Artificial Intelligence Governance Professional Free Sample Questions

20 free sample questions234 in the full practice test

Try simulator

AIGP Sample Questions

  1. Question 1

    A financial services company based in Canada is deploying a high-risk credit scoring AI system that will process applications from EU citizens. The company is already compliant with PIPEDA. To comply with the EU AI Act, which of the following represents the MOST critical additional governance requirement for them as a 'provider'?

    Answer and explanation

    Correct answer: B

    While PIPEDA and GDPR (which would also apply) have stringent data protection requirements, the EU AI Act introduces a product safety framework for high-risk AI systems. As a 'provider' placing a high-risk system on the EU market, the company must conduct a conformity assessment to demonstrate compliance with the Act's requirements and affix a CE marking, similar to other regulated products. Appointing an EU representative is necessary, but the conformity assessment is the core procedural requirement for market entry. Data processing agreements and DPIAs are GDPR requirements, which are related but distinct from the AI Act's conformity process.

  2. Question 2

    Multiple answers

    An AI development team is building a model to predict equipment failure in a factory. They are in the process of establishing data provenance for their training dataset. Which THREE of the following activities are essential for this process? (Select THREE)

    Answer and explanation

    Correct answers: A, C, D

    Data provenance requires a detailed audit trail of the data's entire lifecycle. This includes its origin, any transformations, and its final state. Recording the origin (e.g., sensor IDs), the transformations (including software versions, as different versions can produce different results), and cryptographic hashes to ensure integrity are all critical components. The cost of storage is an operational metric, not a part of data provenance. The model's final accuracy is a performance metric derived from the data but not part of the data's history itself. The names of the engineers are part of project management, not the technical data lineage.

  3. Question 3

    A large multinational corporation has a centralized AI ethics board but allows individual business units to develop and deploy their own AI applications. This has led to inconsistent application of corporate AI principles and duplicated risk assessment efforts. To address this, the Chief AI Governance Officer proposes a 'hub-and-spoke' governance model. What is the primary advantage of this model in this scenario?

    Answer and explanation

    Correct answer: C

    A hub-and-spoke model (also known as a federated model) is designed to solve this exact problem. The central 'hub' (the corporate AI governance office) sets the policies, standards, and provides expertise. The 'spokes' (embedded AI governance leads within business units) execute these policies in a way that is tailored to their specific context. This structure ensures consistency and efficiency (from the hub) while maintaining business unit agility and domain-specific knowledge (at the spokes). It does not completely centralize development nor does it make units fully autonomous.

  4. Question 4

    During a post-deployment audit of an AI-powered recruitment tool, it was discovered that the system disproportionately rejects qualified candidates from a specific demographic group for technical roles. The model was trained on the company's historical hiring data. This is a classic example of which type of AI risk?

    Answer and explanation

    Correct answer: C

    This scenario describes ethical and bias risk, specifically amplification of historical bias. The AI model learned patterns from past hiring data, which likely contained societal or organizational biases. The model is now perpetuating and potentially amplifying this bias, leading to discriminatory outcomes. Model drift refers to performance degradation over time as data distributions change. Brittleness refers to a model failing on inputs slightly different from its training data. Lack of robustness is a general term for susceptibility to errors or attacks.

  5. Question 5

    Case Study

    A healthcare provider, 'WellCare,' wants to deploy a third-party, cloud-hosted AI model that analyzes medical images to detect early signs of a specific disease. The AI vendor claims a 98% accuracy rate in their lab tests. WellCare's patient population has a significantly different demographic and genetic makeup compared to the population used for the vendor's training data. The vendor's contract has a strict limitation of liability clause and does not provide access to the model's internal logic or full training dataset, citing intellectual property concerns.

    WellCare's AI Governance Council is reviewing the deployment decision. The primary business objective is to improve patient outcomes by catching the disease earlier. However, the legal team is concerned about potential misdiagnoses and the associated liability. The IT department is concerned about data security, as patient images will be processed by the third-party vendor.

    Which of the following is the MOST critical governance activity for WellCare to perform before signing the contract and deploying the model?

    Answer and explanation

    Correct answer: C

    Given the mismatch between the vendor's training data and WellCare's patient population, the claimed 98% accuracy is unreliable for their specific use case. The most critical step is to validate the model's actual performance and fairness on their own data. This pre-deployment pilot or testing will quantify the real-world risk of misdiagnosis and bias. While negotiating liability, ensuring data security, and creating a human-in-the-loop process are all vital governance steps, none are as fundamental as first determining if the model is safe and effective for its intended population. Without this validation, the other controls are meaningless.

  6. Question 6

    True or False: According to the NIST AI Risk Management Framework (RMF), the 'GOVERN' function is primarily focused on post-deployment monitoring and measurement of AI system performance.

    Answer and explanation

    Correct answer: B

    This statement is false. The 'GOVERN' function is a cross-cutting function that applies throughout the AI lifecycle. It is about cultivating a risk management culture, establishing processes, and providing the overarching structure for risk management. Post-deployment monitoring and measurement are primarily addressed within the 'MANAGE' and 'MEASURE' functions of the NIST AI RMF.

  7. Question 7

    An insurance company uses an AI model to detect fraudulent claims. The model is a complex deep learning system, making its decisions difficult to interpret. To meet the 'explainability' principle of responsible AI, the company uses SHAP (SHapley Additive exPlanations) to generate a report for each decision, highlighting the top three factors that contributed to the outcome. This approach is an example of which type of explainability?

    Answer and explanation

    Correct answer: B

    This is an example of post-hoc explainability. The AI model itself is a 'black box' (a complex deep learning system). Techniques like SHAP or LIME are applied after the model makes a prediction to approximate and explain its behavior for a specific instance. Intrinsic explainability, by contrast, comes from using models that are inherently simple and understandable, such as linear regression or decision trees. Global explainability describes the model's overall behavior, while local explainability (which SHAP provides) explains individual predictions.

  8. Question 8

    A retail company deploys a generative AI chatbot for customer service. To improve performance, they decide to fine-tune the base model using transcripts of their own customer service calls. From a governance perspective, what is the MOST significant new risk introduced by this fine-tuning process?

    Answer and explanation

    Correct answer: B

    While all options are considerations, the most significant governance risk is data privacy. Customer service transcripts are rich with PII (names, addresses, account numbers). Fine-tuning on this data creates a high risk that the model will 'memorize' this sensitive information and could potentially reveal it in responses to other users' queries. This is a major privacy breach and liability issue. Increased cost is a business concern, model collapse is a technical risk, and vendor lock-in is a strategic risk, but the PII disclosure risk is the most acute and immediate governance failure.

  9. Question 9

    An AI governance professional is reviewing the design of a new AI model intended for a high-risk application. They are applying the 'risk mitigation hierarchy' as part of their assessment. According to this principle, what should be their first consideration?

    Answer and explanation

    Correct answer: B

    The risk mitigation hierarchy, a standard concept in safety and risk management, prioritizes controls from most to least effective. The highest priority is always elimination—designing the system so the hazard cannot occur in the first place. If elimination is not possible, the next steps are substitution, engineering controls, administrative controls, and finally, personal protective equipment (or its equivalent). Therefore, the first consideration should be if the risk can be designed out of the system entirely.

  10. Question 10

    A city's transportation authority plans to use an AI system to optimize traffic light timing. The system uses real-time camera feeds from intersections. Under the EU AI Act's risk classification framework, which category would this system MOST likely fall into?

    Answer and explanation

    Correct answer: B

    According to Annex III of the EU AI Act, AI systems intended to be used as safety components in the management and operation of road traffic are classified as high-risk. Optimizing traffic light timing directly impacts road safety, and therefore falls into this category. It is not prohibited (like social scoring), does not merely have transparency obligations (limited-risk), and is not considered minimal risk due to its direct impact on public safety.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 234 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon