Courseiva
hardMultiple Select

AIF-C01 Practice Question: A healthcare startup is deploying an AI model to…

A healthcare startup is deploying an AI model to assist with diagnosis. They want to comply with the EU AI Act, which classifies medical AI as high-risk. Which THREE requirements must they fulfill? (Choose three.)

⚠ Common exam trap

The trap is mixing GDPR principles (data minimization) into the AI Act requirements, and forgetting that human oversight is mandatory — candidates who pick 'model decides autonomously' fail the high-risk test.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Provide technical documentation and logs for traceability

Under the EU AI Act, high-risk AI systems such as medical diagnostic AI must satisfy a set of mandatory requirements, and option A is correct because providers must supply technical documentation and maintain automatically generated logs that enable traceability and post-market monitoring of the system's operation. Option B is correct because Article 9 requires a risk management system that is established, implemented, documented, and maintained as a continuous iterative process throughout the entire lifecycle of the high-risk AI system. Option C is correct because high-risk systems must be designed to allow effective human oversight, enabling humans to prevent or minimize risks to health, safety, or fundamental rights, which is especially critical in a clinical diagnosis context. Option D is not a stated EU AI Act requirement; the Act addresses data governance, quality, and representativeness rather than mandating minimization of training data to only necessary data. Option E is incorrect because allowing the model to make final decisions without human review directly contradicts the human oversight requirement for high-risk AI systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Provide technical documentation and logs for traceability

    Why this is correct

    High-risk systems under the EU AI Act require technical documentation and automatic logging to enable traceability and post-market monitoring. This satisfies the stem's compliance constraint by letting regulators and deployers reconstruct the model's operation and verify conformity.

  • ✓

    Establish a risk management system throughout the AI system's lifecycle

    Why this is correct

    The EU AI Act mandates a continuous, documented risk management system across the entire lifecycle of high-risk systems, not a one-off assessment. This satisfies the stem's compliance constraint by requiring iterative identification, evaluation and mitigation of risks as the diagnostic model evolves.

  • ✓

    Ensure human oversight to prevent or minimize risks

    Why this is correct

    High-risk medical AI must be designed for effective human oversight, allowing clinicians to interpret outputs, intervene and override. This satisfies the EU AI Act's requirement to prevent or minimise risks to patients, ensuring the diagnostic tool remains under qualified professional control.

  • ✗

    Minimize the amount of training data to only necessary data

    Why it's wrong here

    The EU AI Act requires data governance and quality, not data minimisation; high-risk systems must train on sufficiently representative datasets to limit bias. It is tempting because GDPR-style minimisation feels privacy-friendly, and would be correct for reducing personal data collection under data protection law, not for AI Act conformity.

  • ✗

    Allow the model to make final decisions without human review

    Why it's wrong here

    High-risk obligations mandate human oversight, so removing human review directly contradicts the EU AI Act. It is tempting because automation promises faster diagnosis, and would be correct for certain low-risk or fully automated administrative tasks where the Act imposes no oversight requirement.

About these practice questions

One of 862 original AIF-C01 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This AIF-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AIF-C01 exam.