Courseiva

CCNA AI Risk Program Management Questions

75 of 83 questions · Page 1/2 · AI Risk Program Management · Answers revealed

1
Multi-Selectmedium

Which THREE metrics should be tracked to assess the 'Risk' of an AI model in production?

Select 3 answers
A.Model accuracy/error rate
B.The brand of the coffee machine
C.The number of employees in the break room
D.Model latency (response time)
E.Data drift
AnswersA, D, E

Errors represent a direct risk to the business.

Why this answer

Risk is measured by performance stability (drift), accuracy, and operational health.

2
MCQhard

A firm is using the NIST AI Risk Management Framework to document its AI risk program. Which approach best ensures that AI risk metrics are dynamic?

A.Conducting annual risk assessments
B.Setting static thresholds for model accuracy
C.Limiting AI deployment to offline systems
D.Integrating model performance metrics into operational dashboards
AnswerD

Continuous monitoring and dashboarding provide the real-time visibility needed for dynamic risk management.

Why this answer

Mapping specific risk indicators to model performance monitoring allows metrics to evolve as the model's environment changes.

3
Multi-Selectmedium

Which TWO documents are essential to include in the AI Risk Project 'Review Pack'?

Select 2 answers
A.A summary of the team's lunch schedule.
B.A detailed risk mitigation and action plan.
C.A list of all software installed on company laptops.
D.A copy of the company's lease agreement.
E.A comprehensive AI Risk Assessment report.
AnswersB, E

Defines how risks will be handled.

Why this answer

The Risk Assessment report documents the analysis, and the Mitigation Plan shows how identified risks will be addressed.

4
Multi-Selectmedium

Which TWO factors should be included in an AI risk appetite statement?

Select 2 answers
A.The intended impact on company revenue
B.The specific programming language allowed
C.The preferred office software
D.Financial thresholds for model-related incidents
E.Maximum tolerable level of model bias
AnswersD, E

Financial impact limits are a classic component of risk appetite.

Why this answer

Risk appetite must be specific to the impact and the tolerance levels for failure.

5
MCQeasy

Which document is essential for defining the roles and responsibilities within an AI Risk Program?

A.AI Governance RACI Matrix.
B.Data Privacy Impact Assessment (DPIA).
C.Model Training Log.
D.AI Incident Response Plan.
AnswerA

A RACI matrix is the standard tool to formalize organizational roles in a governance program.

Why this answer

The RACI matrix clearly defines who is Responsible, Accountable, Consulted, and Informed for AI risk activities.

6
MCQhard

When integrating AI risk into the broader ERM (Enterprise Risk Management) framework, which approach is most effective?

A.Only report AI risks if they result in a financial loss
B.Keep AI risks in a separate, isolated tracking system
C.Map AI risks to existing risk categories (e.g., operational, compliance)
D.Automate the removal of AI risks from the main risk register
AnswerC

Integration ensures AI risk is treated with the same rigor as traditional enterprise risks.

Why this answer

AI risks should not be siloed; they should be categorized alongside existing operational and reputational risks to ensure they are visible to the Board.

7
MCQmedium

When documenting an AI Risk Program, what should be included in the 'AI Asset Register'?

A.The raw hardware serial numbers of the servers.
B.The model purpose, data lineage, stakeholders, and risk classification.
C.The exact lines of code in the model.
D.The home addresses of all developers.
AnswerB

These are essential for understanding the risk and accountability for each AI model.

Why this answer

An asset register must track the model's purpose, data sources, and business owner to ensure oversight.

8
MCQeasy

In the context of AI risk management, what does the 'Human-in-the-Loop' (HITL) concept primarily aim to achieve?

A.To reduce the cost of model development.
B.To maintain accountability and oversight for AI-driven decisions.
C.To increase the speed of model inference.
D.To automate the labeling of training data.
AnswerB

HITL is designed to provide oversight and accountability for critical decisions.

Why this answer

HITL ensures that human judgment and ethics remain integrated into high-risk AI decision processes to prevent unmonitored failures.

9
Multi-Selectmedium

Which TWO stakeholders are most important to engage when establishing an AI risk appetite?

Select 2 answers
A.The building security personnel.
B.The Board of Directors or Executive Committee.
C.The office cleaning staff.
D.Legal and Compliance officers.
E.The company's social media followers.
AnswersB, D

Leadership defines the organization's appetite for risk.

Why this answer

The Board/Executive Leadership defines the appetite, while Legal/Compliance ensures that the definition meets legal requirements.

10
MCQmedium

Which role is primarily responsible for ensuring that AI-generated content adheres to intellectual property risk policies?

A.Chief Legal Officer
B.System Administrator
C.Product Manager
D.Data Engineer
AnswerA

Legal counsel manages the risk associated with IP infringement and copyright.

Why this answer

The Chief Legal Officer or Legal counsel is accountable for IP rights and contractual obligations related to AI output.

11
MCQmedium

An enterprise is establishing an AI Governance Committee. Which organizational structure best ensures that risk management is integrated into the AI development lifecycle?

A.Centralized control under the Chief Data Officer
B.External advisory board oversight
C.Cross-functional membership including Legal, Security, and Engineering
D.Automated AI risk assessment tools alone
AnswerC

Cross-functional teams provide the holistic view required for AI risk management.

Why this answer

A cross-functional approach involving data science, legal, compliance, and IT security ensures risk is addressed at every SDLC phase.

12
MCQhard

An organization discovers that their AI model exhibits bias toward a specific demographic. What is the most important step in the Incident Response process?

A.Suspend the model's production use until the issue is investigated and remediated.
B.Retrain the model immediately.
C.Delete all training data related to the demographic.
D.Issue a public press release.
AnswerA

Suspending the model is the primary containment strategy to prevent continued harm.

Why this answer

Immediate containment is necessary to prevent further harm while the root cause is investigated.

13
MCQeasy

What is 'Shadow AI'?

A.A marketing term for new AI tools
B.A feature in a programming language
C.AI used without formal approval or oversight
D.An AI model that only works in the dark
AnswerC

This represents an unmanaged risk.

Why this answer

Shadow AI refers to AI tools or models used within an organization without the knowledge or approval of the IT/Risk governance teams.

14
Multi-Selecthard

Which TWO aspects of 'Data Governance' are critical for AI risk management?

Select 2 answers
A.Data access control and security
B.The number of pens in the supply closet
C.The speed of the local internet
D.The interior design of the office
E.Data quality and consistency
AnswersA, E

Controlling who can touch the data is a primary risk control.

Why this answer

Data quality and security (access control) are the pillars of data governance for AI.

15
MCQhard

In a cross-functional AI governance meeting, the Data Science team wants to deploy a new model, but the Legal team is concerned about data privacy. How should the AI Risk Manager resolve this?

A.Order the Data Science team to stop work immediately
B.Ask the CEO to decide
C.Conduct a joint risk assessment to identify potential mitigations
D.Ignore the Legal team's concerns
AnswerC

This is a proactive, collaborative approach that allows for risk-based decision making.

Why this answer

The manager should facilitate a risk assessment to quantify the concern and identify potential technical controls to mitigate the privacy risk.

16
MCQhard

When defining KPIs for an AI Governance program, which metric is most predictive of long-term model robustness?

A.Number of users accessing the AI interface.
B.The frequency of model retraining triggered by performance drift alerts.
C.Total number of AI models currently in production.
D.The budget spent on GPU cloud computing resources.
AnswerB

Retraining frequency related to drift is a direct indicator of whether a model remains robust in a changing environment.

Why this answer

Model drift and retraining frequency serve as leading indicators for the degradation of AI reliability over time.

17
Multi-Selecthard

When considering the 'Risk of Bias' in an AI system, which THREE components should be audited?

Select 3 answers
A.The physical location of the cloud data center.
B.The post-processing decisions made on the model outputs.
C.The composition and representativeness of the training dataset.
D.The number of coffee breaks the data science team takes.
E.The objective function or loss function used for model training.
AnswersB, C, E

Decisions made after the model generates an output can introduce bias.

Why this answer

Bias can enter the model through the training data, the algorithm's objective function, or through post-processing of results.

18
MCQmedium

When addressing 'Explainability' as an AI risk, which approach is most effective for a non-technical stakeholder?

A.Presenting the feature weights of a neural network.
B.Explaining the gradient descent optimization process.
C.Showing the mathematical formula used for loss reduction.
D.Providing counterfactual explanations like 'If your income had been $5k higher, the loan would have been approved'.
AnswerD

Counterfactuals provide intuitive, actionable insight into the model's logic.

Why this answer

Counterfactual explanations (e.g., 'What would have to change for this decision to be different?') are highly intuitive and effective for non-technical stakeholders.

19
MCQhard

When drafting a vendor management policy for AI, what is the most important clause to include?

A.Requirement for vendor to provide coffee
B.Requirement to use a specific font
C.Vendor must provide free hardware
D.Right-to-audit the vendor's AI training practices
AnswerD

Audit rights are critical for evaluating third-party risks.

Why this answer

Right-to-audit clauses ensure that the organization can verify the vendor's AI risk controls, which is essential for third-party risk management.

20
MCQhard

When assessing the risk of AI-generated content, which factor is the most important for calculating 'Impact'?

A.The potential for reputational and legal consequences
B.The speed at which the content is generated
C.The color of the font used for the output
D.The number of GPUs used to create the content
AnswerA

Impact is measured by the potential harm to the organization.

Why this answer

The potential for reputational or legal harm (consequence) is the most critical component when assessing the impact of AI-generated content.

21
MCQeasy

Which of the following is an example of an 'AI Risk Metric'?

A.Budget spent on office supplies
B.Rate of false negatives in model output
C.Employee headcount in AI department
D.Number of coffee machines in the breakroom
AnswerB

This measures the potential harm or financial risk caused by the model's inaccuracy.

Why this answer

The rate of false negatives in a credit approval model is a direct measure of AI-specific operational risk.

22
MCQmedium

What is the primary responsibility of a 'Model Owner' in an AI risk framework?

A.Writing all the Python code for the model
B.Approving company-wide bonuses
C.Fixing broken office furniture
D.Maintaining the risk profile and performance of the model
AnswerD

The owner is responsible for the model's performance and associated risks.

Why this answer

The model owner is accountable for the entire lifecycle and risk profile of a specific AI model.

23
MCQhard

A company is scaling its AI initiatives across five business units. What is the most effective way to ensure consistent risk measurement?

A.Using different platforms for each business unit
B.Implementing a centralized AI risk taxonomy
C.Allowing each business unit to define its own risk metrics
D.Focusing only on the highest-risk model
AnswerB

A common language/taxonomy is essential for aggregating AI risk across diverse business units.

Why this answer

Standardizing a taxonomy ensures that all business units report risks using the same language and impact levels.

24
MCQhard

You are analyzing the risk of a generative AI implementation. Which metric most effectively measures 'model transparency' for a risk dashboard?

A.The number of unique contributors to the codebase.
B.The average latency of model inference.
C.Percentage of models deployed with a completed Model Card covering data provenance, limitations, and intended use.
D.The number of parameters in the neural network.
AnswerC

Model Cards are the industry standard for documenting AI transparency for risk assessment.

Why this answer

Documentation completeness (Model Cards) provides a standardized measure of transparency, enabling auditors to assess accountability.

25
Multi-Selecthard

When implementing an AI Risk Management program, which THREE components are necessary for effective monitoring?

Select 3 answers
A.A requirement that all staff undergo coding training.
B.A mechanism for logging and auditing model outputs.
C.A daily newsletter for employees about AI advancements.
D.A process for human intervention or override.
E.Automated real-time monitoring of model performance and drift.
AnswersB, D, E

Audit logs are necessary for accountability and incident investigation.

Why this answer

Real-time performance metrics, a process for human oversight, and a log of model decisions are foundational for continuous monitoring.

26
Multi-Selecthard

The AI Risk Governance Committee is defining the risk appetite for a new generative AI chatbot. Which THREE factors must be considered to align with organizational risk tolerance?

Select 3 answers
A.The speed of the development team's sprint cycles
B.Data privacy and residency requirements for training sets
C.The likelihood of model drift impacting output accuracy
D.The impact of potential hallucination on brand reputation
E.The total cost of GPU infrastructure
AnswersB, C, D

Compliance with data regulations is critical to risk appetite.

Why this answer

Risk appetite for AI depends on the domain, data sensitivity, and potential for harm.

27
Multi-Selecthard

Which THREE factors should be considered when assessing the 'Risk Level' of an AI application?

Select 3 answers
A.The sensitivity of the input data.
B.The criticality of the decision-making process being automated.
C.The complexity of the neural network architecture.
D.The potential impact on human rights and individual safety.
E.The color scheme of the user interface.
AnswersA, B, D

Data sensitivity directly correlates to privacy and regulatory risk.

Why this answer

Criticality of the decision, the nature of the data involved, and the potential impact on individuals are the standard pillars of AI risk assessment.

28
Multi-Selectmedium

Which THREE roles should have oversight authority in the AI Risk Program?

Select 3 answers
A.The company's social media influencer
B.Chief Technology Officer
C.Chief Risk Officer
D.The office receptionist
E.Head of Business Unit (where AI is used)
AnswersB, C, E

CTO oversees technical feasibility and risk.

Why this answer

Oversight requires representatives from business, technology, and risk management.

29
MCQmedium

Your organization is implementing an AI Risk Register. Which approach provides the most effective cross-functional coordination for identifying bias in a new HR recruitment AI?

A.Perform a technical audit on the training dataset distribution.
B.Automate all bias detection using internal library scripts without human review.
C.Update the AI policy to forbid the use of demographic attributes in training data.
D.Conduct a mandatory tabletop exercise involving HR, legal, and data science teams to simulate potential discriminatory outcomes.
AnswerD

Tabletop exercises facilitate cross-functional alignment and identification of subjective risk scenarios.

Why this answer

Cross-functional engagement ensures that legal, ethics, and technical teams validate the model against disparate impact standards.

30
Multi-Selecthard

Which THREE components are necessary for effective cross-functional AI risk coordination?

Select 3 answers
A.Clearly defined RACI matrix for AI initiatives
B.Weekly team lunches
C.Standardized AI risk taxonomy
D.A centralized AI risk register
E.Unrestricted access to all production servers for all staff
AnswersA, C, D

A RACI (Responsible, Accountable, Consulted, Informed) matrix defines cross-functional roles.

Why this answer

Coordination requires clear communication, defined roles, and a shared vocabulary.

31
MCQhard

A company is utilizing a third-party LLM service. Which risk is specifically heightened by this arrangement?

A.Data leakage and privacy violations
B.Server downtime
C.Model training cost inflation
D.Lack of software updates
AnswerA

Third-party services introduce risks related to data handling and unauthorized use of inputs.

Why this answer

Data leakage is a significant risk when sending proprietary or sensitive data to external AI service providers.

32
MCQeasy

Why is 'Data Lineage' important in an AI risk management program?

A.It helps ensure data quality and integrity
B.It makes user interfaces more attractive
C.It improves server load times
D.It reduces the amount of storage needed
AnswerA

Knowing the provenance of data is key to managing the risk of poor-quality or biased inputs.

Why this answer

Data lineage allows you to trace data back to its source, which is critical for identifying and mitigating bias or training data contamination.

33
MCQmedium

You are defining KPIs for an AI project in a regulated industry. Which metric best captures model reliability over time?

A.Model drift (data drift/concept drift)
B.Frequency of model retraining
C.Number of training iterations
D.Total cost of compute resources
AnswerA

Tracking drift is a direct indicator of model performance stability and reliability.

Why this answer

Drift metrics indicate whether the model's accuracy is degrading, which is a proxy for reliability.

34
MCQmedium

What is the primary reason for maintaining an 'AI Model Inventory'?

A.To share model code with competitors
B.To make the database easier to back up
C.To identify and mitigate shadow AI risks
D.To increase the size of the IT department
AnswerC

Visibility is the first requirement for managing risks effectively.

Why this answer

An inventory ensures that no 'shadow AI' exists, allowing for comprehensive risk assessment and oversight.

35
Multi-Selecteasy

Which TWO items are considered 'AI Infrastructure' risks?

Select 2 answers
A.The color of the server room walls
B.The type of desk chair in the office
C.The number of windows in the office
D.Unauthorized access to the model environment
E.System uptime/availability
AnswersD, E

Security breach is a major infrastructure risk.

Why this answer

Infrastructure risks focus on availability and security of the compute environment.

36
MCQmedium

Which metric is useful for measuring the 'Efficiency' of an AI risk program?

A.Number of emails sent
B.Total weight of the hardware
C.Number of meetings held
D.Time to complete a risk assessment for new models
AnswerD

This measures the speed and process maturity of the risk program.

Why this answer

The time required to complete a risk assessment for a new model tracks how streamlined the governance process is.

37
Multi-Selecthard

Which TWO items are considered 'AI Model Artifacts' that should be kept for audit purposes?

Select 2 answers
A.The training dataset version
B.The lunch menu for the developers
C.Model hyperparameters and architecture configuration
D.The name of the company's favorite mascot
E.The local weather report from last week
AnswersA, C

Data provenance is essential for auditing.

Why this answer

Documentation and training parameters are crucial for reproducing and auditing model behavior.

38
Multi-Selectmedium

When designing an AI Risk Committee, which TWO of the following roles are essential for ensuring a holistic view of risk?

Select 2 answers
A.Chief Legal Counsel.
B.Office Assistant.
C.Lead Data Scientist.
D.Social Media Manager.
E.Facilities Manager.
AnswersA, C

Essential for regulatory and compliance guidance.

Why this answer

Legal ensures compliance with evolving regulations, while Data Science/Engineering provides the technical understanding of how the model functions.

39
Multi-Selecteasy

Which TWO teams should define the 'Risk Appetite' for a new AI project?

Select 2 answers
A.Senior Leadership/Business Owners
B.The Risk Management/Compliance Office
C.The local weather station
D.The office landscaping team
E.The company's mascot
AnswersA, B

They decide the acceptable risk for business goals.

Why this answer

Risk appetite is a strategic decision involving both business leaders (who own the risk) and risk managers (who define the framework).

40
MCQhard

You are auditing an AI project. Which finding suggests a failure in AI risk management governance?

A.The model was trained on historical data.
B.No individual is designated as the accountable owner for the model's production outcomes.
C.The team uses a cloud-based GPU provider.
D.The model has a 2% prediction error rate.
AnswerB

Lack of accountability is a fundamental failure of AI governance.

Why this answer

If no one is designated as accountable for the model's outcomes, the governance structure is non-existent or dysfunctional.

41
Multi-Selecteasy

Which TWO tasks are part of the 'AI Risk Assessment' process?

Select 2 answers
A.Evaluating the likelihood and impact of identified risks
B.Choosing the font color for the dashboard
C.Writing marketing copy for the AI product
D.Identifying potential AI-related threats
E.Hiring new office staff
AnswersA, D

Quantifying risk is the core of the assessment.

Why this answer

Risk assessment involves identifying risks and then evaluating them based on impact/likelihood.

42
MCQmedium

Which document is the most appropriate starting point for an AI Risk assessment for a new machine learning project?

A.The marketing slide deck for the AI feature.
B.The technical API documentation.
C.An AI Risk Assessment Protocol/Template.
D.The project budget spreadsheet.
AnswerC

A formal protocol ensures that all systemic risks are considered at the start of the project.

Why this answer

A Data Protection Impact Assessment (DPIA) or an AI-specific Risk Assessment protocol is the formal process for identifying risks early.

43
MCQmedium

Which action should be taken if a model's performance consistently falls outside the 'Risk Appetite' threshold?

A.Only inform the IT team
B.Take the model offline for remediation
C.Ignore the result as it is just a statistical outlier
D.Increase the threshold to match current performance
AnswerB

Stopping the risk-producing activity is the correct risk management response.

Why this answer

Once a threshold is breached, the model should be taken offline or placed under remediation until it is back within acceptable risk parameters.

44
MCQeasy

Which activity is a foundational requirement for building a sustainable AI risk program?

A.Creating an enterprise AI inventory
B.Signing contracts with AI vendors
C.Automating all model retraining cycles
D.Purchasing third-party AI auditing tools
AnswerA

Identifying and logging all AI assets is the mandatory first step.

Why this answer

An AI inventory is the starting point for any risk program, as you cannot manage risks for models you haven't identified.

45
MCQeasy

When drafting an AI risk policy, which element must be defined to provide clear guidance on acceptable AI outcomes?

A.AI model training data source list
B.Vendor procurement list
C.Technical architecture diagram
D.Risk appetite statement
AnswerD

The risk appetite defines the level of risk the organization is willing to accept for AI initiatives.

Why this answer

Risk appetite statements provide the boundary of acceptable risk, which is foundational to any AI risk management program.

46
MCQmedium

An enterprise is establishing its AI Governance Committee. Which stakeholder is most critical to include to ensure alignment between AI technical capabilities and the organization's enterprise risk appetite?

A.Head of Legal
B.Chief Information Security Officer
C.Chief Risk Officer
D.Lead Data Scientist
AnswerC

The CRO is responsible for enterprise-wide risk strategy, making them the primary stakeholder for AI risk appetite.

Why this answer

The Chief Risk Officer (CRO) ensures that AI development aligns with the risk appetite and risk management framework, acting as the bridge between technical execution and business oversight.

47
MCQeasy

Which phase of the AI lifecycle is most critical for initial risk mitigation?

A.Deployment.
B.Decommissioning.
C.Model Monitoring.
D.Design and Problem Formulation.
AnswerD

Addressing risks at the design stage is the most efficient way to ensure safety and ethical alignment.

Why this answer

Risk mitigation is most effective during the Design phase, before the model is developed, to avoid costly re-engineering.

48
MCQeasy

An organization is integrating AI risk into its enterprise risk management (ERM) framework. What is the first step in this integration process?

A.Assign a Chief AI Officer.
B.Identify and classify all AI applications by criticality and risk level.
C.Install automated model monitoring tools.
D.Create an AI acceptable use policy.
AnswerB

Establishing a baseline inventory and classification is mandatory for effective risk management integration.

Why this answer

Before integrating, the organization must understand the AI scope and criticality relative to existing assets.

49
MCQhard

A project lead argues that AI model performance metrics alone are sufficient for risk management. Why is this incorrect?

A.They change too quickly to report
B.They are too difficult to calculate for small models
C.They are too subjective
D.They do not capture social and compliance risk dimensions
AnswerD

AI risk management requires a holistic view that includes non-technical factors.

Why this answer

Performance metrics do not account for external risks such as legal exposure, compliance violations, or social impact.

50
Multi-Selecthard

Which THREE actions should be taken when integrating AI risk into the broader ERM (Enterprise Risk Management) framework?

Select 3 answers
A.Outsource all AI risk management to a third-party consultant.
B.Establish aligned risk scoring criteria across all business functions.
C.Prohibit all AI initiatives that carry any inherent risk.
D.Define a common risk taxonomy that includes AI-specific concepts like bias and drift.
E.Ensure that AI risk owners report into the same governance channels as other risk owners.
AnswersB, D, E

Standardized criteria allow for accurate prioritization across the organization.

Why this answer

Standardizing risk language, establishing clear reporting lines, and aligning risk criteria are essential for ERM integration.

51
MCQmedium

You are establishing an AI risk appetite framework using the NIST AI RMF. Which action best ensures alignment between AI innovation velocity and organizational risk tolerance?

A.Set a static threshold for model accuracy at 95% across all AI projects.
B.Define risk tolerance levels based on potential impact to human rights and safety, differentiated by model deployment context.
C.Require all AI teams to use exclusively open-source models to mitigate vendor-related risks.
D.Delegate all AI risk acceptance decisions to the lead data scientist.
AnswerB

Differentiating by context is a core requirement of the NIST AI RMF for tailored risk management.

Why this answer

Aligning risk appetite requires mapping technical AI performance metrics to business-level risk registers, ensuring that performance trade-offs are explicitly approved by stakeholders.

52
MCQhard

When setting up an AI risk monitoring dashboard, what is the most important consideration for ensuring executive buy-in?

A.Map AI performance metrics to business impact indicators like customer churn or operational downtime.
B.Include the number of GPU hours utilized.
C.Display the raw training error rates.
D.Show a comparison of the organization's AI progress against competitors.
AnswerA

Linking technical risk to business outcomes is essential for executive decision-making.

Why this answer

Executives need to see how AI risk affects business outcomes (e.g., financial impact, reputation) rather than just technical performance.

53
MCQeasy

Which stage of the AI lifecycle should risk management activities begin?

A.When the budget is exhausted
B.After the model is fully deployed
C.During the design and requirements phase
D.Only when a bug is reported
AnswerC

Early integration is key to effective and cost-efficient risk management.

Why this answer

Risk management must be integrated at the beginning (Design/Requirement) to avoid costly redesigns later.

54
MCQmedium

An organization is updating its risk appetite statement for AI. Which specific element should be addressed to manage the 'hallucination' risk of LLMs?

A.Set a performance goal to reduce the model parameter count.
B.Require human-in-the-loop for any AI-generated output used in customer-facing content.
C.Increase the frequency of periodic penetration testing.
D.Limit the training dataset to under 10GB.
AnswerB

Human-in-the-loop is the primary control for mitigating the impact of generative AI hallucinations.

Why this answer

Establishing clear boundaries for where generative AI is acceptable versus prohibited is a key aspect of risk appetite.

55
MCQmedium

When coordinating AI risk across a global organization, why is it critical to include local legal counsel in the AI steering committee?

A.To audit the training datasets for copyright infringement.
B.To handle administrative tasks for the committee.
C.To interpret the varied regulatory landscapes in different operational regions.
D.To approve the technical architecture of the AI models.
AnswerC

Local counsel ensures that global AI strategies do not conflict with regional legal requirements.

Why this answer

AI regulations, such as the EU AI Act, differ significantly by jurisdiction, making local legal expertise essential for compliance risk management.

56
MCQmedium

What is the primary purpose of an 'AI Risk Dashboard' for executive leadership?

A.To replace the need for an AI ethics committee
B.To provide raw model logs to the public
C.To monitor individual developer productivity
D.To provide high-level visibility into AI risk posture and trends
AnswerD

Dashboards facilitate decision-making by summarizing complex risks.

Why this answer

Dashboards allow leadership to see aggregated risk trends across the enterprise, not just individual project metrics.

57
MCQmedium

Which documentation is necessary to provide to auditors for an AI system?

A.A list of all employees who attended a conference
B.The login credentials for the production environment
C.The model card or model documentation
D.The complete source code without comments
AnswerC

Model cards document performance, limitations, and use cases, which are key for auditing.

Why this answer

A model card provides the necessary metadata, performance limitations, and intended use cases required for auditability.

58
MCQmedium

An organization is establishing an AI governance framework. Which approach is most effective for aligning AI risk appetite with enterprise-wide risk management (ERM)?

A.Map AI-specific risk metrics to existing enterprise risk categories like operational, financial, and reputational risk.
B.Establish a top-down mandate that ignores business unit input to ensure uniformity.
C.Focus solely on technical model performance metrics to define the organizational risk appetite.
D.Create a separate AI-specific risk register that operates independently of the corporate risk register.
AnswerA

Mapping ensures AI risk is treated as an extension of existing enterprise risks.

Why this answer

Integrating AI risk appetite into the existing ERM framework ensures consistency and avoids silos.

59
MCQhard

You are managing AI supply chain risk. Which control is most critical for third-party AI models?

A.Requiring a documented 'AI Bill of Materials' to understand data lineage and model provenance.
B.Conducting a manual audit of the vendor's source code.
C.Requiring the vendor to submit a monthly performance report.
D.Setting a limit on the number of third-party vendors allowed.
AnswerA

An AI BOM (or equivalent documentation) is essential for assessing third-party model risk.

Why this answer

Vendor/Model transparency (Software Bill of Materials for AI) is critical for understanding dependencies and hidden risks in black-box models.

60
MCQmedium

To ensure cross-functional coordination, you are designing a workflow for AI incident reporting. Which group should be the first point of contact upon detecting an AI model bias issue?

A.AI Governance/Ethics Committee
B.IT Help Desk
C.Customer Support
D.External Regulators
AnswerA

This body is designed to oversee and resolve AI-specific operational risks such as model bias.

Why this answer

The AI Governance team or AI Ethics office is tasked with immediate triage of AI-specific risks before escalation to legal or IT operations.

61
Multi-Selecthard

Which TWO strategies are recommended for 'Mitigating' AI model bias?

Select 2 answers
A.Removing all data from the database
B.Asking the user to manually fix the bias
C.Applying fairness constraints during model training
D.Ignoring the bias and hoping it goes away
E.Training on more diverse and representative datasets
AnswersC, E

Fairness algorithms directly mitigate bias during the build phase.

Why this answer

Mitigation involves both pre-processing (data) and in-processing (training) techniques.

62
MCQhard

If an AI model relies on an open-source library that is found to have a security vulnerability, who is responsible for managing this risk?

A.The government regulators
B.The AI Risk Manager and Security team
C.The library's author
D.The public at large
AnswerB

Collaborative risk management is needed to address the dependency vulnerability.

Why this answer

The AI Risk Manager, working with the security team, must assess the risk and ensure the library is updated or the dependency is mitigated.

63
MCQeasy

Which of the following is a key component of 'AI Risk Governance'?

A.The choice of programming language
B.The definition of roles and responsibilities
C.The vendor of the cloud hosting platform
D.The speed of model deployment
AnswerB

Governance is defined by who is responsible and accountable for what.

Why this answer

Clear roles and responsibilities are essential for accountability, which is a core component of governance.

64
MCQmedium

When establishing KPIs for an AI program, what is the risk of focusing solely on 'Model Accuracy'?

A.The model will be too computationally expensive.
B.The data scientists will take too long to develop the model.
C.The model will not be deployable in production.
D.Other critical risks such as bias, security, and fairness may be overlooked.
AnswerD

A singular focus on accuracy ignores the socio-technical dimensions of AI risk.

Why this answer

Accuracy ignores other vital risk factors like bias, fairness, and security, which could result in a high-performing but high-risk model.

65
MCQeasy

What is 'Bias' in the context of AI risk?

A.The model is missing documentation
B.Systematic prejudice in model outputs leading to unfair results
C.The model is too expensive to maintain
D.The model is running too fast
AnswerB

This is the standard definition of AI bias.

Why this answer

Bias refers to systematic errors that lead to unfair or discriminatory outcomes, posing both social and regulatory risks.

66
MCQmedium

When coordinating between Legal and Data Science teams, what is the best way to handle 'Explainability' requirements?

A.Require Data Science to translate technical model output into plain language documentation
B.Restrict Legal from reviewing AI model outputs
C.Let Legal define the technical parameters of the models
D.Only document model logic when a lawsuit occurs
AnswerA

This ensures compliance and oversight without compromising technical accuracy.

Why this answer

Bridging technical model features (shapley values, etc.) with legal disclosure requirements requires a common documentation template.

67
MCQeasy

When setting KPIs for an AI risk program, which metric is a leading indicator of potential model bias?

A.Average model inference latency
B.Percentage of customer complaints regarding AI decisions
C.Number of model updates per quarter
D.Demographic parity ratio in training data samples
AnswerD

Analyzing training data for representativeness identifies bias before the model is deployed.

Why this answer

Monitoring training data distribution is a leading indicator, whereas output monitoring is a lagging indicator.

68
MCQmedium

When performing an AI risk assessment, which question is most appropriate to ask?

A.How many people are on the development team?
B.What is the potential impact if the model produces biased results?
C.What is the model's highest accuracy score?
D.Does the model use open-source libraries?
AnswerB

This addresses the core goal of risk assessment: analyzing potential negative outcomes.

Why this answer

Risk assessment focuses on impact and likelihood, and the potential for unintended harm is the core of AI risk analysis.

69
MCQmedium

In a retail company, which AI risk is most likely to cause direct financial loss?

A.The model documentation is outdated
B.The font size in the UI is too small
C.The pricing model provides incorrect, discounted rates
D.The model's name is not catchy
AnswerC

Pricing errors directly impact financial performance.

Why this answer

Inaccurate pricing models can lead to immediate and direct revenue loss, which is a clear financial risk.

70
Multi-Selecteasy

Which TWO factors should be documented in an AI Model Card?

Select 2 answers
A.The developer's favorite snacks
B.The current stock price of the company
C.The employee handbook for new hires
D.Intended use cases
E.Model limitations and known risks
AnswersD, E

Knowing what the model is designed for is essential.

Why this answer

Model cards are designed to inform users about the model's performance and usage limits.

71
Multi-Selecthard

Which TWO actions are required to manage 'Third-Party' AI risks?

Select 2 answers
A.Performing due diligence on the vendor's AI risk practices
B.Ignoring the vendor's feedback
C.Allowing the vendor to set their own rules
D.Asking the vendor for their cafeteria menu
E.Asking the vendor to sign a NDA
AnswersA, E

You must vet the vendor's own risk management.

Why this answer

Management requires due diligence and contractual oversight.

72
Multi-Selectmedium

Which THREE areas should be covered in an AI risk management program?

Select 3 answers
A.The office floor plan
B.Model performance and accuracy
C.Third-party/Vendor risk management
D.The color of the company logo
E.Legal and regulatory compliance
AnswersB, C, E

Technical performance is a critical risk area.

Why this answer

Comprehensive AI programs address technical, legal, and operational risks.

73
Multi-Selectmedium

Which THREE types of 'Bias' need to be managed in an AI project?

Select 3 answers
A.Measurement bias (data collection)
B.The bias towards free coffee
C.The bias of the local weather
D.Sampling bias (data selection)
E.Algorithmic bias (model logic)
AnswersA, D, E

This happens when data collection methods are flawed.

Why this answer

Common forms of AI bias include sampling, measurement, and algorithmic bias.

74
Multi-Selecthard

A cross-functional committee is evaluating the deployment of a high-impact AI model. Which TWO factors are critical to include in the initial AI risk assessment to ensure comprehensive coverage?

Select 2 answers
A.The frequency of software patching for the underlying cloud infrastructure.
B.The socio-technical implications and potential impact on protected groups.
C.The underlying training data lineage, including provenance and potential bias sources.
D.The name of the vendor providing the cloud compute resources.
E.The specific programming language used for the model development.
AnswersB, C

Socio-technical impact is a core requirement for high-impact AI risk assessments.

Why this answer

Data lineage and socio-technical impact are critical for high-impact AI assessments.

75
MCQeasy

Which of the following is a key objective of an AI Risk Management Program?

A.To eliminate all AI risks.
B.To maximize the budget spent on AI tools.
C.To enable the ethical and safe adoption of AI technologies.
D.To replace human employees with AI.
AnswerC

The objective is to enable innovation while managing risk appropriately.

Why this answer

The primary objective is to balance the benefits of AI with the potential risks to the organization.

Page 1 of 2 · 83 questions totalNext →

Ready to test yourself?

Try a timed practice session using only AI Risk Program Management questions.