Courseiva

CCNA AI Risk Governance And Framework Integration Questions

74 questions · AI Risk Governance And Framework Integration · All types, answers revealed

1
MCQhard

You are mapping AI risks to the NIST AI RMF. Which step is essential when documenting the 'Map' function for a high-risk autonomous system?

A.Identifying and documenting the context and intended use
B.Updating the SOC2 Type II report
C.Automating the model deployment pipeline
D.Conducting a quarterly penetration test
AnswerA

The 'Map' function focuses on understanding the context to prioritize risks.

Why this answer

Identifying and documenting the context and intended use is the foundation of mapping AI risks to an enterprise framework.

2
Multi-Selecthard

The AI Governance Committee is defining the roles for AI Risk oversight. Which TWO functions are essential for the 'Three Lines of Defense' model in AI Risk?

Select 2 answers
A.AI development teams performing self-assessments.
B.The AI Ethics Committee drafting external press releases.
C.The Chief Information Officer managing all AI infrastructure.
D.External vendors providing cloud infrastructure.
E.The AI Risk Management function providing independent oversight.
AnswersA, E

The first line of defense is the business unit/developer performing initial risk management.

Why this answer

The 1st line (Model Owners) and 2nd line (Risk/Compliance) are critical for effective AI risk management.

3
MCQeasy

What is the first step in performing an AI Risk Assessment?

A.Hiring a security consultant.
B.Updating the company website.
C.Running a bias test.
D.Defining the scope, context, and purpose of the AI system.
AnswerD

Scoping is always the first step in any risk assessment process.

Why this answer

The first step is identifying the AI system and defining its intended purpose (Context).

4
Multi-Selecthard

You are integrating AI governance into the existing Corporate Governance framework. Which THREE of the following activities are essential to ensure the Board of Directors maintains adequate oversight?

Select 3 answers
A.Reviewing and approving the organization's AI Risk Appetite Statement.
B.Installing software patches on all GPU servers.
C.Designating executive-level accountability for AI risk management outcomes.
D.Conducting daily code reviews of all AI training algorithms.
E.Establishing a reporting cadence for significant AI-related risk incidents and model performance trends.
AnswersA, C, E

This is a fundamental governance responsibility for the board.

Why this answer

Board oversight of AI requires clear policies, defined accountability, and reporting mechanisms that link AI performance to the enterprise's risk and compliance goals.

5
MCQmedium

A firm adopts the 'Three Lines of Defense' model for AI. What is the specific responsibility of the 'Third Line' (Internal Audit)?

A.Providing independent assurance on the design and effectiveness of the AI governance framework.
B.Approving AI model deployment.
C.Developing the AI models.
D.Defining the AI risk appetite.
AnswerA

Internal Audit's role is independent assurance, not operational management.

Why this answer

The Third Line provides independent, objective assurance on the effectiveness of the risk management and governance processes.

6
MCQhard

When reporting AI risk to the board, which approach best demonstrates 'Risk Culture' maturity?

A.Listing all AI projects currently in production with their budget spend.
B.Reporting solely on the number of successful cyber attacks against the AI infrastructure.
C.Presenting a heatmap showing residual risk levels against the defined enterprise risk appetite.
D.Providing a list of all AI models currently undergoing training.
AnswerC

This shows an understanding of risk management and governance maturity.

Why this answer

Risk culture maturity is demonstrated by transparently reporting not just incidents, but the effectiveness of the risk management process itself, including the 'Risk Appetite' vs. 'Actual Risk' gap.

7
MCQeasy

What is the primary objective of a 'post-implementation review' in the AI Risk Governance lifecycle?

A.To decommission the model permanently.
B.To verify that the model continues to operate within established risk thresholds.
C.To ensure the developers received their bonuses.
D.To increase the model's complexity for better performance.
E.To ensure the developers received their bonuses.
.To decommission the model permanently.
AnswerB

Ongoing monitoring ensures that models do not drift into unsafe states.

Why this answer

Post-implementation reviews assess whether the AI model's performance and risk levels remain consistent with the original design and risk appetite.

8
Multi-Selecthard

Which THREE items should be included in an AI 'Risk Assessment' report for a new project?

Select 3 answers
A.Identification of potential failure modes and their impact.
B.The favorite color of the lead developer.
C.The residual risk level after applying controls.
D.A list of all competitors currently using the same software.
E.Documentation of mitigating controls for identified risks.
AnswersA, C, E

Failure mode analysis is a standard risk assessment technique.

Why this answer

A complete report covers the risk identification, the impact analysis, and the control strategy.

9
MCQmedium

What is the primary benefit of documenting 'AI Model Lineage'?

A.It ensures the model is smaller in file size.
B.It provides transparency, auditability, and the ability to reproduce models.
C.It helps the marketing team write better ads.
D.It makes the model run faster.
AnswerB

Reproducibility and auditability are core requirements for AI safety and risk management.

Why this answer

Lineage allows for traceability, enabling auditability and root cause analysis in case of a model failure.

10
Multi-Selecthard

The organization is updating its 'AI Risk Management Policy'. Which THREE components are essential to ensure it aligns with the 'Manage' function of the NIST AI RMF?

Select 3 answers
A.The marketing budget for upcoming AI product launches.
B.A defined mechanism for reporting and remediating non-compliant AI systems.
C.A list of all employees who have access to the source code repository.
D.Criteria for prioritizing AI risks based on impact and likelihood (Risk-based prioritization).
E.Procedures for documenting model performance monitoring and recalibration cycles.
AnswersB, D, E

This ensures that policy violations are identified and fixed.

Why this answer

The 'Manage' function involves implementing controls. Essential components include clear policies on prioritization, documented operational procedures, and a process for ongoing monitoring and improvement.

11
Multi-Selectmedium

Which TWO of the following governance actions should a Chief Risk Officer (CRO) implement to align AI risk with the COSO Enterprise Risk Management (ERM) framework?

Select 2 answers
A.Establish a cross-functional AI Risk Committee
B.Assign AI risk ownership to individual data scientists
C.Disable all open-source AI libraries
D.Mandate daily model training cycles
E.Define AI-specific risk appetite statements within the ERM policy
AnswersA, E

This ensures governance oversight across the enterprise.

Why this answer

COSO ERM requires integrating risk into strategy and performance. Governance structures and risk appetite alignment are key.

12
Multi-Selecteasy

Which TWO of the following are considered 'High-Risk' AI use cases that require enhanced oversight by the Governance Committee?

Select 2 answers
A.Basic spell-checking software.
B.AI-powered biometric identification for facility access.
C.Automated recruitment and hiring filtering tools.
D.Email auto-complete features.
E.AI systems used for internal cafeteria menu suggestions.
AnswersB, C

Biometric systems carry significant privacy and security risks.

Why this answer

AI systems impacting physical safety or fundamental rights require the highest level of governance oversight.

13
Multi-Selectmedium

Which THREE items are necessary for a comprehensive 'AI Governance Policy'?

Select 3 answers
A.Standard Operating Procedures (SOPs) for model lifecycle management.
B.A list of every single line of code in the production models.
C.The personal home addresses of all developers.
D.AI risk classification framework (e.g., Low, Medium, High).
E.Definition of roles and responsibilities for AI risk oversight.
AnswersA, D, E

SOPs operationalize the policy.

Why this answer

A policy needs to define roles, risk classification, and the lifecycle process.

14
MCQmedium

In the context of the Three Lines of Defense, which function constitutes the 'Second Line'?

A.The Internal Audit department.
B.The Board of Directors.
C.The AI Development team.
D.The AI Risk Management and Compliance teams.
AnswerD

The second line provides oversight, sets policies, and monitors risk.

Why this answer

The second line acts as the risk management and compliance oversight function, separate from the business owners.

15
Multi-Selecthard

When integrating AI risk into existing ERM, which THREE aspects of an AI model lifecycle must be audited to ensure compliance?

Select 3 answers
A.Personnel physical security badges
B.Office climate control settings
C.Model validation results
D.Incident response logs
E.Data lineage and provenance
AnswersC, D, E

Confirms the model meets risk thresholds before deployment.

Why this answer

Data lineage, model validation results, and incident response logs are critical audit points for enterprise risk accountability.

16
Multi-Selectmedium

A firm is establishing an AI Governance Committee. Which TWO groups should be represented to ensure comprehensive oversight?

Select 2 answers
A.Data Privacy Office
B.Public relations
C.Legal and Compliance
D.Hardware vendors
E.External marketing agencies
AnswersA, C

Crucial for handling PII within AI datasets.

Why this answer

Legal/Compliance and Data Privacy are essential for addressing the regulatory and ethical risks inherent in AI deployments.

17
MCQeasy

An organization is establishing an AI Risk Committee. Which stakeholder is most critical to include to ensure alignment between enterprise risk appetite and technical AI capabilities?

A.Chief Risk Officer (CRO).
B.Chief Information Security Officer (CISO).
C.Lead Cloud Architect.
D.Head of Human Resources.
AnswerA

The CRO bridges the gap between enterprise-level risk appetite and specific domain risks like AI.

Why this answer

The Chief Risk Officer (CRO) is responsible for the enterprise risk framework. Their involvement is essential to ensure AI risks are measured consistently with other business risks.

18
Multi-Selectmedium

Which THREE factors are essential to consider when determining the 'AI Risk Appetite' for an enterprise?

Select 3 answers
A.The current market share of the company.
B.The organization's tolerance for legal and reputational damage.
C.The complexity and autonomy level of the AI models being deployed.
D.The existing regulatory landscape and sector-specific compliance requirements.
E.Historical data volume.
AnswersB, C, D

Reputational and legal tolerance are core components of risk appetite.

Why this answer

Risk appetite must consider the organization's business strategy, regulatory environment, and technical capability.

19
Multi-Selectmedium

When designing an AI Risk Reporting dashboard for senior management, which TWO of the following should be visualized?

Select 2 answers
A.Server uptime percentages.
B.Raw model prediction scores for every transaction.
C.Status of compliance certifications for high-risk models.
D.Aggregate risk score per business unit.
E.Employee training attendance logs.
AnswersC, D

Compliance status is a key regulatory and board-level indicator.

Why this answer

Management needs to see the current risk levels and compliance status in a summarized format.

20
MCQeasy

What is the goal of an AI 'Model Inventory'?

A.To maintain visibility over all AI models and their associated risk profiles.
B.To automatically delete old models.
C.To provide marketing data to competitors.
D.To increase the speed of model deployment.
AnswerA

You cannot manage the risks of what you do not know exists.

Why this answer

The inventory provides a central repository for tracking all AI assets, which is the baseline for risk management.

21
MCQeasy

Which of the following is an example of an 'AI Risk' in a customer-facing service?

A.A chatbot providing inaccurate information to a customer.
B.The CEO deciding to change the corporate strategy.
C.The office printer running out of ink.
D.A scheduled maintenance window for the website.
AnswerA

This is a model-specific failure that directly impacts the user.

Why this answer

An AI chatbot producing hallucinated information is a clear AI risk involving inaccuracy and potential harm.

22
MCQeasy

Which document should a practitioner review to determine the organization's threshold for acceptable AI model bias?

A.The vendor's Service Level Agreement (SLA).
B.The Enterprise Risk Appetite Statement.
C.The software's End User License Agreement (EULA).
D.The AI development team's sprint backlog.
AnswerB

This defines the organizational boundaries for risk-taking, including AI bias tolerance.

Why this answer

The Risk Appetite Statement is the formal document approved by the board or senior management that defines the level of risk the organization is willing to accept in pursuit of objectives, including AI-specific tolerances.

23
MCQmedium

A manufacturing firm is adopting a 'Privacy by Design' approach for AI. How does this integrate with the AI Risk Governance framework?

A.Privacy becomes the responsibility of the vendor, not the company.
B.Privacy controls are integrated into the MLOps pipeline as automated gates.
C.Privacy is only reviewed after the model is deployed.
D.Privacy impact assessments are excluded to speed up model deployment.
AnswerB

Automated privacy validation ensures compliance is embedded rather than bolted on.

Why this answer

Integrating privacy controls into the development lifecycle (DevOps/MLOps) is a key requirement of modern AI governance frameworks.

24
MCQhard

In the context of the AI RMF, what is the significance of the 'Measure' function for risk management?

A.To identify which employees have access to the AI system.
B.To set the budget for future AI projects.
C.To provide a score for the developers' performance.
D.To evaluate the model's performance and risk outcomes against established benchmarks.
AnswerD

Measuring against benchmarks is how you prove a model is safe and effective.

Why this answer

The 'Measure' function uses quantitative and qualitative assessments to test whether the model is meeting its goals and risk requirements.

25
MCQhard

An organization discovers that an AI model has learned a bias from training data. Per the AI Risk framework, what should be the immediate priority of the Governance function?

A.Suspend the model's usage and conduct a formal root cause analysis.
B.Wait for the quarterly board report to inform the board.
C.Fire the AI development team.
D.Retrain the model on the same data set to see if it fixes itself.
AnswerA

Suspending the model prevents further harm while an investigation occurs.

Why this answer

Stopping the risk is the priority, followed by a root cause analysis to adjust the governance or training processes.

26
MCQmedium

What is the primary risk associated with 'Shadow AI' in an organization?

A.It makes the network run slower.
B.It costs too much.
C.It makes the developers work too hard.
D.It bypasses established AI risk governance and compliance controls.
AnswerD

The lack of governance is the core risk of shadow IT/AI.

Why this answer

Shadow AI refers to AI tools deployed without the knowledge or oversight of the governance team, creating invisible, unmanaged risks.

27
Multi-Selecthard

Which THREE components must be included in an AI Model 'Control Framework' to ensure effective risk mitigation?

Select 3 answers
A.Hardware power usage tracking.
B.Access management controls restricting model usage.
C.Public disclosure of all model architecture details.
D.Manual approval gates for model deployment.
E.Automated version control for model training code.
AnswersB, D, E

Limiting who can trigger or modify models is a foundational security control.

Why this answer

Controls must cover the lifecycle, from development integrity to ongoing monitoring and access management.

28
MCQeasy

Which department is primarily responsible for ensuring AI models comply with data protection regulations like GDPR?

A.The Sales force.
B.The Accounting Department.
C.The Compliance/Legal Department and the Data Protection Officer.
D.The Janitorial staff.
AnswerC

These functions are tasked with regulatory alignment and legal risk management.

Why this answer

The Data Protection Officer (DPO) and Legal/Compliance teams are responsible for regulatory compliance.

29
MCQhard

In the context of AI model risk management, what is the role of an 'AI Model Inventory' within the governance framework?

A.To track model metadata, risk ratings, and owners for oversight and audit purposes.
B.To store the actual training data sets for backup.
C.To limit the number of AI developers in the company.
D.To serve as a marketing catalog for external clients.
AnswerA

An inventory provides the visibility necessary for effective governance and audit.

Why this answer

An inventory is the foundational requirement for knowing what models exist, their criticality, and their risk profile.

30
MCQeasy

Which document defines the 'AI Risk Appetite' for an organization?

A.The Employee Training Manual.
B.The IT Service Catalog.
C.The AI Project Status Report.
D.The AI Risk Appetite Statement.
AnswerD

The Appetite Statement is the official policy document for risk tolerance.

Why this answer

The AI Risk Appetite Statement is the document approved by the Board that defines the risk tolerance for AI activities.

31
Multi-Selecthard

Which THREE activities are part of the 'AI Risk Management' lifecycle?

Select 3 answers
A.Manual approval of all company emails.
B.Risk Treatment/Mitigation.
C.Risk Identification.
D.Ongoing Monitoring and Review.
E.Writing press releases about AI success.
AnswersB, C, D

Treating identified risks is central to the lifecycle.

Why this answer

The cycle consists of identification, assessment/treatment, and ongoing monitoring.

32
MCQeasy

A multinational corporation is establishing an AI Risk Governance Committee. Who should chair this committee to ensure alignment with enterprise-wide risk appetite?

A.The Chief Technology Officer (CTO).
B.The Chief Risk Officer (CRO).
C.The Lead AI Data Scientist.
D.The Head of Marketing.
AnswerB

The CRO ensures that AI risks are mapped to the enterprise risk appetite.

Why this answer

The Chief Risk Officer (CRO) or equivalent enterprise risk lead ensures AI risk is treated as a component of overall enterprise risk.

33
MCQhard

You are configuring the NIST AI Risk Management Framework (AI RMF) 'Govern' function for a high-risk autonomous system. Which activity specifically fulfills the 'Govern' function's requirement for establishing accountability?

A.Performing a red-teaming exercise on the model inputs.
B.Configuring automated PII scrubbing in the data pipeline.
C.Reviewing the training dataset for bias using statistical sampling.
D.Formalizing the AI System Model Owner role with defined risk acceptance and oversight accountabilities.
AnswerD

This directly addresses the requirement for organizational accountability within the Govern function.

Why this answer

NIST AI RMF 'Govern' function involves establishing the culture and processes for AI risk management, including clear definition of roles and accountability. Documenting the designated 'Model Owner' and their specific risk accountabilities is a core component.

34
MCQeasy

Why is 'AI Literacy' for the board of directors a key component of AI Governance?

A.To allow directors to code their own AI models.
B.To enable effective decision-making regarding AI adoption and risk management.
C.To replace the need for the Chief Risk Officer.
D.To reduce the cost of IT infrastructure.
AnswerB

Literacy ensures directors understand the implications of their governance decisions.

Why this answer

Directors must understand AI risks and benefits to provide informed oversight and define the organization's risk appetite.

35
MCQhard

A firm is using a 'Red Teaming' exercise for its AI model. How does this fit into the AI Risk Governance framework?

A.It serves as a validation technique to identify vulnerabilities and edge-case risks.
B.It is the only requirement for model governance.
C.It is a marketing exercise to show off model robustness.
D.It should be performed by the same team that developed the model.
E.It is the only requirement for model governance.
AnswerA

Proactive testing (Red Teaming) is a key control in advanced AI risk frameworks.

Why this answer

Red Teaming is an advanced 'Measure' or 'Verification' activity designed to find weaknesses, bias, or safety risks in a model.

36
MCQhard

An organization is using 'AI Model Monitoring' to track 'Concept Drift'. Why is this a risk governance issue?

A.It indicates the model is running out of memory.
B.It is not a risk issue; it is a maintenance issue.
C.It signals that the model's predictive accuracy is degrading due to changes in the data context.
D.It shows that the model is 'thinking' too slowly.
AnswerC

Drift is a performance risk that requires management intervention.

Why this answer

Concept drift indicates that the model is no longer operating in the environment it was trained for, leading to inaccurate predictions and potential risk.

37
MCQeasy

Which document is the primary reference for defining an organization's AI Risk Governance structure?

A.The IT hardware inventory report.
B.The employee handbook.
C.The AI Governance Charter/Policy.
D.The AI project development backlog.
AnswerC

The Charter outlines the authority, membership, and mandates of the governance body.

Why this answer

The AI Governance Policy or Charter establishes the roles, responsibilities, and decision-making authorities for AI risk.

38
MCQhard

When deploying a generative AI model, what 'Governance Control' is most critical for preventing the generation of harmful/inappropriate content?

A.Increase the number of GPUs to make it faster.
B.Only use the model in an internal environment without internet access.
C.Implement output guardrails and moderation layers.
D.Allow users to provide feedback directly to the model.
AnswerC

Guardrails are the standard control for managing generative AI risk.

Why this answer

Guardrails are technical controls placed on top of models to intercept and filter output, which is a vital part of risk governance.

39
Multi-Selectmedium

When building an AI Governance framework, which TWO of the following are essential for ensuring enterprise adoption?

Select 2 answers
A.Providing mandatory 40-hour weekly training sessions.
B.Integration with existing GRC and software delivery workflows.
C.Establishing a clear, collaborative engagement model between risk teams and developers.
D.Using only manual, spreadsheet-based tracking.
E.Requiring all developers to be lawyers.
AnswersB, C

Integration makes governance feel like part of the work, not an add-on.

Why this answer

Adoption requires alignment with existing processes and clear communication.

40
MCQhard

An organization is evaluating 'Model Risk Management' (MRM) tools for its AI governance. What is the most critical feature to look for to ensure compliance with external regulatory requirements?

A.Automatic social media integration.
B.Comprehensive audit trails of model lineage, versions, and validation results.
C.The ability to run models on mobile devices.
D.The ability to add custom skins to the UI.
AnswerB

Regulatory requirements focus on transparency and evidence of validation.

Why this answer

Audit trails and model lineage are critical for meeting regulatory transparency and accountability standards.

41
MCQmedium

How should an 'AI Ethics Committee' interact with the 'AI Risk Governance' body?

A.The Ethics Committee should be responsible for coding the AI.
B.The Ethics Committee should have final veto power over all projects.
C.The Ethics Committee should serve as an advisory body to the governance framework.
D.The Ethics Committee should replace the Risk Governance body.
AnswerC

Advisory support ensures that human and ethical factors are considered in risk decisions.

Why this answer

The Ethics Committee provides advisory, values-based guidance, while the Governance body maintains decision-making authority for risk.

42
MCQhard

During a board-level review, a bank needs to demonstrate the effectiveness of its AI Risk Governance. Which metric should be presented to the board to align with the 'Accountability' principle of the AI RMF?

A.The total computational cost of running the models.
B.The percentage of AI models with documented, independent model risk management (MRM) validation.
C.The number of lines of code written for the AI model.
D.The frequency of model retraining cycles.
AnswerB

Independent MRM validation is the industry standard for demonstrating institutional accountability.

Why this answer

Board oversight requires metrics on accountability, such as the auditability of model decision-making trails.

43
MCQhard

When configuring the Microsoft Purview AI hub for risk management, which setting must be enabled to ensure AI prompt logs are captured for enterprise risk reporting?

A.Enable Audit (Premium)
B.Set up Data Loss Prevention (DLP) policies
C.Enable sensitivity labels
D.Configure Microsoft Purview AI activity logging
AnswerD

This setting directly captures prompt interactions for audit logs.

Why this answer

Microsoft Purview's AI hub requires activity logging to be enabled to audit interactions with generative AI applications.

44
MCQmedium

You are integrating AI risk into the NIST Risk Management Framework (RMF). Which step requires an explicit evaluation of AI model lineage and data provenance to satisfy the 'Govern' function?

A.Step 2: Select controls
B.Step 1: Categorize system
C.Continuous Monitoring phase
D.Governance mapping during 'Govern' function analysis
AnswerD

The NIST AI RMF emphasizes establishing governance early by tracking provenance and lineage.

Why this answer

The NIST AI RMF 'Govern' function prioritizes understanding the provenance and lineage to establish accountability and transparency.

45
Multi-Selectmedium

The board requires a new reporting structure for AI risk. Which TWO of the following should be included in the quarterly AI Risk Report to effectively communicate risk posture?

Select 2 answers
A.The raw output from the model's most recent training iteration.
B.The daily CPU and memory metrics for the inference clusters.
C.The status of the AI risk control roadmap and effectiveness of implemented mitigations.
D.A list of all individual model parameters and weights.
E.An overview of current AI-related residual risks exceeding the organization's defined risk appetite.
AnswersC, E

This provides insight into the maturity of the risk management program.

Why this answer

Board reports need to focus on strategic risk alignment and the efficacy of the oversight process, specifically tracking the risk management pipeline and significant residual risks.

46
MCQmedium

What is the key purpose of the 'Govern' function in the NIST AI RMF?

A.To troubleshoot hardware issues.
B.To establish the organizational culture, policy, and procedures for AI risk management.
C.To define the marketing strategy for the AI products.
D.To code the AI algorithms.
AnswerB

Governance is about the rules, culture, and oversight of AI activities.

Why this answer

The 'Govern' function focuses on the culture, policies, and structures that foster a risk-aware AI lifecycle.

47
MCQhard

Why is 'Model Validation' (distinct from testing) essential in an AI Governance framework?

A.To ensure the developers have followed the coding standards.
B.To save money on cloud hosting.
C.To provide independent assurance that the model performs as expected and within risk thresholds.
D.To speed up the coding process.
AnswerC

Independence is the defining feature of validation vs testing.

Why this answer

Validation is the independent verification that a model meets its intended purpose and risk performance requirements.

48
MCQmedium

A firm is integrating AI into its ERM (Enterprise Risk Management). What is the primary benefit of a 'Common Risk Taxonomy' for AI?

A.It forces all AI models to be identical.
B.It ensures consistent risk identification, communication, and reporting across the organization.
C.It makes AI code easier to write.
D.It eliminates the need for risk assessments.
AnswerB

Consistency is vital for managing risk at scale.

Why this answer

A common taxonomy ensures that AI risk is understood and communicated consistently across the enterprise.

49
MCQmedium

An organization is considering outsourcing its AI development. How should the 'AI Risk Governance' policy be adjusted for third-party vendors?

A.Include mandatory audit rights, model validation requirements, and risk-sharing clauses in the vendor contract.
B.Assume that the vendor's own governance is sufficient.
C.Only evaluate the vendor for financial stability.
D.Exclude outsourced AI from the internal risk assessment.
AnswerA

Vendor oversight is a critical part of a robust AI governance strategy.

Why this answer

Third-party risk management must include audit rights and clear accountability for the vendor's models.

50
Multi-Selecthard

Which THREE components must be included in an AI Risk Register to satisfy ISO/IEC 42001 requirements?

Select 3 answers
A.Hardware procurement schedules
B.Technical documentation of model architecture
C.Identification of relevant stakeholders
D.Assessment of AI risk levels (likelihood and impact)
E.AI system description and intended use
AnswersC, D, E

ISO 42001 emphasizes stakeholder communication and consultation.

Why this answer

ISO 42001 requires systematic risk identification, analysis, and treatment planning.

51
MCQmedium

During a board meeting, the Chief Risk Officer needs to present AI model performance trends. Which metric is most critical for board-level reporting?

A.Data scientists' training hours per quarter
B.Computational resource utilization percentage
C.Model latency in milliseconds
D.Frequency and severity of model drift incidents
AnswerD

This metric highlights the stability and risk exposure of the models.

Why this answer

The frequency and severity of model drift incidents are direct indicators of operational and reputational risk, which are board-level concerns.

52
MCQhard

An organization is integrating AI risk into its existing ISO 31000 framework. How should the 'Risk Assessment' process be modified to account for AI-specific 'black box' issues?

A.Remove the risk identification step, as AI risks are too unpredictable.
B.Replace the qualitative assessment with a purely quantitative financial impact model.
C.Add a model explainability and interpretability assessment step to the process.
D.Delegate all risk assessments to the external software vendor.
AnswerC

Explainability is a key AI risk control that ensures transparency in decision-making.

Why this answer

Inclusion of model explainability assessments is necessary to address the opacity inherent in deep learning models.

53
MCQmedium

An organization is using a centralized AI Governance structure. What is the biggest risk of this approach compared to a decentralized one?

A.Higher infrastructure costs.
B.Lack of standardized policy.
C.Operational bottlenecks and delayed AI project timelines.
D.Increased risk of shadow AI.
AnswerC

Centralized oversight teams often become overburdened, slowing down delivery.

Why this answer

Centralization can create 'bottlenecks' that slow down innovation and delay deployment.

54
MCQmedium

A bank's AI Governance policy requires a 'bias test' for all customer-facing models. What is the most important element to document in the audit trail?

A.The number of hours the test took to run.
B.The test methodology, criteria for success, and the specific mitigation steps taken.
C.The salary of the testers.
D.The name of the software used for the test.
AnswerB

This provides the 'proof' of due diligence and governance compliance.

Why this answer

Documenting the bias test methodology and results is essential to demonstrate due diligence to regulators.

55
MCQmedium

When reporting to the Board, what is the best way to present 'AI Risk'?

A.State that AI is completely safe and requires no oversight.
B.Provide a list of all model parameters.
C.Link AI risks to overall business impact, strategic goals, and current risk appetite.
D.Give a 4-hour technical lecture on deep learning.
AnswerC

Strategic context allows the Board to make governance decisions.

Why this answer

Risk should be linked to strategic objectives and the organization's appetite to ensure the Board understands the impact.

56
MCQhard

What is the 'Accountability' principle in the NIST AI RMF intended to address?

A.Ensuring the AI can explain itself.
B.Ensuring that there is clear ownership and responsibility for AI system performance and safety.
C.Making sure the model is free of bugs.
D.Ensuring that the AI system is fast.
AnswerB

Accountability focuses on who is responsible for the system's impact.

Why this answer

Accountability ensures that individuals or teams are responsible for the outcomes of AI systems, preventing a 'blame-free' environment for AI failures.

57
MCQmedium

In the context of AI Supply Chain risk, what is the primary governance objective when evaluating a vendor's AI model transparency?

A.To minimize the number of API calls made to the vendor.
B.To verify the vendor's financial stability and market share.
C.To ensure the vendor's training data includes proprietary internal company data.
D.To confirm the vendor's model satisfies the internal 'Model Card' and transparency requirements for risk assessment.
AnswerD

Transparency and documentation are prerequisites for assessing third-party model risk.

Why this answer

Governance in the supply chain requires understanding the 'provenance' and 'limitations' of third-party models to ensure they align with internal risk requirements. Model cards provide the necessary documentation for this assessment.

58
MCQhard

You are auditing the integration of AI risk into the Enterprise Risk Management (ERM) system. Which finding indicates a failure in the governance structure?

A.The risk assessment template is 20 pages long.
B.The AI risk register is updated annually instead of monthly.
C.The AI risk committee meets quarterly rather than monthly.
D.AI models deployed in production are missing from the centralized enterprise risk register.
AnswerD

This demonstrates that models are being released outside of the formal risk governance process.

Why this answer

A core tenet of AI governance is that risk assessments must occur before deployment. If models are deployed without being included in the ERM system, the governance process is bypassed, representing a failure in control.

59
MCQeasy

A board of directors requests a dashboard view of AI model drift. Which metric is most appropriate for a board-level risk report?

A.Feature drift threshold violations
B.Mean Squared Error (MSE)
C.GPU utilization percentage
D.Latency per inference request
AnswerA

Drift threshold violations indicate a system is deviating from its validated risk profile.

Why this answer

The board requires high-level risk indicators rather than granular performance metrics like F1 scores.

60
MCQhard

An organization is revising its AI Governance to include 'Human-in-the-loop' (HITL) requirements. Why is this a critical risk mitigation strategy?

A.It removes the requirement for model bias testing.
B.It is required for every AI model regardless of impact.
C.It ensures human oversight for critical decisions, reducing the risk of 'black box' failures.
D.It eliminates the need for any other automated risk controls.
AnswerC

HITL allows for intervention when the AI model produces unexpected or high-risk outcomes.

Why this answer

HITL provides a necessary safety net for models that may exhibit unpredictable behavior or lack explainability.

61
Multi-Selectmedium

When assessing the organizational readiness for AI risk governance, which TWO areas must be evaluated to ensure the framework is sustainable?

Select 2 answers
A.The availability of cross-functional expertise (e.g., legal, compliance, ethics) within the AI governance body.
B.The speed of the network bandwidth between training sites.
C.The capability of the internal audit team to audit AI models.
D.The total number of GPUs available in the data center.
E.The maturity of the enterprise's existing risk management processes and their compatibility with AI-specific risks.
AnswersA, E

A multi-disciplinary approach is essential for holistic AI risk assessment.

Why this answer

Sustainable governance requires both the human element (culture/skills) and the procedural element (integration into existing systems).

62
MCQmedium

When an AI model is updated (e.g., retrained on new data), what action is required from an AI Risk Governance perspective?

A.The model should be renamed to show it is a new version.
B.No action is needed as the underlying architecture is unchanged.
C.The model should be re-validated to ensure it still meets risk thresholds.
D.The model should be automatically deployed without review.
AnswerC

Changes require re-validation to ensure the model remains safe.

Why this answer

Any significant change to an AI model triggers a re-validation or reassessment to ensure the new version is still within risk thresholds.

63
MCQmedium

A board of directors requests a dashboard to monitor AI risk exposure. Which metric provides the most effective board-level oversight regarding AI regulatory compliance?

A.Percentage of critical AI systems that have undergone a formal regulatory compliance impact assessment.
B.Mean Time to Detect (MTTD) for model adversarial attacks.
C.Current GPU utilization rates for production inference clusters.
D.Average latency of API requests for generative AI models.
AnswerA

This provides a high-level view of governance efficacy and legal exposure.

Why this answer

Board members require high-level indicators of systemic risk rather than granular technical metrics. Tracking the percentage of AI systems with completed regulatory impact assessments provides oversight on compliance posture.

64
MCQeasy

What is the primary role of the AI 'Data Steward' within the AI Governance framework?

A.To oversee the lifecycle of the data, ensuring its quality and compliance.
B.To manage the budget for AI hardware.
C.To build the model architecture.
D.To handle marketing and customer relations.
AnswerA

Data stewardship is foundational to ensuring that training data does not introduce risk.

Why this answer

The data steward is responsible for ensuring the quality, security, and ethical use of data throughout the AI lifecycle.

65
MCQmedium

Your organization is integrating AI risks into the existing COSO Enterprise Risk Management (ERM) framework. Which action best ensures that AI-specific model drift risk is formally addressed within the 'Review and Revision' component?

A.Integrating model performance metrics into the quarterly enterprise risk assessment and management review processes.
B.Establishing automated triggers within the CI/CD pipeline to halt deployment if drift exceeds threshold.
C.Mapping AI model inventory to the IT asset register in the CMDB.
D.Assigning a Data Scientist to the Board Risk Committee.
AnswerA

This aligns with the requirement to review risk management performance against evolving risks.

Why this answer

The COSO ERM framework's 'Review and Revision' component requires assessing whether the risk management practices remain effective as the risk landscape changes. Integrating AI model performance monitoring into established periodic risk reviews ensures the organization adapts to evolving model behaviors.

66
MCQeasy

A financial institution is integrating AI risk into its ERM framework. Which action most effectively aligns AI risk appetite with enterprise risk appetite?

A.Defining quantitative risk thresholds in the AI governance policy
B.Purchasing cybersecurity insurance for AI systems
C.Assigning AI risk ownership to the IT department
D.Implementing a standalone AI audit program
AnswerA

This establishes clear boundaries that align with the broader ERM appetite.

Why this answer

Defining quantitative risk thresholds in the AI governance policy ensures alignment with the organization's overall risk capacity.

67
MCQmedium

A company is deploying an AI system that interacts with human users. According to the AI RMF, what should be the focus of the 'Map' function in the risk governance process?

A.Choosing the most efficient algorithm.
B.Identifying stakeholders, intended use, and potential human impacts.
C.Selecting the cloud service provider.
D.Calculating the total budget for the project.
AnswerB

Mapping the context and impact is central to identifying risk vectors.

Why this answer

Mapping involves understanding the context, intended use, and the human-AI interaction points to identify potential harms.

68
MCQmedium

You are mapping existing ISO 31000 risk management processes to an AI-specific application. Which step is most crucial to ensure 'Risk Treatment' is appropriately scaled for AI?

A.Automating all risk logging in the SIEM.
B.Discontinuing the use of third-party AI APIs to avoid vendor risk.
C.Standardizing all AI models under one security policy regardless of function.
D.Implementing a tiered control framework where mitigations scale based on the system's impact assessment.
AnswerD

ISO 31000 mandates proportionality, which in AI is achieved through risk-based tiering.

Why this answer

Risk treatment in AI requires context-aware decisions based on the risk profile of the specific model (e.g., impact of failure). Tiering controls based on the model's risk impact ensures that high-risk models receive more robust mitigations.

69
MCQmedium

A retail company uses an AI model for dynamic pricing. The model's risk score recently exceeded the 'Moderate' threshold. As per the AI Governance framework, what is the mandatory next step?

A.Automatically disable the model.
B.Perform an mandatory AI model risk assessment and escalate to the Governance Committee.
C.Continue operation while monitoring for additional errors.
D.Update the training data set to improve the score.
AnswerB

Escalation ensures that risk owners are aware and can decide on remediation.

Why this answer

When an AI risk score crosses a predefined threshold, escalation to the risk committee or manual oversight is required.

70
MCQmedium

When integrating AI risk into the corporate GRC (Governance, Risk, and Compliance) platform, what is the best practice for handling 'AI Model Drift' alerts?

A.Send all alerts to the help desk.
B.Ignore drift alerts until a manual audit happens annually.
C.Integrate drift alerts as risk indicators in the GRC platform for automated tracking.
D.Disable the alerts to prevent 'alert fatigue'.
AnswerC

GRC integration allows for consistent monitoring and auditing of model health.

Why this answer

Model drift alerts should be categorized as risk indicators and integrated into the GRC's automated incident response or reporting workflow.

71
Multi-Selectmedium

When reporting AI risks to the Board of Directors, which THREE elements should be included to ensure informed decision-making?

Select 3 answers
A.List of all developers who worked on the model.
B.Granular technical logs of model inference errors.
C.Qualitative overview of ethical AI alignment with company values.
D.Summary of current AI risk appetite and threshold breaches.
E.Strategic assessment of regulatory compliance and potential legal exposure.
AnswersC, D, E

Ethical alignment is a critical board-level oversight responsibility.

Why this answer

Board-level reports must focus on strategic impact, compliance posture, and high-level risk exposure.

72
Multi-Selectmedium

Which THREE factors should be evaluated when reviewing an AI model for 'Fairness'?

Select 3 answers
A.Performance disparity across different demographic cohorts.
B.The number of hours the server was powered on.
C.Defined metrics for success that explicitly account for equity.
D.Training data representation across protected groups.
E.The model's file size in kilobytes.
AnswersA, C, D

Fairness is measured by comparing outcomes between groups.

Why this answer

Fairness assessment covers data representation, metric definitions, and outcome disparities.

73
MCQmedium

Which governance mechanism is most effective for ensuring that AI ethical risks are addressed during the 'Design' phase of the AI Lifecycle?

A.Conducting a formal 'Ethics by Design' review as part of the AI project's stage-gate approval process.
B.Scanning the source code for hardcoded credentials.
C.multi_select
D.Requiring a legal sign-off on the final model deployment.
E.multi_select
.Reviewing the production logs for anomalies.
AnswerA

Stage-gate processes force compliance with governance requirements before moving to the next phase.

Why this answer

Ethical AI reviews (sometimes called 'Ethics by Design' reviews) are proactive assessments conducted during the design phase to identify potential negative societal impacts before code is written, integrating ethics into the development lifecycle.

74
MCQmedium

A financial firm is integrating AI risk into its ERM. The Chief Risk Officer asks for a mapping between the NIST AI Risk Management Framework (RMF) and the existing COSO ERM framework. Which action most effectively facilitates this alignment?

A.Replace the COSO risk taxonomy with the NIST AI RMF taxonomy entirely.
B.Automate all AI model monitoring using only the NIST RMF 'Measure' function.
C.Assign AI model owners to report directly to the NIST oversight board.
D.Map NIST AI RMF 'Govern' and 'Map' functions to COSO 'Governance and Culture' components.
AnswerD

Aligning framework functions ensures that AI-specific risks are visible within the existing enterprise reporting structure.

Why this answer

Mapping functions like 'Govern' and 'Map' in NIST AI RMF directly correlate to COSO's 'Governance and Culture' and 'Strategy and Objective-Setting' components.

Ready to test yourself?

Try a timed practice session using only AI Risk Governance And Framework Integration questions.