AI0-001 AI Security, Ethics and Governance Practice Question
You are an AI governance officer at a bank that uses a machine learning model to predict credit risk. The model was developed by an external vendor and uses a proprietary algorithm. The bank's compliance team has determined that the model must be explainable to meet regulatory requirements. However, the vendor claims the model is a 'black box' and cannot provide explanations. You need to ensure compliance while maintaining the model's performance. What is the best course of action?
⚠ Common exam trap
It's easy for candidates to assume that a 'black box' model cannot be explained at all, leading them to choose replacement with a simpler model (Option C), when in fact model-agnostic techniques like SHAP or LIME can provide explanations without altering the model itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a model-agnostic explanation technique like SHAP
D is correct because model-agnostic explanation techniques like SHAP (SHapley Additive exPlanations) can provide post-hoc interpretability for any black-box model without requiring access to its internal structure or proprietary algorithm. This allows the bank to meet regulatory explainability requirements while preserving the vendor's proprietary model and its predictive performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the requirement as the model is proprietary
Why it's wrong here
Regulatory explainability obligations bind the bank regardless of vendor ownership, so declining to act leaves it non-compliant. Ignoring the gap is tempting because the algorithm is the vendor's intellectual property, but proprietary licensing never transfers accountability for the bank's own credit decisions to the supplier.
- ✗
Ask the vendor to develop a custom explanation module
Why it's wrong here
A vendor-built explanation module is unverifiable and may simply rationalise outputs rather than reveal the true decision logic regulators require. Commissioning one is tempting because it appears to preserve the existing model, but post-hoc vendor explanations lack the independent validation that techniques such as SHAP or LIME applied by the bank provide.
- ✗
Replace the model with a simpler, interpretable model
Why it's wrong here
Replacing the vendor's model discards the proprietary algorithm's predictive performance, which the scenario requires you to maintain. Interpretable models such as linear regression or decision trees are the right choice when building a model from scratch and accuracy trade-offs are acceptable, but here they cannot replicate the black box's outputs.
- ✓
Use a model-agnostic explanation technique like SHAP
Why this is correct
SHAP is model-agnostic: it treats the vendor's proprietary model as a black box, approximating each feature's contribution to individual predictions from input-output behaviour alone. This delivers the per-decision explanations regulators require without retraining or replacing the model, preserving its performance.
About these practice questions
Courseiva writes every AI0-001 question from scratch — 962 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI0-001 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI0-001 exam.