Why the Association exists

A professional home for the people responsible for digital trust, and a way to make trust governance learnable outside the job.

Most people learned this work by being handed it

Privacy arrived with a regulation. Vendor risk arrived with a questionnaire. AI governance arrived with a policy nobody had written yet. Audit readiness arrived with a customer who would not sign without it. Very few people entered this work deliberately, and fewer still were trained for it before it became their responsibility.

That produces a specific and under-discussed problem. Capability developed entirely inside one organisation is shaped by what that organisation needs, and it stops where the employer's requirements stop. A practitioner can spend years becoming genuinely skilled and still find the skill has no standing anywhere else, because nothing outside the company recognises it.

The Association exists to change that. Our purpose is to make trust governance learnable outside the job, so that professional capability belongs to the practitioner rather than to the employer. This has become more urgent rather than less. As automation and AI reshape technical roles, the professionals most exposed are those whose capability is legible only inside one organisation.

What we mean by trust governance

Trust governance spans seven strands: privacy, security, risk, compliance, third-party oversight, AI governance, and trust and assurance.

The Association does not treat these as one discipline. They are distinct fields with their own literatures and their own expert communities. What they increasingly share is a practitioner, and a set of operating problems that look the same regardless of which strand produced them: deciding what an obligation actually requires, translating it into controls and operating practice, producing evidence that it is working, and defending the decision to someone whose role is to question it.

That common practice is what the Association organises around.

Practice, not recall

Most professional qualifications in this field test knowledge of frameworks. That is not a criticism of their rigour; it is a description of their design. A single syllabus that must serve a security engineer, an internal auditor and a privacy manager has to stay broad, and breadth is genuinely useful. It gives a shared vocabulary and a common baseline, and many of our members hold those qualifications and value them.

But breadth has a limit. A practitioner can hold a respected qualification and still be uncertain how to scope a system boundary, or what to do when the evidence a control produces will not survive testing. The gap is practice, not knowledge.

So the curriculum is organised around responsibilities rather than frameworks, and around artefacts rather than recall. Each course is written against two realities, the early-stage version and the enterprise version, because the same obligation is met differently at forty people and at four thousand. The standard we hold ourselves to is whether a member could put the work into practice on Monday.

A professional home

There is a second reason the Association exists, and it is less technical. Accountants have a professional home. Auditors have one. Engineers have one. The professional carrying privacy, vendor risk, AI governance and audit readiness across a single portfolio has generally had to borrow standing from a qualification built for someone whose work looks nothing like theirs.

A profession provides more than training. It provides a definition of the work, a standard of practice, a means of demonstrating capability, and a community that recognises what the work involves. Trust governance has had the responsibility without the structure. Establishing that structure is what the Association is for.

How we distinguish recognition

The Association separates four things deliberately. Participation is engaging with our public resources. Membership is belonging to the Association. A course certificate records completed learning. A professional credential demonstrates capability against published requirements and requires examination.

Membership provides the professional home. Credentials must be earned.

We state this plainly because the distinction is what gives professional recognition its value. An organisation that blurs it may grow faster in the short term and is worth less to its members in the long one.

What the Academy holds today

The curriculum is built in waves and published as each part is ready. Today it stands at 74 courses organised by responsibility, 14 exam pathways for the certifications practitioners are actually asked for (CISSP, CISM, CISA, CRISC, CCSP, Security+, the ISO 27001 and 42001 lead roles, the IAPP privacy credentials, AIGP and others), each with a current blueprint, flashcards and diagnostic questions by domain, and timed readiness checks scored against the pass standard.

Around the courses sit 289 DeepDive articles free to read, a glossary of 972 terms drawn from the same library, 4,880 flashcards and 3,335 practice questions across the pathways, 45 policy and standard templates ready to adopt, and 4 practitioner advisories from continuous threat monitoring. The daily campaigns (Speak to It, Card Drop, One Question, Before You Book, DeepDive) draw from this same material, so what reaches a member's inbox is the curriculum, not a summary of it.

Explore the Academy · Exam pathways · DeepDive · Glossary

How the Association operates

Credentials are earned by assessment and verifiable by anyone, without asking the holder or us, because a paper token nobody can check is worth what it costs to print.

We publish what we can deliver today. Benefits that require a scale we have not yet reached are not promised until they exist.

Open where it should be

A common professional vocabulary should not depend on someone's ability to pay. These are published openly.

What membership adds

The full curriculum and exam pathways, the artefact and policy templates, and the member credential platform.

Credentials are earned

ADTP professional credentials require examination. No membership tier confers one.

Verifiable

Certificates and credentials resolve to a public verification page, checkable by anyone without asking the holder or the Association.