Meeting Financial Compliance Requirements with Vertex AI Agent Builder
A financial institution is implementing a generative AI chatbot to handle customer inquiries. The institution must comply with regulatory requirements (e.g., GDPR, SOX) and ensure data privacy. Which TWO actions should the institution take?
⚠ Common exam trap
The trap here is choosing 'on-premises only' as a silver bullet for data privacy — candidates conflate physical data location with regulatory compliance, but GDPR and SOX require governance, validation, and auditability regardless of where the model runs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a Center of Excellence (CoE) for AI governance to oversee model deployment and monitoring.
Option A is correct because establishing a Center of Excellence (CoE) for AI governance provides the oversight, policy enforcement, and monitoring needed to keep a generative AI chatbot compliant with GDPR and SOX, covering model deployment, risk management, and accountability. Option D is correct because model validation and testing are essential to verify that chatbot outputs meet regulatory standards, detect bias or data leakage, and ensure ongoing compliance before and after deployment. Option B is incorrect because using Vertex AI without additional data governance controls fails to address GDPR and SOX privacy and audit requirements. Option C is incorrect because a pre-trained model without customization does not by itself satisfy regulatory compliance or data privacy obligations. Option E is incorrect because on-premises deployment alone does not guarantee compliance and may not be feasible or sufficient for the institution's regulatory and operational needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Establish a Center of Excellence (CoE) for AI governance to oversee model deployment and monitoring.
Why this is correct
A CoE centralises AI governance, giving the financial institution the oversight structure needed to enforce GDPR and SOX controls across model deployment and monitoring. It assigns accountability, standardises review gates and ensures privacy requirements are applied consistently.
- ✗
Use Vertex AI without additional data governance controls to simplify deployment.
Why it's wrong here
Vertex AI without governance controls leaves data classification, access logging and retention unmanaged, so GDPR and SOX obligations go unmet. It is tempting because Vertex AI supplies the managed model hosting and tooling needed to build the chatbot quickly; it would be correct where the workload carries no regulated personal or financial data requiring those controls.
- ✗
Use a pre-trained model without customization to reduce development time.
Why it's wrong here
A pre-trained model without customisation still processes customer data, so privacy and regulatory controls remain unaddressed; reduced development time does not satisfy GDPR or SOX. It is tempting because pre-trained models genuinely accelerate delivery, and would be the right choice for low-risk, non-regulated use cases where no personal or financial data is handled.
- ✓
Implement model validation and testing to ensure outputs meet regulatory standards.
Why this is correct
Model validation and testing directly satisfies the regulatory compliance constraint by systematically verifying that generative outputs align with GDPR and SOX requirements before deployment. Testing catches outputs that could breach data privacy rules, providing auditable evidence of due diligence. This proactive assurance mechanism is essential for a financial institution facing strict regulatory scrutiny.
- ✗
Deploy the model on-premises only to keep data within local infrastructure.
Why it's wrong here
On-premises deployment does not by itself satisfy GDPR or SOX; those obligations concern data handling, retention and auditability wherever processing occurs. It is tempting because keeping data within local infrastructure genuinely addresses sovereignty and data-residency concerns, and would be the right choice where regulation explicitly forbids cross-border transfer or mandates physical isolation.
Go deeper
Related to this question
About these practice questions
This Generative AI Leader question is part of Courseiva's 1,008-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This Generative AI Leader practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the Generative AI Leader exam.