AIGP Understanding How to Govern AI Development: 426 practice questions
Every question below comes with an explanation for each answer option — not just the correct one. The wrong answers are where most candidates lose marks, so that is where the explanations go into detail.
Preparing for AIGP? Take the free 5-min readiness quiz →
All 426 questions
- A clear statement of the problem: Which output best fulfills this step? →
- Identifying and evaluating the potential harms to affected: Which activity is most central to that assessment →
- Route borderline and high-impact cases to a trained: Which design choice best operationalizes meaningful human →
- Prioritize eliminating or avoiding the risk at its source: What does the mitigation hierarchy direct them to →
- It evidences compliance and supports risk management: Which rationale most accurately captures the governance →
- Confirm the lawful rights to reuse the data for this new: Which action best satisfies data-governance →
- Recording data lineage and provenance: Which practice would have prevented this gap? →
- Bias testing across protected groups together: Beyond validation of predictive performance, which combination →
- Treat the disparity as a material risk and remediate it: Which response best fits risk management during the →
- Records of the datasets used: Which documentation most directly lets the auditor validate results and confirm →
- To document the model's intended use: What is the primary purpose of a model card at release? →
- Real-world data and conditions can drift over time: What is the main reason ongoing monitoring is needed →
- To proactively probe the system for weaknesses and failure: What is the primary goal of red teaming in this →
- Record the incident and act to contain it: Following good post-deployment governance, what should the team do →
- Model or data drift: Which of the following is a recognized technical cause they should examine? →
- Technical documentation and instructions for use that tell: Which disclosure most directly serves that →
- It fixes the problem: Why does defining the business context matter before feature engineering? →
- Evidence that the system would disproportionately flag: Which finding from that assessment would most →
- Engaging affected stakeholders and setting metric: Which practice best reflects embedding ethics into the →
- Stakeholder mapping to find who could be harmed: Which combination best reflects sound pre-deployment risk →
- Record design decisions: Which practice best fulfills that goal? →
- Assess and document the lawful rights to collect and use: Which action most directly addresses the threshold →
- Documented data lineage and provenance tracing each: Which practice should have been in place to answer the →
- Bias testing to measure error-rate disparities across: Which pairing of test activities most directly →
- Remove or correct the leaking feature: What is the most appropriate response? →
- Record datasets and versions: Which documentation approach best satisfies all three aims under the →
- Complete the applicable conformity assessment and prepare: Which combination is the correct precondition →
- Continuously monitor performance and drift metrics: Which approach best satisfies both the ongoing-monitoring →
- Red teaming that has skilled testers adversarially attempt: Which periodic activity most directly probes that →
- Triage and contain the incident: Which response best meets both the management and the documentation →
- Data or model drift: Which term best describes it? →
- Instructions for use provided to deployers: Which item is a public/transparency disclosure aligned with that →
- Articulate the problem the system will solve: Which activity most directly fulfills this first step? →
- Identify and evaluate the system's potential effects: What is the core purpose of that assessment at this →
- Build in human oversight so a qualified reviewer can: Which design practice addresses this? →
- A probability/severity harms matrix that plots each risk: Which tool from the objective's examples is designed →
- Record the rationale for material design decisions: Given III.A.5, what documentation practice during design →
- The data is not fit-for-purpose because its population is: Applying data-governance requirements, which →
- The origin of each portion: To satisfy data lineage and provenance requirements, what must the provenance →
- Security testing that probes the pipeline and model: Within the training-and-testing plan, which test type →
- Investigate the disparity's source in data or design: Under III.B.4, what is the most appropriate way to →
- A test record listing each test type performed: Applying III.B.5, which documentation practice would let the →
- A model card summarizing intended use: Under III.C.1, which readiness artifact fits this need? →
- Ongoing outcome and prediction-quality metrics compared: To satisfy continuous-monitoring requirements, which →
- Threat modeling that systematically identifies potential: Which periodic activity fits this goal? →
- Log the incident in a central register with root cause: Which response best discharges the obligation to →
- Model drift, where the statistical relationship between: Working with data scientists and business owners, →
- Maintain technical documentation: Under the EU AI Act, which combination best satisfies the provider's →
- Specify the intended purpose: Which action most directly fulfills that objective? →
- A structured assessment identifying affected stakeholders: Which assessment most fully meets the objective of →
- Enabling a qualified person to review: When applying best practices to designing and building an AI system, →
- To prioritize identified risks by combining: What is the primary purpose of this probability/severity harms →
- To establish compliance and manage risks by creating: According to design-and-build governance, what is the →
- Verifying and documenting a valid legal basis: Which step most directly addresses the requirement to confirm →
- Recording where each dataset originated and every: What does meeting this requirement primarily involve? →
- Bias testing, which examines the model's outputs across: Which test type is specifically intended to detect →
- Document the disparity as a risk: Which action best fulfills the objective of managing issues and risks during →
- Record the datasets: Which practice best meets the objective of documenting the training and testing process? →
- A model card summarizing the model's intended use: Which artifact should they produce? →
- Track live performance and input distributions: Which practice best fulfills this objective? →
- Red teaming, where testers adversarially probe the model: Which activity is being described? →
- A description of the incident: Which set of contents best fulfills the objective of managing and documenting →
- Lack of quality data: Which contributing factor most accurately explains the failure? →
- Maintaining a post-market monitoring plan that documents: Which ongoing disclosure obligation is specifically →
- Concrete, measurable success criteria and constraints tied: To define the business context and use case →
- The assessment is incomplete because it omits: As reviewer, what is the most defensible conclusion? →
- Select a model whose decisions can be explained: Which design choice best applies responsible-AI policies and →
- Remove the name feature from the design so the identified: Applying a risk mitigation hierarchy that prefers →
- Record each significant design decision with its rationale: Which documentation practice during design and →
- It is not fit-for-purpose despite lawful rights and high: Under data-governance requirements, what is the most →
- Recording the origin of each data source and every: Which activity most directly fulfills that requirement? →
- Examining whether model outcomes differ unjustifiably: Which purpose is served specifically by the bias →
- It should be logged and managed as an identified risk: As a matter of good AI development governance, what →
- To validate results: Which statement best captures the primary purpose of this documentation? →
- To summarize the model's intended use: What is the main function of a model card? →
- Model and data conditions can shift over time: What is the primary reason continuous monitoring is needed →
- Red teaming, in which testers adversarially challenge: Which activity best fits this goal? →
- Contain the impact: Which response best reflects that procedure? →
- Data drift, where the statistical properties of live: Which underlying cause best explains this pattern? →
- Instructions for use that describe the system's: Which artifact is most directly aimed at giving deployers the →
- Specifying the concrete problem: Which step most directly reflects defining the business context and use case →
- The system's potential effects and harms on individuals: Which focus most accurately describes what that →
- Building a review step so a qualified person can examine: Which design choice most directly implements the →
- A probability and severity harms matrix that ranks each: Which technique most directly serves that →
- Documenting the design and build decisions: Which practice, performed during the build, best positions the →
- The data fails on lawful basis: Under data governance requirements, which conclusion is best supported before →
- Documented data lineage and provenance linking each record: What does this gap most directly indicate is →
- Interpretability testing to surface which features drive: Given the goal of understanding the reasoning behind →
- Remove the leaking feature: Which course of action best reflects sound management of issues and risks during →
- Record the datasets: Which improvement most directly satisfies the documentation objective for training and →
- Confirming the system meets its performance: Which outcome best reflects the purpose of that assessment? →
- To refresh the model on current data so its accuracy keeps: What is the main reason retraining is included on →
- Whether the system continues to perform reliably: Which description best captures what such an audit is →
- What happened: Which content is most essential to include in the incident record? →
- Causes such as drift: What is the primary reason this collaboration is emphasized? →
- Instructions for use: Which document is that? →
- Define the business context and intended use case: Which action should the governance lead prioritize? →
- Systematically identifying and evaluating the potential: Which focus best fulfills the impact assessment's →
- Human oversight mechanisms that let a qualified reviewer: Which design-stage control most directly satisfies →
- Eliminate the risk at the source by removing: Applying a risk mitigation hierarchy, which response should the →
- Documenting the design and build process: Which practice during design and build would most directly have →
- That the organization has documented lawful rights: Following data governance requirements, what must the team →
- Establishing data lineage and provenance records: Which data governance practice most directly provides this →
- Bias testing that measures whether model outcomes differ: Among the planned testing activities, which type →
- Investigate the underrepresentation: Following good practice for managing issues and risks during training and →
- Recording datasets: Which practice best satisfies all three needs at once? →
- Delay the launch until conformity requirements are: What is the most defensible release-readiness decision? →
- Treat the input shift as data drift and trigger scheduled: Which maintenance action does this pattern most →
- Red teaming that deliberately stress-tests the system: Which activity best fits this specific goal? →
- Log and document each incident with root cause: Which action best satisfies both aims? →
- Model or data drift: Which contributing factor best describes this cause? →
- To describe the system's design: What is the primary purpose of this technical documentation? →
- Because it clarifies the problem: In the design-and-build phase, why is defining the business context and use →
- During design and build: At what point is performing an impact assessment on the system most appropriate? →
- Stakeholder engagement and feedback: Which best practice does this activity represent? →
- The likelihood that a harm will occur and the severity: What two dimensions does this matrix combine to help →
- It establishes compliance and supports risk management: Which statement best captures the primary governance →
- Whether the data is fit-for-purpose and representative: Under data governance requirements, which concern →
- Establishing provenance by documenting the data's origin: Applying data governance, which practice most →
- Validation and test data held out from training: To produce this evidence, on which data should the decisive →
- Document the proxy-bias and overfitting findings: Which action best fits a training-and-testing →
- A record of datasets: Which artifact most directly satisfies this need? →
- A model card summarizing intended use: Which readiness artifact directly addresses the standardized summary →
- Track performance against thresholds continuously: Which response best reflects that maintenance obligation? →
- Conduct scheduled red teaming and security testing: Which option best fits that periodic safety-assessment →
- Contain the harm: Which approach best satisfies incident management and documentation obligations under →
- Data drift, where production input distributions diverge: Which factor does the evidence most directly →
- Technical documentation: Which set best matches the requirement? →
- Define the business context and use case: Which activity should anchor the effort before architecture →
- Perform an impact assessment evaluating potential effects: Which activity best matches this need at the design →
- Establishing human oversight mechanisms as part: When applying policies, procedures, best practices, and →
- A probability and severity harms matrix that ranks risks: Which tool is designed for that purpose during the →
- To establish compliance and manage risks by recording: What is the primary purpose of that documentation? →
- Assess and document the lawful rights to collect and use: Which requirement is a recognized part of →
- A traceable record of where each dataset originated: Which description best captures what that activity →
- Route forms, flag missing fields, and suggest departments: Which intended-purpose statement is most precise? →
- Compare AI and non-AI methods by benefits: Which comparison satisfies the use-case assessment requirement? →
- Assess non-user effects: What should it add? →
- Rank risks by weighing likelihood and severity: Which distinction should govern prioritization? →
- Assess severity: What should guide the acceptance decision? →
- Define acceptance criteria before reviewing results: What should it do first? →
- Claimant outcomes and distribution of delays: Which outcome should governance examine first? →
- Provide an authorized: Which design decision is most defensible? →
- Revise requirements using the driver feedback: What should the team do before continuing the pilot? →
- Select the least resource-intensive model meeting safety: Which decision best reflects the tradeoff? →
- Design against foreseeable misuse: What should designers address? →
- Escalate to the authorized accountable decision owner: Who should decide the next step? →
- Compare service benefits with energy impacts before: Which decision approach is most defensible? →
- Define intended decisions: Before comparing models, which control is missing? →
- Compare the AI approach with a feasible non-AI workflow: What missing control should assessment address? →
- Map impacts on non-users: Which control is missing? →
- Prioritize high-consequence risks despite low likelihood: Which control is missing? →
- Refer the residual risk under the hospital policy: What control is missing? →
- Set predefined risk-acceptance thresholds: What should be established before accepting residual risk? →
- Measure affected-person outcomes alongside processing: Which control is most direct? →
- Design an authorized human fallback: Which design control is missing? →
- Revise requirements and reassess the use case: What control is missing? →
- Select the feasible model meeting the defined objective: What control is missing? →
- Document foreseeable out-of-scope uses and design controls: Which action is most direct? →
- Assign residual-risk acceptance authority: Which control is missing? →
- Set explicit environmental and service tradeoff criteria: Which action is most direct? →
- Define the intended maintenance purpose and limits before: What do these contrasting observations most →
- Compare AI against the adequate non-AI process before: What conclusion is best supported? →
- Assess impacts on non-users alongside direct customer: What does the contrast most directly indicate? →
- Evaluate both likelihood and severity against defined risk: Which interpretation best supports risk →
- Treat the severe scenario with proportionate controls: What response best reflects the low-frequency severe →
- Define acceptance criteria for severe residual risks: What is the strongest conclusion? →
- Evaluate affected-person outcomes with efficiency before: What does the contrasting evidence most directly →
- Design an empowered human fallback: What does the combined evidence most directly support? →
- Revise requirements to represent transportation barriers: Which conclusion best follows before requirements →
- Choose the simpler model: What decision is best supported? →
- Constrain confidence-score use in customer workflows: What should design address first? →
- The designated risk authority: Who should decide whether the residual risk is accepted? →
- Obtain comparable disclosures before deciding: What evidence should determine the decision? →
- Document intended use and decision authority: Which evidence would resolve that uncertainty? →
- A comparison with the rules-based alternative: Before approval, which evidence is most relevant? →
- Impact evidence from affected non-users and workflows: Before approval, which evidence would resolve →
- The severity and exposure evidence: Before approval, which evidence would most directly resolve the →
- Test rare cascade scenarios: Before approval, which evidence best resolves uncertainty about low-frequency →
- A predefined risk acceptance criterion: What does the threshold represent in this decision? →
- Measure customer resolution and repeat-contact rates: Which evidence best tests the affected-person outcome →
- Test staffed override: At design time, which evidence best resolves whether human fallback is genuinely →
- Documented stakeholder evidence that local stockouts are: Which evidence should determine whether the →
- Compare capability and resource use: What evidence best resolves the capability-resource tradeoff before →
- Test adversarial misuse across both workflows: Before approval, which evidence best addresses both foreseeable →
- The designated accountable risk authority: Who should resolve the approval uncertainty before deployment? →
- Measure efficiency gains alongside computing resource use: Which evidence should resolve the environmental →
- Use defect-task fit and two-second latency as selection: Which requirement should guide model selection? →
- Choose the traceable rules engine and document its slower: Which approach best fits the assessment? →
- Contractor impacts from manager decisions informed: What should the team assess before deployment? →
- Prioritize the severe missed-fraud scenario before: Which risk should receive priority? →
- Require targeted testing and a documented human-review: Before using the tool in screening, what requirement →
- Set risk-acceptance thresholds before the pilot: What should governance require before approving the pilot? →
- Measure correct eligibility decisions: Which evaluation best reflects the affected-person outcome? →
- Define unsafe-weather override triggers and a fallback: What control should be completed before deployment? →
- Revise requirements using technician feedback before: What should happen next? →
- Use the smaller model: Which choice is most defensible? →
- Test misuse scenarios and constrain unsupported inferences: What design decision best addresses the risk? →
- Have an accountable education executive accept it: Which approach satisfies the requirement? →
- Select the lower-resource model and document: Which approach best satisfies the stated constraint? →
- The intended purpose remains editor assistance: Which prior assumption no longer holds? →
- The static FAQ still provides suitable accessible: Which conclusion about the earlier non-AI comparison must →
- Treat consent as excluding non-user impacts: Which assumption must be rejected? →
- Prioritize high-severity harms even when their likelihood: Which risk should receive priority? →
- Escalate the rare safety-critical miss: What should governance do? →
- Risk-acceptance criteria and delegated authority: What should the team establish before deciding whether to →
- The business resolution metric adequately represents: Which prior assumption no longer holds? →
- Specify an operational human fallback: What should be specified during design? →
- Reassess the affected population and data assumptions: Before relying on the earlier validation, what should →
- Constrain purpose and inputs: Which design response best addresses the foreseeable misuse? →
- Escalate documented residual risk to the authorized: What should happen next? →
- Reassess purpose and benefits against alternatives: What action is required? →
- The intended purpose and decision authority remain unclear: What remaining risk must be addressed first? →
- Complex or underserved customers may face delayed human: What is the key remaining risk? →
- Impacts on non-users and underrepresented groups: Which remaining risk should assessment address? →
- Prioritize the severe holiday impact: How should the remaining risk be prioritized? →
- Retain treatment and monitor severe misuse pathways: Which governance conclusion is most defensible? →
- Low-confidence itinerary answers may still be inaccurate: Before accepting residual risk, which demonstrated →
- Unmeasured subgroup false negatives may delay or deny: Which remaining risk most directly concerns →
- High-confidence routing errors can bypass the human: Which remaining risk should be addressed before →
- Average accuracy can hide costly rare-defect failures: What remaining risk should change the requirements? →
- Confident extraction errors may persist on handwritten: Which residual risk remains? →
- Users may influence coworker evaluations with incomplete: Which concrete misuse risk remains? →
- Escalate acceptance to the designated risk authority: What is the decisive response? →
- The missing transformation and version history prevents: Which distinction is decisive for governance? →
- Evaluate across shifts: Which evaluation requirement is decisive? →
- Treat the missingness as systematic: Which conclusion is decisive? →
- Treat historical outcomes as potentially biased labels: What decisive requirement should govern interpretation →
- Evaluate correlated features and subgroup effects: During review, which conclusion is decisive? →
- Use a representative test set untouched by training: What evidence is decisive before deployment? →
- Split by policyholder before testing: What correction is decisive? →
- Report subgroup-specific false-negative rates alongside: Which analysis is decisive? →
- Reduce false negatives first: Which evaluation priority follows? →
- Conduct separate security testing for access: Which evidence is still required? →
- Test for leakage and reidentification risks before relying: What requirement remains decisive for privacy →
- Measure agreement and adjudicate ambiguous cases using: What step is decisive? →
- Link each evaluation to versioned data: What documentation is decisive? →
- Test plausible severe scenarios explicitly: Which testing distinction matters most? →
- Create a documented data lineage record: Which missing control is most direct? →
- Use a deployment-representative test sample: Which control is most direct? →
- Build an adjudicated: Which control most directly addresses both constraints before model training? →
- Define and validate an independent administrative target: Which control is most direct? →
- Test proxy effects and revise affected features: Which control most directly addresses the concern? →
- Keep training and test records separate: Which missing control is most direct before relying on the reported →
- Use grouped, deduplicated partitions by employee or case: Which control is most direct? →
- Report error rates by subgroup: Which additional control is most direct? →
- Set thresholds using documented error costs: Which control is most direct? →
- Test the model and service against attacks: Which missing control most directly addresses the evidence gap? →
- Perform privacy-leakage and re-identification testing: Which control is most direct? →
- Establish adjudication and measure annotator agreement: Which missing control is most direct? →
- Record model-data version identifiers: What is the most direct missing control? →
- Create targeted tests for the rare severe condition: Which additional control most directly addresses this →
- The undocumented lineage prevents reliable provenance: What do these contrasting observations support? →
- Urban-rural performance is comparable in this test set: What does the evidence most directly show? →
- Accuracy is unestablished for affected seasonal products: What does this evidence most directly support? →
- Historical labels may reproduce institutional bias: What does the evidence most directly indicate? →
- Postal-sector codes warrant proxy-bias analysis: What does this evidence most directly suggest? →
- Treat the gap as possible overfitting and investigate: Before approval, what does this contrast most directly →
- The test estimate is likely inflated by record duplication: What interpretation is best supported? →
- Compare line-specific errors: What conclusion is most justified? →
- Measure class errors and capacity before cost-sensitive: Which next step best supports threshold selection? →
- Conduct targeted security and privacy testing: What evidence gap is decisive? →
- Test re-identification and residual disclosure risks: What is the most defensible response? →
- Clarify criteria: What evidence should it prioritize before interpreting model performance? →
- Link model, dataset, transformation, and test versions: What control most directly resolves the uncertainty? →
- Use targeted rare-case testing: Which evaluation response best addresses both rarity and consequence? →
- Document data lineage for training and testing artifacts: What evidence should be required before approval? →
- Compare training distributions with deployment conditions: Which evidence most directly resolves that →
- Audit label completeness and department coverage: Before approval, which evidence best addresses both →
- Compare labels with independently assessed service needs: What should reviewers examine first? →
- Compare model outcomes with and without distance: Which analysis is most informative? →
- Evaluate once on a held-out December-like set: Which evidence would most directly address whether performance →
- Create a deduplicated held-out clip set: Which evidence should reviewers request? →
- Use subgroup acceptance criteria and investigate: What evidence should determine approval? →
- Control false negatives: Which evidence should receive priority before approval? →
- Conduct security testing alongside targeted robustness: Which plan is most defensible? →
- Test re-identification risk and real-image subgroup: Before approval, which evidence is most important? →
- Adjudicate a stratified disagreement sample using: Which evidence most directly resolves that uncertainty? →
- Obtain access to linked model: Which evidence should the team obtain? →
- Test targeted rare failure scenarios: Which evidence best addresses this risk before purchase? →
- Require source records: Which approach satisfies that constraint? →
- Evaluate balanced urban and rural samples with separate: Which validation approach best addresses →
- Investigate missingness and add targeted labels: Which approach fits? →
- Replace choices with independently defined suitability: Which approach is appropriate? →
- Exclude the proxy and validate subgroup performance: Which approach meets the condition? →
- Use a representative: Which approach satisfies that requirement? →
- Deduplicate records before creating train and test: Which approach should replace the current evaluation? →
- Measure each subgroup's false-positive rate against 5%: Which evaluation approach best satisfies that →
- Use a cost-sensitive threshold: Which approach best addresses both the asymmetric error costs and limited →
- Validate captions on representative data and test leakage: Which validation plan best addresses these →
- Test synthetic records for privacy leakage before use: Which action is most immediately necessary? →
- Adjudicate sampled disagreements and revise the labeling: What should the team do first? →
- Version the model: Which documentation choice is most useful? →
- Build a targeted defect test set and require: Which evaluation change is most defensible? →
- Provenance documentation alone establishes suitability: Considering provenance documentation specifically, →
- The validation population represents the new users: Which prior assumption requires reassessment first? →
- Treat the labeled sample as representative of every: Which validation conclusion is not justified? →
- Evaluate it on a held-out set excluded from training: Which evaluation design best distinguishes learning from →
- Group duplicate shipment records before creating training: What control directly addresses this evaluation →
- Set subgroup acceptance criteria and investigate: Before deployment, which evaluation decision is most →
- Estimate costs and capacity before comparing: Which next decision best supports a defensible threshold? →
- Conduct security testing for prompt injection: Which evidence gap should receive priority? →
- Measure agreement and adjudicate disputed labels using: What should happen before training proceeds? →
- Version the data and model artifacts: What documentation control is most immediately required? →
- Test representative languages and severe safety scenarios: What is the decisive next step before relying on →
- Evaluate rural pediatric records before deployment: Which proposed mitigation leaves the decisive risk? →
- Audit and improve label quality: Which mitigation best addresses the immediate evidence gap? →
- Revalidate labels against document requirements: Which mitigation addresses the remaining risk most directly? →
- Test subgroup outcomes and inspect correlated inputs: Which mitigation best addresses the remaining risk? →
- Collect a fresh: Which action provides credible release evidence? →
- Report pediatric and adult error rates: What evidence controls release? →
- Compare evaluation scope with deployment conditions: Which model-card distinction matters most? →
- Validate rejection outcomes on reviewed documents: What is the decisive next step? →
- Retrain when evidence shows changed risk or performance: What distinguishes a trigger-based approach from this →
- Revalidate the changed version for the intended use: What is the decisive requirement before deployment? →
- Resolve or control the finding: What should the release decision prioritize? →
- Contain affected processing while investigating the cause: What should the response team do first? →
- Verify current-record compatibility and rollback path: What must precede restoring the prior release? →
- Known limitations and relevant operating conditions: What should the developer provide to the deployer? →
- Measure outcomes after mitigation: Which evidence best determines whether the mitigation works? →
- Require update details: What procurement control best addresses this dependency? →
- Contain logging exposure and retest the integrated system: Which decision best addresses the regression? →
- Record the near miss and preserve relevant evidence: What should governance require now? →
- Deployment feedback loop amplifying allocation bias: Which concept most decisively explains the observed →
- Define shared duties: What governance distinction determines whether maintenance is genuinely owned after →
- Map downstream dependencies and transition arrangements: What should happen first? →
- Test release criteria across representative applicant: What control is missing? →
- Restrict deployment to tested routing use: What control is most directly missing? →
- Validate outcome quality after the drift signal: What is the most direct missing control? →
- Define monitored retraining triggers and approval criteria: What control is most directly missing? →
- Revalidate the changed version against contextual: What control is most directly missing before release? →
- Block release pending remediation decision: What is the most direct missing control? →
- Contain affected decisions while preserving evidence: What should happen first? →
- Test rollback against retained claims data: Which missing control is most direct? →
- Require documented developer disclosure to deployers: Which control is missing? →
- Define outcome measures and mitigation review thresholds: What is missing? →
- Require update impact assessment before production: Which control is most direct? →
- Test the integrated workflow for security regressions: Which control is missing? →
- Log near misses with owners and corrective actions: Which missing control best addresses this gap? →
- Track subgroup outcomes over time: Which control most directly addresses the concern? →
- Document owner: Which control best resolves both constraints? →
- Map dependencies before decommissioning: What is the most direct missing control? →
- Evidence is incomplete for a defensible release decision: What do these observations support about release →
- The model needs context-specific subgroup testing: What does the evidence most directly support? →
- The input change warrants targeted outcome validation: What is the most defensible interpretation? →
- Trigger retraining review: What decision follows? →
- Revalidate the changed version in the intended workflow: What should the deployer do before relying on the new →
- The red-team result identifies a release-blocking risk: What should the release team conclude? →
- Pause automated recommendations and preserve incident: What is the appropriate immediate governance response? →
- Restore the prior model with compatible data handling: What must accompany the rollback decision? →
- Disclose the model’s handwritten-form limitations: What should the insurer request before deployment? →
- Evaluate both disparity and delay before adjusting: What should the agency do? →
- Document the update: What should the provider do first? →
- The integrated system needs contextual security testing: What does this evidence most directly support? →
- Record the event as a near miss: What should the evidence support? →
- The feedback loop can reinforce historical bias: What is the clearest concern? →
- Document monitoring: What governance action is best supported? →
- Trace dependencies: What evidence is needed before decommissioning under the organization’s risk-management →
- Test accuracy separately on representative scripts: Which evidence would resolve that uncertainty under the →
- Test representative dialects and document intended-use: What evidence should precede approval? →
- Validate outcomes by neighborhood and relevant applicant: What evidence should resolve whether performance →
- Investigate the policy shift: Under the organization’s monitoring and change-control process, which evidence →
- Revalidate the changed version: What is required before approval? →
- Run stratified tests on multilingual workflow samples: Which evidence best resolves the uncertainty? →
- Reproduce the disclosure across controlled model: Which evidence should be prioritized? →
- Test rollback with current records: Which evidence is most important? →
- Obtain use-case tests covering applicant subgroups: Which evidence should it require? →
- Measure comparable subgroup outcomes before and after: Which evidence is most probative? →
- Obtain change records: Which evidence should the agency obtain? →
- Run targeted access-control and data-exposure tests: Before approval, which evidence best addresses the →
- Maintain structured near-miss records with context: Before expansion, what evidence should governance require? →
- Compare outcomes across departments over repeated cycles: Which evidence should resolve the uncertainty? →
- An approved plan assigning monitors: Before handoff approval, which evidence is most important? →
- Validate dependent workflows and fallback owners: Which evidence best resolves that uncertainty? →
- Rebuild held-out tests with subgroup coverage and leakage: Which approach satisfies both constraints? →
- Restrict deployment to editorial summarization: What should the team do? →
- Measure issue-specific outcomes against prior performance: What is the best next step? →
- Review quarterly: Which approach satisfies both requirements? →
- Revalidate the changed model: Which release action is most defensible? →
- Assess and address the routing vulnerability before: What should the quality team do first? →
- Contain misrouting through fallback processing while: What response best satisfies the immediate governance →
- Verify data compatibility: Which action is best? →
- Obtain use-case limits: What should the buyer require? →
- Sample subgroup decisions: Which choice best addresses incomplete evidence while enabling action before →
- Test the update against claims-specific acceptance: Before enabling the update, which action best satisfies →
- Block release and restore the prior security baseline: Which action is most appropriate? →
- Log the near miss: What should the team do? →
- Measure outcomes by service area: Which monitoring action best addresses this feedback loop? →
- Name an owner empowered to intervene: Which decision best establishes that control? →
- Map dependencies before shutdown: What should it do first? →
- The tested population and context represent the proposed: Which prior assumption no longer holds? →
- The intended-use assumption no longer holds: What limitation is most directly implicated? →
- Validate outcomes before attributing degradation: What prior assumption must be tested before concluding →
- Trigger targeted revalidation for the changed traveler: What should govern the next decision? →
- Revalidate in the actual context: What is the strongest decision? →
- Remediate the finding and pass a retest: What should happen next? →
- Activate containment while preserving evidence: What is the immediate governance action? →
- Validate rollback compatibility before switching: What should the team do before rollback? →
- Known limitations and intended-use boundaries: What information should the developer provide to the deployer? →
- Compare small-vendor outcomes with baseline: What should it examine? →
- Require reassessment before continued use: What response is most defensible? →
- Contain the integration and assess exposure: What is the most immediate response? →
- Create a structured near-miss record: What documentation best meets that requirement? →
- Feedback stays unbiased across changed groups: For the specific risk that this feedback loop may amplify →
- Assign ongoing monitoring ownership: What is the decisive governance requirement? →
- Map dependencies and establish a tested fallback: What should governance address before retirement? →
- Aggregate accuracy may conceal subgroup failures: What specific remaining risk matters most? →
- Evidence does not establish performance for rural primary: What limitation remains decisive? →
- Validate rural outcomes before setting a retraining: Which mitigation is most defensible? →
- Set a risk-based retraining trigger: What risk-responsive mitigation should replace reliance on the calendar →
- Revalidate 3.2 against applicable acceptance criteria: Under the organization’s release-control procedure, →
- Test translated narratives against subgroup criteria: What is the most appropriate next step before release? →
- Contain duplicate reminders and preserve incident evidence: What should the organization do first? →
- Rollback may misread the current schema: What specific risk remains? →
- The disclosure omits operational limitations and supplier: Which disclosure deficiency most directly threatens →
- Aggregate data can hide subgroup harm: What specific risk remains? →
- The supplier update may perform differently: What remaining risk is most specific? →
- The integrated endpoint may expose applicant results: What specific risk remains? →
- The team may miss recurring failure patterns because: What mitigation gap remains? →
- Retraining may reinforce under-investigation because: What risk arises specifically from the label-generation →
- No internal owner may act on alerts or coordinate: What risk remains? →
- Retirement may disrupt the scheduling dashboard because: What risk remains? →
- The product owner should verify evidence against: Who should own the next handoff? →
- Limit deployment to FAQ drafting: Which handoff best respects the documented limitation and governance roles? →
- Require subgroup outcome testing: What is most defensible? →
- Test the new category and retrain only if defined evidence: Which action is correct? →
Which Understanding How to Govern AI Development topics are you weakest in?
Five minutes, and you get a score per domain instead of one number.
Test your AIGP readiness — freePart of the Certsqill AIGP question bank.