hardMultiple Select
AIF-C01 Practice Question: A healthcare startup is deploying an AI model to…
A healthcare startup is deploying an AI model to assist with diagnosis. They want to comply with the EU AI Act, which classifies medical AI as high-risk. Which THREE requirements must they fulfill? (Choose three.)
⚠ Common exam trap
The trap is mixing GDPR principles (data minimization) into the AI Act requirements, and forgetting that human oversight is mandatory — candidates who pick 'model decides autonomously' fail the high-risk test.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide technical documentation and logs for traceability
Under the EU AI Act, high-risk AI systems such as medical diagnostic AI must satisfy a set of mandatory requirements, and option A is correct because providers must supply technical documentation and maintain automatically generated logs that enable traceability and post-market monitoring of the system's operation. Option B is correct because Article 9 requires a risk management system that is established, implemented, documented, and maintained as a continuous iterative process throughout the entire lifecycle of the high-risk AI system. Option C is correct because high-risk systems must be designed to allow effective human oversight, enabling humans to prevent or minimize risks to health, safety, or fundamental rights, which is especially critical in a clinical diagnosis context. Option D is not a stated EU AI Act requirement; the Act addresses data governance, quality, and representativeness rather than mandating minimization of training data to only necessary data. Option E is incorrect because allowing the model to make final decisions without human review directly contradicts the human oversight requirement for high-risk AI systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Provide technical documentation and logs for traceability
Why this is correct
High-risk systems under the EU AI Act require technical documentation and automatic logging to enable traceability and post-market monitoring. This satisfies the stem's compliance constraint by letting regulators and deployers reconstruct the model's operation and verify conformity.
- ✓
Establish a risk management system throughout the AI system's lifecycle
Why this is correct
The EU AI Act mandates a continuous, documented risk management system across the entire lifecycle of high-risk systems, not a one-off assessment. This satisfies the stem's compliance constraint by requiring iterative identification, evaluation and mitigation of risks as the diagnostic model evolves.
- ✓
Ensure human oversight to prevent or minimize risks
Why this is correct
High-risk medical AI must be designed for effective human oversight, allowing clinicians to interpret outputs, intervene and override. This satisfies the EU AI Act's requirement to prevent or minimise risks to patients, ensuring the diagnostic tool remains under qualified professional control.
- ✗
Minimize the amount of training data to only necessary data
Why it's wrong here
The EU AI Act requires data governance and quality, not data minimisation; high-risk systems must train on sufficiently representative datasets to limit bias. It is tempting because GDPR-style minimisation feels privacy-friendly, and would be correct for reducing personal data collection under data protection law, not for AI Act conformity.
- ✗
Allow the model to make final decisions without human review
Why it's wrong here
High-risk obligations mandate human oversight, so removing human review directly contradicts the EU AI Act. It is tempting because automation promises faster diagnosis, and would be correct for certain low-risk or fully automated administrative tasks where the Act imposes no oversight requirement.
Go deeper
Related to this question
About these practice questions
One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.