AIGP Understanding How Laws, Standards and Frameworks Apply to AI: 394 practice questions
Every question below comes with an explanation for each answer option — not just the correct one. The wrong answers are where most candidates lose marks, so that is where the explanations go into detail.
Preparing for AIGP? Take the free 5-min readiness quiz →
All 394 questions
- Purpose limitation: Under core data protection principles applied to AI, which principle most directly governs →
- Privacy by design paired with data minimization: Which pair of data protection concepts best matches this →
- Conducting a data protection impact assessment to evaluate: Before deployment, which controller obligation is →
- It is treated as a special category warranting heightened: Compared with ordinary personal data, how do data →
- Intellectual property law: Which legal domain most directly governs whether that training use of the material →
- Nondiscrimination law: Which body of law is most directly implicated by this outcome? →
- Consumer protection law: Which body of law is most directly implicated by this marketing conduct? →
- Product liability law: Which body of law is most directly implicated by this harm? →
- Limited risk, meaning the system is permitted but must: Into which risk tier does such a system typically →
- Risk management: Which set of obligations is the provider most directly required to satisfy for that system →
- Human oversight: Which EU AI Act requirement is the regulator specifically invoking here? →
- Maintain technical documentation: Under the EU AI Act, which obligations apply to it specifically as a →
- Fines are tiered by violation severity and set as: Setting aside the exact numeric caps, which statement best →
- Importer, meaning it places a non-EU provider's system: Under the EU AI Act's role framework, which role does →
- They are a non-binding recommendation of values-based: Which statement most accurately characterizes them? →
- Govern, Map, Measure and Manage, structured as: Which set correctly lists the framework's four core functions? →
- ISO/IEC 42001: Among the core ISO AI standards, which one provides an AI management system (AIMS) that an →
- Transparency, which requires informing individuals about: Applying core data protection principles, which →
- Collecting only the personal data that is adequate: Which practice best reflects that principle? →
- The controller must use only processors that provide: Under data protection obligations on controllers, what →
- It is a special category of data whose processing is: Under the GDPR, how is the biometric data used for that →
- Reproducing copyrighted works to assemble a training set: Which intellectual-property consideration most →
- Disparate-impact liability can arise from a facially: Under nondiscrimination law, why can this still create →
- The prohibition on deceptive acts applies because: Under consumer-protection law, which theory applies most →
- A design-defect claim: Under product-liability law, which theory most directly fits? →
- Unacceptable risk: Into which risk tier does this social-scoring use most clearly fall? →
- Establishing a risk-management system: Under the EU AI Act, which set of requirements is a core obligation for →
- Human oversight: Under the EU AI Act, which requirement does this design measure most directly implement? →
- Maintaining technical documentation: Under the EU AI Act, which obligation applies specifically to providers →
- Engaging in a prohibited AI practice under Article 5: Which type of infringement attracts the highest maximum →
- Provider, because placing a high-risk system on the market: Under the EU AI Act, which role does the European →
- Inclusive growth: Which option lists the OECD AI principles rather than another framework's structure? →
- GOVERN, the cross-cutting function establishing a risk: Which core function is cross-cutting and informs the →
- ISO/IEC 42001: Which standard fits a certifiable AI management system? →
- Purpose limitation: Under data-protection law, which principle most directly challenges this secondary use? →
- Data minimization and privacy by design: Which data-protection principles do these two choices reflect? →
- Conducting a data protection impact assessment: Under GDPR, which obligation is most directly triggered before →
- A valid Article 9 condition: Because fingerprints used to identify people are special-category data, what must →
- Copyright can restrict copying protected works: From an intellectual-property standpoint, which is the most →
- They apply to AI-driven hiring: From a nondiscrimination-law standpoint, which statement most accurately →
- The prohibition on unfair or deceptive practices: From a consumer-protection standpoint, which principle does →
- A design-defect theory: Which product-liability theory most directly fits a flaw inherent in the design? →
- Limited risk, where transparency duties such as disclosing: Into which risk tier does this transparency-only →
- Data governance: Under the EU AI Act, which core requirement does this practice implement? →
- Transparency and provision of information: Which requirement does this most directly implement? →
- Maintain technical documentation and publish: Under the EU AI Act, which obligation applies to it as a →
- Placing on the market an AI system that breaches: Which category of violation is subject to the highest tier →
- Deployer - it must operate the system per the instructions: Which role does the hospital hold under the EU AI →
- Inclusive growth: Which of the following is one of the OECD's five values-based principles for trustworthy AI? →
- MAP - it frames context, intended purpose and a system's: Which core function is this? →
- ISO/IEC 42001 for the management system and ISO/IEC 22989: Which pairing of ISO/IEC standards meets these two →
- Purpose limitation: Which GDPR principle is most directly violated? →
- Retain only data needed for the defined purpose: Which measure best satisfies those requirements here? →
- Complete a Data Protection Impact Assessment before: Before the processing begins, which GDPR controller →
- Facial templates are biometric special-category data: Which characterization of this processing under GDPR is →
- Copyright can bar using protected works as training data: Which of the following is an example of how →
- Nondiscrimination law: Which body of law is most directly implicated? →
- Consumer protection law: Which legal regime is most directly triggered? →
- Product liability law: Which body of law most directly addresses the manufacturer's responsibility for that →
- Limited risk - systems that must meet transparency duties: Under the EU AI Act's risk-based approach, which →
- Risk management: Which set of obligations does the EU AI Act impose on high-risk AI systems? →
- Human oversight: Which EU AI Act requirement does this describe? →
- Run adversarial model evaluation and report serious: Beyond the duties owed by every GPAI provider, which →
- A cap set at a fixed euro sum or a share of global annual: How are administrative fines generally structured →
- The non-EU company is the provider: Under the EU AI Act, what roles do the two companies hold respectively? →
- Fostering an inclusive AI-enabling ecosystem with digital: Which of the following is one of those →
- GOVERN - the cross-cutting function that instills a risk: Within the NIST AI RMF, which core function is →
- ISO/IEC 42005: Which ISO/IEC standard provides guidance specifically on conducting an AI system impact →
- The controller's legitimate interests: Which of the following is a recognized lawful basis under GDPR? →
- Building data-protection safeguards into the system: Which action best reflects that principle at the design →
- Complete a DPIA: Acting as the GDPR data controller, which combination of measures must be in place before →
- Biometric templates used to uniquely identify staff are: Under GDPR, which analysis best fits processing this →
- Copyright can restrict use of the scraped works: Considering intellectual property law and the EU AI Act →
- A materially lower selection rate for a protected group: Under nondiscrimination law, which conclusion is most →
- Unsupported performance claims: Under consumer protection law against unfair or deceptive practices, which →
- Harm caused by design or manufacturing defects: In the context of AI-enabled products, what does product →
- Limited risk, so it is chiefly subject to transparency: Under the EU AI Act's risk-based pyramid, a →
- Establish a risk-management system and maintain technical: Under the EU AI Act, which requirement is a core →
- To let natural persons effectively monitor the system: What is the primary purpose of this requirement? →
- Maintain technical documentation and provide information: Under the EU AI Act, which obligation applies to →
- It uses tiered maximums scaled to the violation's: How does the EU AI Act structure its administrative fines →
- The vendor is the provider responsible for conformity: Under the EU AI Act, how are the roles and their core →
- They set out values-based principles such as inclusive: Which statement accurately describes the OECD AI →
- MAP, because the function establishes context and frames: Which core function are these activities most →
- ISO/IEC 42001: Which ISO/IEC standard fits, and how does it differ from its companions? →
- Purpose limitation and transparency: Under existing data-protection principles, which concern is most directly →
- Data minimization and privacy by design: Which data-protection concept does this approach most directly →
- A Data Protection Impact Assessment: Under GDPR controller obligations, which step is required before →
- Processing special-category data such as health: Under GDPR, which statement best describes the baseline rule →
- The research-only licence does not authorize commercial: Considering intellectual property law, which →
- Test the features for proxy discrimination: Considering nondiscrimination and adverse-action expectations →
- Substantiate or drop the lowest-price claim: Under consumer protection law, which governance step is most →
- A defect rooted in training data can be a design: Considering product liability law, which statement is most →
- The emotion tool is prohibited in the workplace: Under the EU AI Act tiers, which classification is most →
- Operate a risk-management process and appropriate data: Which sequence best reflects the EU AI Act's →
- Human oversight: Which specific requirement does this obligation describe? →
- Publish a sufficiently detailed summary of the content: Which of the following is one of those baseline →
- Engaging in one of the prohibited AI practices: Which category of violation sits in the highest (most severe) →
- Provider, because it develops the AI system and puts it: Under the EU AI Act's operator roles, which category →
- Inclusive growth: Which of the following is one of those five values-based principles? →
- Measure, which uses quantitative and qualitative methods: Which of the following is one of those four core →
- ISO/IEC 42001: Which ISO/IEC standard is designed for this purpose? →
- Purpose limitation: Under GDPR, which principle most directly governs whether this new use is permitted? →
- Data minimization: Under GDPR, which requirement most directly challenges this plan? →
- Carrying out a data protection impact assessment before: Before deployment, which GDPR controller obligation →
- The facial data is a special category: Under GDPR, why does this processing face a stricter standard than →
- Whether the copyright holders retain rights that can limit: Which intellectual property consideration most →
- Disparate impact: Under nondiscrimination law, which theory of liability is most directly implicated? →
- An unfair or deceptive practice: Under consumer protection law, which characterization most directly applies →
- Product liability: Which legal theory most directly governs the manufacturer's exposure? →
- Prohibited practice: Under the EU AI Act, how is this use most accurately classified? →
- Completing the conformity assessment procedure so: Under the EU AI Act, which step fulfills this requirement? →
- Give clinicians the tool's confidence and key reasoning so: Which design measure best achieves meaningful →
- Performing state-of-the-art model evaluation: Beyond the baseline duties owed by all GPAI providers, which →
- The first faces the top fine tier for a prohibited: Under the EU AI Act's fine structure, how do their maximum →
- Deployer, because it uses an AI system under its own: Under the EU AI Act, which operator role does the →
- A set of intergovernmental recommendations promoting: Which statement best describes the OECD AI Principles →
- Govern, the cross-cutting function that sets policies: Which function is this? →
- ISO/IEC 22989: Which core ISO/IEC AI standard provides this? →
- Transparency, requiring that individuals be clearly: Under GDPR, when an organization collects personal data →
- Collect only the personal data that is adequate: Which practice best reflects the data minimization and →
- Carry out a data protection impact assessment: Considering the controller's obligations, which step is →
- Processing is prohibited by default and requires: Because this involves a special category of personal data, →
- Copyright may prohibit or limit using the material: From an intellectual-property standpoint, which →
- The tool may cause unlawful disparate impact: Under nondiscrimination law, what is the primary legal risk even →
- Whether the team can establish lawful basis and purpose: What is the decisive issue before reuse? →
- The new counseling prediction purpose must be assessed: Which distinction controls the reuse analysis? →
- A non-consent basis must still satisfy GDPR conditions: What is the decisive distinction? →
- Collect only data necessary for the recommendation purpose: Which distinction is decisive before collection? →
- Pseudonymized personal data: How should the records be classified for GDPR purposes? →
- The authority is controller and provider processor under: Which role allocation follows actual purposes and →
- Use an Article 28 processor agreement: Which control reflects the provider’s role? →
- Whether processing is likely to create high risk: Before processing begins, which distinction determines →
- Consult the supervisory authority: What is required before processing starts? →
- A trained decision-maker independently examines relevant: Which review arrangement is meaningful? →
- Assess the Article 9 exception and another lawful basis: Which procurement issue is decisive? →
- Documented adequacy or Chapter V safeguards: What evidence is missing? →
- Verify the retention exception and process the rights: What should it do first? →
- Document an applicable lawful basis for the training: Which direct control is still missing? →
- Assess compatibility between the original and proposed: What missing control is most direct? →
- Document the applicable non-consent lawful basis: Which missing control addresses consent versus other lawful →
- Define only necessary fields: Before collection, which missing control most directly implements data →
- Treat the coded records as personal data: Which control most directly reflects the correct classification? →
- Map each processing purpose to its GDPR role: What is the most direct missing control? →
- Execute an Article 28-compliant processor arrangement: Which missing control is most direct? →
- Complete and document a GDPR Article 35 DPIA first: Which missing control is required before processing when →
- Consult the competent supervisory authority before: What is the most direct missing control before processing? →
- Empower a qualified reviewer to examine evidence and alter: Which missing control most directly creates →
- Assess the applicable Article 9 exception: What missing control is most direct? →
- Document the applicable Chapter V safeguard and supporting: Which missing control is most direct? →
- Define retention limits and a coordinated workflow: Which missing control most directly addresses both gaps? →
- Treat public availability as access evidence: Which interpretation best fits these observations? →
- Assess purpose compatibility and lawful basis before: What should procurement require first? →
- Use the applicable legal-obligation basis: Which conclusion is most supportable? →
- Collect only age band and region: Which action best applies minimization? →
- Treat it as personal data because reidentification remains: How should the dataset be treated for the agency’s →
- Classify the provider as controller for its own analytics: Which role best describes that separate activity? →
- Require an Article 28 processor arrangement: What procurement decision best addresses the evidence? →
- Complete a GDPR DPIA before processing: What must happen before processing begins? →
- Consult the competent supervisory authority before launch: What must happen first? →
- Require a reviewer with authority: What control is needed? →
- Potential biometric special-category processing: What does this evidence support? →
- Applicable adequacy decision or documented Chapter V: What evidence is still decisive before approval? →
- The request requires lifecycle handling and an exception: What is the clearest immediate distinction? →
- Document lawful basis: Which evidence should resolve approval uncertainty first? →
- A documented purpose-and-lawful-basis compatibility: What evidence should it obtain before approval? →
- A comparison of consent voluntariness and alternative: What evidence should resolve the uncertainty? →
- Define the minimum fields needed for invoice matching: What evidence should resolve approval? →
- Run a realistic reidentification test: What evidence should resolve whether the data are anonymized? →
- Document each party’s purposes and means: What evidence should resolve the parties’ roles? →
- Verify Article 28 terms for instructions: Which evidence should be verified before approval? →
- Document purposes: Which evidence should resolve the approval uncertainty? →
- Escalate for Article 36 prior consultation: What should resolve this uncertainty before deployment? →
- Reviewers can examine reasons: Which evidence best shows that review is meaningful rather than a rubber stamp? →
- Document the identification purpose and Article 9 basis: Which evidence should resolve approval? →
- Document the Chapter V mechanism and destination-risk: Which evidence is most decisive? →
- Map copies, define retention, and test the erasure-request: Which evidence should resolve approval of the →
- Document a suitable lawful basis and assess purpose: Which approach satisfies the stated constraint? →
- Compare the proposed use with the original purpose: Which approach best addresses the explicit purpose →
- Assess whether another documented lawful basis fits: Which approach best resolves the lawful-basis →
- Collect only fields necessary for itinerary assistance: Which approach satisfies data minimization? →
- Use pseudonymization with separately protected: Which approach best satisfies both constraints? →
- Controller processing for the supplier’s independent reuse: How should the supplier’s reuse be characterized? →
- An Article 28 processor agreement: Which contract feature is decisive? →
- A DPIA addressing necessity: What must the bank complete before processing begins? →
- Seek prior consultation with the competent supervisory: What is the required next governance step before →
- An informed reviewer evaluates reasons: Which review arrangement is meaningful? →
- Apply Article 9 conditions alongside an ordinary GDPR: Which governance approach is required? →
- Document an applicable Chapter V safeguard and assess: What should happen before transfer? →
- Assess the request: What should the agency do first? →
- Disparate impact requiring investigation: Which issue is most directly presented? →
- Show the tool measures job-related attributes and is: Which distinction is decisive under US →
- Adopt the equally effective feature with the smaller: What should the retailer do? →
- Provide a reasonable accommodation: What is the legally appropriate response under applicable US employment →
- A disparity signal requiring investigation: What does the disparity represent? →
- Human contribution to protectable expression may support: Which distinction is most relevant to potential →
- Treat training permission and output copyrightability as: Which distinction must it preserve under US →
- Substantiate accuracy claims with reliable evidence: What is the decisive requirement? →
- Support the bias claim with evidence covering relevant: Which distinction matters before making that claim? →
- Verify the capability claim with evidence for the intended: Which control best addresses the US →
- Escalate the foreseeable safety risk for legal review: What is the most appropriate legal-governance →
- Analyze selection-rate disparities by protected group: What is the most direct missing control for this →
- Validate the test against job performance: What control is missing? →
- Evaluate and adopt the less discriminatory rule: What control most directly addresses the finding? →
- Offer an individualized reasonable accommodation process: What is the most direct missing control? →
- Investigate the disparity and potential alternatives: What is the missing control? →
- Human creative contributions: What should the administrator document? →
- Verify rights or permissions for the training materials: What control addresses the remaining issue? →
- Substantiate accuracy across the advertised population: What control is most directly missing under →
- Align the claim with substantiated scope: What control is most directly missing? →
- Verify evidence substantiates the company's specific claim: What control addresses the remaining →
- Substantiate claims and assess foreseeable accuracy risks: What missing control most directly addresses both →
- Possible disparate impact requiring further analysis: What does the evidence support? →
- The validation criterion is not job-related: What conclusion best fits the evidence? →
- Evaluate adopting the less discriminatory alternative: What does the evidence support? →
- Provide the accessible equivalent and document: What does the evidence support? →
- Treat the disparity as an investigation signal: What is the most supportable characterization? →
- Assess the designer’s protectable contributions: What does the evidence support about copyrightability? →
- Analyze training permission separately: What should the employer analyze separately? →
- Representative production evidence supporting the stated: What evidence is most relevant before continuing the →
- Withdraw the unsupported phrase: What action best fits consumer-protection principles? →
- Test the advertised claim on representative local: consumer-protection rules, what does this evidence support →
- Investigate the missed overheating event before expansion: Under US consumer-protection rules and the →
- Analyze group outcomes alongside qualifications: Which evidence would best determine whether the concern →
- A criterion-related validation study: employment law? →
- Validate a less-discriminatory alternative: employment law, what evidence would show whether a →
- Assess an equivalent accommodation for the essential: employment law? →
- A larger, qualification-adjusted outcome analysis: employment law? →
- Records showing selection: copyrightability? →
- Verify permission: copyright law, what evidence plan addresses both uncertainties? →
- Examine representative defect data supporting: Before approving the claim, which evidence best resolves →
- Obtain the supplier’s substantiation records: Before approval under US consumer-protection and competition →
- Escalate the unsupported safety claim to counsel: Under US consumer-protection and competition rules, what →
- Classify direct status use as treatment: employment-selection law, which review is appropriate? →
- Complete job-related validation: Before relying on the tool, which control is decisive? →
- Retain Tool A unless testing establishes that Tool B: covered employment-selection rules, which approach →
- Provide an accessible alternative assessment with equal: Under applicable US employment-selection and →
- Investigate the disparity before drawing a legal: Under applicable US employment-discrimination rules, what →
- Document the engineer’s creative selection: Under US copyrightability principles, which approach best →
- Analyze training permission and output authorship as: Under US copyright principles, which approach is →
- Independently test representative inquiries: Under applicable US consumer-protection rules, which approach →
- Withdraw the bias-free claim pending representative: Which approach best addresses the marketing claim while →
- Test the retailer’s deployment before making the claim: Which action best meets the decisive →
- Escalate the hazard for legal and product review: Reviewers find an unverified step that could foreseeably →
- Disparate impact requiring further analysis: Which legal concept best describes the changed risk under covered →
- Prior validation automatically transfers to maintenance: Which prior assumption no longer holds for the new →
- Adopt the alternative: Under applicable US employment-selection rules, what principle applies? →
- Provide a comparable accessible assessment: Under applicable US employment-selection and →
- The disparity is a signal requiring investigation: What is the most accurate characterization under covered →
- Human-authored expression may support protection: For US copyrightability analysis, which assumption is most →
- Pause the claim pending required revalidation: Under US consumer-protection and employment-selection →
- Withdraw the unsupported claim pending: Under US consumer-protection and competition rules, what immediate →
- Validate the rural population and revise public claims: What should the agency do first? →
- Its recruitment-ranking purpose can place it within the EU: Which distinction determines the system’s EU AI →
- Treat it as high-risk and apply the relevant controls: What is the decisive classification? →
- Deployer: Which role best describes the retailer for this deployment? →
- Own-brand placement can make the company a provider: Which actor distinction is most important? →
- Reassess substantial modification: What review is decisive? →
- Update the risk file through the system lifecycle: Which documentation approach best satisfies the EU AI Act →
- Record data-governance evidence for the intended: Which evidence most directly addresses the decisive →
- Implement deployer-side human oversight procedures: What is the decisive governance gap? →
- Monitor performance and address post-market findings: Which response reflects the decisive distinction? →
- Separate GPAI model duties from application-level controls: Which distinction should guide the compliance →
- Evidence of systemic-risk evaluation: Which additional evidence should the purchaser seek from the provider →
- Treat open licensing as limited and assess the company’s: Which conclusion is most defensible? →
- Disclose synthetic content while retaining separate: Which implementation best addresses the stated →
- Stop the prohibited use: Which conclusion is correct? →
- Provide prior notice and label generated messages as: Which distinction should the compliance plan reflect? →
- Map each issue to the AI Office or national authority: Which authority distinction should guide the initial →
- Document the risk-management process: Which missing control is most direct? →
- Provide an AI interaction notice: Which missing control is most direct? →
- Define deployer oversight: Which missing control is most direct? →
- Assess provider responsibilities: Which missing control is most direct? →
- Assess substantial modification: Before distribution, which missing control is most direct? →
- Document risk management: Which missing control is most direct? →
- Document data-governance evidence: Which missing control is most direct? →
- Provide deployer oversight instructions: Which missing control is most direct? →
- Establish post-market monitoring and incident response: Which missing control is most direct? →
- Assess application-level duties: Which missing control is most direct? →
- Add a formal serious-incident reporting and response: What is the most direct missing control? →
- Adopt a copyright-compliance policy: Which control is missing? →
- Label the generated interview videos as AI-generated: What control is missing? →
- Stop the prohibited practice: What is the most direct control? →
- Give prior notice and label generated content: Which action addresses both requirements? →
- Map escalation routes to the responsible authorities: What control is most direct? →
- Reassess intended purpose: What does the evidence support about risk analysis? →
- The stated facts support stopping the prohibited use: What does the evidence support? →
- Reassess provider and deployer roles against: What does the evidence support? →
- Assess whether modification and own-name distribution: What does the evidence support? →
- Assess the retailer as a potential provider: What does this evidence most defensibly support? →
- Document mitigations and post-deployment verification: Which documentation action best addresses the evidence →
- Assess representativeness and label quality across: What evidence should it prioritize? →
- Name trained overseers and authorize pause: What additional control is most necessary? →
- Begin post-market monitoring: Which requirement does the evidence most directly trigger? →
- The model and application may have different obligations: Which distinction should guide the manufacturer’s →
- Add systemic-risk safeguards: What does the evidence most directly support? →
- Check applicable exception conditions: What is the most defensible next step? →
- Require context-specific viewer disclosure: What should the buyer require? →
- Stop the prohibited use: What is the correct governance response? →
- The insurer may have content labeling: What does the evidence most directly support? →
- National authorities and the AI Office have distinct: Which interpretation best diagnoses the authorities’ →
- Document intended uses: Which evidence would best resolve the risk-category uncertainty before approval? →
- The documented purpose: What evidence should resolve whether prohibited-practice analysis or high-risk →
- Review contracts and deployment records for market: Which evidence best resolves whether the university is →
- Branding, modification records, intended purpose,: What evidence should resolve the company’s actor duties? →
- Maintain before-and-after technical and purpose records: What evidence best resolves substantial-modification →
- File the maintained lifecycle risk register: Which evidence most directly addresses that requirement? →
- A documented data-governance assessment: Which evidence best addresses high-risk data-governance uncertainty →
- Document role-specific instructions: What evidence should resolve whether deployer instructions and human →
- Obtain the completed conformity-assessment evidence: Which evidence best resolves whether approval →
- Request model documentation plus application-level role: Which request best resolves the remaining uncertainty →
- Obtain a systemic-risk evidence package: Which evidence should procurement require before approval? →
- Verify license conditions and applicable exceptions: Which evidence should procurement obtain before approval? →
- Map each output type to its applicable Article 50: Which evidence best resolves the transparency uncertainty →
- Obtain a prohibited-practice analysis tied to intended: Which evidence should resolve approval? →
- Separate evidence for prior notice and generated-content: Which evidence should it obtain before approval? →
- Classify the breach and jurisdiction: Which evidence best resolves the uncertainty before escalation? →
- Classify it from its intended purpose before selecting: Which approach satisfies the explicit constraint? →
- Pause deployment pending prohibited-practice analysis: Which approach should govern the decision? →
- Recognize provider duties for the company’s own-brand: Which approach correctly allocates responsibility? →
- The supplier remains provider: What is the clearest classification? →
- Assess whether the retraining and refund function: Assuming EU AI Act duties apply, which approach best →
- Maintain an iterative risk file covering identified risks: Which documentation approach best supports risk →
- Document data provenance and representativeness gaps: Which evidence is most important first? →
- Issue role-specific instructions and define review: What should the deployer do? →
- Begin post-market monitoring and investigate: Which response addresses the immediate legal distinction? →
- Model-level obligations and downstream high-risk: Which allocation is most accurate? →
- Complete systemic-risk evaluation: Which next step best addresses both constraints? →
- Check whether the specific open-license conditions: Assuming EU AI Act model duties apply, which statement →
- Disclose the summaries’ AI-generated nature to clients: Which approach addresses the specific client-facing →
- Suspend the prohibited inference and redesign: What should the employer do? →
- Give prior notice and label generated outputs when: Which implementation best preserves that distinction? →
- Identify the applicable national authority’s remit: What is the sound first step? →
- The prior low-risk assumption no longer fits the changed: Which prior assumption must be revisited? →
- The high-risk-controls pathway governs the changed use: Which prior assumption no longer holds? →
- The buyer can rely on deployer-only responsibilities: Which prior assumption no longer holds? →
- The employer must verify audit: What assumption must change? →
- The prior internal-population assumption no longer: Which assumption must be revisited? →
- Document intended use: Which change belongs specifically in the developer’s documentation for the new →
- Document the employer’s actual use and decision process: Which responsibility is primarily the deployer’s? →
- Disclose limitations and support informed human review: What developer action most directly addresses the →
- Reassess whether low-stakes use still fits insurance: What prior assumption must be revisited? →
- GOVERN by assigning escalation authority: Which NIST AI RMF function most directly addresses this →
- MAP actual use: Which NIST function should frame the next analysis? →
- Measure subgroup results: Which NIST function addresses this immediate gap? →
- Manage identified risks through treatment: Which NIST function governs this case-specific decision? →
- Use GOVERN throughout and revisit roles as context changes: Which approach reflects the framework →
- It evaluates organizational AI management processes: Which distinction determines what a scoped →
- Assess administrative impacts across the lifecycle: What assessment conclusion best fits ISO/IEC 42005 →
- Shared concepts for consistent communication about AI: The team is deciding what ISO/IEC 22989 should provide →
- Apply Canadian law: Which governance position is most defensible? →
- Obtain use-case assurance: What additional conclusion is required for this specific use case? →
- Assign decision authority and third-party accountability: Which missing control most directly reflects NIST →
- Map purpose, users, affected workers, and foreseeable uses: Which control is most direct? →
- Test subgroups and record uncertainty: Which control is most direct? →
- Prioritize treatments and document residual risks: Which control is most direct? →
- Re-map affected people and coordinate reassessment: Which action reflects the NIST AI RMF's iterative, →
- Run documented improvement reviews: Which control most directly addresses it? →
- Update the impact assessment as context and lifecycle: What missing control most directly addresses this →
- Adopt ISO/IEC 22989 concepts for consistent AI terminology: Which action best fits ISO/IEC 22989’s purpose? →
- Use OECD principles alongside applicable legal compliance: What is the most defensible governance position? →
- Validate this use case and document impacts: What control is most direct? →
- GOVERN is present formally but weak operationally across: Which interpretation best fits the evidence about →
- Map intended purpose: Which NIST AI RMF MAP conclusion is most appropriate? →
- Run disaggregated tests and document coverage: Under NIST MEASURE, what does the evidence most directly →
- Prioritize treatment: Which MANAGE action is most direct? →
- Iterate among functions as evidence and context change: Which interpretation best reflects the relationship →
- The scoped management system exists: What do these observations support? →
- Update the impact assessment and separately address: What conclusion is best supported under ISO/IEC →
- Provide shared AI terminology for procurement discussions: A retailer is procuring software and finds that →
- Use the OECD Principles for responsible governance: What should the company do? →
- Use-case assurance evidence: What evidence is still decisive? →
- Documented decision authority and escalation assignments: Which evidence would most directly resolve this →
- A documented contextual map of users: What should they obtain first? →
- Representative rural tests: Which evidence best addresses the approval gap? →
- A documented treatment plan with owners: Which evidence is most relevant? →
- A reassessed context record linked to new measurements: Which evidence would resolve the disagreement? →
- Verify the documented AIMS scope covers this admissions: Which evidence best resolves that uncertainty? →
- Review a lifecycle impact assessment covering affected: Which evidence best resolves the approval uncertainty? →
- A terminology crosswalk applying ISO/IEC 22989 concepts: Which evidence should reviewers request? →
- A contextual crosswalk linking OECD principles: Which evidence best resolves whether the organization has →
- A use-case assessment documenting applicant impacts: Which evidence should the administrator request first? →
- Maintain cross-functional policies: Which approach best reflects NIST GOVERN? →
- A MAP record covering purpose: Which evidence should reviewers prioritize to resolve the contextual →
- Representative subgroup tests with uncertainty: Which evidence best satisfies that condition? →
- MANAGE: Which NIST function should guide this decision? →
- Use an iterative: Which plan better reflects the NIST AI RMF distinction? →
- Certify management processes and assess screening impacts: Which approach fits the stated scope? →
- Update the impact assessment: Under ISO/IEC 42005 guidance, what should it do? →
- ISO/IEC 22989 concepts and terminology for artificial: Which resource most directly fits this task? →
- Apply applicable law and OECD guidance: Which approach is most defensible? →
- Assess the use case: What should it do before relying on the priorities? →
- The intended use remains the same: Which prior governance assumption no longer holds under NIST AI RMF GOVERN? →
- The original intended audience and use conditions remain: Which prior MAP assumption must be revisited first? →
Which Understanding How Laws, Standards and Frameworks Apply to AI topics are you weakest in?
Five minutes, and you get a score per domain instead of one number.
Test your AIGP readiness — freePart of the Certsqill AIGP question bank.