AGZIT-AIG
Intermediate · Artificial Intelligence

AGZIT Certified AI Governance Analyst

Awarded on completion of Free AI Governance Certificate

A free, globally recognised certificate in AI governance. Certifies that the holder can inventory the AI systems an organisation actually runs, classify each against the obligations that apply to it, and produce the evidence a supervisor or auditor asks for. Study free and sit the assessment free — you pay only for the ONRIGA-accredited certificate, and only once you have passed.

ONRIGA Accredited Globally Recognised Verifiable Certificate ★★★★★ 4.7 88 ratings

What you earn

On passing the final assessment you are awarded the AGZIT Certified AI Governance Analyst (AGZIT-AIG), issued with a credential ID anyone can check at app.agzit.com/verify.

Curriculum

  1. Study Material 1 module · 1 lesson, each with a downloadable ebook you keep
    • Section: Study Material AGZIT-AIG Study Guide
    Full syllabus, module by module
    Module 1 — What AI governance is 1.1 Why AI governance is not IT governance under a new name 1.2 Where the risk sits — the use, not the model 1.3 What your existing controls already cover, and what they miss 1.4 Who owns it: three lines of defence and the seat you are in Module 2 — The regulatory map 2.1 The EU AI Act: risk tiers, and which obligation lands on whom 2.2 What applies today and what does not — the timeline after the Digital Omnibus 2.3 General-purpose AI, and the duties that arrived with it 2.4 Beyond the EU — the US patchwork, the UK, and where else it reaches 2.5 Reading a new AI law — the four questions that tell you if it reaches you Module 3 — Frameworks 3.1 ISO/IEC 42001, and what certification against it actually assesses 3.2 NIST AI RMF: Govern, Map, Measure, Manage 3.3 What model risk management already solved, and what it did not 3.4 Choosing a framework matters less than the evidence it produces Module 4 — Inventory and classification 4.1 What counts as an AI system — the definition decides everything after it 4.2 Building an inventory that survives contact with the business 4.3 Classifying by use case, not by technology 4.4 Vendor and third-party AI: governing what you did not build 4.5 Shadow AI, and the systems your inventory does not know about Module 5 — Lifecycle controls 5.1 Data provenance, and the questions nobody can answer later 5.2 Testing for bias, and what a fairness metric does not tell you 5.3 Human oversight that is real rather than nominal 5.4 Monitoring, drift, and knowing when a system has changed underneath you 5.5 When it goes wrong: incidents, rollback and disclosure Module 6 — Assurance and evidence 6.1 What a supervisor or an auditor actually asks for 6.2 Technical documentation — writing it once, properly 6.3 Governance theatre: the controls that exist only on paper 6.4 The evidence pack, assembled
  2. Practice Assessment A rehearsal under the same clock — your result here does not affect your certificate.
    50 questions60 min70% to pass2 attempts
  3. Final Assessment Passing this awards the certificate.
    50 questions57 min70% to pass2 attempts

How the assessment works

Questions are drawn from a larger bank, so attempts differ.

No webcam or microphone is required, and there is no proctoring. Sit it online from anywhere, at any time — you need a stable connection and a laptop or desktop, which the timed navigation is built for.

Syllabus

Module 1 — What AI governance is
1.1 Why AI governance is not IT governance under a new name
1.2 Where the risk sits — the use, not the model
1.3 What your existing controls already cover, and what they miss
1.4 Who owns it: three lines of defence and the seat you are in
Module 2 — The regulatory map
2.1 The EU AI Act: risk tiers, and which obligation lands on whom
2.2 What applies today and what does not — the timeline after the Digital Omnibus
2.3 General-purpose AI, and the duties that arrived with it
2.4 Beyond the EU — the US patchwork, the UK, and where else it reaches
2.5 Reading a new AI law — the four questions that tell you if it reaches you
Module 3 — Frameworks
3.1 ISO/IEC 42001, and what certification against it actually assesses
3.2 NIST AI RMF: Govern, Map, Measure, Manage
3.3 What model risk management already solved, and what it did not
3.4 Choosing a framework matters less than the evidence it produces
Module 4 — Inventory and classification
4.1 What counts as an AI system — the definition decides everything after it
4.2 Building an inventory that survives contact with the business
4.3 Classifying by use case, not by technology
4.4 Vendor and third-party AI: governing what you did not build
4.5 Shadow AI, and the systems your inventory does not know about
Module 5 — Lifecycle controls
5.1 Data provenance, and the questions nobody can answer later
5.2 Testing for bias, and what a fairness metric does not tell you
5.3 Human oversight that is real rather than nominal
5.4 Monitoring, drift, and knowing when a system has changed underneath you
5.5 When it goes wrong: incidents, rollback and disclosure
Module 6 — Assurance and evidence
6.1 What a supervisor or an auditor actually asks for
6.2 Technical documentation — writing it once, properly
6.3 Governance theatre: the controls that exist only on paper
6.4 The evidence pack, assembled

What holders say

★★★★★ 4.7 from 88 ratings
★★★★★

I have sat several AI governance courses and this is the only one whose assessment I could not have passed without reading the material.

Cecilia L. Feb 2027
★★★★☆

Good depth and honest limits. Would recommend to anyone whose AI governance role arrived on top of an existing job.

Omar B. Feb 2027
★★★★★

The best treatment of monitoring I have seen. Watching whether the system works and whether it is right are genuinely different problems.

Julia P. Jan 2027
★★★★★

The guide made a claim I doubted — that most of the estate is bought rather than built — and then our own discovery proved it.

Stefan A. Jan 2027
★★★★☆

Very good. The tables are the most practical part and I have extracted three of them.

Wanjiru M. Jan 2027
★★★★★

Clear-headed about a subject that attracts a lot of noise. No hype, no scare stories, just what to do.

Gabriel T. Jan 2027
★★★★★

The point that governing by department misses everything the organisation bought is the observation that restructured our programme.

Nina S. Jan 2027
★★★★☆

Well built. My reservation is that the study time estimate is optimistic if you actually work the scenarios.

Rashid Q. Jan 2027
★★★★★

Serious material treated seriously. It assumes the reader can handle a complicated answer, which most training does not.

Emily R. Jan 2027
★★★★★

Finished it over a fortnight and immediately reread Module 6. The evidence pack list is what I am working from now.

Andrei B. Dec 2026
★★★★☆

Good. I would like a version aimed at the vendor side, since we supply AI rather than deploy it.

Zara M. Dec 2026
★★★★★

The advice to build to the strictest applicable requirement and map downward, rather than running a programme per jurisdiction, is exactly right and rarely said.

Peter K. Dec 2026
★★★★★

Our register was built from what people volunteered and this explained why that was never going to work. Rebuilt it from spend data instead.

Layla H. Dec 2026
★★★★☆

Solid throughout. The glossary is genuinely useful rather than padding.

Magnus O. Dec 2026
★★★★★

The example of the same model in two deployments is used throughout and never wears out. It is the right teaching device.

Adaora N. Dec 2026
★★★★★

I run an AI programme and this told me which parts of it were theatre. Uncomfortable and correct.

Chen H. Nov 2026
★★★★☆

Very good. The closing pages on what the credential does not cover are refreshingly specific.

Sinead F. Nov 2026
★★★★★

Comprehensive and well organised. The dependency between modules is real and reading out of order would not work.

Dmitri V. Nov 2026
★★★★★

The distinction between an indicator and a demographic in the fairness chapter applies far beyond AI. I have used it in three other contexts since.

Rosa M. Nov 2026
★★★★☆

Good and demanding. Module 4 is long and I understand why after finishing it.

Lars N. Nov 2026
★★★★★

Written for somebody who has to do the work, not somebody commissioning it. That difference shows on every page.

Amara D. Nov 2026
★★★★★

The detection interval point in the incident chapter is the finding we have taken away. Eleven months to notice and two days to fix is a monitoring failure.

Ben C. Nov 2026
★★★★☆

Strong. I would value more on procurement language, since that is where most of our AI arrives.

Johanna E. Oct 2026
★★★★★

Practical and unusually honest about the limits of what a certificate proves — including its own.

Tariq S. Oct 2026
★★★★★

I work in a regulated firm and the section on where model risk management stops was worth the entire course. We had assumed coverage we did not have.

Sanne V. Oct 2026
★★★★☆

Good material. The assessment format is on the course page rather than in the guide, which confused me briefly but is sensible.

Emeka U. Oct 2026
★★★★★

Excellent. The scenario where the review board approves everything is deliberately ambiguous and I appreciated being trusted with that.

Clara B. Oct 2026
★★★★★

The impossibility result on fairness metrics is stated in two paragraphs and settles an argument our team had been having for months.

Idris K. Oct 2026
★★★★☆

Well paced. I read a module an evening as suggested and that worked.

Yuki N. Oct 2026
★★★★★

The guide is clear that most of this work is discovery and record-keeping, and says so without apology. That honesty made me trust the rest of it.

Robert A. Sep 2026
★★★★★

I have recommended this to two colleagues in internal audit. The evidence framing translates directly into an audit programme.

Meera J. Sep 2026
★★★★☆

Thorough. Some of the lifecycle material is dry but it is where the actual work sits.

Stefan H. Sep 2026
★★★★★

Applied the discovery methods and found an AI feature enabled by default in a tool we have had for three years. Nobody knew.

Nkechi O. Sep 2026
★★★★★

The bit about a register that states its own coverage honestly being a foundation, while one that overstates it is a liability, is the most useful sentence in Module 4.

Julien P. Sep 2026
★★★★☆

Very good. The vendor chapter is realistic about what you will and will not get, which most guidance is not.

Elena K. Sep 2026
★★★★★

I expected a compliance course and got something closer to a way of thinking. The scenarios do most of that work.

Hassan A. Sep 2026
★★★★★

The four conditions for real human oversight are now written into our procedure. Three of our arrangements failed on practical ability.

Fiona C. Aug 2026
★★★★☆

Good throughout. The regulatory module will need updating and the guide is upfront that it will, which I respect.

Alexei M. Aug 2026
★★★★★

Rigorous without being dense. I finished it able to reason about cases rather than recite requirements.

Selin Y. Aug 2026
★★★★★

The observation that a pilot operating on real people is a deployment with an optimistic name has already stopped one of our projects proceeding as it was.

Patrick O. Aug 2026
★★★★☆

Clear and practical. The glossary cross-references to chapters saved me a great deal of flicking back.

Riya D. Aug 2026
★★★★★

I supervise firms rather than work in one, and this describes what we actually look for more accurately than most compliance training does.

Gustav L. Aug 2026
★★★★★

The point about building the substance before the form, because artefacts survive a change of statute and templates do not, is advice I wish I had had two years ago.

Nour F. Aug 2026
★★★★☆

Well made and demanding. The difficult questions in the assessment are genuinely difficult.

Mateo G. Jul 2026
★★★★★

Honest about uncertainty. Where something is contested the guide says so rather than picking a side and presenting it as settled.

Astrid H. Jul 2026
★★★★★

The inventory chapter alone justified the time. Everything downstream depends on it and almost nobody says so this plainly.

Diego C. Jul 2026
★★★★☆

Good. I would like more on how to size a programme against available resource, which the guide touches on but does not develop.

Ling W. Jul 2026
★★★★★

The scenario about the certificate that answered a different question is one I have watched happen. Painful and accurate.

Sean M. Jul 2026
★★★★★

Passed on the first attempt after two weeks of evening reading. The assessment tests whether you understood rather than whether you memorised.

Bianca R. Jul 2026
★★★★☆

Very good. The material on codes of practice is brief but it clears up a genuine confusion about whether signing up counts as compliance.

Karim Z. Jun 2026
★★★★★

I have read four books on AI governance this year and this is the only one that told me what to do on Monday.

Ruth E. Jun 2026
★★★★★

The best explanation of the provider and deployer distinction I have found, including the part about how a deployer becomes a provider without meaning to.

Oscar V. Jun 2026
★★★★☆

Genuinely useful. The chapter on when it goes wrong made me realise our logging cannot identify which model version produced which output.

Hana T. Jun 2026
★★★★★

I deploy AI in a small firm with no compliance function and expected this to be written for banks. It is not. The sequencing advice works at any size.

Felix W. Jun 2026
★★★★★

The distinction between a model and a system runs through everything and is stated once, early, and then relied on. Good writing.

Ananya M. Jun 2026
★★★★☆

Well structured. Module 6 assumes all five before it and the guide says so, which I ignored and regretted.

Thomas B. Jun 2026
★★★★★

Our audit function now uses the theatre tests as a standard programme. The one about asking three practitioners what the policy requires found more than a week of document review.

Marta S. May 2026
★★★★★

The four questions for reading a new AI law are the most durable thing here. I have used them twice on legislation published after I finished the course.

Piotr K. May 2026
★★★★☆

Strong material. I would have liked a worked example of a complete technical documentation file rather than a description of one.

Aisha B. May 2026
★★★★★

Clear, rigorous and free of padding. Nothing is repeated to reach a page count and several chapters are shorter than I expected.

Samuel H. May 2026
★★★★★

The observation that the framework debate persists because it is tractable, while the inventory is a year of unglamorous work, is the truest sentence in the guide.

Emilia D. May 2026
★★★★☆

Good depth. The tables are the parts I return to — particularly the one on where existing controls stop.

Kofi A. May 2026
★★★★★

I am moving into this field from privacy and the guide assumes exactly the right amount. No prior AI knowledge and no hand-holding.

Grace M. May 2026
★★★★★

The governance theatre chapter is the one I did not expect and got most from. Asking what a control has ever stopped has already changed two of ours.

Viktor L. Apr 2026
★★★★☆

Very good, though the assessment is harder than the study time suggests. Work the scenarios properly.

Freya N. Apr 2026
★★★★★

Written by somebody who has clearly done this work rather than read about it. The failure modes are the ones that actually happen.

Ahmed R. Apr 2026
★★★★★

The scenario about the reclassification nobody triggered described our situation almost exactly. We found three systems whose use had drifted and whose entries were untouched.

Isabella G. Apr 2026
★★★★☆

Solid. The provenance chapter is bleak reading if you have legacy models, which I do, but it is accurate.

Jonas P. Apr 2026
★★★★★

Module 4 is long and every page of it earns its place. Our register went from 19 systems to 61 after applying the discovery methods.

Chioma E. Apr 2026
★★★★★

I have implemented both NIST and ISO and this is the first source that says plainly the choice matters less than the evidence. Correct, and unpopular with framework vendors.

Erik B. Apr 2026
★★★★☆

Well written and honest. The material on upstream change versus drift saved us a wasted retraining cycle two months later.

Nadia S. Mar 2026
★★★★★

Excellent. The seven questions an examiner asks are worth the course on their own, and the note about which weak answer contaminates the rest is the useful part.

Lucas F. Mar 2026
★★★★★

The point that an assessment after go-live always answers yes is one of those observations that is obvious once stated and had never occurred to me.

Zeynep A. Mar 2026
★★★★☆

Comprehensive. I would value a follow-up on programme design, which this deliberately stops short of.

Adam W. Mar 2026
★★★★★

I work in procurement and the vendor chapter changed our questionnaire. We were asking about the supplier and not about what the model does to our population.

Mei-Ling C. Mar 2026
★★★★★

The shadow AI chapter is the only treatment I have seen that does not moralise. It says plainly that prohibition moves the problem somewhere worse.

Owen T. Mar 2026
★★★★☆

Good material and well paced. My only note is that Module 2 assumes more comfort with legal instruments than it claims to.

Devika N. Feb 2026
★★★★★

Honest about what it does not cover, which is rarer than it should be. It repeatedly tells you when a question is legal rather than analytical.

Henrik J. Feb 2026
★★★★★

Used this to brief our board. The framing that a control leaving no record cannot be shown to have operated landed better than any maturity model I have presented.

Yasmin K. Feb 2026
★★★★☆

Clear and demanding. The scenarios are harder than the length suggests and I got two wrong on first reading.

Daniel O. Feb 2026
★★★★★

The fairness metrics chapter finally explained why our vendor's bias report and our own testing disagreed. They were measuring different things and neither said so.

Sofia L. Feb 2026
★★★★★

I came from model risk management and assumed most of this was covered. The table showing exactly where MRM stops was uncomfortable and entirely fair.

Rahul B. Feb 2026
★★★★☆

Very good. The regulatory chapter is deliberately built to age in one place, which I appreciated once I understood why.

Ingrid M. Feb 2026
★★★★★

Module 5 on human oversight is the best thing I have read on the subject. The four numbers in the scenario — reviews, overrides, seconds per case, and who checks an override — are now our standard diagnostic.

Callum S. Jan 2026
★★★★★

The distinction between what an ISO certificate attests and what people assume it attests should be printed and pinned above every compliance desk.

Leila H. Jan 2026
★★★★☆

Strong throughout. I would have liked more on agentic systems, though the guide is honest that the frameworks do not cover them either.

Tobias R. Jan 2026
★★★★★

I run a second-line function and Module 4 told me why our inventory kept decaying. Nothing was attached to a process that recurs. Obvious in hindsight and nobody had said it.

Anneke V. Jan 2026
★★★★★

The chapter on why the risk attaches to the use rather than the technology reframed our whole programme. We had been governing by model type and missing everything the business had bought.

Marcus D. Jan 2026

Questions

Is this an AI certification?
It is an AI governance certificate, which is a different thing from a technical AI certificate. It is for the people who have to govern AI systems — compliance, risk, audit, privacy and the analysts who inherit an AI use case and are asked whether it is allowed.
It does not teach you to build, train or evaluate models, and it does not cover prompt engineering or security testing of AI systems. If you want to learn to build with AI, this is not that course, and it says so rather than blurring the line to widen its audience.
Is it really free?
The course, the study guide and both assessments are free. There is no trial, no time limit and nothing withheld — you can read all six modules and sit the final assessment without paying anything.
The certificate is paid, at US$79, shown in your local currency at checkout. You only reach that decision after you have passed, so you are never asked to pay for something you have not yet earned. If you never buy it, you keep the material and your result; you simply do not hold the certificate.
What happens the moment I pass?
You immediately receive a sample certificate — watermarked, with no visible certificate ID, and a QR code that reports honestly that no certificate has been issued. Your score, your pass date and your certificate ID are all fixed at that moment.
Paying converts the sample into your issued certificate. The watermark comes off, the ID becomes visible, and the verification page confirms it to anyone who checks. Payment reveals the certificate you already earned; it does not mint a new one, and the date on it is the date you passed, not the date you paid.
Do I need experience in compliance or in AI to take this?
No. The course assumes no legal training, no data science background and no prior exposure to AI governance. It starts from what an AI system is and why the existing control set does not reach it.
It is demanding for a foundation-level subject, because the questions test whether you can apply an obligation to a situation rather than recite it. But nothing in it requires a qualification you do not already have.
What is in the assessment?
Fifty questions in 60 minutes, at a 70 percent pass mark, with two attempts. Questions are drawn from a larger bank, so your two attempts differ. There is a separate practice assessment with its own pool and its own two attempts, and nothing in it counts towards your result.
The questions are scenario-based. You will not be asked what an article says; you will be given a system, a use and a jurisdiction, and asked which obligations reach it and what you would need to evidence.
Is it proctored? Do I need a webcam?
No. There is no proctoring, no webcam and no microphone requirement. You sit it in your browser, from anywhere, whenever you choose. You need a stable connection and a laptop or desktop, which the timed navigation is built for.
The certificate carries the name currently on your AGZIT profile, captured at the moment you pass. Check that before you sit it — correcting your profile afterwards does not reissue the certificate.
This field changes constantly. How current is the material?
The guide states the date on which its regulatory position was verified, and every regulatory claim in it is tied to that date rather than left floating. That matters more here than in most subjects: obligation dates have moved and a national statute has been repealed and rewritten in the time this credential was being built.
Holders receive updated editions as the position changes, for as long as the certificate is valid. One module is devoted to reading a law you have never seen before and working out whether it reaches you, because that skill outlasts any particular statute.
How long is the certificate valid, and what happens then?
Two years from the date of issue. Renewal is US$20 and issues a fresh two-year term running from the day you renew, together with the current edition of the guide. You are reminded 30, 15 and 7 days before expiry, and once after.
The term is not an administrative formality. A 2026 statement about AI obligations will be substantially wrong by 2028, and a certificate that never expired would be asserting currency it does not have.
Who accredits this, and what does that mean?
ONRIGA — the Organization for Next-gen Regulatory Intelligence and Global Accreditation — at Gold tier. It is an independent body that assesses training programmes against current regulatory benchmarks.
Gold requires the material to be maintained against changing regulation, the assessment to distinguish candidates who understood the subject from those who memorised it, and the issuer's claims about its own certificate to be accurate. A certificate that accredits itself is a claim; one assessed independently is a certificate that means something.
What will I be able to do afterwards?
Build an inventory of the AI systems an organisation actually runs, including the ones nobody registered. Classify each by use rather than by technology, and work out which obligations reach it. Ask a vendor the questions that reveal whether their system is governable. And assemble the evidence pack a supervisor or auditor asks for, rather than the policy document that looks like governance and proves nothing.
It is a foundation certificate. It does not cover drafting an enterprise AI policy from scratch, board reporting, or the technical assurance work of testing a model yourself — and it says so plainly rather than overstating its reach.
Set Your Currency
Scroll to Top