IAPP AIGP Artificial Intelligence Governance Professional Exam Practice Test
Artificial Intelligence Governance Professional Questions and Answers
All of the following are potential benefits of using private over public LLMs EXCEPT?
Which of the following may bepermissible usesof an AI system under the EU AI ActEXCEPT?
What is the primary purpose of conducting ethical red-teaming on an Al system?
Scenario:
A public sector agency is reviewing proposed AI use cases for improving services. It wants to prioritize implementations that deliver value butminimize unintended negative consequences.
When evaluating which AI use cases to implement, an organization should consider all of the following EXCEPT:
You asked a generative Al tool to recommend new restaurants to explore in Boston, Massachusetts that have a specialty Italian dish made in a traditional fashion without spinach and wine. The generative Al tool recommended five restaurants for you to visit.
After looking up the restaurants, you discovered one restaurant did not exist and two others did not have the dish.
This information provided by the generative Al tool is an example of what is commonly called?
Which of the following deployments of generative Al best respects intellectual property rights?
All of the following are examples of biometric data in the US EXCEPT?
What is the most important reason for documenting risks when developing an AI system?
The planning phase of the Al life cycle articulates all of the following EXCEPT the?
During the first month when the company monitors the model for bias, it is most important to?
Pursuant to the White House Executive Order of November 2023, who is responsible for creating guidelines to conduct red-teaming tests of Al systems?
All of the following analyses are part of a deactivating risk strategy EXCEPT?
A bank is aiming to comply with ISO/IEC 42005:2025, and is studying how to adopt the standard in light of a new AI customer service system that it would like to implement.
In addition to the risk management process the bank already has in place to assess the risks of any potential new systems, which of the following actions is the most effective in adopting the ISO/IEC 42005:2025 standard?
CASE STUDY
Please use the following answer the next question:
ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.
ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed tA. human underwriter for final review.
ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women ' s loan applications due primarily to women historically receiving lower salaries than men.
Each of the following steps would support fairness testing by the compliance team during the first month in production EXCEPT?
According to the GDPR, what is an effective control to prevent a determination based solely on automated decision-making?
What is the best reason for a company adopt a policy that prohibits the use of generative Al?
The processes and methods that allow human users to understand and trust the outputs produced by AI are important in addressing which key regulatory concern?
MULTI-SELECT
Please select 3 of the 5 options below. No partial credit will be given.
Training an AI model is time-consuming because of?
A US-based mortgage lender has purchased a chatbot. They plan to have the chatbot collect information from consumers who are interested in loans and offer the consumers 2-3 different options based on its current pricing and product offerings, which change frequently. This chatbot was initially developed and previously deployed by a Russian airline for booking flights.
The best option for the part of the process that generates the loan offers is?
CASE STUDY
Please use the following answer the next question:
A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant agreed-upon criteria (e.g., a confidence score below a threshold).
To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.
The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.
In the design phase, what is the most important step for the healthcare network to take when mapping its existing data to the clinical research partner data?
MULTI-SELECT
Please select 3 of the 5 options below. No partial credit will be given.
From a governance perspective, which of the following correctly describe the responsibilities of AI developers or deployers?
Scenario:
An enterprise is evaluating multiple third-party generative AI tools to integrate into its platform. As part of its AI governance policy, it is assessing themost effective methodsto reduce risks related to bias, data misuse, and liability when using third-party solutions.
All of the following are commonly adopted processes and policies in reducing potential risks introduced by third-party AI tools or applications EXCEPT:
CASE STUDY
A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.
All of the following are obligations of the company as a data controller when implementing its AI system EXCEPT?
An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.
What additional obligations must the bank fulfill prior to deployment?
Which of the following use cases would be best served by a non-AI solution?
Scenario:
An organization wants to leverage its existing compliance structures to identify AI-specific risks as part of an ongoing data governance audit.
Which of the following compliance-related controls within an organization ismost easily adaptedto identify AI risks?
CASE STUDY
Please use the following answer the next question:
XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.
It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.
Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.
The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.
The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.
All of the following are potential negative consequences created by using the Al tool when making hiring decisions EXCEPT?
In the machine learning context, feature engineering is the process of?
Which risk management framework/guide/standard focuses on value-based engineering methodology?
A company plans on procuring a tool from an Al provider for its employees to use for certain business purposes.
Which contractual provision would best protect the company ' s intellectual property in the tool, including training and testing data?
A company ' s AI-powered hiring tool is found to be consistently ranking male candidates higher than female candidates with similar qualifications.
Which of the following is the most immediate and critical governance action required to address this issue?
What is the term for an algorithm that focuses on making the best choice achieve an immediate objective at a particular step or decision point, based on the available information and without regard for the longer-term best solutions?
After completing model testing and validation, which of the following is the most important step that an organization takes prior to deploying the model into production?
Under the Canadian Artificial Intelligence and Data Act, when must the Minister of Innovation, Science and Industry be notified about a high-impact Al system?
An Al system that maintains its level of performance within defined acceptable limits despite real world or adversarial conditions would be described as?
All of the following may be permissible uses of an Al system under the EU Al Act EXCEPT?
You are a privacy program manager at a large e-commerce company that uses an Al tool to deliver personalized product recommendations based on visitors ' personal information that has been collected from the company website, the chatbot and public data the company has scraped from social media.
A user submits a data access request under an applicable U.S. state privacy law, specifically seeking a copy of their personal data, including information used to create their profile for productrecommendations.
What is the most challenging aspect of managing this request?
CASE STUDY
Please use the following to answer the next question:
A mid-size US healthcare network has decided to develop an AI solution to detect a type of cancer that is most likely to arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records to a radiologist for secondary review pursuant to agreed-upon criteria such as a confidence score below a threshold.
To date, the healthcare network has:
Defined its AI ethical principles
Conducted discovery to identify the intended uses and success criteria for the system
Established an AI risk committee
Assembled a cross-functional team with clear roles and responsibilities
Created policies and procedures to document standards, workflows, timelines and risk thresholds during the project
The healthcare network intends to retain a cloud provider to host the solution. It also intends to retain a large consulting firm to supplement its small data science team and help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.
Which of the following steps can best mitigate the possibility of discrimination prior to training and testing the AI solution?
A Canadian company is developing an Al solution to evaluate candidates in the course of job interviews.
Before offering the Al solution in the EU market, the company must take all of the following steps EXCEPT?
A shipping service based in the US is looking to expand its operations into the EU. It utilizes an in-house developed multimodal AI model that analyzes all personal data collected from shipping senders and recipients, and optimizes shipping routes and schedules based on this data.
As they expand into the EU, all of the following descriptions should be included in the technical documentation for their AI model EXCEPT?
A company has trained an ML model primarily using synthetic data, and now intends to use live personal data to test the model.
Which of the following is NOT a best practice apply during the testing?
What is the primary reason the EU is considering updates to its Product Liability Directive?
Which of the following use cases would be best served by a non-AI solution?
The framework set forth in the White House Blueprint for an Al Bill of Rights addresses all of the following EXCEPT?
CASE STUDY
Please use the following answer the next question:
A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.
The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.
The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.
The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.
During the procurement process, what is the most likely reason that the third-party consultant asked each vendor for information about the diversity of their datasets?
CASE STUDY
Please use the following answer the next question:
XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.
It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.
Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.
The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.
The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.
Which other stakeholder groups should be involved in the selection and implementation of the Al hiring tool?
CASE STUDY
A global marketing agency is adapting a large language model ( " LLM " ) to generate content for an upcoming marketing campaign for a client ' s new product: a hard hat designed for construction workers of any gender to better protect them from head injuries.
The marketing agency is accessing the LLM through an application programming interface ( " API " ) developed by a third-party technology company. They want to generate text to be used for targeted advertising communications that highlight the benefits of the hard hat to potential purchasers. Both the marketing agency and the technology company have taken reasonable steps to address Al governance.
The marketing company has:
• Entered into a contract with the technology company with suitable representations and warranties.
• Completed an impact assessment on the LLM for this intended use.
• Built technical guidance on how to measure and mitigate bias in the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Followed applicable regulatory requirements.
• Created specific legal statements and disclosures regarding the use of the Al on its client ' s advertising.
The technology company has:
• Provided guidance and resources to developers to address environmental concerns.
• Build technical guidance on how to measure and mitigate bias in the LLM.
• Provided tools and resources to measure bias specific to the LLM.
• Enabled technical aspects of transparency, explainability, robustness and privacy.
• Mapped and mitigated potential societal harms and large-scale impacts.
• Followed applicable regulatory requirements and industry standards.
• Created specific legal statements and disclosures regarding the LLM. including with respect to IP and rights to data.
Which stakeholder is responsible for the lawful collection of data used to train the foundational AI model?
Which of the following is a subcategory of Al and machine learning that uses labeled datasets to train algorithms?
Which of the following most encourages accountability over Al systems?
Scenario:
A European AI technology company was found to be non-compliant with certain provisions of the EU AI Act. The regulator is considering penalties under the enforcement provisions of the regulation.
According to the EU AI Act, which of the following non-compliance examples could lead to fines of up to €15 million or 3% of annual worldwide turnover(whichever is higher)?
The benefit of having a clear process for handling AI-related incidents is that it reduces?
Which of the following is NOT a common type of machine learning?
According to the GDPR, an individual has the right to have a human confirm or replace an automated decision unless that automated decision?
CASE STUDY
Please use the following answer the next question:
Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.
In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.
GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.
Which of the following risks should be of the highest concern to individual teachers using generative Al to ensure students learn the course material?
What is the most important reason to document the results of AI testing?
Scenario:
A global organization wants to align with international frameworks on AI governance. They are reviewing guidance from the OECD on how to incorporate broader governance tools into their AI program.
Codes of conductandcollective agreementsare what type of assessment tools as defined by theOrganization for Economic Cooperation and Development (OECD)?
Machine learning is best described as a type of algorithm by which?
CASE STUDY
Please use the following answer the next question:
ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.
ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed a human underwriter for final review.
ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women ' s loan applications due primarily to women historically receiving lower salaries than men.
Which of the following is the most important reason to train the underwriters on the model prior to deployment?