Schedule periodic audits that independently verify: Which activity best meets this need?
Independent periodic verification that controls operate and residual risk is acceptable is an audit.
The question
A deployer's governance board wants independent, periodic verification that the controls around a deployed AI system are operating as intended and that residual risks remain acceptable. It must select a fitting periodic assurance activity. Which activity best meets this need?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Increase the frequency of end-user satisfaction surveys to gather sentiment about the system's helpfulness in practice.Plausible but wrong: satisfaction surveys capture user perception, not independent verification that controls operate.
- Schedule periodic audits that independently verify the deployed system's controls and reliability are operating. ✓Correct because IV.C.3 lists audits among periodic activities to assess a deployed system's performance, reliability, and safety.
- Rewrite the user instructions-for-use so operators receive clearer guidance on the system's known operational limits.Almost right because guidance helps, but updating instructions is a transparency measure, not an independent assurance activity.
- Publish a consumer-facing privacy notice describing what personal data the deployed system collects during use.Plausible but wrong: a privacy notice is a disclosure, not a periodic verification of control effectiveness.
The trap
Confusing user feedback or disclosures with independent audit-based assurance. How to remember it
Independent periodic verification that controls operate and residual risk is acceptable is an audit.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Deployment and Use questions
- Continuously monitor outputs against thresholds: Which approach best meets the monitoring-and-maintenance →
- Document each incident: Which documentation activity best fits this deployment obligation? →
- Define documented permitted-use boundaries enforced: Which control most directly addresses the risk? →
- All 424 Understanding How to Govern AI Deployment and Use questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Deployment and Use ·
Every answer, right and wrong, comes with its own explanation.