Deliver mandatory user training on the tool's approved: Which best applies the organization's deployment
The gaps are human: staff untrained on limits and skipping review, which mandatory user training on approved use fixes most immediately.
The question
A bank deploys a generative assistant to help agents draft customer letters. Post-launch, agents paste confidential customer records into it, no one reviews its drafts before sending, and staff say they were never told the tool's limits. The governance lead can fund one control first. Which best applies the organization's deployment policies to close the most immediate gap?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Deliver mandatory user training on the tool's approved uses, its data-handling limits and required human review before letters are sent. ✓Correct: the failures stem from staff not knowing the limits or the review requirement, which targeted user training on approved use directly addresses.
- Commission an external red-team exercise to probe the model for unsafe or manipulable outputs under sustained adversarial prompting conditions.Almost right but mistimed: red teaming tests model safety, yet the immediate breakdown is human misuse and missing oversight, not adversarial model behavior.
- Retrain the underlying model on redacted customer data so it is less likely to reproduce confidential details in its drafts.Plausible but wrong: retraining is slow and addresses model outputs, not the operational failures of staff pasting records and skipping review.
- Purchase expanded cyber-insurance so the bank can transfer the financial risk of any confidentiality breach that occurs.Plausible but wrong: insurance transfers residual financial risk but does nothing to stop the ongoing misuse and lack of oversight.
The trap
Reaching for a technical or financial control when the operative failure is untrained users and missing oversight. How to remember it
The gaps are human: staff untrained on limits and skipping review, which mandatory user training on approved use fixes most immediately.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- The company assumes greater direct accountability: Which risk best answers this? →
- Data or concept drift: Which continuous-monitoring finding best explains the decline and should trigger →
- Threat modeling: Which periodic assessment activity fits this proactive, pre-deployment structuring need? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.