I have sat several AI governance courses and this is the only one whose assessment I could not have passed without reading the material.
AGZIT Certified AI Governance Analyst
Awarded on completion of Free AI Governance Certificate
A free, globally recognised certificate in AI governance. Certifies that the holder can inventory the AI systems an organisation actually runs, classify each against the obligations that apply to it, and produce the evidence a supervisor or auditor asks for. Study free and sit the assessment free — you pay only for the ONRIGA-accredited certificate, and only once you have passed.
What you earn
On passing the final assessment you are awarded the AGZIT Certified AI Governance Analyst (AGZIT-AIG), issued with a credential ID anyone can check at app.agzit.com/verify.
Curriculum
-
Study Material 1 module · 1 lesson, each with a downloadable ebook you keep
- Section: Study Material AGZIT-AIG Study Guide
Full syllabus, module by module
Module 1 — What AI governance is 1.1 Why AI governance is not IT governance under a new name 1.2 Where the risk sits — the use, not the model 1.3 What your existing controls already cover, and what they miss 1.4 Who owns it: three lines of defence and the seat you are in Module 2 — The regulatory map 2.1 The EU AI Act: risk tiers, and which obligation lands on whom 2.2 What applies today and what does not — the timeline after the Digital Omnibus 2.3 General-purpose AI, and the duties that arrived with it 2.4 Beyond the EU — the US patchwork, the UK, and where else it reaches 2.5 Reading a new AI law — the four questions that tell you if it reaches you Module 3 — Frameworks 3.1 ISO/IEC 42001, and what certification against it actually assesses 3.2 NIST AI RMF: Govern, Map, Measure, Manage 3.3 What model risk management already solved, and what it did not 3.4 Choosing a framework matters less than the evidence it produces Module 4 — Inventory and classification 4.1 What counts as an AI system — the definition decides everything after it 4.2 Building an inventory that survives contact with the business 4.3 Classifying by use case, not by technology 4.4 Vendor and third-party AI: governing what you did not build 4.5 Shadow AI, and the systems your inventory does not know about Module 5 — Lifecycle controls 5.1 Data provenance, and the questions nobody can answer later 5.2 Testing for bias, and what a fairness metric does not tell you 5.3 Human oversight that is real rather than nominal 5.4 Monitoring, drift, and knowing when a system has changed underneath you 5.5 When it goes wrong: incidents, rollback and disclosure Module 6 — Assurance and evidence 6.1 What a supervisor or an auditor actually asks for 6.2 Technical documentation — writing it once, properly 6.3 Governance theatre: the controls that exist only on paper 6.4 The evidence pack, assembled -
Practice Assessment A rehearsal under the same clock — your result here does not affect your certificate.50 questions60 min70% to pass2 attempts
-
Final Assessment Passing this awards the certificate.50 questions57 min70% to pass2 attempts
How the assessment works
Questions are drawn from a larger bank, so attempts differ.
No webcam or microphone is required, and there is no proctoring. Sit it online from anywhere, at any time — you need a stable connection and a laptop or desktop, which the timed navigation is built for.
Syllabus
What holders say
Good depth and honest limits. Would recommend to anyone whose AI governance role arrived on top of an existing job.
The best treatment of monitoring I have seen. Watching whether the system works and whether it is right are genuinely different problems.
The guide made a claim I doubted — that most of the estate is bought rather than built — and then our own discovery proved it.
Very good. The tables are the most practical part and I have extracted three of them.
Clear-headed about a subject that attracts a lot of noise. No hype, no scare stories, just what to do.
The point that governing by department misses everything the organisation bought is the observation that restructured our programme.
Well built. My reservation is that the study time estimate is optimistic if you actually work the scenarios.
Serious material treated seriously. It assumes the reader can handle a complicated answer, which most training does not.
Finished it over a fortnight and immediately reread Module 6. The evidence pack list is what I am working from now.
Good. I would like a version aimed at the vendor side, since we supply AI rather than deploy it.
The advice to build to the strictest applicable requirement and map downward, rather than running a programme per jurisdiction, is exactly right and rarely said.
Our register was built from what people volunteered and this explained why that was never going to work. Rebuilt it from spend data instead.
Solid throughout. The glossary is genuinely useful rather than padding.
The example of the same model in two deployments is used throughout and never wears out. It is the right teaching device.
I run an AI programme and this told me which parts of it were theatre. Uncomfortable and correct.
Very good. The closing pages on what the credential does not cover are refreshingly specific.
Comprehensive and well organised. The dependency between modules is real and reading out of order would not work.
The distinction between an indicator and a demographic in the fairness chapter applies far beyond AI. I have used it in three other contexts since.
Good and demanding. Module 4 is long and I understand why after finishing it.
Written for somebody who has to do the work, not somebody commissioning it. That difference shows on every page.
The detection interval point in the incident chapter is the finding we have taken away. Eleven months to notice and two days to fix is a monitoring failure.
Strong. I would value more on procurement language, since that is where most of our AI arrives.
Practical and unusually honest about the limits of what a certificate proves — including its own.
I work in a regulated firm and the section on where model risk management stops was worth the entire course. We had assumed coverage we did not have.
Good material. The assessment format is on the course page rather than in the guide, which confused me briefly but is sensible.
Excellent. The scenario where the review board approves everything is deliberately ambiguous and I appreciated being trusted with that.
The impossibility result on fairness metrics is stated in two paragraphs and settles an argument our team had been having for months.
Well paced. I read a module an evening as suggested and that worked.
The guide is clear that most of this work is discovery and record-keeping, and says so without apology. That honesty made me trust the rest of it.
I have recommended this to two colleagues in internal audit. The evidence framing translates directly into an audit programme.
Thorough. Some of the lifecycle material is dry but it is where the actual work sits.
Applied the discovery methods and found an AI feature enabled by default in a tool we have had for three years. Nobody knew.
The bit about a register that states its own coverage honestly being a foundation, while one that overstates it is a liability, is the most useful sentence in Module 4.
Very good. The vendor chapter is realistic about what you will and will not get, which most guidance is not.
I expected a compliance course and got something closer to a way of thinking. The scenarios do most of that work.
The four conditions for real human oversight are now written into our procedure. Three of our arrangements failed on practical ability.
Good throughout. The regulatory module will need updating and the guide is upfront that it will, which I respect.
Rigorous without being dense. I finished it able to reason about cases rather than recite requirements.
The observation that a pilot operating on real people is a deployment with an optimistic name has already stopped one of our projects proceeding as it was.
Clear and practical. The glossary cross-references to chapters saved me a great deal of flicking back.
I supervise firms rather than work in one, and this describes what we actually look for more accurately than most compliance training does.
The point about building the substance before the form, because artefacts survive a change of statute and templates do not, is advice I wish I had had two years ago.
Well made and demanding. The difficult questions in the assessment are genuinely difficult.
Honest about uncertainty. Where something is contested the guide says so rather than picking a side and presenting it as settled.
The inventory chapter alone justified the time. Everything downstream depends on it and almost nobody says so this plainly.
Good. I would like more on how to size a programme against available resource, which the guide touches on but does not develop.
The scenario about the certificate that answered a different question is one I have watched happen. Painful and accurate.
Passed on the first attempt after two weeks of evening reading. The assessment tests whether you understood rather than whether you memorised.
Very good. The material on codes of practice is brief but it clears up a genuine confusion about whether signing up counts as compliance.
I have read four books on AI governance this year and this is the only one that told me what to do on Monday.
The best explanation of the provider and deployer distinction I have found, including the part about how a deployer becomes a provider without meaning to.
Genuinely useful. The chapter on when it goes wrong made me realise our logging cannot identify which model version produced which output.
I deploy AI in a small firm with no compliance function and expected this to be written for banks. It is not. The sequencing advice works at any size.
The distinction between a model and a system runs through everything and is stated once, early, and then relied on. Good writing.
Well structured. Module 6 assumes all five before it and the guide says so, which I ignored and regretted.
Our audit function now uses the theatre tests as a standard programme. The one about asking three practitioners what the policy requires found more than a week of document review.
The four questions for reading a new AI law are the most durable thing here. I have used them twice on legislation published after I finished the course.
Strong material. I would have liked a worked example of a complete technical documentation file rather than a description of one.
Clear, rigorous and free of padding. Nothing is repeated to reach a page count and several chapters are shorter than I expected.
The observation that the framework debate persists because it is tractable, while the inventory is a year of unglamorous work, is the truest sentence in the guide.
Good depth. The tables are the parts I return to — particularly the one on where existing controls stop.
I am moving into this field from privacy and the guide assumes exactly the right amount. No prior AI knowledge and no hand-holding.
The governance theatre chapter is the one I did not expect and got most from. Asking what a control has ever stopped has already changed two of ours.
Very good, though the assessment is harder than the study time suggests. Work the scenarios properly.
Written by somebody who has clearly done this work rather than read about it. The failure modes are the ones that actually happen.
The scenario about the reclassification nobody triggered described our situation almost exactly. We found three systems whose use had drifted and whose entries were untouched.
Solid. The provenance chapter is bleak reading if you have legacy models, which I do, but it is accurate.
Module 4 is long and every page of it earns its place. Our register went from 19 systems to 61 after applying the discovery methods.
I have implemented both NIST and ISO and this is the first source that says plainly the choice matters less than the evidence. Correct, and unpopular with framework vendors.
Well written and honest. The material on upstream change versus drift saved us a wasted retraining cycle two months later.
Excellent. The seven questions an examiner asks are worth the course on their own, and the note about which weak answer contaminates the rest is the useful part.
The point that an assessment after go-live always answers yes is one of those observations that is obvious once stated and had never occurred to me.
Comprehensive. I would value a follow-up on programme design, which this deliberately stops short of.
I work in procurement and the vendor chapter changed our questionnaire. We were asking about the supplier and not about what the model does to our population.
The shadow AI chapter is the only treatment I have seen that does not moralise. It says plainly that prohibition moves the problem somewhere worse.
Good material and well paced. My only note is that Module 2 assumes more comfort with legal instruments than it claims to.
Honest about what it does not cover, which is rarer than it should be. It repeatedly tells you when a question is legal rather than analytical.
Used this to brief our board. The framing that a control leaving no record cannot be shown to have operated landed better than any maturity model I have presented.
Clear and demanding. The scenarios are harder than the length suggests and I got two wrong on first reading.
The fairness metrics chapter finally explained why our vendor's bias report and our own testing disagreed. They were measuring different things and neither said so.
I came from model risk management and assumed most of this was covered. The table showing exactly where MRM stops was uncomfortable and entirely fair.
Very good. The regulatory chapter is deliberately built to age in one place, which I appreciated once I understood why.
Module 5 on human oversight is the best thing I have read on the subject. The four numbers in the scenario — reviews, overrides, seconds per case, and who checks an override — are now our standard diagnostic.
The distinction between what an ISO certificate attests and what people assume it attests should be printed and pinned above every compliance desk.
Strong throughout. I would have liked more on agentic systems, though the guide is honest that the frameworks do not cover them either.
I run a second-line function and Module 4 told me why our inventory kept decaying. Nothing was attached to a process that recurs. Obvious in hindsight and nobody had said it.
The chapter on why the risk attaches to the use rather than the technology reframed our whole programme. We had been governing by model type and missing everything the business had bought.
Questions
Is this an AI certification?
It does not teach you to build, train or evaluate models, and it does not cover prompt engineering or security testing of AI systems. If you want to learn to build with AI, this is not that course, and it says so rather than blurring the line to widen its audience.
Is it really free?
The certificate is paid, at US$79, shown in your local currency at checkout. You only reach that decision after you have passed, so you are never asked to pay for something you have not yet earned. If you never buy it, you keep the material and your result; you simply do not hold the certificate.
What happens the moment I pass?
Paying converts the sample into your issued certificate. The watermark comes off, the ID becomes visible, and the verification page confirms it to anyone who checks. Payment reveals the certificate you already earned; it does not mint a new one, and the date on it is the date you passed, not the date you paid.
Do I need experience in compliance or in AI to take this?
It is demanding for a foundation-level subject, because the questions test whether you can apply an obligation to a situation rather than recite it. But nothing in it requires a qualification you do not already have.
What is in the assessment?
The questions are scenario-based. You will not be asked what an article says; you will be given a system, a use and a jurisdiction, and asked which obligations reach it and what you would need to evidence.
Is it proctored? Do I need a webcam?
The certificate carries the name currently on your AGZIT profile, captured at the moment you pass. Check that before you sit it — correcting your profile afterwards does not reissue the certificate.
This field changes constantly. How current is the material?
Holders receive updated editions as the position changes, for as long as the certificate is valid. One module is devoted to reading a law you have never seen before and working out whether it reaches you, because that skill outlasts any particular statute.
How long is the certificate valid, and what happens then?
The term is not an administrative formality. A 2026 statement about AI obligations will be substantially wrong by 2028, and a certificate that never expired would be asserting currency it does not have.
Who accredits this, and what does that mean?
Gold requires the material to be maintained against changing regulation, the assessment to distinguish candidates who understood the subject from those who memorised it, and the issuer's claims about its own certificate to be accurate. A certificate that accredits itself is a claim; one assessed independently is a certificate that means something.
What will I be able to do afterwards?
It is a foundation certificate. It does not cover drafting an enterprise AI policy from scratch, board reporting, or the technical assurance work of testing a model yourself — and it says so plainly rather than overstating its reach.
