GAICC AI Conference & Awards 2026 "Governing the Future – Building Responsible, Safe and Human-centric AI"
GAICC certifies individuals to design, run and audit AI governance against recognised standards — from foundation to senior auditor, plus dedicated AI-governance and discipline specialities. There’s an optimal next step at every level.
The credential landscape is what this body of knowledge looks like once it is examined: four categories of credential, each extracted from a defined part of the framework, the maturity model and the implementation roadmap. This article is the map of which part each one takes.
A credential catalogue answers “what is available?”. A framework answers “what does the organisation need?”. The map exists because those are different questions, and the gap between them is where training budgets get spent badly — on the credential somebody heard of rather than the one their layer of the framework actually requires.
The organising principle is that competence should sit where the decision sits. A board member does not need implementer depth; they need enough to ask why a reported metric should be believed. An engineer does not need audit competence; they need to know what evidence the build must emit. Matching credential to layer is what makes capability a control rather than a budget line.
| Category | What it builds | Which framework layer needs it |
|---|---|---|
| ISO/IEC 42001 Core | Designing, operating and auditing the AI management system itself — foundation through senior implementer and senior auditor. | The Governance Core; Risk, Assurance & Audit; Delivery & Operations |
| ISO/IEC 27001 Core | The information security management discipline that data provenance, third-party control and resilience build on. | The Governance Core; Delivery & Operations; the data control domain |
| AI Governance Core | Cross-domain governance judgement: scope, risk appetite, autonomy, proportionality, board oversight. | Board & Executive; the AI governance lead; programme leadership |
| AI Governance Speciality | Discipline-specific depth for the federated spokes — legal and compliance, HR, cost and control. | People, Functions & Capability; the domain experts |
| If you are… | Start with | Then |
|---|---|---|
| On the board or accountable executive | Foundation-level literacy | Governance core, for autonomy and risk-appetite judgement |
| The AI governance lead | Governance core | Management system implementer, to build what you own |
| In risk, compliance or internal audit | Internal auditor | Lead auditor, then senior lead auditor for programme scale |
| A system owner, engineer or data scientist | Foundation | Implementer, for the controls you operate |
| A function champion in legal, HR or finance | Foundation | The speciality lane for your discipline |
The direction of derivation matters, and it runs one way. The framework, the maturity model and the implementation roadmap are the body of knowledge; a credential is an examined extract from it — a defined slice, tested. That is why every article closes with a quiet Associated credentials list, ordered by the kind of work each one suits, and why no article treats a credential as a prerequisite. The guidance stands on its own. A credential is how a person demonstrates they can apply it, not how they gain access to it.
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Governing AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceWorking anywhere inside the management system and needing the shared vocabularyISO/IEC 42001 FoundationExtending the management system across sectors, borders and business unitsISO/IEC 42001 Senior Lead ImplementerRelated standards. ISO/IEC 42001 clause 7 (competence and awareness) · ISO/IEC 17024 (requirements for bodies certifying persons) · NIST AI RMF — the Govern function’s workforce elements.
Related articles. People, Functions & Capability · Foundations · Capability & culture · Phase 5 · Embed across disciplines
Choosing your path means matching credential to the layer of the framework you actually work in. Everyone starts with shared literacy; the second credential follows the decisions you make.
Training budgets get spent badly when the credential is chosen by reputation rather than by role. A board member does not need implementer depth; they need enough to ask why a reported metric should be believed and to recognise a non-answer. An engineer does not need audit competence; they need to know what evidence the build must emit.
The organising rule is that competence should sit where the decision sits. Depth concentrated in one expert who is not in the room when systems are approved produces governance that looks resourced and cannot act.
| If you are… | Start with | Then | Because |
|---|---|---|---|
| On the board or accountable executive | Foundation literacy | Governance core | You approve risk appetite and autonomy limits, and must be able to challenge what you are told |
| The AI governance lead | Governance core | Management system implementer | You own the standard, the control framework and the inventory |
| In risk, compliance or internal audit | Internal auditor | Lead auditor, then senior lead auditor | You test independently and your findings must withstand challenge |
| A system owner, engineer or data scientist | Foundation | Implementer | You operate the controls and produce all the evidence |
| A function champion in legal, HR or finance | Foundation | The speciality lane for your discipline | You translate the framework into your own workflow |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Working anywhere inside the management system and needing the shared vocabularyISO/IEC 42001 FoundationGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceProviding second-line assurance and running internal auditsISO/IEC 42001 Internal AuditorRelated standards. ISO/IEC 42001 clause 7.2 (competence) · ISO/IEC 17024.
Related articles. How the credential landscape maps to the framework · People, Functions & Capability · Capability & culture
The AI Governance Core category builds cross-domain governance judgement: scoping a programme, setting risk appetite and autonomy limits, deciding what is proportionate, and framing all of it for a governing body.
The decisions this category supports have no technically correct answer. How much autonomy is acceptable for this class of system, what depth of control is proportionate to this risk tier, whether a residual position can be defended publicly — these are judgement calls, and the cost of getting them wrong is asymmetric.
It is deliberately not a technical track. The competence it builds is the ability to interrogate a technical claim, follow the answer, and decide — which is a different skill from producing the claim.
| Credential | What it proves in framework terms |
|---|---|
| Certified Professional in AI Governance (CPAIG) | Scoping a programme, setting appetite and autonomy limits, judging proportionality, and framing AI governance for a governing body. The planned AI Governance for Directors credential extends this to board level. |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Governing AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 38507 · ISO/IEC 42001 clause 5 · ISO/IEC 17024.
Related articles. Board & Executive · The Governance Core · Choosing your path
The ISO/IEC 42001 Core category builds the competence to design, operate and audit the AI management system: six credentials from shared literacy through senior implementer and senior auditor.
This is the category that maps most directly onto a framework layer: the AI management system is what these credentials build and test. It splits into two tracks that should stay separate in the same person’s organisation — the people who implement controls should not be the people who independently audit them.
Depth follows scale rather than seniority. Senior-level credentials exist for federated implementation and portfolio-wide audit programmes, not as a reward for tenure.
| Credential | What it proves in framework terms |
|---|---|
| ISO/IEC 42001 Foundation | Shared literacy: the management system, its clauses, and the vocabulary every role needs |
| ISO/IEC 42001 Lead Implementer | Designing and operating the management system, the control set and the Statement of Applicability |
| ISO/IEC 42001 Senior Lead Implementer | Leading implementation at scale across a federated hub-and-spoke model |
| ISO/IEC 42001 Internal Auditor | Running an internal audit that finds real weakness before an assessor does |
| ISO/IEC 42001 Lead Auditor | Leading audits to an assessable standard, including certification readiness |
| ISO/IEC 42001 Senior Lead Auditor | Designing and governing an audit programme across a portfolio |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Working anywhere inside the management system and needing the shared vocabularyISO/IEC 42001 FoundationStanding up and running the AI management systemISO/IEC 42001 Lead ImplementerAuditing an AI management system independentlyISO/IEC 42001 Lead AuditorRelated standards. ISO/IEC 42001 clauses 4–10 and Annex A · ISO 19011 · ISO/IEC 42006 · ISO/IEC 17024.
Related articles. The AI management system · Risk, Assurance & Audit · Phase 6 · Assure & certify
The ISO/IEC 27001 Core category builds the information security management discipline that several AI control domains depend on — data, third parties, and secure-and-resilient behaviour.
Three AI control domains — data, third parties, and the secure-and-resilient trustworthiness characteristic — are extensions of information security practice rather than new disciplines. Organisations that already run a security management system have most of the machinery; those that do not are building two systems at once and usually discover it late.
The AI-specific additions are real: adversarial robustness, prompt and instruction injection, tool misuse, and the widened attack surface of agentic systems. But they extend a security posture rather than replacing one.
| Credential | What it proves in framework terms |
|---|---|
| ISO/IEC 27001 Foundation | The security management vocabulary and structure the AI data and third-party controls build on |
| ISO/IEC 27001 Lead Implementer | Implementing the security controls that underpin trustworthy AI, integrated with the AI management system |
| ISO/IEC 27001 Lead Auditor | Auditing the information security management system that AI assurance depends on |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Needing information-security literacy alongside AI governanceISO/IEC 27001 FoundationRunning an information security management system alongside the AI oneISO/IEC 27001 Lead ImplementerAuditing information security scopeISO/IEC 27001 Lead AuditorRelated standards. ISO/IEC 27001 and Annex A · ISO/IEC 42001 Annex A data and third-party controls · ISO/IEC 24029.
Related articles. Control domains · Foundations · Crosswalk · Accuracy, robustness and cybersecurity
The AI Governance Speciality category builds discipline-specific depth for the federated spokes: the people who translate the framework into legal, HR and financial practice inside their own function.
Phase 5 of the roadmap transfers governance from the central hub into the functions, and that transfer only works if the champion in each function has both governance literacy and domain depth. Foundation literacy alone lets somebody follow the rails; the speciality lane lets them translate the rails into their discipline’s own workflow.
These are the credentials that make the spokes real. A named champion without the competence to interpret the framework in their own domain escalates everything, which recreates the queue the federated model exists to prevent.
| Credential | What it proves in framework terms |
|---|---|
| Certified AI Law & Compliance Professional | Interpreting AI regulation and translating it into governance requirements: obligations, contracts, role determination, disclosure |
| Certified AI HR Professional | Governing AI used on employees and candidates — hiring and performance tools, oversight of decisions about people, handling a challenge |
| AI Cost & Control Professional | The cost, estimating and control discipline, including where AI spend surfaces systems nobody registered |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Cost engineering, estimating, planning and project controlsAI Cost & Control ProfessionalDelivering AI projects and programmesCertified AI Project ProfessionalHR, people and workforce functionsCertified AI HR ProfessionalRelated standards. ISO/IEC 42001 clause 7 (competence and awareness) · ISO/IEC 17024.
Related articles. People, Functions & Capability · Phase 5 · Embed across disciplines · Capability & culture