Mnemonics

53 memory aids for the lists the exam expects you to hold, in the order the syllabus teaches them. Every one cites the instrument and the exact provision it comes from, so you can check it against the source — and so you learn where each list lives as well as what is in it.

Domain I — Foundations

What artificial intelligence (AI) is, why it is hard to govern, and the principles every framework shares.

What makes something an AI system

Organisation for Economic Co-Operation and Development (OECD) Recommendation on AI (2019, revised 2024) · European Union Artificial Intelligence Act (EU AI Act), Regulation (EU) 2024/1689, Art. 3(1)

A machine that infers

Machine-based
software, hardware or both
Varying autonomy
operates with some independence from human involvement
May adapt after deployment
adaptiveness is possible, not required
Explicit or implicit objectives
the goal need not be stated to the system
Infers from input
the defining element — it derives how to produce outputs rather than following fixed rules
Generates outputs
predictions, content, recommendations or decisions
Influences environments
physical or virtual

Why it sticks: The two-word device holds the one element that separates AI from ordinary software. Rule-based automation does not infer, which is why robotic process automation usually falls outside the definition.

Why AI needs its own governance

International Association of Privacy Professionals (IAPP) AIGP Body of Knowledge v2.1, performance indicator I.A.3

Crafty Owls Always Spot Hidden Dormice Promptly

Complexity
too many interacting parts for any one person to hold
Opacity
the reasoning behind an output can be hard or impossible to see
Autonomy
acts with limited human involvement
Speed and scale
one error repeats across millions of decisions before anyone notices
Harm or misuse potential
including uses nobody designed for
Data dependency
inherits every flaw in what it was trained on
Probabilistic outputs
the same input can give a different answer — unlike deterministic software

Why it sticks: Seven owls for seven traits. When a question asks why existing information technology (IT) controls are not enough, the answer is one of these — usually opacity or probabilistic output.

The principles of responsible AI

IAPP AIGP Body of Knowledge v2.1, performance indicator I.A.4

Friendly Sheep Prefer Tall Apple Hedges

Fairness
no unjustified disparate outcomes
Safety and reliability
works as intended and fails safely
Privacy and security
protects data and resists attack
Transparency and explainability
people can see that AI is used and understand why it decided
Accountability
a named person answers for it
Human-centricity
humans stay in control and benefit

Why it sticks: The Body of Knowledge (BOK)’s own list. OECD, National Institute of Standards and Technology (NIST) and International Organization for Standardization (ISO) word these differently, but the six ideas recur in every framework — learn this set and the others become translations of it.

The six AI use-case types

IAPP AIGP Body of Knowledge v2.1, performance indicator I.A.1

Recognise it · Detect it · Forecast it · Personalise it · Optimise it · Talk to it

Recognition
identify what something is — a face, a product in a photo
Detection
find that something is present or anomalous — fraud, threats, defects
Forecasting
predict a future value — demand, churn, prices
Personalisation
tailor to a known individual — recommendations
Optimisation
find the best option under constraints — routing, scheduling
Interaction
converse with people — chatbots, assistants

Why it sticks: The near-miss pairs are where the marks go: recognition names the thing, detection only flags that it is there; forecasting predicts for everyone, personalisation for one person.

Who can be harmed

NIST AI Risk Management Framework 1.0 (NIST AI 100-1, January 2023), §1.1 and Figure 1

People, Organisations, Ecosystems — and people come in three sizes

People — individual
one identifiable person worse off
People — group or community
a rate difference across a class of people
People — societal
damage to the shared environment: trust, democracy, access
Organisations
reputation, operations, fines, security
Ecosystems
interconnected systems, supply chains, the natural environment

Why it sticks: This answers WHO was harmed. It is a different question from where bias came from — which is the list below, from a different NIST publication.

The three sources of bias

NIST Special Publication 1270, Towards a Standard for Identifying and Managing Bias in AI (March 2022)

Society · Statistics · Self

Systemic
historical and institutional bias already present in society and in the data
Statistical / computational
sampling, measurement and algorithmic artefacts
Human-cognitive
how people design, read and rely on output — including automation bias

Why it sticks: Each source takes a different fix: reframe the problem, repair the data, or redesign the human process. Classify first, then choose the control.

Domain II — Privacy law and the GDPR

Where modern privacy law comes from, then the General Data Protection Regulation in article order.

The Fair Information Practices

OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data (1980, revised 2013), Part Two, paras 7–14

Cats Don’t Purr Until Someone Offers Idle Affection

7 Collection limitation
lawful, fair, with knowledge or consent where appropriate
8 Data quality
relevant, accurate, complete, up to date
9 Purpose specification
purposes stated no later than collection
10 Use limitation
no use beyond those purposes without consent or legal authority
11 Security safeguards
reasonable protection against loss and misuse
12 Openness
policies and practices are transparent
13 Individual participation
access and challenge
14 Accountability
the controller answers for all of the above

Why it sticks: First drafted in a 1973 United States (US) Department of Health, Education, and Welfare report, codified by the OECD in 1980. If a question asks which family of principles underlies privacy law across jurisdictions, this is it.

The seven principles

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 5

Little Penguins Dance Around Seven Icy Arches

5(1)(a) Lawfulness, fairness, transparency
a basis, no unjustified harm, people understand
5(1)(b) Purpose limitation
specified, explicit, legitimate; no incompatible reuse
5(1)(c) Data minimisation
adequate, relevant, limited to what is necessary
5(1)(d) Accuracy
including inferences and outputs about a person
5(1)(e) Storage limitation
identifiable no longer than necessary
5(1)(f) Integrity and confidentiality
appropriate security
5(2) Accountability
comply AND be able to demonstrate it

Why it sticks: Six sit in Art. 5(1); accountability stands alone in Art. 5(2) because it governs the other six. "How many principles" appears as a distractor — the answer is seven.

The six lawful bases

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 6(1)

Cool Cats Love Vanilla Pop Lollies

6(1)(a) Consent
freely given, specific, informed, unambiguous, withdrawable
6(1)(b) Contract
necessary for a contract or pre-contract steps
6(1)(c) Legal obligation
required by EU or member-state law
6(1)(d) Vital interests
life or death
6(1)(e) Public task
official authority or public interest
6(1)(f) Legitimate interests
the AI workhorse — needs a three-part assessment

Why it sticks: In article order, (a) to (f). Legitimate interests is last in both — and the one that needs documented balancing work rather than a box tick.

Children’s consent age

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 8(1)

16 by default, 13 at the floor

Default
a child can consent to online services at 16
Member-state option
may lower it, but not below 13
Contrast — US
the Children’s Online Privacy Protection Act of 1998 uses 13 flat

Why it sticks: Because member states pick within the range, there is no single EU age — so "one global consent age" is wrong twice over.

The nine special categories

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 9(1)

Three beliefs, three bodily, three identity

Beliefs
political opinions · religious or philosophical beliefs · trade union membership
Bodily
genetic · biometric (only when used to uniquely identify) · health
Identity
racial or ethnic origin · sex life · sexual orientation

Why it sticks: A 3×3 grid beats a nine-letter acronym. Processing needs BOTH an Art. 6 basis and an Art. 9(2) condition.

The data subject rights

General Data Protection Regulation, Regulation (EU) 2016/679, Arts. 13–22

In All Reasonable Events, Rights Need Protecting Or Appeal

13–14 Information
what is collected and why — directly (13) or indirectly (14)
15 Access
a copy of your data and how it is used
16 Rectification
correct inaccurate data
17 Erasure
the "right to be forgotten", in defined cases
18 Restriction
freeze processing while a dispute is resolved
19 Notification
recipients are told of rectification, erasure or restriction
20 Portability
take your data to another controller
21 Objection
object to processing, absolutely so for direct marketing
22 Automated decisions
not to be subject to solely automated significant decisions

Why it sticks: Nine words, nine rights, and they run in article order from 13 to 22 — so the device also tells you where each one lives.

The four-step solely-automated decision test

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 22

Solely? Significant? Exception? Safeguards!

22(1) Solely automated?
meaningful human involvement defeats it — rubber stamps do not
22(1) Legal or similarly significant effect?
credit, employment, insurance, benefits
22(2)(a)–(c) Which exception?
contract · law · explicit consent
22(3) Safeguards
human intervention · express a point of view · contest the decision

Why it sticks: Sub-mnemonic for the safeguards: "I Protest, Contest" — Intervention, Point of view, Contest.

What a processor contract must say

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 28(3)

One I, one C, and six S’s

28(3)(a) Instructions
process only on documented instructions
28(3)(b) Confidentiality
staff bound to confidentiality
28(3)(c) Security
the Art. 32 measures
28(3)(d) Sub-processors
only with authorisation, on the same terms
28(3)(e) Subject rights
help the controller answer requests
28(3)(f) Support
help with security, breaches, impact assessments and consultation (Arts. 32–36)
28(3)(g) Sunset
delete or return the data at the end
28(3)(h) Scrutiny
provide information and allow audits

Why it sticks: Eight clauses in order (a) to (h). Relevant to every AI vendor that touches personal data on your behalf.

Security of processing

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 32(1)

Hide it, Hold it, Heal it, Hammer it

32(1)(a) Hide it
pseudonymisation and encryption
32(1)(b) Hold it
ongoing confidentiality, integrity, availability and resilience
32(1)(c) Heal it
restore availability and access promptly after an incident
32(1)(d) Hammer it
regularly test and evaluate the measures

Breach notification

General Data Protection Regulation, Regulation (EU) 2016/679, Arts. 33–34

72 to the regulator, straight away to the person — but only if it hurts

33(1) To the supervisory authority
within 72 hours of becoming aware, unless unlikely to result in risk
33(2) Processor to controller
without undue delay
34(1) To affected individuals
without undue delay, but only where the risk is high

Why it sticks: The clock runs from awareness, not from the incident. The threshold rises as you go outward: any risk for the regulator, high risk for the individual.

When a data protection impact assessment is mandatory

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 35(3)

Profile · Sensitive · Surveil

35(3)(a) Profile
systematic, extensive evaluation with legal or similarly significant effects
35(3)(b) Sensitive
large-scale special-category or criminal-offence data
35(3)(c) Surveil
systematic monitoring of a publicly accessible area on a large scale

Why it sticks: The general trigger is "likely to result in a high risk" (Art. 35(1)); these three are the cases the Regulation names outright.

What a data protection impact assessment contains

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 35(7)

Don’t Neglect Risk Management

35(7)(a) Description
the processing and its purposes
35(7)(b) Necessity
necessity and proportionality
35(7)(c) Risks
to the rights and freedoms of individuals
35(7)(d) Measures
to address those risks

Why it sticks: If high risk remains after the measures, Art. 36 requires prior consultation with the supervisory authority before processing starts.

When a data protection officer is mandatory

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 37(1)

Public · Watching · Sensitive

37(1)(a) Public
a public authority or body (courts acting judicially excepted)
37(1)(b) Watching
core activities involve regular and systematic monitoring on a large scale
37(1)(c) Sensitive
core activities involve large-scale special-category or criminal data

Why it sticks: Deliberately rhymes with the impact-assessment triggers above: two of the three are the same idea, so learn them as a pair.

International transfers — order of preference

General Data Protection Regulation, Regulation (EU) 2016/679, Chapter V, Arts. 44–49

Always Seek Derogations last

45 Adequacy
the simplest route where a Commission decision exists
46–47 Appropriate safeguards
standard contractual clauses, binding corporate rules, codes, certifications — plus a transfer risk assessment
49 Derogations
narrow, occasional, non-repetitive — genuinely a last resort

Which fine tier?

General Data Protection Regulation, Regulation (EU) 2016/679, Art. 83(4)–(5)

4 for the Fundamentals, 2 for the To-dos

83(5) €20M or 4%
principles (5, 6, 7, 9), data subject rights (12–22), transfers (44–49)
83(4) €10M or 2%
process duties — by design, records, security, impact assessments, processors, officers

Why it sticks: Breach a principle or a right: the higher tier. Fail a process: the lower one. Always whichever is higher, measured against worldwide annual turnover.

Domain II — Other law that already applies to AI

No AI statute needed: sectoral privacy, anti-discrimination and consumer protection law bite in full.

US sectoral privacy — which sector holds the data

US federal statutes, by year enacted

Credit, School, Health, Kids, Banks — 1970 to 1999

1970 Fair Credit Reporting Act
consumer reports and background screening
1974 Family Educational Rights and Privacy Act
education records at funded institutions
1996 Health Insurance Portability and Accountability Act
protected health information at covered entities and business associates
1998 Children’s Online Privacy Protection Act
online data from children under 13
1999 Gramm-Leach-Bliley Act
nonpublic personal information at financial institutions

Why it sticks: In date order. The US has no general privacy statute, so the first question in any US scenario is which sector the data sits in — each of these reaches exactly one.

US anti-discrimination statutes that reach AI

US federal statutes, by year enacted

Jobs, Age, Homes, Credit, Disability — 1964 to 1990

1964 Title VII, Civil Rights Act
employment — race, colour, religion, sex, national origin
1967 Age Discrimination in Employment Act
employment — workers aged 40 and over
1968 Fair Housing Act
housing sales, rentals and lending
1974 Equal Credit Opportunity Act
credit, including specific adverse-action reasons
1990 Americans with Disabilities Act
disability, including reasonable accommodation

Why it sticks: Disparate impact is the theory that catches AI: a neutral tool with an unjustified adverse effect on a protected group is unlawful with no intent at all.

Unfair versus deceptive

Federal Trade Commission Act of 1914, §5 (15 U.S.C. §45); unfairness test at §45(n)

Unfair is three I’s; deceptive is three M’s

§45(n) Unfair — Injury
the injury to consumers is substantial
§45(n) Unfair — Inescapable
consumers could not reasonably have avoided it
§45(n) Unfair — Imbalanced
it is not outweighed by benefits to consumers or competition
Deceptive — Message
a representation, omission or practice
Deceptive — Misleads
likely to mislead a consumer acting reasonably in the circumstances
Deceptive — Matters
material — it would affect the consumer’s decision

Why it sticks: Pick the prong from what the stem gives you: a false statement is deception; a harm is unfairness. Remedy to remember: algorithmic disgorgement — delete the model built on unlawful data.

Automated hiring tools in New York City

New York City Local Law 144 of 2021 (enforced from 5 July 2023)

Audit, Publish, Warn

Audit
an independent bias audit within the year before use
Publish
a summary of the audit results on the employer’s website
Warn
notify candidates at least 10 business days before the tool is used

Why it sticks: Independent is the operative word — a self-audit does not satisfy it.

Domain II — The EU AI Act, in article order

Regulation (EU) 2024/1689. Every list below cites its article, so you can find it in the text.

When each part applies

EU AI Act, Regulation (EU) 2024/1689, Art. 113 — as enacted

Bans at 6, Big models at 12, Bulk at 24, Built-in at 36 (months)

113 Entry into force
1 August 2024
113(a) Bans — prohibitions and AI literacy
2 February 2025 (6 months)
113(b) Big models — general-purpose AI, governance, penalties
2 August 2025 (12 months)
113 Bulk — most of the rest, including Annex III high-risk
2 August 2026 (24 months)
113(c) Built-in — high-risk AI inside regulated products
2 August 2027 (36 months)

Why it sticks: These are the enacted dates, which is what BoK v2.1 tests. The 2026 Digital Omnibus later moved Annex III high-risk to 2 December 2027 and product-embedded high-risk to 2 August 2028 — see the AI Act updates page.

The operators

EU AI Act, Regulation (EU) 2024/1689, Art. 3(3)–(8)

Please Pay Due Attention In Distribution

3(3) Provider
develops it, or has it developed, and places it on the market under its own name
25(3) Product manufacturer
treated as the provider when the AI is a safety component of its own regulated product
3(4) Deployer
uses it under its own authority, other than for personal use
3(5) Authorised representative
EU-based agent appointed in writing by a non-EU provider
3(6) Importer
places a non-EU provider’s system on the EU market
3(7) Distributor
makes it available further down the chain

Why it sticks: Art. 3(8) defines "operator" as all six together — and lists them in exactly the order the device does. The product manufacturer has no definition of its own; Art. 25(3) is where it becomes the provider.

The eight prohibited practices

EU AI Act, Regulation (EU) 2024/1689, Art. 5(1)(a)–(h)

Many Vultures Scavenge Past Farms, Eating Brown Rats

5(1)(a) Manipulation
subliminal or deceptive techniques that distort behaviour and cause significant harm
5(1)(b) Vulnerabilities
exploiting age, disability or social or economic situation
5(1)(c) Social scoring
scoring people on behaviour or traits, leading to unjustified detrimental treatment
5(1)(d) Predictive policing
predicting crime from profiling or personality traits alone
5(1)(e) Facial scraping
untargeted scraping of faces from the internet or closed-circuit television (CCTV) to build databases
5(1)(f) Emotion recognition
in the workplace or education, save for medical or safety reasons
5(1)(g) Biometric categorisation
inferring race, politics, union membership, religion, sex life or orientation
5(1)(h) Real-time remote biometric identification
in public spaces for law enforcement, save narrow exceptions

Why it sticks: In article order. The 2026 Digital Omnibus adds two more — AI-generated non-consensual intimate imagery and child sexual abuse material — from 2 December 2026.

The four risk tiers

EU AI Act, Regulation (EU) 2024/1689, Arts. 5, 6, 50 and 95

Pyramids Have Lovely Masonry

5 Prohibited
the eight practices above
6 High-risk
Annex I products and Annex III uses
50 Limited — transparency
chatbots, deepfakes, synthetic content
95 Minimal
everything else — voluntary codes of conduct

Why it sticks: Descending severity, like a pyramid narrowing to the top: very few systems are prohibited, most are minimal.

The eight Annex III high-risk areas

EU AI Act, Regulation (EU) 2024/1689, Annex III, points 1–8

Big Cats Eat Every Evening, Lions Munch Jackals

1 Biometrics
remote identification, categorisation, emotion recognition
2 Critical infrastructure
safety components in digital infrastructure, traffic, utilities
3 Education and vocational training
admission, assessment, proctoring
4 Employment
recruitment, promotion, termination, task allocation, monitoring
5 Essential services
public benefits, credit scoring, life and health insurance pricing, emergency triage
6 Law enforcement
risk assessment, evidence evaluation
7 Migration, asylum and border control
risk assessment, application examination
8 Justice and democratic processes
assisting judges; influencing elections

Why it sticks: Point 5 is the one to know in detail: its credit and insurance uses are what pull private deployers into the fundamental rights impact assessment.

The Annex III escape hatch

EU AI Act, Regulation (EU) 2024/1689, Art. 6(3)

Narrow, Improve, Pattern, Prep — unless it Profiles

6(3)(a) Narrow
performs a narrow procedural task
6(3)(b) Improve
improves the result of a completed human activity
6(3)(c) Pattern
detects decision patterns without replacing human assessment
6(3)(d) Prep
performs a preparatory task for an assessment
6(3) final Unless it Profiles
an Annex III system that profiles people is always high-risk

Why it sticks: A provider relying on this must document the assessment and still register the system (Art. 49(2)).

The high-risk requirements

EU AI Act, Regulation (EU) 2024/1689, Chapter III, Section 2, Arts. 9–15

Really Dull Tasks Require Thorough Human Attention

9 Risk management system
continuous and iterative across the life cycle
10 Data and data governance
relevant, representative, examined for bias
11 Technical documentation
drawn up before market, per Annex IV
12 Record-keeping
automatic logs for traceability
13 Transparency to deployers
instructions for use
14 Human oversight
understand, intervene, override, stop
15 Accuracy, robustness and cybersecurity
declared levels, maintained

Why it sticks: Seven words, seven articles, and they run consecutively from 9 to 15 — the device tells you the article number if you count.

From built to on the market

EU AI Act, Regulation (EU) 2024/1689, Arts. 43, 47, 48, 49

Assess, Declare, Mark, Register — and the numbers only go up

43 Conformity assessment
internal control for most Annex III systems
47 EU declaration of conformity
the provider signs that it complies
48 Conformité Européenne (CE) marking
affixed to show conformity
49 Registration
in the EU database, before placing on the market

Why it sticks: The order is the article order. Registering before assessing, or marking before declaring, is the standard wrong sequence.

When you become the provider

EU AI Act, Regulation (EU) 2024/1689, Art. 25(1)

Name it, Modify it, Repurpose it

25(1)(a) Name it
put your name or trademark on a high-risk system
25(1)(b) Modify it
make a substantial modification that keeps it high-risk
25(1)(c) Repurpose it
change its intended purpose so it becomes high-risk

Why it sticks: Any one is enough. The original provider is then no longer the provider for that system.

What a deployer of a high-risk system must do

EU AI Act, Regulation (EU) 2024/1689, Art. 26

I Only Invite Monkeys, Lions, Wolves and Tigers

26(1) Instructions
use it as the instructions for use say
26(2) Oversight
assign competent, trained people with authority
26(4) Inputs
input data relevant and representative, where you control it
26(5) Monitor
watch it, and tell the provider and authorities about risks and incidents
26(6) Logs
keep automatic logs for at least six months
26(7) Workers
inform workers’ representatives before workplace use
26(11) Tell people
inform people subject to its decisions

Why it sticks: Public-body deployers must also register their use (26(8)) and use the provider’s information for their data protection impact assessment (26(9)).

What a fundamental rights impact assessment contains

EU AI Act, Regulation (EU) 2024/1689, Art. 27(1)(a)–(f)

Six P’s: Process, Period, People, Perils, People-in-the-loop, Plan B

27(1)(a) Process
how the deployer will use the system
27(1)(b) Period
how long and how often
27(1)(c) People
who is likely to be affected
27(1)(d) Perils
the specific risks of harm to them
27(1)(e) People-in-the-loop
the human oversight measures
27(1)(f) Plan B
what happens if the risks materialise, including complaints

Why it sticks: Owed only by public bodies, private providers of public services, and deployers of Annex III point 5(b) credit scoring and 5(c) life and health insurance pricing. Notified to the market surveillance authority.

The four transparency duties

EU AI Act, Regulation (EU) 2024/1689, Art. 50(1)–(4)

Chat, Mark, Feel, Fake — two for providers, two for deployers

50(1) Chat — provider
tell people they are interacting with AI, unless obvious
50(2) Mark — provider
machine-readable marking of synthetic audio, image, video and text
50(3) Feel — deployer
disclose emotion recognition or biometric categorisation
50(4) Fake — deployer
disclose deepfakes, and AI text published on matters of public interest

Why it sticks: Numbered in the order the device runs. Not to be confused with Art. 13, which is transparency to the deployer about a high-risk system.

General-purpose model duties

EU AI Act, Regulation (EU) 2024/1689, Arts. 51, 53 and 55

Everyone: Document, Downstream, Copyright, Content. Systemic: Test, Treat, Tell, Toughen

53(1)(a) Document
technical documentation for the AI Office
53(1)(b) Downstream
information for providers building on the model
53(1)(c) Copyright
a policy to respect EU copyright, including opt-outs
53(1)(d) Content
a public summary of training content
51(2) Systemic risk threshold
presumed above 10²⁵ floating-point operations of training compute
55(1)(a) Test
model evaluations, including adversarial testing
55(1)(b) Treat
assess and mitigate systemic risks
55(1)(c) Tell
track and report serious incidents
55(1)(d) Toughen
adequate cybersecurity

Why it sticks: Four duties for every provider, four more for systemic-risk models — and both sets run (a) to (d).

Serious incident reporting clocks

EU AI Act, Regulation (EU) 2024/1689, Art. 73

15, 10, 2 — the worse it is, the shorter the clock

73(2) Standard
within 15 days of becoming aware
73(4) A death
within 10 days
73(3) Widespread or critical infrastructure
immediately, and no later than 2 days

Why it sticks: Reported to the market surveillance authority — a different recipient and trigger from the 72-hour GDPR personal data breach.

Penalty tiers

EU AI Act, Regulation (EU) 2024/1689, Arts. 99 and 101

Ban, Break, Bluff — 7, 3, 1

99(3) €35M or 7% — Ban
breaching the Art. 5 prohibitions
99(4) €15M or 3% — Break
breaching most other operator obligations
99(5) €7.5M or 1% — Bluff
incorrect or misleading information to authorities
99(6) Small firms
whichever is lower — the reverse of everyone else
101 General-purpose model providers
up to €15M or 3%, imposed by the Commission

Why it sticks: Descending 7-3-1: banned practices, broken duties, bluffing the regulator. The small-firm reversal is the favourite trap.

Domain II — Standards and frameworks

Voluntary, certifiable or both. Every one cited by its formal number and year.

The four core functions

NIST AI Risk Management Framework 1.0 (NIST AI 100-1, January 2023), §5

Govern is the hub; Map, Measure, Manage is the loop

Govern
cross-cutting culture, policy, roles, accountability
Map
establish context and identify risks
Measure
analyse, assess, benchmark, track
Manage
prioritise, respond, monitor

Why it sticks: Govern is not step one of four — it wraps the other three. Companion documents: the Playbook, and the Generative AI Profile (NIST AI 600-1, July 2024).

The seven trustworthiness characteristics

NIST AI Risk Management Framework 1.0 (NIST AI 100-1, January 2023), §3

Very Safe Systems Are Explained, Private, Fair

3.1 Valid and reliable
the base condition the others build on
3.2 Safe
no endangerment of life, health, property, environment
3.3 Secure and resilient
withstands attack and adverse events
3.4 Accountable and transparent
who answers, and is information available
3.5 Explainable and interpretable
mechanism and meaning of output
3.6 Privacy-enhanced
anonymity, confidentiality, control
3.7 Fair, with harmful bias managed
equality and equity

Why it sticks: Valid and reliable is drawn as the foundation beneath the rest — the others mean nothing if the system does not work.

The ISO/IEC numbers

International standards, by number and year of publication

22989 names it, 23894 risks it, 42001 runs it, 42005 weighs it, 5338 lives it

International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 22989:2022
concepts and terminology — the vocabulary
ISO/IEC 23894:2023
AI risk management, adapting ISO 31000:2018
ISO/IEC 42001:2023
the AI management system — the one you certify against
ISO/IEC 42005:2025
AI system impact assessment
ISO/IEC 5338:2023
AI system life cycle processes

Why it sticks: Options are built by swapping these numbers. Only 42001 certifies anything, and it certifies an organisation — not a model, and not a person.

The management system clauses

ISO/IEC 42001:2023, Clauses 4–10 (plus Annex A controls)

Clever Leaders Plan, Support, Operate, Evaluate, Improve

4 Context of the organisation
scope, stakeholders, the AI system’s role
5 Leadership
top management commitment and AI policy
6 Planning
risks, opportunities, objectives, impact assessment
7 Support
resources, competence, awareness, documentation
8 Operation
run the processes, assessments and treatments
9 Performance evaluation
monitoring, internal audit, management review
10 Improvement
nonconformity, corrective action, continual improvement

Why it sticks: Maps onto Plan-Do-Check-Act: Plan is 4–7, Do is 8, Check is 9, Act is 10. The same clause structure as every modern ISO management system standard.

The OECD AI Principles

OECD Recommendation of the Council on Artificial Intelligence (May 2019, revised May 2024), §1.1–1.5

Inclusive Humans Trust Robust AI

1.1 Inclusive growth, sustainable development and well-being
AI should benefit people and the planet
1.2 Human rights and democratic values
including fairness and privacy
1.3 Transparency and explainability
meaningful information, and the ability to challenge outcomes
1.4 Robustness, security and safety
functions appropriately throughout its life cycle
1.5 Accountability
actors answer for proper functioning

Why it sticks: Section 2 adds five recommendations to governments. The EU AI Act adopted the OECD’s definition of an AI system, which is why this soft-law text matters so much.

The international soft-law timeline

Principles, declarations and treaties, by date adopted

Only Good Unions Help Build Consensus — 2019 to 2024

May 2019 OECD AI Principles
the first intergovernmental AI standard
June 2019 Group of Twenty (G20) AI Principles
the OECD text, adopted by the G20
Nov 2021 United Nations Educational, Scientific and Cultural Organization (UNESCO) Recommendation on the Ethics of AI
adopted by all member states
Oct 2023 Group of Seven (G7) Hiroshima AI Process
guiding principles and code of conduct for advanced AI
Nov 2023 Bletchley Declaration
the first AI Safety Summit, on frontier risk
Sep 2024 Council of Europe Framework Convention
the first binding AI treaty (Council of Europe Treaty Series (CETS) No. 225)

Why it sticks: All soft law except the last: the Council of Europe Convention is a treaty, binding the states that ratify it — though still not companies directly.

Domains III and IV — Building and deploying

Sequences and checklists from the life cycle. For why each order holds, see the order-of-operations page.

The planning sequence

IAPP AIGP Body of Knowledge v2.1, performance indicators III.A.1–III.A.2

Pigs Use Lipstick, Goats Don’t

1 Problem
the business problem to be solved
2 Use cases
the specific intended uses
3 Law
the laws that apply to those uses
4 Gaps and risks
where the use cases could fail or harm
5 Data
what data the system will need

Why it sticks: Purpose fixes the law, the law fixes the design, the design fixes the data. The distractor nearly always moves data to the front.

Data attributes to assess before training

IAPP AIGP Body of Knowledge v2.1, performance indicator III.B.1

Two Q’s, an I, an F — and the right to use it

Quality
accurate, complete, consistent
Quantity
enough to train and test
Integrity
unaltered, with known lineage
Fitness for purpose
representative of where it will be used
Lawful rights
a basis, licences and permissions to use it at all

Why it sticks: The fifth is what makes this governance rather than data science: perfect data you may not lawfully use is no use at all.

The kinds of testing

IAPP AIGP Body of Knowledge v2.1, performance indicator III.B.3

Unusually Industrious Volunteers Perform Several Big Inspections

Unit
each component alone
Integration
components working together
Validation
does it meet its requirements
Performance
accuracy and speed against thresholds
Security
resistance to attack, including adversarial inputs
Bias
outcomes across groups
Interpretability
can its outputs be explained

Why it sticks: In the order the BOK lists them, which roughly runs from the smallest part to the whole system and then out to its effects.

Incident response

IAPP AIGP Body of Knowledge v2.1, performance indicator III.C.4

Can All Nurses Remain Reasonable

1 Contain
suspend it or take it out of the decision path
2 Assess
severity, scope and root cause
3 Notify
users, regulators and integrated third parties as required
4 Remediate
fix the defect and validate the fix
5 Review
feed the lessons back into the controls

Why it sticks: Containment is unconditionally first — every other step can happen while the harm is stopped, but none should happen instead of stopping it.

Deployment context factors

IAPP AIGP Body of Knowledge v2.1, performance indicator IV.A.1

Bosses Prefer Data, Ethics and Workers

Business objectives
what the deployment is for
Performance requirements
how good it must be
Data availability
whether the data exists and can be used
Ethical considerations
who could be harmed and how
Workforce readiness
whether people can use and oversee it

The four ways to tell models apart

IAPP AIGP Body of Knowledge v2.1, performance indicator IV.A.2

Four yes-or-no questions: Generates? Open? Large? Multimodal?

Classic or generative
predicts and classifies, or creates new content
Proprietary or open source
licensed and closed, or inspectable and modifiable
Small or large
narrow and cheap, or broad and costly
Language-only or multimodal
text alone, or text with images, audio and video

The adaptation ladder

IAPP AIGP Body of Knowledge v2.1, performance indicator IV.A.3

Prompt, Retrieve, Refine, Rebuild — lightest first

1 Prompt
prompt engineering on the model as it is
2 Retrieve
retrieval-augmented generation over your own documents
3 Refine
fine-tuning on your own data
4 Rebuild
training a model from scratch

Why it sticks: Governance favours the least invasive step that meets the need. Each rung up adds data exposure, cost and obligations — at the top you may become a provider.

Making them stick

Test yourself

Five questions on what is above, with every option explained. Your score is kept in this browser and shown on your dashboard, and saved to your account if you are signed in.

Quick check: the lists worth memorising1 / 5 · score 0

How many principles does GDPR Art. 5 contain?

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →