The OECD AI Principles, adopted in 2019, were the first intergovernmental standard on AI, and today they sit alongside newer references such as ISO/IEC 42001 and the EU AI Act. Governing AI well means drawing on several of them at once, which is why the subject is so easy to pick up in fragments: a little risk here, a policy template there, a regulation you half-remember. A body of knowledge answers that by mapping the whole field. At the AI Governance Certification Institute (AIGCI), the AI Governance Body of Knowledge is the structured map of everything a competent professional should understand, and it is the foundation our courses are built on.
The body of knowledge does one core job: it structures the AI governance discipline into clear domains, so nothing important is missed and every topic has a place. It is organized in layers, grounded in the ISO 42001 standard at its core, and aligned to the other frameworks that define responsible AI. This page walks through what it contains and how it fits together.
What a body of knowledge is, and why it matters
A body of knowledge is an agreed, structured account of what a field consists of. For AI governance, that means the concepts, processes, controls, and standards a professional needs to understand to govern AI responsibly. It is not a reading list and not a single course. It is the map that tells you what the territory contains and how the parts relate.
The value is completeness and shared language. When a governance lead, a risk manager, and an auditor all draw on the same body of knowledge, they stop defining AI governance in different ways and start working from one picture. That shared picture is usually the first thing an organization is missing, and it is what makes capability transferable from one person or team to the next.
How the body of knowledge is organized
The body of knowledge is arranged as a foundations layer plus five discipline domains. The foundations give everyone the shared language and context, and the five disciplines cover the whole AI governance ecosystem that a professional works across. You do not need equal depth in all six, but you do need to know where your work sits in the whole.
The six domains below are the top level of the map. Each one contains knowledge areas, and each area maps to the standards and to a capability you can demonstrate.
Six domains structure the body of knowledge
|
Domain |
What it covers |
What you can then do |
|---|---|---|
|
Foundations |
AI systems and the AI lifecycle, responsible AI principles, the AI governance ecosystem, and the standards landscape |
Speak the shared language and place any topic in context |
|
AI Governance |
Oversight structures, board-level accountability, roles and responsibilities, AI policy, and decision and escalation paths |
Set up who decides what, and how AI is governed |
|
Risk Management |
Identifying, assessing, and treating AI risks such as bias, security, safety, and third-party models, plus impact assessment and monitoring |
Identify and treat AI risks across the lifecycle |
|
Compliance |
ISO/IEC 42001 requirements, Annex A controls, EU AI Act obligations, sector regulation, and mapping evidence to each |
Show alignment to standards and regulation with evidence |
|
Audit and Assurance |
Internal audit, evidence and conformity evaluation, findings and corrective action, and the certification audit |
Evaluate whether governance actually works |
|
Management Systems |
The AIMS structure, Plan-Do-Check-Act, documented information, management review, and integration with ISO 27001 |
Run and continually improve the management system |
Read top to bottom, the domains move from understanding to action: you learn the language, decide how AI is governed, manage the risks, prove compliance, test that it works, and keep improving. That progression is deliberate, and it is what a professional grows through over time.
Grounded in ISO 42001 and aligned to the major frameworks
The body of knowledge is not one organization's opinion. Its backbone is ISO/IEC 42001, the international AI management system standard, which supplies the management-system structure and the Annex A controls. Around that core it aligns to the NIST AI Risk Management Framework for risk, ISO/IEC 23894 for AI risk management guidance, the EU AI Act for regulatory obligations, and the OECD AI Principles for the values beneath responsible AI. Mapping the knowledge to these shared references is what keeps it current and credible as the field evolves.
From knowledge to capability: the learning path
A map is useful, but you still need a route. The body of knowledge defines what to know; our learning path sequences it into a sensible order, so you build understanding step by step rather than in isolated pieces. The two work together: the body of knowledge is the territory, and the learning path is the way through it, from foundational language to the depth your role requires.
The body of knowledge at a glance
Put together, the map has one foundations layer and five discipline domains, each grounded in ISO 42001 and aligned to the major frameworks. The one-page summary below is available as a download, so teams can use it to see what they already cover and where the gaps are.
|
Layer or domain |
Its role in the map |
Anchored to |
|---|---|---|
|
Foundations |
Shared language and context for everything else |
Responsible AI principles, the standards landscape |
|
AI Governance |
Who is accountable and how AI is governed |
ISO 42001 leadership, AI policy |
|
Risk Management |
How AI risks are found and treated |
ISO 23894, NIST AI RMF |
|
Compliance |
How alignment is shown with evidence |
ISO 42001, EU AI Act |
|
Audit and Assurance |
How you test that governance works |
ISO 42001 performance evaluation |
|
Management Systems |
How the whole system keeps improving |
ISO 42001 clauses, PDCA |
Frequently asked questions
What is the AI Governance Body of Knowledge?
It is a structured map of everything a competent AI governance professional should understand, organized into a foundations layer and five discipline domains. It structures the discipline so nothing important is missed, and it is the basis the AIGCI courses are built on.
Is the body of knowledge the same as ISO 42001?
No. ISO/IEC 42001 is the international AI management system standard and sits at the core of the body of knowledge, but the body of knowledge is broader. It also covers foundations, risk, compliance, audit, and the wider framework landscape, organizing them into one coherent map.
What are the domains of the body of knowledge?
A foundations layer plus five disciplines: AI Governance, Risk Management, Compliance, Audit and Assurance, and Management Systems. Foundations give shared language and context, and the five disciplines cover the areas a professional works across.
How is the body of knowledge different from the learning path?
The body of knowledge defines what to know; the learning path sequences it into a route you can follow. The map shows the territory, and the path shows the way through it, from foundational language to role-specific depth.
Who is the body of knowledge for?
Anyone building AI governance capability, whether new to the field or moving in from governance, risk, compliance, security, or audit. It gives every function one shared picture, which makes capability easier to build and to transfer across a team.
Where to start
The body of knowledge is the map; the fastest way to start covering it is through structured learning. Most professionals begin with the ISO 42001 Foundation certification, which builds the foundations and shared language, then move deeper through the Lead Implementer certification or the wider range of ISO/IEC 42001 certification courses as their role requires. Wherever you begin, the body of knowledge keeps every step connected to the same complete picture.