Create AI-specific governance requirements: Before expansion, which approach best addresses both constraints?
The legacy policy and incomplete provenance evidence require AI-specific governance requirements before expansion.
The question
A school district uses a vendor-hosted admissions assistant under a legacy security policy covering access controls but not model changes, training data, or supplier responsibilities. Evidence about data provenance is incomplete. Before expansion, which approach best addresses both constraints?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Apply the legacy access policy to deployment.Existing access controls address one security dimension but do not resolve model-change governance, supplier accountability, or data provenance gaps.
- Require additional student-data encryption controls.Encryption can reduce confidentiality risk, but it does not establish model governance or demonstrate that training data is appropriate and traceable.
- Create AI-specific governance requirements. ✓AI-specific requirements can assign supplier responsibilities and require provenance evidence where the legacy policy leaves material gaps.
- Obtain a vendor security certification.Certification may provide scoped evidence, yet it cannot replace requirements for provenance, responsibilities, and use-case-specific supplier assessment.
The trap
When multiple AI-specific gaps remain, choose the control that closes both governance and evidence deficiencies rather than one technical subset. How to remember it
The legacy policy and incomplete provenance evidence require AI-specific governance requirements before expansion.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Require advance supplier change notification: Which contract term best satisfies that constraint? →
- Add event-based review triggers alongside annual review: Which trigger design is strongest? →
- The approved purpose and input-data scope: Which original approval assumption must be reopened? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.