AIB-C01 Exam Prep Notes
A complete summary of the AIB-C01 exam scope, short enough to reread in the last 30 minutes before the exam. Use it as a final check after working through all four domains in the learning course and finding your weak spots with the practice questions. This exam tests strategic judgment rather than technical implementation, so read the table of question cues and answer directions and the wrong-answer patterns first.
Exam facts and approach
- As of October 2026, the exam is in beta, with 85 questions and an exam time of 170 minutes, and the start date of the standard version (130 minutes in the exam guide) has not been announced.
- The certification category is Business (separate from levels such as Foundational), and the exam is offered in English and Japanese.
- Results are reported as a scaled score from 100 to 1,000, the passing score is 700, and scoring is compensatory with no per-domain passing line.
- There are only two question types, multiple choice and multiple response; multiple response scores only when you select all correct answers, unanswered questions are scored as incorrect, and there is no penalty for guessing.
- AI Strategy and Business Value Creation carries the largest weight at 28%, and the remaining three domains are 24% each.
- The beta exam can be taken only once (if you fail, you retake it as the standard version).
- No official practice exam is offered during the beta period, so get used to the format with the official practice question set.
- This exam tests strategic judgment rather than technical implementation, and developing models or algorithms, tuning hyperparameters, and configuring AWS services are out of scope.
- Know Amazon Bedrock, Amazon SageMaker AI, and Amazon Quick at a business level, and also cover AWS CAF, the shared responsibility model, pricing models and cost tools, and AWS Marketplace.
Question cues and the right answer
| Cue in the question | Direction of the answer |
|---|---|
| Fastest, least operational effort, work that does not need differentiation | Buy (off-the-shelf products, AWS Marketplace) and managed services |
| Expertise is lacking, the timeline is limited, you want to transfer skills | Partner |
| Core differentiation, proprietary data, strict regulations | Build on Bedrock or SageMaker AI |
| Rules are clear, a complete explanation is required, errors are not acceptable | Rule-based automation (do not use AI) |
| You want up-to-date answers and sources based on internal documents | RAG |
| You want to align tone, formatting, or behavior in a specialized field | Fine-tuning |
| The first step when answer quality is low | Improve the prompt |
| You want to prove the effect and keep the budget | A pre-adoption baseline, business KPIs, and ROI that includes operating costs |
| You want to foresee success or failure at an early stage | Leading indicators: usage rate (adoption rate), usage frequency, satisfaction, data readiness |
| Usage fluctuates widely, is sporadic, or is at the PoC stage | Consumption-based pricing where you pay only for what you use (Bedrock on-demand) |
| Steady, high-volume usage with predictable volume | Instance-based pricing or Provisioned Throughput with long-term commitments |
| You want to forecast costs by the number of users | Per-seat pricing (Amazon Quick) |
| You want to lower the cost of processing that need not be immediate and can wait | Bedrock Flex or batch inference (discounted) |
| You want to prioritize response speed even at a somewhat higher price | Bedrock Priority |
| You want a discount on long-term use of SageMaker AI | Savings Plans |
| You want to estimate costs before adoption and visualize them after adoption | AWS Pricing Calculator and AWS Cost Explorer |
| Credit, hiring, healthcare, legal matters, safety, operations that cannot be undone | Human oversight, explainability, and auditing |
| Harmful output, prohibited topics, personal information, attacks on prompts | Amazon Bedrock Guardrails |
| You want to decide how strict governance should be | Risk classification (controls proportional to risk) |
| Who is accountable for AI decisions | A cross-functional governance committee and clear accountability |
| Unapproved AI tools are being used (shadow AI) | Publish a list of AI tools classified as approved, blocked, or under evaluation, and provide alternatives and training |
| International standard and certification for AI management systems | ISO/IEC 42001 (ISO/IEC 23053 is the framework for AI systems that use ML) |
| When to consider responsible AI | From the planning stage, at every stage |
| When to check for bias | Monitor continuously at every stage of the lifecycle |
| The next step that fits your current position | Measure your position with a maturity model first, then choose |
| Data is scattered across departments | Break down silos, data owners on the business side, a data catalog |
| Momentum fades and departments are fragmented | Executive sponsors, leadership alignment, and appointing champions |
| The front line resists and fears failure | Early involvement, safe spaces for experimentation, transparent communication, reskilling |
| You want to raise AI literacy across the company | Role-based training, responsible AI training, PoCs and hackathons |
| What to do after the pilot | Build reusable foundations from short-term wins and expand across the company |
| The PoC works, so you want to move to production | Put governance, monitoring, an operating structure, SLAs, and cost management in place |
| How to carry out the transformation | Iterate through the envision, experiment, launch, and scale phases |
| You want users to know they are talking with AI | Transparency (disclosing that it is AI) |
Wrong-answer patterns
- Rule out options that roll out across the whole company at once.
- Rule out options that add governance after deployment.
- Rule out options that adopt without measuring, or that take the baseline after adoption.
- Rule out options that train a foundation model from scratch in-house.
- Rule out options in which the IT department decides alone without involving executives.
- Rule out options in which the technical team only builds something and hands it over to the front line.
- Rule out options that apply AI to a problem that does not need AI.
- Rule out options that leave pilots unattended or rebuild from zero every time.
- Rule out both options that remove humans entirely and options in which humans review every case.
- Rule out options that deal with shadow AI with a total ban.
- Rule out options that sign large long-term contracts from the start.
- Rule out options that buy facilities such as GPUs up front.
- Rule out options that use model accuracy directly as a KPI.
- Rule out options that calculate ROI without including operating costs.
- Rule out options that claim hiring a large number of data scientists will solve the problem.
- Rule out options that make an announcement while keeping the impact on employees hidden.
- Rule out options whose answer is a technical detail such as IAM policies or encryption key settings, because they are out of scope.
Key points by domain
Domain 1 AI Fundamentals and Literacy (24%)
- ML and deep learning sit within AI, and generative AI is the field that creates content such as text and images.
- An algorithm is the procedure for learning, a model is the product of training, and inference is the process of using the model; day-to-day costs arise from inference.
- Structured data is tables and unstructured data is text and images; because AI learns from past data, quality determines the results, and past biases are carried over too.
- ISO/IEC 22989 covers AI concepts and terminology, ISO/IEC 23053 is the framework for AI systems that use ML, and ISO/IEC 42001 is the certifiable standard for AI management systems.
- Choose rule-based automation when the rules are clear and explanation and accuracy are essential, and AI when there are many exceptions and the work is complex; AI is also unsuitable when there is no data or the cost exceeds the benefit.
- AI agents have autonomy, tool use, collaboration between agents, and orchestration, and unlike chatbots that only answer, they take actions.
- AI in production suffers model drift, in which performance declines as data and assumptions change, so keep monitoring and updating it.
- Publishing AI tools classified as approved, blocked, or under evaluation lowers the risk of shadow AI.
- Write the role, context, instructions, and output format specifically in prompts; exceeding the token limit or the context window lowers answer quality.
- To improve answers, consider prompt improvements first, then RAG (adding knowledge), then fine-tuning (aligning behavior).
Domain 2 AI Strategy and Business Value Creation (28%)
- Look for use cases department by department, such as customer service, sales and marketing, research and development, and software development, and tie AI capabilities to concrete business outcomes.
- Decide to build, buy, or partner based on budget, timeline, internal capabilities, vendor proposals, and regulatory compliance, and give priority to managed services and off-the-shelf products in areas that do not differentiate you.
- Rank initiatives by business value, feasibility, sustainability, and strategic alignment, and decide whether to scale, pause, or end them.
- When moving work to AI or switching AI platforms, check business continuity, changes in cost, data readiness, and the impact on performance.
- KPIs include tangible benefits (cost reduction, revenue growth) and intangible benefits (customer satisfaction, employee productivity), and technical metrics such as accuracy are translated into business outcomes before being measured.
- Measure the baseline before adoption; ROI is the value of the benefits obtained minus the cost, divided by the cost, and the cost includes operating costs for inference, monitoring, retraining, and governance.
- Leading indicators are usage rate (adoption rate), usage frequency, satisfaction, and data readiness, while revenue and ROI are lagging indicators that appear later.
- The representative pricing models are consumption-based, instance-based, and per-seat, and you start small, measure actual usage, and then move to long-term commitments.
- Set the level of investment according to industry maturity and competitors' moves, and build a sustainable advantage through proprietary data and integration into business processes.
- Opportunities to change the business model with AI lie in embedding AI into products, shifting to service-based offerings, and new services that make use of data.
- For simple uses, choosing a small model whose quality is sufficient for the use, and so reducing cost and response time, is the basis of cost optimization.
Domain 3 AI Governance and Responsible AI Leadership (24%)
- AWS's eight dimensions of responsible AI are fairness, explainability, privacy and security, safety, controllability, veracity and robustness, governance, and transparency.
- When business objectives conflict with responsible AI principles, decide on the trade-off based on who is affected and the level of risk, and keep a record of that decision.
- Build responsible AI in from the planning stage rather than after deployment, and apply governance at the design stage.
- The representative patterns of human oversight are approval before execution, monitoring and intervening in automated execution, and full automation only for low-risk routine tasks, and the representative safeguards are hallucination detection, guardrails, escalation criteria, audit records, and a means of stopping.
- Build the governance structure across business, technology, legal, and compliance functions, and make clear who holds accountability.
- Risk classification sets tiers based on who is affected, severity, whether outcomes can be undone, the degree of automation, data sensitivity, and regulation, with stronger controls the higher the risk.
- Examples of regulations and frameworks are the EU AI Act (prohibited, high risk, limited, minimal), the NIST AI RMF (GOVERN, MAP, MEASURE, MANAGE), and ISO/IEC 42001.
- In the shared responsibility model, AWS protects the cloud infrastructure and the environment that provides foundation models, and customers are responsible for data, prompts, access permissions, guardrail settings, and how outputs are used.
- Bias enters at multiple stages of the lifecycle, so continuously monitor for bias drift.
- Curb harmful content with guardrails, intellectual property risks with output review and usage policies, and reliability risks such as hallucination, degraded data quality, and model drift with production monitoring and checking the grounds of answers.
Domain 4 Business Readiness, Leadership, and AI Transformation (24%)
- Measure readiness by representative dimensions such as leadership alignment, data quality, cultural readiness, technical infrastructure, and governance frameworks.
- Use a maturity model to measure where you are between the experimentation stage and enterprise-scale deployment, and choose the next step that fits your current position.
- Identify gaps in four areas (people, process, technology, and governance), and decide the order of investment in line with strategic goals and maturity.
- Measure data readiness by quality, ease of access, and the impact of silos; a data strategy, data owners on the business side, and a sharing framework form the foundation.
- Align executive sponsors and leaders, and appoint champions to sustain momentum across the company.
- Communicate the timing of adoption, the expected outcomes, and changes in roles transparently, and leaders address cultural barriers such as risk aversion, resistance to change, and fear of failure.
- Raise AI literacy across the company by combining PoCs, hackathons, training, and responsible AI training.
- Shift human roles from manual work to overseeing and collaborating with AI, and leave critical thinking, empathy, and creativity to people.
- Scale by iterating through the envision, experiment, launch, and scale phases, moving from short-term wins to enterprise-wide deployment, with a CoE supporting cross-functional collaboration.
- When moving from experiment to production, put in place governance and operational requirements, continuous feedback, and success metrics, and keep checking business continuity and performance.
- AWS CAF is a framework for preparing the company-wide adoption of cloud and AI from six perspectives: Business, People, Governance, Platform, Security, and Operations.
Services in one line
| Name | In one line |
|---|---|
| Amazon Bedrock | A generative AI platform for using off-the-shelf foundation models through an API |
| Amazon Bedrock Guardrails | Stops harmful output, prohibited topics, and personal information |
| Amazon Bedrock Knowledge Bases | Build RAG on your own data |
| Amazon SageMaker AI | Build, train, and operate your own ML models |
| Amazon Quick | AI assistant and analytics for business users (per-seat pricing) |
| AWS CAF | A framework for planning and scaling company-wide adoption of AI and the cloud |
| Shared responsibility model | AWS is responsible for the cloud infrastructure, and customers for the data and settings in the cloud |
| Responsible AI Lens | A collection of responsible AI best practices in Well-Architected |
| AWS Marketplace | Procurement of third-party products, models, and agents with consolidated billing |
| AWS Pricing Calculator | Cost estimates before adoption |
| AWS Cost Explorer | Cost visibility and analysis after adoption |
| Savings Plans | Discounts the cost of SageMaker AI and other services in exchange for long-term commitments (as of October 2026, Bedrock is not covered) |
| Consumption-based pricing | Pay only for what you use (Bedrock on-demand) |
| Instance-based pricing | Pay by the hour for reserved capacity (SageMaker AI, Provisioned Throughput) |
| Per-seat pricing | Pay by the number of users (Amazon Quick) |
| Bedrock pricing tiers | As of October 2026, Standard / Flex / Priority / Reserved, among others. Flex makes processing that tolerates delays cheaper, Priority prioritizes response speed, and Reserved reserves throughput in tokens per minute |
Top 15 traps
- Transforming the business model with AI is not only about making existing work more efficient; it also includes embedding AI into products and shifting to service-based offerings.
- Intellectual property risk is not left to the legal department alone; it is also curbed within business operations through output review and usage policies, and it is considered separately from the guardrails that stop harmful content.
- Migrating AI platforms is not decided by comparing features alone; check the impact on business continuity, cost, data, and performance.
- Time saved is not a benefit in itself; it becomes a benefit only when redirected to other valuable work.
- As of October 2026, Savings Plans discounts cover SageMaker AI; Bedrock costs are lowered with batch inference, Flex, and Provisioned Throughput or Reserved, and Priority costs more than Standard. Flex is a tier for synchronous processing called one request at a time that tolerates delays; for large asynchronous volumes sent in bulk, choose batch inference.
- Using AI for a process with clear rules is a wrong answer; choose rule-based automation.
- Reflecting new knowledge is done with RAG, and fine-tuning is a means of aligning behavior.
- Even when AWS provides the foundation model, guardrail settings and how outputs are used are the customer's responsibility, not AWS's.
- Leading indicators are not a substitute for revenue; they are indicators for foreseeing success or failure before the lagging indicators appear.
- Checking for bias is not a one-time check before training; it continues at every stage of the lifecycle.
- A setup in which management approves everything does not scale, so delegate authority from a cross-functional committee according to the risk tier.
- A step that does not fit your maturity (an enterprise-wide rollout at the experimentation stage) is a wrong answer; build the foundation and pursue short-term wins in parallel.
- Data ownership lies with the business side, not the IT department, and silos are broken down before AI.
- A working PoC alone is not production; it becomes production once governance, monitoring, an operating structure, SLAs, and cost management are in place.
- A CoE is not a department that builds everything; it is an enabler that supports each department (hub and spoke).
Last-minute checklist
- I can state the number of questions, the exam time, the passing score, and the difference in exam time between the beta and standard versions.
- I can name the four domains and their weights.
- I can name the two question types and explain how multiple response is scored.
- I can name three tasks that are out of scope.
- I can name three AWS services to know at a business level and what each is used for.
- I can explain the differences between an algorithm, a model, training, and inference.
- I can name three conditions for choosing rule-based automation.
- I can name four characteristics of AI agents.
- I can name the three classifications used to counter shadow AI.
- I can explain when to use RAG versus fine-tuning, and the order in which to consider improvements.
- I can explain the different roles of ISO/IEC 22989, 23053, and 42001.
- I can name four factors for build, buy, or partner decisions.
- I can name four viewpoints for deciding whether to scale, pause, or end an initiative.
- I can name two tangible benefits and two intangible benefits.
- I can explain how ROI is calculated and the operating costs included in the cost.
- I can name three leading indicators.
- I can name the representative pricing models and the situations each suits.
- I can name the eight dimensions of responsible AI.
- I can name the representative patterns of human oversight and the situations each suits.
- I can name four safeguards to combine with human oversight.
- I can name four axes of risk classification.
- I can name the four tiers of the EU AI Act and the four functions of the NIST AI RMF (GOVERN / MAP / MEASURE / MANAGE).
- I can name four responsibilities that customers bear in the shared responsibility model.
- I can name the representative dimensions of readiness.
- I can name the four areas for identifying gaps.
- I can name three cultural barriers and the measures leaders take.
- I can name the four phases of transformation in order.
- I can state the role of a CoE in one sentence.
- I can name four things to put in place before moving from PoC to production.