AIGP Sample Questions & Answers
Ground runs from why AI needs governance and setting organizational policy, to how privacy and other existing laws, plus the EU AI Act, apply, overseeing how a model gets designed and trained, plus deciding when and how to deploy it.
Launch the full AIGP simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Understanding how laws, standards and frameworks apply to AI · Understand the main industry standards and tools that apply to AI
True or False: According to the NIST AI Risk Management Framework (RMF), the 'GOVERN' function is primarily focused on post-deployment monitoring and measurement of AI system performance.
Show answer & explanation
Correct answer: B
This statement is false. The 'GOVERN' function is a cross-cutting function that applies throughout the AI lifecycle. It is about cultivating a risk management culture, establishing processes, and providing the overarching structure for risk management. Post-deployment monitoring and measurement are primarily addressed within the 'MANAGE' and 'MEASURE' functions of the NIST AI RMF.
- Question 2Advanced
Understanding the foundations of AI governance · Identify and apply the common principles of responsible AI
An insurance company uses an AI model to detect fraudulent claims. The model is a complex deep learning system, making its decisions difficult to interpret. To meet the 'explainability' principle of responsible AI, the company uses SHAP (SHapley Additive exPlanations) to generate a report for each decision, highlighting the top three factors that contributed to the outcome. This approach is an example of which type of explainability?
Show answer & explanation
Correct answer: B
This is an example of post-hoc explainability. The AI model itself is a 'black box' (a complex deep learning system). Techniques like SHAP or LIME are applied after the model makes a prediction to approximate and explain its behavior for a specific instance. Intrinsic explainability, by contrast, comes from using models that are inherently simple and understandable, such as linear regression or decision trees. Global explainability describes the model's overall behavior, while local explainability (which SHAP provides) explains individual predictions.
- Question 3Intermediate
Understanding how to govern AI deployment and use · Govern the deployment and use of the AI model
A retail company deploys a generative AI chatbot for customer service. To improve performance, they decide to fine-tune the base model using transcripts of their own customer service calls. From a governance perspective, what is the MOST significant new risk introduced by this fine-tuning process?
Show answer & explanation
Correct answer: B
While all options are considerations, the most significant governance risk is data privacy. Customer service transcripts are rich with PII (names, addresses, account numbers). Fine-tuning on this data creates a high risk that the model will 'memorize' this sensitive information and could potentially reveal it in responses to other users' queries. This is a major privacy breach and liability issue. Increased cost is a business concern, model collapse is a technical risk, and vendor lock-in is a strategic risk, but the PII disclosure risk is the most acute and immediate governance failure.
- Question 4Intermediate
Understanding how to govern AI development · Govern the designing and building of the AI model
An AI governance professional is reviewing the design of a new AI model intended for a high-risk application. They are applying the 'risk mitigation hierarchy' as part of their assessment. According to this principle, what should be their first consideration?
Show answer & explanation
Correct answer: B
The risk mitigation hierarchy, a standard concept in safety and risk management, prioritizes controls from most to least effective. The highest priority is always elimination—designing the system so the hazard cannot occur in the first place. If elimination is not possible, the next steps are substitution, engineering controls, administrative controls, and finally, personal protective equipment (or its equivalent). Therefore, the first consideration should be if the risk can be designed out of the system entirely.
- Question 5Intermediate
Understanding how laws, standards and frameworks apply to AI · Understand the main elements of the EU AI Act
A city's transportation authority plans to use an AI system to optimize traffic light timing. The system uses real-time camera feeds from intersections. Under the EU AI Act's risk classification framework, which category would this system MOST likely fall into?
Show answer & explanation
Correct answer: B
According to Annex III of the EU AI Act, AI systems intended to be used as safety components in the management and operation of road traffic are classified as high-risk. Optimizing traffic light timing directly impacts road safety, and therefore falls into this category. It is not prohibited (like social scoring), does not merely have transparency obligations (limited-risk), and is not considered minimal risk due to its direct impact on public safety.
- Question 6Intermediate
Understanding how laws, standards and frameworks apply to AI · Understand the main elements of the EU AI Act
A company is conducting a conformity assessment for its high-risk AI system under the EU AI Act. Which of the following is NOT a mandatory component of the technical documentation they must prepare?
Show answer & explanation
Correct answer: B
The EU AI Act (Article 11 and Annex IV) specifies detailed requirements for technical documentation. These include descriptions of the AI system, its data, performance metrics, risk management system, and instructions for use. However, it does not mandate the inclusion of personal information like the CVs of the development team. The focus is on the system's characteristics and governance, not the personal qualifications of the individuals who built it.
- Question 7Intermediate
Understanding how to govern AI development · Govern the release, monitoring and maintenance of the AI model
A social media company develops a new AI feature to summarize long text posts. During pre-deployment testing, the 'red team' discovers that by crafting a specific type of input, they can cause the summarizer to generate offensive and harmful content, even if the original post was benign. From a governance standpoint, this vulnerability is primarily a failure in which model property?
Show answer & explanation
Correct answer: C
Robustness refers to an AI system's ability to maintain its level of performance and safety under a variety of circumstances, including unexpected or adversarial inputs. The 'red team's' discovery of a crafted input that causes harmful output is a classic example of a lack of robustness against adversarial attacks. While accuracy (correctness on normal inputs) and interpretability (understanding decisions) are important, this specific failure mode directly relates to the model's inability to handle malicious inputs safely.
- Question 8AdvancedSelect 2
Understanding how laws, standards and frameworks apply to AI · Understand how existing data privacy laws apply to AI
The 'right to an explanation' for automated decisions under Article 22 of the GDPR poses a significant challenge for complex AI systems. An AI governance program must establish policies to address this. Which TWO of the following measures would be most effective in helping an organization meet this obligation? (Select TWO)
Show answer & explanation
Correct answers: A, C
Meeting the 'right to an explanation' requires a multi-faceted approach. Using intrinsically interpretable models is the most direct way to ensure decisions can be explained. For complex 'black box' models, implementing post-hoc explanation techniques (like LIME/SHAP) and training staff to translate those technical outputs into meaningful, human-understandable language is essential. Simply providing raw data or source code does not constitute a meaningful explanation. Relying solely on data subject consent may not be sufficient if the explanation itself cannot be provided upon request.
Meeting the 'right to an explanation' requires a multi-faceted approach. Using intrinsically interpretable models is the most direct way to ensure decisions can be explained. For complex 'black box' models, implementing post-hoc explanation techniques (like LIME/SHAP) and training staff to translate those technical outputs into meaningful, human-understandable language is essential. Simply providing raw data or source code does not constitute a meaningful explanation. Relying solely on data subject consent may not be sufficient if the explanation itself cannot be provided upon request.
- Question 9Intermediate
Understanding how to govern AI development · Collaborate with cross-functional stakeholders to understand why incidents arise from AI models
After six months in production, the performance of an AI model that predicts customer churn has degraded significantly. An investigation reveals that a new marketing campaign has attracted a different type of customer whose behavior does not match the patterns in the original training data. This issue is best described as:
Show answer & explanation
Correct answer: B
This scenario is a textbook example of data drift. Data drift occurs when the statistical properties of the input data to the model change over time, making the original patterns learned during training less relevant. The new marketing campaign changed the input data distribution (the type of customer). Concept drift, in contrast, is when the relationship between the input data and the target variable changes (e.g., the reasons why customers churn change). Overfitting is a training-time issue, not a post-deployment one.
- Question 10Advanced
Understanding how to govern AI deployment and use · Govern the deployment and use of the AI model
Case Study
'Innovate Corp,' a technology startup, has developed a proprietary generative AI model for code generation. They decide to deploy this model internally to assist their own developers. There is no external customer access. The legal department advises that while the EU AI Act may not directly apply to this purely internal use case yet, adopting a robust governance framework is still a critical risk management activity. The development team is small and agile, and they are concerned that a heavy governance process will slow down innovation.
The Head of AI Governance is tasked with creating a lightweight but effective governance plan for this internal deployment. They need to prioritize activities that provide the most significant risk reduction without creating excessive bureaucracy. The primary risks identified are the generation of insecure or non-compliant code and the potential for the model to leak proprietary information it was trained on.
What is the most appropriate first step in governing the deployment and use of this internal AI model?
Show answer & explanation
Correct answer: C
For an internal tool in an agile environment, the most effective and lightweight first step is to establish clear rules and empower the users. An AUP sets the boundaries for use, while practical training ensures developers understand the risks (like generating insecure code) and their non-negotiable duty to act as the human-in-the-loop, validating all outputs. This addresses the primary risks through administrative controls and user empowerment, which is less bureaucratic than immediately procuring new tools, less theoretical than a long training course, and more foundational than creating a complex monitoring dashboard before usage patterns are even established.
Ready for the real thing?
The full AIGP simulator has every exam-style question, timed mode, and instant scoring.