Describe Artificial Intelligence workloads and considerations →mediumMultiple ChoiceObjective-mapped
AI-900 Practice Question: Describe Artificial Intelligence workloads and considerations
What is 'AI governance' and what tools does Azure provide for it?
⚠ Common exam trap
It's easy for candidates to confuse 'AI governance' with external regulation (Option A) or a specific approval process (Option C), rather than recognizing it as the internal framework of policies and controls that Azure implements through tools like Azure Policy and RBAC.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policies, processes, and controls ensuring AI systems are developed and operated responsibly
AI governance refers to the framework of policies, processes, and controls that guide the responsible development, deployment, and operation of AI systems. Azure provides tools like Azure Policy, Azure Role-Based Access Control (RBAC), and Microsoft Purview to enforce governance rules, audit AI usage, and ensure compliance with ethical standards. Option B correctly captures this definition, as it focuses on the organizational and technical mechanisms for responsible AI, not external restrictions or certifications.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Government regulation that prohibits certain types of AI systems
Why it's wrong here
Government regulation that prohibits certain types of AI systems is external legislation, which is distinct from an organisation's own AI governance. AI governance is the organisation's internal set of policies, processes, and controls for managing AI responsibly, while government regulation represents legal constraints imposed from outside. Furthermore, governance is broader than prohibition: it includes enabling responsible innovation, defining acceptable uses, monitoring bias and drift, and maintaining audit trails, none of which are captured by simply banning certain systems.
- ✓
The policies, processes, and controls ensuring AI systems are developed and operated responsibly
Why this is correct
This is the correct definition because AI governance is precisely the framework of policies, processes, and controls that guide responsible AI development and operation across the system's lifecycle. It covers areas such as fairness, reliability, privacy, security, transparency, and accountability, and is operationalised through tools like Azure Machine Learning's Responsible AI dashboard, which provides model explanations, fairness assessment, error analysis, and counterfactuals. Effective governance requires continuous oversight, auditing, and feedback loops, not just a one-time review or external rule.
- ✗
Electing a board of AI experts to approve all AI projects before they go to production
Why it's wrong here
Electing a board of AI experts to approve all AI projects before they go to production is too narrow to define AI governance. While an approval board can be one governance mechanism, true AI governance encompasses a broader system of policies, processes, and controls that operate throughout the entire AI lifecycle, including data preparation, model training, evaluation, deployment, and ongoing monitoring. It also includes auditing, fairness checks, transparency requirements, and incident response procedures that cannot be reduced to a single pre-production gate.
- ✗
Restricting AI development to organisations with formal AI certifications
Why it's wrong here
Restricting AI development to organisations with formal AI certifications describes an external assurance or accreditation scheme, not the internal governance practice itself. AI governance refers to how an organisation structures its own policies, procedures, and controls to ensure responsible development and operation of AI systems. Certification programs may support compliance or maturity assessment, but they do not capture the ongoing, embedded practices like bias mitigation, explainability, and model monitoring that governance requires within each organisation.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This AI-900 question is part of Courseiva's 985-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AI-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-900 exam.