An audit, in which an independent reviewer systematically: Which periodic assessment activity best fits this
An independent audit provides objective assurance that the system still complies with documented policies and controls.
The question
A regulated insurer must periodically demonstrate to its board that a deployed underwriting model still operates within documented policies and controls, with objective evidence gathered by someone independent of the model team. Which periodic assessment activity best fits this need?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Red teaming, in which testers adversarially attack the system to discover exploitable safety and security failures before real malicious actors do so.Plausible as a listed assessment, but red teaming probes adversarial failures rather than verifying compliance with documented controls for the board.
- Threat modeling, in which the team maps assets and attacker goals to prioritize where security weaknesses are most likely to arise.Plausible and related, but threat modeling is a security-planning exercise, not independent assurance of control compliance.
- An audit, in which an independent reviewer systematically examines controls, records, and compliance to provide objective assurance to the board. ✓Correct because an audit provides the independent, evidence-based assurance of policy and control adherence the scenario requires.
- A/B testing, in which two model variants are compared on live production traffic to determine which one produces better performance.Plausible as evaluation, but A/B testing compares variants for performance, not independent verification of compliance and controls.
The trap
Choosing an adversarial security technique when the governance need is independent compliance assurance. How to remember it
An independent audit provides objective assurance that the system still complies with documented policies and controls.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Model drift, where changing real-world fraud patterns: What does this pattern most likely indicate? →
- Record it in a risk register with owner and mitigations: To govern this responsibly, what should the company →
- Constrain the chatbot's scope so out-of-domain requests: To reduce this unintended downstream harm, which →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.