WorksheetsPage 1
Total questions: 49
Worksheet time: 25mins
Tailoring governance drivers: Which combination best reflects why AI governance approaches differ across organisations?
Only the AI model type and vendor
Company size, maturity, industry/sector, products/services, objectives, and risk tolerance
Only regulatory requirements and cybersecurity maturity
Only whether the AI is internal or customer-facing
Small company governance design: Which approach is most consistent with how smaller companies often implement AI governance?
Create a new AI office with separate committees for every model
Combine AI governance responsibilities into existing privacy/legal oversight functions and reuse existing screening tools
Avoid governance and rely on vendor guarantees
Only focus on employee training and skip policies
Large company governance design: What is a common governance pattern for larger organisations?
They typically eliminate model monitoring due to scale
They tend to create AI-specific offices, oversight, and detailed processes
They rely only on user feedback as a control
They only govern new AI, not existing AI features
Roles overlap across the AI life cycle: Which statement is correct about AI life cycle roles?
A developer can never be a deployer
Only one organisation can be a developer or deployer for a system
A developer can also be a deployer, and multiple entities can serve as developers/deployers over a system’s lifespan
Providers and deployers are always the same entity
Developer core responsibility: Which best describes what developers do from a governance perspective?
Only market the AI system and handle consumer notifications
Design, develop, implement models, manage data for training, test for accuracy and bias, and document limitations
Only run production monitoring and maintain logs
Only write internal policies
Developer documentation content: Which item is explicitly part of documentation developers provide to deployers?
Limitations of the system and potentially harmful uses
Internal marketing slogans and branding guidelines
Salary bands for the model development team
A list of unrelated consumer products the company sells
What are developers expected to do regarding algorithmic discrimination?
Ignore discrimination until a regulator complains
Identify and mitigate known or foreseeable risks, and notify authorities and deployers of newly discovered risks
Only notify their internal legal team
Only provide a disclaimer to end users
Which is an explicit expectation of developers in the lesson?
They must publish their entire training dataset
They make public statements about the types of AI systems they develop and how risks are managed
They must directly notify every end user of model updates
They must guarantee zero bias
Which statement best captures a provider’s pre-market responsibility?
Ensure AI meets safety, transparency and accountability standards before going to market
Only ensure the AI meets performance requirements
Only ensure the AI has an attractive user interface
Avoid all legal compliance until after launch
Providers must comply with relevant legal and regulatory requirements, including:
Data security and ethical use
Only branding and marketing standards
Only uptime and availability standards
Only internal HR policy
Which is a provider obligation across the AI technology life cycle?
Assess and manage associated risks effectively throughout the life cycle
Only conduct an assessment pre-launch
Only respond to issues when customers terminate contracts
Only provide a helpdesk
Which is specifically emphasised for providers of general-purpose AI models?
Minimal documentation to protect trade secrets
Comprehensive technical documentation including detailed information on training content
Only UI documentation
Only FAQs for end users
In the event of serious incidents, who is responsible for reporting occurrences and notifying authorities if systemic risks arise?
Users
Deployers only
Providers
Developers only
Deployers must ensure AI systems are used:
Only for internal purposes
In accordance with regulations and provider instructions
Only with vendor staff present
Only during pilot periods
Deployer oversight expectation Which is explicitly required of deployers, particularly for high-risk AI systems?
Full automation with no human involvement
Adequate human oversight
Oversight only during initial testing
Outsourcing oversight to end users
Deployer AI literacy control Why do deployers provide training and promote AI literacy among staff?
To reduce the need for documentation
To foster effective interaction with AI tools
To replace risk management programs
To eliminate monitoring requirements
High-risk input data quality For high-risk AI systems, deployers are responsible for ensuring input data is:
Randomised and anonymised
Relevant, representative, error-free and complete
Only collected from public sources
As large as possible regardless of quality
Continuous monitoring purpose. Why must deployers continuously monitor AI operations?
To increase model size over time
To identify and address emerging risks
To avoid documenting limitations
To remove the need for impact assessments
Incident escalation path. When deployers identify risks or serious incidents, they must:
Keep them internal unless media reports occur
Promptly report them to providers
Report only to end users
Wait for annual audits
Logging obligation. Which deployer obligation supports traceability and regulatory expectations for high-risk systems?
Publishing training data publicly
Maintaining detailed logs of AI system usage
Disabling user feedback
Avoiding monitoring to reduce cost
Impact assessments for deployers: What additional activity is described for deployers operating high-risk AI?
Quarterly marketing reviews
Regular impact assessments (as required by legislation in some cases)
Annual staff surveys only
No formal reviews after deployment
Consumer notice obligation: Deployers must notify consumers when:
Any AI system is used for any purpose
A high-risk AI system will be used to make consequential decisions about them
A model is trained on open data
A chatbot is used for routine FAQs only
High-risk risk management program: To further mitigate risks, deployers implement and maintain:
A model leaderboard
A comprehensive risk management policy and program for high-risk AI systems
A sales enablement package
Only a privacy policy
User recognition requirement Why must users recognise when they are engaging with an AI system?
To improve model compression
Because interaction may not be immediately apparent, and recognition supports responsible use and appropriate escalation
Because it is required only for entertainment products
Because it replaces provider documentation
User feedback role Which user obligation directly supports governance feedback loops?
Refusing to use the tool
Offering feedback on AI performance, outcomes, and issues that arise
Publishing outputs on social media
Demanding the source code
User rights awareness Users should understand and exercise rights related to AI-driven decisions such as:
Right to free software upgrades
Right to notice or human review for consequential decisions
Right to retrain the model themselves
Right to remove all logs
What is identified as vital for fostering trust and accountability within AI systems?
Only vendor warranties
Clear communication and collaboration among all stakeholders
Only strong encryption
Only model interpretability tools
Which is an explicitly listed performance indicator topic for this lesson?
Building neural network architectures from scratch
Differentiating approaches to AI governance based on organisational context
Writing model training code
Designing GPU clusters
Which option best matches the intended scope of AI governance policies?
Deployment only
Use case assessment through to incident management across the life cycle
Risk tolerance misconception: Which statement is most accurate about risk tolerance and AI adoption decisions?
If AI reduces one risk, it reduces all risks
AI can ameliorate some risks but almost certainly introduces new risks, so decisions must be use case based
Risk tolerance only applies to model developers
Risk tolerance is irrelevant if the model is bought from a vendor
“Relative score” limitation: Why is a risk assessment score alone insufficient for decision-making?
Scores are always wrong
Scores are relative, so organisations must determine fit with operational position, values, and strategic plans
Scores remove the need for monitoring
Scores eliminate the need for stakeholder analysis
Use case assessment definition: What best defines a use case assessment?
A marketing exercise to justify AI spend
A structured process to evaluate viability, risks and ethical implications of applying AI to a specific problem or opportunity
A security test performed after deployment
A data migration plan
NIST AI RMF core components: Which set are listed as key components of the NIST AI Risk Management Framework in the lesson?
Plan, Build, Ship
Map, Measure, Manage
Define, Code, Deploy
Identify, Patch, Restore
Map phase purpose: What is the primary purpose of the “Map” function?
To write a model card after deployment
To establish context and identify risks related to that context by surveying the operating environment and impacts
To retrain the model weekly
To choose a cloud provider
Map phase key activities: Which is a correct "Map" activity?
Only measuring accuracy on a test set
Identifying stakeholders and impacts, characterising positive and negative impacts
Writing incident reports for historical events only
Selecting marketing channels
System categorisation in Map: Why does the RMF recommend categorising the AI system (tasks and methods such as generative models or recommenders)?
To choose a corporate logo
To understand capabilities, targeted usage, goals, and expected benefits and costs
To reduce the need for measurement
To avoid documentation
Which Map activity addresses overreliance and misuse risk most directly?
Choosing a larger model
Documenting knowledge limits and how humans may use and oversee output
Increasing marketing budget
Removing logs
What does the “Measure” function do?
Only tracks customer satisfaction
Assesses, analyses and tracks mapped risks, quantifying risks across technical, societal and organisational domains
Removes the need for managing risk
Focuses only on cost reduction
Which set matches examples of "trustworthy characteristics" in the Measure phase?
Profit, market share, headcount
Accuracy, robustness, fairness
Brand awareness, NPS, conversion rate
Latency, uptime, sales pipeline
What must be assessed when measuring identified risks?
Only likelihood
Severity, likelihood and scope, including biases and security vulnerabilities
Only severity
Only the cost of mitigation
Which mechanism is explicitly required in Measure?
One-time testing only
Mechanisms to continuously track identified AI risks and gather feedback on measurement efficacy
Only executive sign-off
Only vendor attestations
Manage phase objective: What is the primary aim of “Manage” in NIST AI RMF?
Increase inference speed
Prioritise and act on risks identified and measured during assessment
Replace stakeholder engagement
Prevent any need for documentation
Risk response options: Which set are explicitly listed as possible risk response approaches in Manage?
Ignore, delay, deny, deflect
Mitigate, transfer, avoid, accept
Outsource, automate, monetise, rebrand
Predict, classify, generate, retrieve
Controls and interventions in Manage: Which is a Manage activity?
Implement security controls, safeguards and interventions to reduce risk
Remove all guardrails to improve user experience
Stop monitoring to avoid false alarms
Rely solely on user goodwill
Continuous improvement expectation. Which statement is consistent with Manage?
Governance ends at launch
Regularly monitor system behaviour, update controls as needed, and establish continuous improvement plans
Only measure risk, do not act
Only act on risks once per year
When to perform a use case assessment. Which option is correct?
Only after deployment
Before implementation, early in the life cycle, for new initiatives, throughout the life cycle, and for regulatory compliance
Only for low-risk use cases
Only when a regulator asks
Healthcare image analysis: why assess early. In the medical imaging example, why is a use case assessment needed during the design phase?
To select a marketing slogan
To map risks like life-critical false positives/negatives, bias due to lack of diverse training data, data security, and the need for human oversight
To avoid any testing
To prevent radiologists from reviewing results
Third-party sentiment tool: key evaluation focus Before integrating a third-party sentiment tool, what should a use case assessment evaluate?
Only the vendor’s sales references
Vendor AI governance practices, transparency, performance on relevant data, and compliance with internal policies and external regulations
Only the cloud region location
Only whether the tool is popular on social media
Bank chatbot: the “best solution” test In the customer service chatbot example, what is a key reason to assess before committing resources?
To ensure the chatbot replaces all human staff
To assess whether a chatbot is the best solution versus alternatives, and to identify risks like misinterpreting intent, incorrect information, privacy concerns, and workforce impacts
To avoid defining scope and capabilities
To skip risk management because it is routine enquiries
