Eliminate the risk at the source by removing: Applying a risk mitigation hierarchy, which response should the
A mitigation hierarchy tries to eliminate or avoid the hazard first; removing a non-essential high-risk feature is the top option.
The question
A design team has identified that a facial-analysis feature in their AI product creates a serious, hard-to-mitigate risk, and the feature is not essential to the core use case. Applying a risk mitigation hierarchy, which response should the team consider first?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Transfer the residual risk to an insurer through a specialized policy covering the specific claims that could arise from the facial-analysis feature.Plausible but wrong: risk transfer sits low in the hierarchy and is considered only after avoidance and reduction options are exhausted.
- Eliminate the risk at the source by removing the non-essential facial-analysis feature from the design before other controls are weighed. ✓Correct: a mitigation hierarchy prioritizes eliminating or avoiding the hazard first, which fits a serious risk from a non-essential feature.
- Reduce the risk by adding human review and confidence thresholds around the facial-analysis feature so flagged outputs are checked.Plausible but wrong: reduction controls are appropriate for necessary features, but here elimination is available and ranks higher.
- Accept the residual risk and document the rationale, since the probability of a harmful outcome is judged to be relatively low.Plausible but wrong: acceptance is the last resort in the hierarchy and is inappropriate when the hazard can simply be removed.
The trap
Reaching for reduction or transfer controls when eliminating the hazard entirely is available. How to remember it
A mitigation hierarchy tries to eliminate or avoid the hazard first; removing a non-essential high-risk feature is the top option.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Development questions
- Human oversight mechanisms that let a qualified reviewer: Which design-stage control most directly satisfies →
- Documenting the design and build process: Which practice during design and build would most directly have →
- That the organization has documented lawful rights: Following data governance requirements, what must the team →
- All 426 Understanding How to Govern AI Development questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Development ·
Every answer, right and wrong, comes with its own explanation.