Which TWO actions should be taken when a model exhibits significant drift?
Crucial to deciding whether to retrain or adjust inputs.
Why this answer
The model should be assessed for retraining and the production environment should be audited.
199 questions total · 3pages · All types, answers revealed
Page 1 of 3
Page 2Which TWO actions should be taken when a model exhibits significant drift?
Crucial to deciding whether to retrain or adjust inputs.
Why this answer
The model should be assessed for retraining and the production environment should be audited.
You are mapping AI risks to the NIST AI RMF. Which step is essential when documenting the 'Map' function for a high-risk autonomous system?
The 'Map' function focuses on understanding the context to prioritize risks.
Why this answer
Identifying and documenting the context and intended use is the foundation of mapping AI risks to an enterprise framework.
Which THREE metrics should be tracked to assess the 'Risk' of an AI model in production?
Errors represent a direct risk to the business.
Why this answer
Risk is measured by performance stability (drift), accuracy, and operational health.
The AI Governance Committee is defining the roles for AI Risk oversight. Which TWO functions are essential for the 'Three Lines of Defense' model in AI Risk?
The first line of defense is the business unit/developer performing initial risk management.
Why this answer
The 1st line (Model Owners) and 2nd line (Risk/Compliance) are critical for effective AI risk management.
A firm is using the NIST AI Risk Management Framework to document its AI risk program. Which approach best ensures that AI risk metrics are dynamic?
Continuous monitoring and dashboarding provide the real-time visibility needed for dynamic risk management.
Why this answer
Mapping specific risk indicators to model performance monitoring allows metrics to evolve as the model's environment changes.
Which TWO documents are essential to include in the AI Risk Project 'Review Pack'?
Defines how risks will be handled.
Why this answer
The Risk Assessment report documents the analysis, and the Mitigation Plan shows how identified risks will be addressed.
What is the first step in performing an AI Risk Assessment?
Scoping is always the first step in any risk assessment process.
Why this answer
The first step is identifying the AI system and defining its intended purpose (Context).
You are integrating AI governance into the existing Corporate Governance framework. Which THREE of the following activities are essential to ensure the Board of Directors maintains adequate oversight?
This is a fundamental governance responsibility for the board.
Why this answer
Board oversight of AI requires clear policies, defined accountability, and reporting mechanisms that link AI performance to the enterprise's risk and compliance goals.
Which TWO factors should be included in an AI risk appetite statement?
Financial impact limits are a classic component of risk appetite.
Why this answer
Risk appetite must be specific to the impact and the tolerance levels for failure.
A developer is using 'Shadow Deployments' for a new AI model. What is the main risk being addressed?
Shadow mode validates the model against live data without impacting the end-user experience.
Why this answer
Shadow deployments allow real-world data validation without exposing end-users to potential model failures.
A firm adopts the 'Three Lines of Defense' model for AI. What is the specific responsibility of the 'Third Line' (Internal Audit)?
Internal Audit's role is independent assurance, not operational management.
Why this answer
The Third Line provides independent, objective assurance on the effectiveness of the risk management and governance processes.
When reporting AI risk to the board, which approach best demonstrates 'Risk Culture' maturity?
This shows an understanding of risk management and governance maturity.
Why this answer
Risk culture maturity is demonstrated by transparently reporting not just incidents, but the effectiveness of the risk management process itself, including the 'Risk Appetite' vs. 'Actual Risk' gap.
Which document is essential for defining the roles and responsibilities within an AI Risk Program?
A RACI matrix is the standard tool to formalize organizational roles in a governance program.
Why this answer
The RACI matrix clearly defines who is Responsible, Accountable, Consulted, and Informed for AI risk activities.
What is the primary objective of a 'post-implementation review' in the AI Risk Governance lifecycle?
Ongoing monitoring ensures that models do not drift into unsafe states.
Why this answer
Post-implementation reviews assess whether the AI model's performance and risk levels remain consistent with the original design and risk appetite.
When integrating AI risk into the broader ERM (Enterprise Risk Management) framework, which approach is most effective?
Integration ensures AI risk is treated with the same rigor as traditional enterprise risks.
Why this answer
AI risks should not be siloed; they should be categorized alongside existing operational and reputational risks to ensure they are visible to the Board.
Which THREE items should be included in an AI 'Risk Assessment' report for a new project?
Failure mode analysis is a standard risk assessment technique.
Why this answer
A complete report covers the risk identification, the impact analysis, and the control strategy.
Why is 'Explainability' considered a key risk management control in the AI lifecycle?
Understanding *why* a model made a decision is essential for debugging and legal compliance.
Why this answer
Explainability allows stakeholders to audit decisions and ensure they comply with regulatory requirements (like GDPR).
What is the primary benefit of documenting 'AI Model Lineage'?
Reproducibility and auditability are core requirements for AI safety and risk management.
Why this answer
Lineage allows for traceability, enabling auditability and root cause analysis in case of a model failure.
When documenting an AI Risk Program, what should be included in the 'AI Asset Register'?
These are essential for understanding the risk and accountability for each AI model.
Why this answer
An asset register must track the model's purpose, data sources, and business owner to ensure oversight.
In the context of AI risk management, what does the 'Human-in-the-Loop' (HITL) concept primarily aim to achieve?
HITL is designed to provide oversight and accountability for critical decisions.
Why this answer
HITL ensures that human judgment and ethics remain integrated into high-risk AI decision processes to prevent unmonitored failures.
A practitioner is reviewing the 'Model Card' for an AI system. What is the primary purpose of this artifact in the AI lifecycle risk management process?
Model cards serve as the foundational documentation for risk assessment and compliance.
Why this answer
Model cards provide transparency and documentation about the intended use, limitations, and performance characteristics.
Which TWO stakeholders are most important to engage when establishing an AI risk appetite?
Leadership defines the organization's appetite for risk.
Why this answer
The Board/Executive Leadership defines the appetite, while Legal/Compliance ensures that the definition meets legal requirements.
Which THREE risks are associated with 'Automated Deployment' of AI models without a human-in-the-loop?
A major risk when automation isn't constrained.
Why this answer
Without human checks, bad models can propagate quickly, causing cascading failures and security gaps.
Which role is primarily responsible for ensuring that AI-generated content adheres to intellectual property risk policies?
Legal counsel manages the risk associated with IP infringement and copyright.
Why this answer
The Chief Legal Officer or Legal counsel is accountable for IP rights and contractual obligations related to AI output.
An enterprise is establishing an AI Governance Committee. Which organizational structure best ensures that risk management is integrated into the AI development lifecycle?
Cross-functional teams provide the holistic view required for AI risk management.
Why this answer
A cross-functional approach involving data science, legal, compliance, and IT security ensures risk is addressed at every SDLC phase.
An organization discovers that their AI model exhibits bias toward a specific demographic. What is the most important step in the Incident Response process?
Suspending the model is the primary containment strategy to prevent continued harm.
Why this answer
Immediate containment is necessary to prevent further harm while the root cause is investigated.
The organization is updating its 'AI Risk Management Policy'. Which THREE components are essential to ensure it aligns with the 'Manage' function of the NIST AI RMF?
This ensures that policy violations are identified and fixed.
Why this answer
The 'Manage' function involves implementing controls. Essential components include clear policies on prioritization, documented operational procedures, and a process for ongoing monitoring and improvement.
During the AI lifecycle, when should a 'Data Quality' assessment be performed to minimize long-term risk?
Performing quality checks before the model sees the data prevents propagation of errors into model weights.
Why this answer
Data quality must be validated prior to training to ensure model reliability.
Which THREE factors should be monitored to detect 'Model Drift' in the deployment phase?
Detects if the model's behavior is changing significantly.
Why this answer
Feature distribution, target distribution, and model confidence scores all provide signals of drift.
Which TWO of the following are key components of a robust AI lifecycle risk management program?
This is essential for identifying drift and errors.
Why this answer
Continuous monitoring and version control are fundamental for governing the model's entire lifespan.
Which TWO of the following governance actions should a Chief Risk Officer (CRO) implement to align AI risk with the COSO Enterprise Risk Management (ERM) framework?
This ensures governance oversight across the enterprise.
Why this answer
COSO ERM requires integrating risk into strategy and performance. Governance structures and risk appetite alignment are key.
During the 'Monitoring' phase, which activity is most critical for identifying model 'feedback loops'?
If outputs drift significantly, it may indicate the model is creating a feedback loop in the input data.
Why this answer
Feedback loops occur when model outputs influence the future training data, which must be detected by comparing output distributions over time.
Which TWO of the following are considered 'High-Risk' AI use cases that require enhanced oversight by the Governance Committee?
Biometric systems carry significant privacy and security risks.
Why this answer
AI systems impacting physical safety or fundamental rights require the highest level of governance oversight.
Which THREE items are necessary for a comprehensive 'AI Governance Policy'?
SOPs operationalize the policy.
Why this answer
A policy needs to define roles, risk classification, and the lifecycle process.
What is 'Shadow AI'?
This represents an unmanaged risk.
Why this answer
Shadow AI refers to AI tools or models used within an organization without the knowledge or approval of the IT/Risk governance teams.
Which TWO aspects of 'Data Governance' are critical for AI risk management?
Controlling who can touch the data is a primary risk control.
Why this answer
Data quality and security (access control) are the pillars of data governance for AI.
Which THREE artifacts should be reviewed during a post-incident AI risk analysis?
Identifies the intended purpose vs. actual misuse.
Why this answer
Model lineage, inference logs, and the original model card are critical for understanding *what* happened.
In a cross-functional AI governance meeting, the Data Science team wants to deploy a new model, but the Legal team is concerned about data privacy. How should the AI Risk Manager resolve this?
This is a proactive, collaborative approach that allows for risk-based decision making.
Why this answer
The manager should facilitate a risk assessment to quantify the concern and identify potential technical controls to mitigate the privacy risk.
When defining KPIs for an AI Governance program, which metric is most predictive of long-term model robustness?
Retraining frequency related to drift is a direct indicator of whether a model remains robust in a changing environment.
Why this answer
Model drift and retraining frequency serve as leading indicators for the degradation of AI reliability over time.
In the context of the Google Cloud Vertex AI Model Registry, what is the best approach to mitigate the risk associated with a model update that performs poorly on edge cases?
Shadow deployments allow testing with live data without impacting actual users.
Why this answer
A/B testing (or canary deployments) allows for traffic splitting to validate performance before full rollout.
In the context of the Three Lines of Defense, which function constitutes the 'Second Line'?
The second line provides oversight, sets policies, and monitors risk.
Why this answer
The second line acts as the risk management and compliance oversight function, separate from the business owners.
When integrating AI risk into existing ERM, which THREE aspects of an AI model lifecycle must be audited to ensure compliance?
Confirms the model meets risk thresholds before deployment.
Why this answer
Data lineage, model validation results, and incident response logs are critical audit points for enterprise risk accountability.
A firm is establishing an AI Governance Committee. Which TWO groups should be represented to ensure comprehensive oversight?
Crucial for handling PII within AI datasets.
Why this answer
Legal/Compliance and Data Privacy are essential for addressing the regulatory and ethical risks inherent in AI deployments.
When considering the 'Risk of Bias' in an AI system, which THREE components should be audited?
Decisions made after the model generates an output can introduce bias.
Why this answer
Bias can enter the model through the training data, the algorithm's objective function, or through post-processing of results.
An organization is establishing an AI Risk Committee. Which stakeholder is most critical to include to ensure alignment between enterprise risk appetite and technical AI capabilities?
The CRO bridges the gap between enterprise-level risk appetite and specific domain risks like AI.
Why this answer
The Chief Risk Officer (CRO) is responsible for the enterprise risk framework. Their involvement is essential to ensure AI risks are measured consistently with other business risks.
You are managing a model that utilizes 'Online Learning'. What is the most critical risk requiring constant lifecycle vigilance?
Because the model learns from every input, a malicious actor can influence the model's logic through carefully crafted inputs.
Why this answer
Online learning models are constantly updating, making them highly susceptible to 'poisoning' attacks.
When addressing 'Explainability' as an AI risk, which approach is most effective for a non-technical stakeholder?
Counterfactuals provide intuitive, actionable insight into the model's logic.
Why this answer
Counterfactual explanations (e.g., 'What would have to change for this decision to be different?') are highly intuitive and effective for non-technical stakeholders.
Which THREE factors are essential to consider when determining the 'AI Risk Appetite' for an enterprise?
Reputational and legal tolerance are core components of risk appetite.
Why this answer
Risk appetite must consider the organization's business strategy, regulatory environment, and technical capability.
You are utilizing Azure Machine Learning to manage a deployment. You detect a sudden drop in model performance due to 'concept drift'. Which specific configuration in the Azure ML Model Monitoring dashboard should be adjusted to better detect this?
Concept drift often manifests as changes in the distribution of target variables relative to inputs, requiring sensitive drift monitoring.
Why this answer
Concept drift occurs when the relationship between input variables and target variables changes, requiring adjustments to data drift detection parameters.
When drafting a vendor management policy for AI, what is the most important clause to include?
Audit rights are critical for evaluating third-party risks.
Why this answer
Right-to-audit clauses ensure that the organization can verify the vendor's AI risk controls, which is essential for third-party risk management.
A practitioner is setting up a model monitoring service in AWS SageMaker Model Monitor. They observe that the ground truth data is significantly delayed. What action ensures risk identification remains effective?
Input feature monitoring serves as a proxy for performance when ground truth labels are missing.
Why this answer
When ground truth is delayed, practitioners must rely on feature drift detection rather than accuracy metrics.
When assessing the risk of AI-generated content, which factor is the most important for calculating 'Impact'?
Impact is measured by the potential harm to the organization.
Why this answer
The potential for reputational or legal harm (consequence) is the most critical component when assessing the impact of AI-generated content.
Which of the following is an example of an 'AI Risk Metric'?
This measures the potential harm or financial risk caused by the model's inaccuracy.
Why this answer
The rate of false negatives in a credit approval model is a direct measure of AI-specific operational risk.
What is the primary responsibility of a 'Model Owner' in an AI risk framework?
The owner is responsible for the model's performance and associated risks.
Why this answer
The model owner is accountable for the entire lifecycle and risk profile of a specific AI model.
When designing an AI Risk Reporting dashboard for senior management, which TWO of the following should be visualized?
Compliance status is a key regulatory and board-level indicator.
Why this answer
Management needs to see the current risk levels and compliance status in a summarized format.
What is the goal of an AI 'Model Inventory'?
You cannot manage the risks of what you do not know exists.
Why this answer
The inventory provides a central repository for tracking all AI assets, which is the baseline for risk management.
Which of the following is an example of an 'AI Risk' in a customer-facing service?
This is a model-specific failure that directly impacts the user.
Why this answer
An AI chatbot producing hallucinated information is a clear AI risk involving inaccuracy and potential harm.
Which TWO factors are essential when documenting a model for risk management?
Defines the scope of risk.
Why this answer
Intended use and performance boundaries are essential for governance.
A company is scaling its AI initiatives across five business units. What is the most effective way to ensure consistent risk measurement?
A common language/taxonomy is essential for aggregating AI risk across diverse business units.
Why this answer
Standardizing a taxonomy ensures that all business units report risks using the same language and impact levels.
You are analyzing the risk of a generative AI implementation. Which metric most effectively measures 'model transparency' for a risk dashboard?
Model Cards are the industry standard for documenting AI transparency for risk assessment.
Why this answer
Documentation completeness (Model Cards) provides a standardized measure of transparency, enabling auditors to assess accountability.
When implementing an AI Risk Management program, which THREE components are necessary for effective monitoring?
Audit logs are necessary for accountability and incident investigation.
Why this answer
Real-time performance metrics, a process for human oversight, and a log of model decisions are foundational for continuous monitoring.
The AI Risk Governance Committee is defining the risk appetite for a new generative AI chatbot. Which THREE factors must be considered to align with organizational risk tolerance?
Compliance with data regulations is critical to risk appetite.
Why this answer
Risk appetite for AI depends on the domain, data sensitivity, and potential for harm.
Which document should a practitioner review to determine the organization's threshold for acceptable AI model bias?
This defines the organizational boundaries for risk-taking, including AI bias tolerance.
Why this answer
The Risk Appetite Statement is the formal document approved by the board or senior management that defines the level of risk the organization is willing to accept in pursuit of objectives, including AI-specific tolerances.
Which THREE factors should be considered when assessing the 'Risk Level' of an AI application?
Data sensitivity directly correlates to privacy and regulatory risk.
Why this answer
Criticality of the decision, the nature of the data involved, and the potential impact on individuals are the standard pillars of AI risk assessment.
Which THREE roles should have oversight authority in the AI Risk Program?
CTO oversees technical feasibility and risk.
Why this answer
Oversight requires representatives from business, technology, and risk management.
Your organization is implementing an AI Risk Register. Which approach provides the most effective cross-functional coordination for identifying bias in a new HR recruitment AI?
Tabletop exercises facilitate cross-functional alignment and identification of subjective risk scenarios.
Why this answer
Cross-functional engagement ensures that legal, ethics, and technical teams validate the model against disparate impact standards.
Which THREE components are necessary for effective cross-functional AI risk coordination?
A RACI (Responsible, Accountable, Consulted, Informed) matrix defines cross-functional roles.
Why this answer
Coordination requires clear communication, defined roles, and a shared vocabulary.
A company is utilizing a third-party LLM service. Which risk is specifically heightened by this arrangement?
Third-party services introduce risks related to data handling and unauthorized use of inputs.
Why this answer
Data leakage is a significant risk when sending proprietary or sensitive data to external AI service providers.
Why is 'Data Lineage' important in an AI risk management program?
Knowing the provenance of data is key to managing the risk of poor-quality or biased inputs.
Why this answer
Data lineage allows you to trace data back to its source, which is critical for identifying and mitigating bias or training data contamination.
A manufacturing firm is adopting a 'Privacy by Design' approach for AI. How does this integrate with the AI Risk Governance framework?
Automated privacy validation ensures compliance is embedded rather than bolted on.
Why this answer
Integrating privacy controls into the development lifecycle (DevOps/MLOps) is a key requirement of modern AI governance frameworks.
A team notices that an AI model's performance decreases when the input data contains abbreviations that were not present in the training set. This is a risk associated with which lifecycle stage?
The risk is that the training data did not represent the expected operational environment (data variety).
Why this answer
This is a Data Quality/Data Representation risk, where the model's understanding of data is limited by the training corpus.
A company is implementing 'Human-in-the-Loop' (HITL) for its AI decision system. What is the primary risk of relying on HITL?
Humans tend to accept automated suggestions without critical evaluation, defeating the purpose of the control.
Why this answer
Human fatigue and cognitive bias can lead to poor oversight, potentially creating a false sense of security.
You are defining KPIs for an AI project in a regulated industry. Which metric best captures model reliability over time?
Tracking drift is a direct indicator of model performance stability and reliability.
Why this answer
Drift metrics indicate whether the model's accuracy is degrading, which is a proxy for reliability.
In the context of the AI RMF, what is the significance of the 'Measure' function for risk management?
Measuring against benchmarks is how you prove a model is safe and effective.
Why this answer
The 'Measure' function uses quantitative and qualitative assessments to test whether the model is meeting its goals and risk requirements.
What is the primary reason for maintaining an 'AI Model Inventory'?
Visibility is the first requirement for managing risks effectively.
Why this answer
An inventory ensures that no 'shadow AI' exists, allowing for comprehensive risk assessment and oversight.
Page 1 of 3
Page 2Practice AAIR by domain
Target a specific domain to shore up weak areas.
See all domains with question counts →