland: EUR 4,440 net plus the mandatory EUR 2,555 net Professional prerequisite, so roughly EUR 7,000 net.

University programmes sit in the same band: Oxford Saïd's AI Ethics, Regulation and Compliance Programme GBP 1,750 over 5 weeks; LSE's AI Law, Policy and Governance GBP 2,420 over 6 weeks; Cambridge Advance Online's Responsible AI for Leaders EUR 2,500 for the October 2026 cohort, rising to EUR 2,685 for 2027; MIT Professional Education's Ethics and Risks of AI USD 4,200 for 4 days on campus, though that page now shows "Course is closed"; York University's Certificate in AI Governance CAD 3,650 for 36 contact hours, no exams. ForHumanity courses are free with exam fees largely unpublished - all 14 exam products are password-protected and the only stated fee is USD 200 for the AEDT exam. Responsible AI Institute's "RAISE Pathways" is no longer an individual credential; the URL now redirects to a rebranded organisational assurance offering with no published price.

The accreditation question nobody asks about AI compliance certification

The finding most buyers will not expect: the AIGP is not ANAB/ISO 17024 accredited. IAPP's own accreditation page names CIPM, CIPP/E, CIPP/US and CIPT as ANAB-recognised under ISO 17024:2012. AIGP is absent. On that dimension, the best-known AI governance certification in the market sits behind a USD 367.50 CertNexus exam.

That does not make it bad. Body of Knowledge v2.1 was approved on 9 September 2025, effective 2 February 2026, superseding v2.0.1 (BoK), and the blueprint publishes question ranges: Domain I foundations 16-20; Domain II laws, standards and frameworks 19-23; Domain III governing AI development 21-25; Domain IV governing AI deployment and use 21-25. Domain II names the EU AI Act, the South Korean AI Basic Law, the OECD principles, the NIST AI RMF and Playbook, and "the core ISO AI standards (i.e., 22989, 42001 and 42005)". The BoK is reviewed annually and changes are communicated at least 90 days ahead. That is more transparency than most competitors offer.

Two figures you should not repeat. IAPP does not publish the number of AIGP holders; the only IAPP-sourced figure is CEO J. Trevor Hughes saying at the 5 March 2024 launch that "over 4,000 professionals have already signed up to complete the AIGP training curriculum" - training sign-ups, not certified holders (launch release). The circulating "~2,000" and "~4,000 certified" figures are not traceable to IAPP. Nor does IAPP publish pass rates, so the "45-55% first attempt" numbers are exam-prep vendor estimates with no methodology.

The 42001 picture is thinner. CQI/IRCA runs no ISO/IEC 42001 scheme; its schemes page lists 14, none for AI. The only live accreditation route for 42001 auditor training is Exemplar Global, where AI exists solely as a TPECS competency unit, not a standalone auditor certification. The one 42001 auditor route found examined under ISO 17024 is TÜV Rheinland's, via PersCert TÜV.

The requirement that is real sits at organisational level: ISO/IEC 42006:2025, "Requirements for bodies providing audit and certification of artificial intelligence management systems", adds more prescriptive competence requirements for personnel involved in certification activities at clauses 7.1 and 7.2, and is used as accreditation criteria by ANAB, UKAS, SCC and RvA (SCC bulletin).

Nobody can honestly tell you how many organisations hold 42001: ISO does not certify, 42001 is not yet in the ISO Survey, and IAF CertSearch requires login. What exists are company claims - BCG said in January 2026 it was "among the first 100 organisations certified globally", Doppel on 13 April 2026 "among the first 350 organisations globally" (ISO explainer).

The PECB title trap

If you take one operational warning from this piece, take this. PECB's ISO 42001 lead auditor title is experience-gated, not exam-gated. Passing the exam alone gets you "Provisional Auditor". Full Lead Auditor requires 5 years' professional experience, 2 of them in AI, plus 300 audit hours; Senior Lead Auditor requires 10 years, 7 in AI, plus 1,000 hours. The same ladder applies on the implementer side, where Lead Implementer needs 300 hours of AIMS project activity.

So a candidate can pay, sit, pass, and still not be entitled to put "ISO 42001 Lead Auditor" on a profile. Managers approving budgets should ask which rung the spend reaches. Note also the pricing spread: USD 99 self-paced against USD 1,000 for the same PECB credential, with BSI and TÜV variants three times higher again. A ten-fold spread for an identical certificate name means the market is pricing delivery and brand, not measured competence.

What employers actually ask for

The most directly relevant evidence is a recruiter-analysed dataset of 1,997 US AI governance postings since January 2026 (Axial Search). It is a postings dataset, not a survey, and should be read as such.

Signal Share of 1,997 US postings
NIST frameworks mentioned 27%
CISSP 11%
AIGP 9%
CISM 9%
Degree required 83%

Median salary is USD 169,000, median experience 5 years, and roughly 71 new US postings appear per week. The honest conclusion: employers overwhelmingly do not require a certification, and framework knowledge is asked for about three times more often than any specific credential. With a fixed budget and a fixed number of study evenings, spend them on the NIST AI RMF and the AI Act text before an exam voucher.

What the salary data does and does not show

IAPP's Salary and Jobs Report 2025-26 (1,600-plus professionals, 60-plus countries, fielded March to April 2025) reports that AIGP-certified professionals earn 26% more than those with no certification, that average base pay for AI governance legal and compliance professionals is USD 190,000, and regional medians of USD 190k in North America, USD 139k in Asia, USD 115k in Oceania and USD 112k in Europe. Combined privacy plus AI governance median pay is USD 169,700, against USD 123,000 for privacy alone and USD 151,800 for AI governance alone.

Two caveats, neither small. This is IAPP measuring the value of IAPP's own certification. And holders self-select for seniority, training budgets and ambition, so a 26% gap is at least as consistent with "senior people buy certificates" as with "certificates make you senior".

The independent numbers are more modest and more useful. Stanford HAI's 2026 AI Index (13 April 2026) found AI-specific governance roles grew 17% in 2025 and the share of businesses with no responsible AI policy fell from 24% to 11%, with knowledge gaps at 59% the top obstacle, ahead of budget 48% and regulatory uncertainty 41%. Lightcast reported that 2.5% of US job postings mention AI skills, up 55% year over year.

The sharpest supply-gap datapoint is the IAPP and Credo AI AI Governance Profession Report 2025 (671 respondents, 45 countries): only 1.5% of organisations, 10 of 671, say they will not need additional AI governance staff in the next 12 months. They expect to task an average of 9.8 people with it, yet only 8% were actively recruiting and 23.5% named finding qualified AI professionals a significant challenge. In the same study 77% are working on AI governance, above 85% among AI users and 30% among non-users, and half of practitioners sit in ethics, compliance, privacy or legal teams.

Demand is real, then, but it is being met by redeploying existing staff rather than hiring certified specialists. ISACA's May 2026 research across 3,400-plus digital trust professionals agrees: only 38% have a formal comprehensive AI policy, up from 28% in 2025, 25% have none, and 36% expect to increase AI-related jobs in the next 12 months. One caution on numbers you will see quoted: LinkedIn publishes no per-skill growth percentages, so "AI governance +150%" traces only to a vendor whitepaper, and there is no AI Governance Profession Report 2026.

The ISACA question: three credentials in under two years

ISACA AAIA (Advanced in AI Audit) launched in May 2025, gated behind an active CISA or a CIA/CPA in an IT-audit or advisory role. AAISM (AI Security Management) followed on 19 August 2025, gated behind CISM or CISSP, weighted AI Governance and Program Management 31%, AI Risk Management 31%, AI Technologies and Controls 38%. AAIR (AI Risk) arrived on 15 April 2026, weighted AI Risk Governance and Framework Integration 37%, AI Life Cycle Risk Management 21%, AI Risk Program Management 42%.

All three are add-ons for people already inside that ecosystem, not entry points: without a CISA, CISM, CRISC, CGEIT, CDPSE, CISSP, CIA, PMI-RMP or an accountancy qualification they are unavailable to you. And three overlapping AI credentials in under two years is a statement about market conditions, not the discovery of three distinct bodies of knowledge. ISACA publishes holder counts for none of them.

What is coming

The most forward-looking development is not a certification. CEN-CENELEC's EN 18274, "Competence requirements for professional AI ethicists", passed Final Vote with 100% approval and no comments and is expected to publish before end-2026 (AI Standards Hub). It is the first European standard defining competence for an AI governance role, designed to be compatible with existing certification infrastructure across member states. Be precise about what it is not: voluntary, not harmonised, not OJ-cited, conferring no legal presumption. It is still the closest thing to an EU-recognised definition of AI governance competence, so expect it to be marketed as an EU-recognised credential within weeks of publication.

On the systems side, EN 18286 - quality management, supporting Article 17 - was made available in July 2026 as the first AI Act-specific European standard. prEN 18228 on risk management was at Public Enquiry until end July 2026; prEN 18283 on bias is still in development. No JTC 21 deliverable has been cited in the Official Journal, so none confers presumption of conformity today. Timelines moved too: the Digital Omnibus deferred high-risk obligations to 2 December 2027 for Annex III stand-alone systems and 2 August 2028 for Annex I embedded systems, while 2 August 2026 remains live for Article 50 transparency and Chapter III Section 5 (Gibson Dunn).

Finally, NIST certifies nobody against the AI RMF. Its FAQ says: "Will private or public sector organizations be required to use the Framework? No. NIST has produced the AI RMF as a voluntary Framework." So any "NIST AI RMF certified" credential is a vendor credential in government-sounding clothes. The framework is also moving: NIST states "The AI RMF 1.0 is being revised as part of the White House AI Action Plan", and released a concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure on 7 April 2026 (NIST). Ask any 2026 AI RMF course which version it teaches before you pay.

So should you buy an AI governance certification?

Privacy professional pivoting. AIGP is the most defensible purchase, not because it is accredited (it is not) but because its Body of Knowledge is published, versioned and mapped to the law and standards you will be questioned on, and because half of this work already sits in privacy, legal, compliance and ethics teams. Budget the true USD 2,199.

Internal auditor. AAIA is the natural add-on if you already hold a CISA: cheap relative to everything else here, and it slots into a CPE regime you already run. If you hold no qualifying designation the route is closed, and buying a CISA to unlock it is not worth it.

Security leader. AAISM sits on top of CISM or CISSP for the same money. Watch CompTIA SecAI+ rather than buying while its 17024 accreditation is pending and no price is published.

Someone who will actually audit an AIMS. Here paying more is rational. If you need something a national accreditation body's assessor will respect, TÜV Rheinland's PersCert route is the only 42001 auditor path found examined under ISO 17024, at roughly EUR 7,000 net all-in. If Exemplar Global recognition suffices, BSI US and TÜV SÜD are credible. If you go PECB, go in knowing you are a Provisional Auditor until the gates are met.

Everyone else: buy nothing. Read Articles 4, 14, 26, 31, 40, 42 and 50, read ISO/IEC 42001 and 42005, read the NIST AI RMF, and build one real artefact - an AI inventory, a risk assessment for a live system, or an internal literacy record you could hand to a market surveillance authority. That evidence trail is what the Commission asked for and what an assessor will want to see, and it costs the price of the standards. Frameworks appear in 27% of postings; the leading credential in 11%.

The market will keep telling you otherwise: three ISACA credentials in two years, an EC-Council suite in beta with no published price, and a European competence standard that will be sold as a licence. Buy deliberately, budget the real total, check every accreditation claim against the certifier's own page, and remember the sentence the Commission wrote down. There is no need for a certificate.