Document the vendor’s purposes: What specific governance risk | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Document the vendor’s purposes: What specific governance risk must be resolved before deployment?

AIGP Understanding How to Govern AI Deployment and Use Hard

Before deployment, clarify the vendor’s GDPR role, purposes, subprocessors, and incident responsibilities.

The question

A travel company proposes replacing its itinerary model with a vendor model that retrieves airline data. Under the GDPR, the vendor has supplied benchmarks but has not documented its data-use purposes, controller or processor role, subprocessors, or incident contacts; performance by traveler population is also absent. What specific governance risk must be resolved before deployment?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. Obtain traveler-group evidence for retrieval performance and limitations.
    This addresses deployment-specific evidence, but the stated unresolved risk is the vendor's undocumented processing and accountability structure under the GDPR.
  2. Test retrieval quality across traveler groups.
    Use-case testing is important, but it does not resolve who determines purposes and means or which subprocessors handle the data.
  3. Document the vendor’s purposes, GDPR role, subprocessors, and incident responsibilities before approval.
    Under the GDPR, actual purposes and means determine controller or processor responsibilities; supplier labels do not settle them. The missing documentation also prevents effective subprocessor and incident accountability.
  4. Request a larger benchmark set.
    A larger benchmark does not establish processing purposes, GDPR roles, subprocessors, or incident accountability.
The trap
Separate performance evidence from documented processing purposes, roles, subprocessors, and incident responsibilities.

How to remember it

Before deployment, clarify the vendor’s GDPR role, purposes, subprocessors, and incident responsibilities.

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding How to Govern AI Deployment and Use questions

Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use · Every answer, right and wrong, comes with its own explanation.