The Certified in the Governance of General-Purpose Artificial Intelligence Systems (CGGPAIS) credential is awarded to candidates who exhibit a comprehensive understanding of enabling effective governance for general-purpose artificial intelligence (GPAI) systems, ensuring compliance with the EU AI Act requirements. This includes achieving ethical behavior, responsible stewardship, and successful performance—all aligned with stakeholder expectations and the specific obligations for GPAI systems under the EU AI Act, such as transparency, risk management, and documentation. Candidates must demonstrate competence in adapting or enhancing the established components of the AI governance system to ensure it remains effective, efficient, and suitable for the unique and dynamic nature of GPAI systems, addressing challenges like continuous learning, lack of transparency, and systemic risks, within the organizational and regulatory context.

The governance of GPAI systems is defined as "the system by which the current and future use of general-purpose artificial intelligence (GPAI) is directed and controlled. This involves evaluating and directing the use of GPAI systems to support the organisation’s purposes and monitoring this use to achieve its strategic plans, while ensuring compliance with the EU AI Act. It includes the organisational structures, principles, values, strategy, policies, processes, and controls for using GPAI within the organisation, with a focus on meeting regulatory obligations such as transparency (Article 50), risk management for systemic risks (Article 51), and documentation (Article 52)."
Certified in the Governance of General-Purpose Artificial Intelligence Systems (CGGPAIS)
This credential is granted to candidates who demonstrate a strategic understanding of the organisational and regulatory implications of using GPAI systems under the EU AI Act. They possess the expertise to direct and control GPAI system usage within their organisations, ensuring compliance with the EU AI Act, the General Data Protection Regulation (GDPR), relevant ISO standards (e.g., ISO/IEC 42001:2023), authoritative guidance (e.g., OECD AI Principles), and best practices from institutions like the European AI Office. Candidates are expected to comprehend the specific accountability requirements for GPAI providers, including transparency obligations, risk management, and incident reporting, as outlined in Chapter V of the EU AI Act.
The Certified in the Governance of GPAI Systems exam consists of 100 questions covering 13 job practice domains, all testing the candidate's knowledge and ability in real-life governance practices for GPAI systems, as leveraged by expert professionals. The exam comprises a similar number of questions from each domain. A passing score is 70% or more questions answered correctly.
JOB PRACTICE DOMAINS
Domain 1: Governance, Value Generation, and Ethical Outcomes from GPAI Systems
Description: The governing body should approve GPAI system value generation objectives (i.e., purpose) that support the organisation's purpose in line with its values, the natural environment, and the social and economic context within which it operates, while ensuring compliance with EU AI Act requirements for GPAI, such as transparency and risk management.
| Its value generation model should clarify: |
| • |
what value the organisation intends the GPAI system to generate (define), ensuring alignment with EU AI Act transparency obligations (Article 50). |
| • |
how the GPAI system should generate that value (create), considering systemic risk management (Article 51). |
| • |
how the generation of value will be assured (deliver), including through documentation and information provision (Article 52). |
| • |
how the value generated by the GPAI system is to be retained and distributed (sustain), ensuring ethical outcomes and stakeholder trust. |
| |
|
| Tasks: |
| • |
Optimise value creation for stakeholders from investments in GPAI systems, ensuring compliance with EU AI Act transparency requirements. |
| • |
Set parameters for the ethical intentions of the GPAI system towards the natural environment and the social and economic context, aligning with EU AI Act principles (Recital 47). |
| • |
Ensure value-generation objectives fulfil organisational purposes, can be delivered, and remain viable over time, adhering to EU AI Act risk management requirements (Article 51). |
| • |
Evaluate the benefits realised from GPAI-enabled investments, processes, services, and systems, ensuring transparency (Article 50). |
| • |
Review whether the deployment of the GPAI system remains consistent with the organisation's strategic intent, purpose, and values, and EU AI Act obligations. |
Domain 2: Components of AI Governance, Risk Management, and Compliance Frameworks for GPAI Systems
Description: The governing body should establish a GPAI governance framework, encompassing risk management, compliance management, and post-market monitoring systems, to ensure GPAI systems perform effectively, adhere to responsible stewardship, and uphold ethical behavior as required by the EU AI Act, particularly addressing systemic risks and transparency.
| Often the components for the governance of GPAI systems already exist: |
| • |
Adapt or improve existing components to ensure governance of the GPAI system remains effective, efficient, and appropriate for its unique and dynamic nature, addressing EU AI Act transparency and risk requirements. |
| • |
Use a conceptual governance framework to identify, plan, organise, and direct the adaptation or improvement of components necessary for GPAI governance under the EU AI Act. |
| |
|
| Tasks: |
| • |
Establish the GPAI governance framework to meet EU AI Act requirements (e.g., transparency, Article 50). |
| • |
Establish an accountability framework for GPAI providers and deployers (Article 52). |
| • |
Ensure that those to whom responsibilities are delegated are empowered to create management policies consistent with EU AI Act governance requirements and propose changes to governance policies. |
| • |
Approve a GPAI governance charter, clarifying delegations within the organisation, including in relation to the strategy process. |
| • |
Appoint a GPAI oversight body to ensure compliance with EU AI Act obligations. |
| • |
Approve the GPAI development framework and process model, ensuring transparency and risk management (Articles 50-51). |
| • |
Establish a risk management system for GPAI, setting expectations for internal controls, compliance, and risk-taking (Article 51). |
| • |
Establish a compliance management system to meet EU AI Act requirements (Article 52). |
| • |
Establish a post-market monitoring system for GPAI systems (Article 61). |
| • |
Direct the implementation of a system of internal control for GPAI compliance. |
| • |
Establish governance policies ensuring alignment with EU AI Act requirements for GPAI, clarifying intentions and expectations regarding organisational purpose, values, and value generation objectives. |
| • |
Evaluate the results of GPAI system tests, validation, compliance, conformance, and performance audits to ensure EU AI Act compliance. |
Domain 3: AI Governance Scope: Purpose, Type, Functionality, Benefits, Risks, Role for GPAI Systems
Description: The governing body should ensure that the GPAI system's purpose is clearly defined and aligned with organisational purposes, while meeting EU AI Act requirements for transparency and risk management. The GPAI system's purpose should define its intentions towards the natural environment, society, and stakeholders, ensuring compliance with EU AI Act obligations.
| • |
Ensure the GPAI system's purpose and organisational values are defined, communicated, and embedded, aligning with EU AI Act transparency requirements (Article 50). |
| • |
Create clarity for GPAI system stakeholders on the system’s intentions, behaviors, and activities, ensuring transparency (Article 50). |
| • |
Provide a framework within which GPAI systems are created and executed in a focused manner, avoiding unnecessary risks (Article 51). |
| • |
Identify issues and stakeholders the GPAI system addresses, mitigating negative impacts as per EU AI Act requirements (Recital 47). |
| • |
Ensure the GPAI system achieves its intended purposes in a manner that demonstrates organisational values and EU AI Act compliance. |
| • |
Provide a basis for stakeholders to assess GPAI system outcomes and compliance with EU AI Act objectives (Article 52). |
Domain 4: Principles for the Governance of GPAI Systems
Description: The governing body should ensure that the GPAI system's principles are clearly defined, aligned with organisational values, and compliant with EU AI Act requirements, including transparency, risk management, and accountability.
| • |
Oversee the GPAI system’s performance to ensure compliance with EU AI Act transparency (Article 50) and risk management obligations (Article 51). |
| • |
Require delegated parties to provide timely and accurate reports on all material aspects of GPAI system management, including compliance documentation (Article 52). |
| • |
Ensure an internal control system is implemented, including a risk management system, compliance management system, and post-market monitoring system, as required by the EU AI Act (Articles 51, 61). |
| • |
Oversee corrective actions for GPAI system non-compliance (Article 62). |
| • |
Obtain assurance of the accuracy of reports and effectiveness of internal controls for GPAI systems (Article 65). |
| • |
Evaluate the effectiveness of governance policies in guiding GPAI system development and deployment under EU AI Act requirements. |
| • |
Obtain risk information on GPAI system threats and opportunities, considering systemic risks (Article 51). |
| • |
Ensure GPAI system stakeholders are identified, prioritised, and engaged, meeting EU AI Act transparency requirements (Article 50). |
| • |
Ensure ethical leadership throughout the GPAI system's lifecycle, aligning with EU AI Act principles (Recital 47). |
| • |
Set expectations for GPAI systems using robust decision-making processes compliant with EU AI Act. |
| • |
Direct GPAI system behavior to align with organisational values and EU AI Act requirements. |
| • |
Direct organisational alignment through GPAI system integration, ensuring compliance. |
| • |
Direct management to act in good faith and in the best interests of the organisation and stakeholders under EU AI Act. |
| • |
Hold people accountable along the GPAI value chain for EU AI Act compliance. |
| • |
Hold people accountable for non-compliance with EU AI Act, regulatory, and ethical requirements. |
Domain 5: Organisational Values Impacting the Deployment of GPAI Systems
Description: The governing body should ensure that organisational values are clearly defined and aligned with EU AI Act requirements for GPAI systems. The governing body shall demonstrate accountability for the GPAI system's lawfulness, trustworthiness, fairness, integrity, effectiveness, efficiency, resilience, explainability, and acceptable use to stakeholders, ensuring compliance with EU AI Act transparency (Article 50) and risk management (Article 51) obligations, and hold operators to account.
| • |
Oversee organisational values and governance policies guiding GPAI system development and use, ensuring alignment with EU AI Act ethical principles (Recital 47). |
| • |
Engage relevant stakeholders when defining organisational values for GPAI systems (Article 50). |
| • |
Clearly express ethical behavior expected from GPAI systems, aligning with EU AI Act requirements. |
| • |
Understand consequences of unethical behavior under EU AI Act (Article 71 penalties). |
| • |
Demonstrate commitment to organisational values aligned with EU AI Act. |
| • |
Demonstrate accountability for GPAI system compliance (Article 52). |
| • |
Hold processors along the GPAI value chain accountable for EU AI Act compliance. |
Domain 6: Strategic Importance and GPAI Strategy Development
Description: The governing body shall direct and engage with the GPAI system strategy, following the value generation model, to achieve the GPAI system purpose, fulfil its EU AI Act regulatory compliance obligations (e.g., transparency, risk management), and enable data subject rights under GDPR.
| • |
Provide strategic direction and set outcomes expected from the GPAI system, ensuring transparency (Article 50). |
| • |
Implement privacy by design and default for GPAI systems (Recital 81, GDPR). |
| • |
Approve timescales for GPAI system strategic outcomes, ensuring compliance timelines (e.g., February 2, 2025, "AI lit.pdf"). |
| • |
Approve choices between open-source and proprietary GPAI models, considering EU AI Act requirements. |
| • |
Approve choices between decentralised products and centralised GPAI platforms, ensuring compliance. |
| • |
Ensure the GPAI system strategy considers the natural environment, social, and economic context, aligning with EU AI Act principles (Recital 47). |
| • |
Ensure the GPAI system strategy includes developing capacities and competencies required during its lifecycle, as per EU AI Act literacy requirements (Article 4). |
| • |
Ensure selection of GPAI models and training data aligns with EU AI Act transparency and risk management requirements (Articles 50-51). |
Domain 7: GPAI System and Data Sourcing Strategies and Suppliers in the AI Value Chain
Description: The governing body should ensure GPAI acquisitions are made for valid reasons, based on appropriate and ongoing analysis, with clear and transparent decision-making, ensuring compliance with EU AI Act documentation and transparency requirements (Article 52).
| • |
Evaluate options for providing GPAI systems to realise approved proposals, balancing risks and value, ensuring EU AI Act compliance (Article 51). |
| • |
Direct that GPAI assets (systems and infrastructure) be acquired appropriately, including suitable technical documentation and instructions for use, ensuring compliance with EU AI Act (Article 52). |
| • |
Direct that supply arrangements (internal and external) support EU AI Act transparency and risk management obligations (Articles 50-51). |
| • |
Monitor GPAI investments to ensure compliance with EU AI Act requirements. |
| • |
Monitor the extent to which the organisation and suppliers maintain a shared understanding of EU AI Act compliance for GPAI acquisitions. |
| • |
Oversee acquisition, design, development, and deployment for GPAI compliance. |
| • |
Ensure human resource competency development aligns with EU AI Act literacy requirements (Article 4). |
| • |
Oversee capacity planning for GPAI compliance. |
| • |
Ensure test and training data comply with EU AI Act risk management requirements (Article 51). |
| • |
Manage relationships, contracted services, and data sharing under EU AI Act (Article 28). |
Domain 8: Legal and Regulatory Compliance Obligations for GPAI Systems
Description: The governing body should regularly evaluate the extent to which the GPAI system satisfies EU AI Act obligations (e.g., transparency, risk management, documentation), GDPR, internal policies, standards, and best practices.
| • |
Establish mechanisms ensuring GPAI system compliance with EU AI Act (Articles 50-55) and GDPR (Recital 81). |
| • |
Regularly evaluate internal conformance to EU AI Act governance requirements for GPAI systems. |
| • |
Direct policies to meet EU AI Act obligations for GPAI systems (e.g., transparency, Article 50). |
| • |
Ensure all GPAI actions are ethical, aligning with EU AI Act principles (Recital 47). |
| • |
Monitor GPAI system compliance and conformance through reporting and audits, ensuring timely reviews (Article 65). |
| • |
Monitor GPAI system activities, including data disposal, to meet EU AI Act and GDPR obligations (Recital 81). |
Domain 9: Key GPAI System Management, Process, and Internal Control Domains
Description: The governing body shall oversee the GPAI system’s performance (concerning people, process, technology, and data) to ensure compliance with EU AI Act requirements, including transparency, risk management, and ethical behavior, to achieve the GPAI system's purpose and strategic outcomes.
| • |
Acknowledge data as a critical asset for GPAI systems, ensuring compliance with EU AI Act (Article 51). |
| • |
Ensure effective decision-making relies on quality data for GPAI systems (Article 51). |
| • |
Validate data processing adheres to EU AI Act and GDPR standards (Recital 81). |
| • |
Prioritise responsible data utilisation for GPAI systems. |
| • |
Advocate for ethical handling of data in GPAI systems (Recital 47). |
| • |
Recognise varying risk levels in GPAI data processing (Article 51). |
| • |
Provide guidance on managing GPAI data risks (Article 51). |
| • |
Implement controls for GPAI data risks throughout the system’s lifecycle (Article 61). |
| • |
Oversee design, development, deployment, and operation of GPAI systems for EU AI Act compliance. |
| • |
Oversee risk management, compliance, and post-market monitoring systems for GPAI (Articles 51, 61). |
| • |
Ensure robust data processing, incident handling, and malfunction controls for GPAI systems (Article 62). |
| • |
Collect, share, and process personal data in GPAI systems only as necessary, avoiding indiscriminate collection (Recital 81). |
| • |
Address inaccuracies through rigorous GPAI data controls (Article 51). |
| • |
Ensure reliable GPAI outcomes through EU AI Act compliance. |
| • |
Limit GPAI system’s collection, sharing, and processing of personal data to legitimate purposes, ensuring compliance with EU AI Act and GDPR (Recital 81). |
| • |
Mitigate risks of data inaccuracy in GPAI systems through input, processing, and output controls (Article 51). |
| • |
Monitor GPAI system’s internal controls, assurance, and transparency processes (Article 50). |
| • |
Monitor GPAI system behavior and fine-tune responses for accuracy (Article 61). |
| • |
Implement change control and configuration management for GPAI systems (Article 15). |
Domain 10: Governance of Risk in Deployed GPAI Systems
Description: The governing body should ensure the effect of uncertainty on the GPAI system's purpose and strategic outcomes is analysed, measured, and evaluated, addressing EU AI Act requirements for systemic risk management (Article 51).
| • |
Set the tone for managing GPAI system risk to achieve EU AI Act compliance (Article 51). |
| • |
Determine the nature and extent of risks the GPAI system shall accept (Article 51). |
| • |
Determine how to oversee GPAI system risk management under EU AI Act. |
| • |
Position risk as a key consideration in GPAI governance policies (Article 51). |
| • |
Ensure risk appetite and tolerance for GPAI systems are communicated (Article 51). |
| • |
Set risk criteria and limits for GPAI systems (Article 51). |
| • |
Ensure management assesses, treats, and monitors GPAI risks per EU AI Act (Article 61). |
| • |
Integrate risk management into all GPAI system activities. |
| • |
Recognise data risks in GPAI systems and direct management on managing these risks (Article 51). |
| • |
Consider external (AI value chain) and internal context impacts on GPAI systems (Article 51). |
| • |
Ensure effective data analytics assess GPAI system risks (Article 51). |
| • |
Monitor mitigation to ensure GPAI risk appetite is not exceeded (Article 51). |
| • |
Consider external and internal context impacts on GPAI systems (Article 51). |
| • |
Ensure proactive notification of new GPAI risks (Article 61). |
| • |
Disclose GPAI risk limits and expectations to stakeholders (Article 50). |
| • |
Identify risks from foreseeable misuse of GPAI systems (Article 51). |
Domain 11: Social Responsibility and Stakeholder Engagement for GPAI Systems
Description: The governing body shall ensure GPAI system decisions and activities are transparent and aligned with societal expectations, meeting EU AI Act transparency and fairness requirements (Article 50, Recital 47).
| • |
Identify all relevant GPAI system stakeholders within and outside the enterprise (Article 50). |
| • |
Establish and maintain positive relationships with GPAI stakeholders. |
| • |
Ensure stakeholder expectations are understood (Article 50). |
| • |
Continually engage stakeholders through an engagement process. |
| • |
Implement strategies to avoid unfair bias, discrimination, and exclusion in GPAI system use (Recital 47). |
| • |
Ensure GPAI system performs socially responsibly within acceptable behavior parameters (Recital 47). |
| • |
Prohibit actions permissible but not aligned with EU AI Act stakeholder expectations regarding human rights, inclusion, and fairness (Recital 47). |
| • |
Ensure user-centric and human-rights-based approaches in GPAI system design and deployment (Recital 47). |
| • |
Measure performance against social responsibility objectives for GPAI systems. |
| • |
Report GPAI system’s social responsibility objectives transparently to stakeholders (Article 50). |
Domain 12: GPAI Viability and Performance Over Time
Description: The governing body should ensure the GPAI system remains viable (concerning social, economic, and environmental goals) and performs as expected over time, without compromising stakeholder needs, aligning with EU AI Act post-market monitoring requirements (Article 61).
| • |
Define acceptable performance metrics, measure, and evaluate results for: |
| |
• |
Achievement of GPAI system purposes (Article 50). |
| |
• |
Influence on organisation’s functioning. |
| |
• |
Inter-relationship with external systems (Article 51). |
| |
• |
Use over time via post-market monitoring (Article 61). |
| |
• |
Performance metrics for GPAI systems. |
| |
• |
Financial performance. |
| |
• |
Ethical behavior (Recital 47). |
| |
• |
Compliance with EU AI Act obligations (Articles 50-55). |
| |
• |
Viability over time, protecting dependent systems (Article 61). |
| • |
Report on evaluated performance metrics to stakeholders (Article 50). |
| • |
Ensure GPAI system is protected and restorable (Article 61). |
| • |
Measure GPAI system impact on climatic stability, biodiversity, and social equality (Recital 47). |
Domain 13: Post-Market Monitoring, Conformance, and Reporting to Authorities for GPAI Systems
Description: The governing body should log the GPAI system's post-market operation, monitor its conformance, instances of misuse, serious incidents, and malfunctions, and report non-conformance to competent authorities as required by the EU AI Act (Article 62).
| • |
Implement logging of all post-market processing activities for GPAI systems (Article 61). |
| • |
Detect environmental changes impacting GPAI risk profiles and risk appetite (Article 61). |
| • |
Perform functional and configuration changes for GPAI systems when required (Article 15). |
| • |
Ensure change control for GPAI systems (Article 15). |
| • |
Detect and respond to GPAI system incidents and malfunctions (Article 62). |
| • |
Correct GPAI system processing errors (Article 62). |
| • |
Report serious incidents and non-conformance to competent authorities as per EU AI Act (Article 62). |