Log the incident in a central register with root cause: Which response best discharges the obligation to
Proper incident management combines a documented central record (cause, severity, owner), timely mandated reporting, and a risk-register feedback loop that drives corrective action.
The question
A deployed high-risk credit-scoring model begins rejecting a protected group at an abnormal rate; the vendor confirms a systemic issue but the deployer wants only a quiet configuration rollback. As governance lead, you must satisfy regulatory reporting duties, preserve internal accountability, and prevent recurrence. Which response best discharges the obligation to manage and document incidents, issues and risks?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Apply the vendor's configuration rollback immediately, record a brief note in the change log, and treat the matter as resolved once the group's rejection rates return to their normal level.Plausible because rollback does address the symptom, but a change-log note omits root cause, severity, accountability and any external reporting, so the incident is neither properly documented nor prevented from recurring.
- Escalate the matter solely to the model's developer for a retraining fix, document the retraining ticket, and defer any authority notification until the retrained model has itself been validated in live production.Plausible because developer retraining is a legitimate corrective step, but deferring mandated notification and narrowing documentation to a retraining ticket fails the reporting and accountability constraints of incident management.
- Open a data-quality investigation with the data team, document the suspected training-data gap, and pause external reporting until the underlying dataset defect is fully confirmed.Plausible because data-quality review is often relevant, but withholding mandated reporting pending full confirmation and scoping documentation to a single hypothesis leaves regulatory duties and the risk register unaddressed.
- Log the incident in a central register with root cause, severity and owner, notify the required authority within the mandated window, and feed the finding into the risk register to drive corrective action. ✓Correct because managing and documenting incidents requires a durable record with cause, severity and ownership, timely external reporting where mandated, and a feedback loop into the risk register so corrective action prevents recurrence.
The trap
Believing that fixing the technical symptom (rollback or retraining) satisfies the incident-management obligation without formal documentation and mandated reporting. How to remember it
Proper incident management combines a documented central record (cause, severity, owner), timely mandated reporting, and a risk-register feedback loop that drives corrective action.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Development questions
- Threat modeling that systematically identifies potential: Which periodic activity fits this goal? →
- Model drift, where the statistical relationship between: Working with data scientists and business owners, →
- Maintain technical documentation: Under the EU AI Act, which combination best satisfies the provider's →
- All 426 Understanding How to Govern AI Development questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Development ·
Every answer, right and wrong, comes with its own explanation.