AIGP Practice Questions
Prepare for AIGP with more than an answer.
- Level
- Professional
- Valid for
- 2 years
Domains covered on the exam 4
- Understanding the foundations of AI governance
- Understanding how laws, standards and frameworks apply to AI
- Understanding how to govern AI development
- Understanding how to govern AI deployment and use
- 1
A core principle of the OECD's framework for trustworthy AI is 'Accountability'. In practice, what does this principle require an organization to do?
Show answer details
Correct answer: C
The OECD principle of 'Accountability' centers on the idea that organizations and individuals responsible for AI systems should be answerable for their proper functioning in line with the other principles. This involves having identifiable roles and responsibilities, clear governance structures, and the ability to demonstrate that responsible measures were taken throughout the AI lifecycle. It is not about making code public or achieving perfection (which is impossible), but about taking responsibility for the system's operation and outcomes.
- 2
Which of the following scenarios would be considered a 'prohibited' AI practice under Article 5 of the EU AI Act?
Show answer details
Correct answer: B
Article 5 of the EU AI Act explicitly prohibits certain AI practices deemed to pose an unacceptable risk. This includes AI systems used by public authorities for the purpose of social scoring, which leads to detrimental treatment of individuals or groups. Credit scoring is high-risk but not prohibited. Biometric identification by law enforcement is high-risk and has strict conditions but is not entirely prohibited. Emotion recognition in the workplace is also prohibited, but social scoring by governments is one of the clearest and most cited examples of a prohibited practice.
- 3
A key activity in governing AI development is the creation of a 'model card'. What is the primary purpose of this document?
Show answer details
Correct answer: B
A model card is a document that provides transparency and context about a machine learning model. Its primary purpose is to clearly communicate key information to stakeholders, including performance metrics (often disaggregated by subgroups), fairness evaluations, intended use cases, and known limitations or out-of-scope uses. It is a critical tool for responsible AI governance, not a legal contract, a project plan, or a security certificate.
- 4
True or False: Using synthetic data to train an AI model completely eliminates the risk of perpetuating societal biases.
Show answer details
Correct answer: B
This statement is false. While synthetic data can be a powerful tool to mitigate bias (e.g., by creating a more balanced dataset), it does not automatically eliminate it. The generative model used to create the synthetic data is itself trained on real-world data and can inherit and replicate the biases present in that original data. If not carefully governed, synthetic data generation can inadvertently embed or even amplify existing biases.
- 5
An organization is implementing an AI governance program based on the core functions of the NIST AI Risk Management Framework (RMF). They are currently focused on establishing a culture of risk management and defining roles and responsibilities. Which function of the RMF are they primarily engaged in?
flowchart LR A(GOVERN) --> B(MAP) B --> C(MEASURE) C --> D(MANAGE) A -.-> C A -.-> DShow answer details
Correct answer: D
The 'GOVERN' function is the cross-cutting foundation of the NIST AI RMF. It is specifically tasked with establishing the overall risk management culture, defining roles and responsibilities, creating policies, and ensuring accountability across the entire AI lifecycle. The other functions—MAP (contextualizing risks), MEASURE (testing and evaluation), and MANAGE (allocating resources to mitigate risks)—all rely on the foundation established by the GOVERN function.
- 6
A financial services company based in Canada is deploying a high-risk credit scoring AI system that will process applications from EU citizens. The company is already compliant with PIPEDA. To comply with the EU AI Act, which of the following represents the MOST critical additional governance requirement for them as a 'provider'?
Show answer details
Correct answer: B
While PIPEDA and GDPR (which would also apply) have stringent data protection requirements, the EU AI Act introduces a product safety framework for high-risk AI systems. As a 'provider' placing a high-risk system on the EU market, the company must conduct a conformity assessment to demonstrate compliance with the Act's requirements and affix a CE marking, similar to other regulated products. Appointing an EU representative is necessary, but the conformity assessment is the core procedural requirement for market entry. Data processing agreements and DPIAs are GDPR requirements, which are related but distinct from the AI Act's conformity process.
- 7
An AI development team is building a model to predict equipment failure in a factory. They are in the process of establishing data provenance for their training dataset. Which THREE of the following activities are essential for this process? (Select THREE)
Show answer details
Correct answer: A, C, D
Data provenance requires a detailed audit trail of the data's entire lifecycle. This includes its origin, any transformations, and its final state. Recording the origin (e.g., sensor IDs), the transformations (including software versions, as different versions can produce different results), and cryptographic hashes to ensure integrity are all critical components. The cost of storage is an operational metric, not a part of data provenance. The model's final accuracy is a performance metric derived from the data but not part of the data's history itself. The names of the engineers are part of project management, not the technical data lineage.
Data provenance requires a detailed audit trail of the data's entire lifecycle. This includes its origin, any transformations, and its final state. Recording the origin (e.g., sensor IDs), the transformations (including software versions, as different versions can produce different results), and cryptographic hashes to ensure integrity are all critical components. The cost of storage is an operational metric, not a part of data provenance. The model's final accuracy is a performance metric derived from the data but not part of the data's history itself. The names of the engineers are part of project management, not the technical data lineage.
Data provenance requires a detailed audit trail of the data's entire lifecycle. This includes its origin, any transformations, and its final state. Recording the origin (e.g., sensor IDs), the transformations (including software versions, as different versions can produce different results), and cryptographic hashes to ensure integrity are all critical components. The cost of storage is an operational metric, not a part of data provenance. The model's final accuracy is a performance metric derived from the data but not part of the data's history itself. The names of the engineers are part of project management, not the technical data lineage.
- 8
A large multinational corporation has a centralized AI ethics board but allows individual business units to develop and deploy their own AI applications. This has led to inconsistent application of corporate AI principles and duplicated risk assessment efforts. To address this, the Chief AI Governance Officer proposes a 'hub-and-spoke' governance model. What is the primary advantage of this model in this scenario?
Show answer details
Correct answer: C
A hub-and-spoke model (also known as a federated model) is designed to solve this exact problem. The central 'hub' (the corporate AI governance office) sets the policies, standards, and provides expertise. The 'spokes' (embedded AI governance leads within business units) execute these policies in a way that is tailored to their specific context. This structure ensures consistency and efficiency (from the hub) while maintaining business unit agility and domain-specific knowledge (at the spokes). It does not completely centralize development nor does it make units fully autonomous.
- 9
During a post-deployment audit of an AI-powered recruitment tool, it was discovered that the system disproportionately rejects qualified candidates from a specific demographic group for technical roles. The model was trained on the company's historical hiring data. This is a classic example of which type of AI risk?
Show answer details
Correct answer: C
This scenario describes ethical and bias risk, specifically amplification of historical bias. The AI model learned patterns from past hiring data, which likely contained societal or organizational biases. The model is now perpetuating and potentially amplifying this bias, leading to discriminatory outcomes. Model drift refers to performance degradation over time as data distributions change. Brittleness refers to a model failing on inputs slightly different from its training data. Lack of robustness is a general term for susceptibility to errors or attacks.
- 10
Case Study
A healthcare provider, 'WellCare,' wants to deploy a third-party, cloud-hosted AI model that analyzes medical images to detect early signs of a specific disease. The AI vendor claims a 98% accuracy rate in their lab tests. WellCare's patient population has a significantly different demographic and genetic makeup compared to the population used for the vendor's training data. The vendor's contract has a strict limitation of liability clause and does not provide access to the model's internal logic or full training dataset, citing intellectual property concerns.
WellCare's AI Governance Council is reviewing the deployment decision. The primary business objective is to improve patient outcomes by catching the disease earlier. However, the legal team is concerned about potential misdiagnoses and the associated liability. The IT department is concerned about data security, as patient images will be processed by the third-party vendor.
Which of the following is the MOST critical governance activity for WellCare to perform before signing the contract and deploying the model?
Show answer details
Correct answer: C
Given the mismatch between the vendor's training data and WellCare's patient population, the claimed 98% accuracy is unreliable for their specific use case. The most critical step is to validate the model's actual performance and fairness on their own data. This pre-deployment pilot or testing will quantify the real-world risk of misdiagnosis and bias. While negotiating liability, ensuring data security, and creating a human-in-the-loop process are all vital governance steps, none are as fundamental as first determining if the model is safe and effective for its intended population. Without this validation, the other controls are meaningless.
