Good AI governance is a capability people carry, not a document they file away. At the AI Governance Certification Institute (AIGCI), everything we teach follows one methodology built on that belief. This page explains it plainly: the principles behind it, the disciplines it covers, the standards it aligns to, and how it becomes a path you can actually follow.
We built the methodology because organizations kept meeting the same wall. Regulators, procurement teams, and audit committees now expect documented AI oversight, yet the people involved often define AI governance six different ways. Our approach gives governance, risk, compliance, audit, and technology professionals a shared language and a practical route from principle to evidence.
What the AIGCI methodology is
Our methodology, which we call the Practice-First approach, is the structured way AIGCI turns AI governance from an abstract goal into professional capability. It rests on four principles, is organized around the five disciplines of AI governance, aligns to the international standards that define the field, and is delivered through role-based certification pathways. Plan-Do-Check-Act runs through all of it, so capability keeps improving rather than ageing.
Two connected assets make the methodology concrete. It is grounded in the body of knowledge behind it, which codifies what a competent AI governance professional should understand, and it drives the learning path it drives, which sequences that knowledge into a route you can take one step at a time.
Four principles shape how we teach
Every course decision traces back to four principles. They are what keep the methodology consistent from Foundation through the professional levels.
-
Practice-first. We teach capability that works in real governance, risk, and audit situations, not theory for its own sake. The test of a course is whether a professional can carry a responsibility afterwards.
-
Responsibility-based. We organize learning around the responsibility you actually hold, rather than generic awareness. An implementer, an auditor, and a board sponsor need different depth, so the path differs by role.
-
Standards-aligned. ISO/IEC 42001 sits at the core, aligned to the NIST AI Risk Management Framework, ISO/IEC 23894, the EU AI Act, and the OECD AI Principles, so what you learn matches what regulators and auditors expect.
-
Shared language. Teams should not define AI governance six different ways. The methodology gives every function a common vocabulary, which is often the first thing an organization is missing.
The Five Disciplines of AI Governance
AI governance is not a single role or team. Our methodology treats it as five connected disciplines, and every professional needs a working grasp of all five before going deep in their own area.
|
Discipline |
What it covers |
|---|---|
|
AI Governance |
Oversight structures, board-level accountability, and decision-making processes for AI systems |
|
Risk Management |
Identifying, assessing, treating, and monitoring AI-specific risks such as bias, security, and third-party models |
|
Compliance |
Aligning with ISO/IEC 42001, the EU AI Act, the NIST AI RMF, and sector-specific regulation |
|
Audit and Assurance |
Testing whether controls and governance processes operate effectively, then documenting evidence and reporting findings |
|
Management Systems |
Applying Plan-Do-Check-Act for continual monitoring, review, and improvement of governance |
The disciplines run through every course. What changes by level is depth: Foundation builds shared understanding across all five, while the professional certifications go deep in the ones your role owns.
Delivered as role-based pathways
Because responsibility differs by role, the methodology delivers capability through pathways rather than one generic course. Each pathway develops the disciplines a role depends on most, and maps to a specific AIGCI certification.
|
If your responsibility is |
The focus |
Where it is developed |
|---|---|---|
|
New to AI governance |
Shared language and the fundamentals across all five disciplines |
Foundation certification |
|
Implementing an AIMS |
Management system design, controls, and risk treatment across the AI lifecycle |
Lead Implementer certification |
|
Auditing AI controls |
Audit planning, evidence evaluation against ISO/IEC 42001, and findings |
Lead Auditor certification |
|
Evaluating internal controls |
Internal review, objective evidence, and management reporting |
Internal Auditor certification |
This is the learning path in practice. Most professionals begin with the Foundation certification for shared language, then move into the Lead Implementer certification to build and run a management system, or into the Lead Auditor certification and Internal Auditor certification to evaluate one. Teams that need everyone aligned can work across the full range of ISO/IEC 42001 certification courses.
Aligned to the standards that define AI governance
The methodology is standards-aligned rather than opinion-led, which is what lets a certified professional speak the same language as a regulator, an auditor, and a board. Its backbone is ISO/IEC 42001, the international AI management system standard. Around that core it draws on the NIST AI Risk Management Framework, ISO/IEC 23894 for AI risk management guidance, the EU AI Act for regulatory obligations, and the OECD AI Principles for the values that underpin responsible AI. Teaching to these shared references keeps the methodology current as the rules evolve.
The AIGCI methodology at a glance
Put together, the methodology has four layers. Each answers a different question, and together they turn a belief about governance into a route a professional can follow.
|
Layer |
What it is |
Its purpose |
|---|---|---|
|
Principles |
Practice-first, responsibility-based, standards-aligned, shared language |
The beliefs that shape every course |
|
Disciplines |
The five disciplines of AI governance |
The knowledge every professional needs |
|
Pathways |
Role-based certification routes |
How capability is delivered by responsibility |
|
Improvement |
Plan-Do-Check-Act |
Keeps governance capability current |
This at-a-glance model is available as a one-page download, so teams can use it to plan who learns what and in which order.
Frequently asked questions
What is the AIGCI AI governance methodology?
It is the structured, practice-first approach the AI Governance Certification Institute uses to build AI governance capability. It combines four principles, the five disciplines of AI governance, role-based certification pathways, and a Plan-Do-Check-Act improvement loop, all aligned to ISO/IEC 42001 and the major AI governance frameworks.
Is the methodology the same as ISO 42001?
No. ISO/IEC 42001 is the international AI management system standard. Our methodology is how AIGCI teaches people to govern AI in line with that standard, translating it, along with the NIST AI RMF, the EU AI Act, and the OECD AI Principles, into capability a professional can carry.
What are the five disciplines of AI governance?
AI Governance, Risk Management, Compliance, Audit and Assurance, and Management Systems. The methodology treats AI governance as all five working together rather than as a single role, and every course builds understanding across them before going deep by role.
How do the body of knowledge and learning path fit in?
The body of knowledge codifies what a competent professional should understand, and the methodology is built on it. The learning path sequences that knowledge into a route, which the methodology drives so learners progress in a sensible order rather than in isolated pieces.
Which certification should I start with?
It depends on the responsibility you carry. Most people begin with Foundation for shared language, then move to Lead Implementer, Lead Auditor, or Internal Auditor. You can also tell us your role through the Institute and we will point you to the right starting point.
Does the methodology cover the EU AI Act?
Yes. Compliance is one of the five disciplines, and the methodology aligns to the EU AI Act alongside ISO/IEC 42001, so professionals learn how the standard supports the obligations the regulation introduces.
Where to go next
If this approach fits how your organization needs to work, there are three natural next steps. Learn more about the Institute behind the methodology, explore the full range of ISO/IEC 42001 certification courses, or follow the sequence set out in the learning path it drives. Wherever you begin, the methodology is designed to take you from a shared understanding to capability you can prove.