wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Page 1

Total questions: 49

Worksheet time: 25mins

Name
Class
Date
1.

Tailoring governance drivers: Which combination best reflects why AI governance approaches differ across organisations?

a)

Only the AI model type and vendor

b)

Company size, maturity, industry/sector, products/services, objectives, and risk tolerance

c)

Only regulatory requirements and cybersecurity maturity

d)

Only whether the AI is internal or customer-facing

2.

Small company governance design: Which approach is most consistent with how smaller companies often implement AI governance?

a)

Create a new AI office with separate committees for every model

b)

Combine AI governance responsibilities into existing privacy/legal oversight functions and reuse existing screening tools

c)

Avoid governance and rely on vendor guarantees

d)

Only focus on employee training and skip policies

3.

Large company governance design: What is a common governance pattern for larger organisations?

a)

They typically eliminate model monitoring due to scale

b)

They tend to create AI-specific offices, oversight, and detailed processes

c)

They rely only on user feedback as a control

d)

They only govern new AI, not existing AI features

4.

Roles overlap across the AI life cycle: Which statement is correct about AI life cycle roles?

a)

A developer can never be a deployer

b)

Only one organisation can be a developer or deployer for a system

c)

A developer can also be a deployer, and multiple entities can serve as developers/deployers over a system’s lifespan

d)

Providers and deployers are always the same entity

5.

Developer core responsibility: Which best describes what developers do from a governance perspective?

a)

Only market the AI system and handle consumer notifications

b)

Design, develop, implement models, manage data for training, test for accuracy and bias, and document limitations

c)

Only run production monitoring and maintain logs

d)

Only write internal policies

6.

Developer documentation content: Which item is explicitly part of documentation developers provide to deployers?

a)

Limitations of the system and potentially harmful uses

b)

Internal marketing slogans and branding guidelines

c)

Salary bands for the model development team

d)

A list of unrelated consumer products the company sells

7.

What are developers expected to do regarding algorithmic discrimination?

a)

Ignore discrimination until a regulator complains

b)

Identify and mitigate known or foreseeable risks, and notify authorities and deployers of newly discovered risks

c)

Only notify their internal legal team

d)

Only provide a disclaimer to end users

8.

Which is an explicit expectation of developers in the lesson?

a)

They must publish their entire training dataset

b)

They make public statements about the types of AI systems they develop and how risks are managed

c)

They must directly notify every end user of model updates

d)

They must guarantee zero bias

9.

Which statement best captures a provider’s pre-market responsibility?

a)

Ensure AI meets safety, transparency and accountability standards before going to market

b)

Only ensure the AI meets performance requirements

c)

Only ensure the AI has an attractive user interface

d)

Avoid all legal compliance until after launch

10.

Providers must comply with relevant legal and regulatory requirements, including:

a)

Data security and ethical use

b)

Only branding and marketing standards

c)

Only uptime and availability standards

d)

Only internal HR policy

11.

Which is a provider obligation across the AI technology life cycle?

a)

Assess and manage associated risks effectively throughout the life cycle

b)

Only conduct an assessment pre-launch

c)

Only respond to issues when customers terminate contracts

d)

Only provide a helpdesk

12.

Which is specifically emphasised for providers of general-purpose AI models?

a)

Minimal documentation to protect trade secrets

b)

Comprehensive technical documentation including detailed information on training content

c)

Only UI documentation

d)

Only FAQs for end users

13.

In the event of serious incidents, who is responsible for reporting occurrences and notifying authorities if systemic risks arise?

a)

Users

b)

Deployers only

c)

Providers

d)

Developers only

14.

Deployers must ensure AI systems are used:

a)

Only for internal purposes

b)

In accordance with regulations and provider instructions

c)

Only with vendor staff present

d)

Only during pilot periods

15.

Deployer oversight expectation Which is explicitly required of deployers, particularly for high-risk AI systems?

a)

Full automation with no human involvement

b)

Adequate human oversight

c)

Oversight only during initial testing

d)

Outsourcing oversight to end users

16.

Deployer AI literacy control Why do deployers provide training and promote AI literacy among staff?

a)

To reduce the need for documentation

b)

To foster effective interaction with AI tools

c)

To replace risk management programs

d)

To eliminate monitoring requirements

17.

High-risk input data quality For high-risk AI systems, deployers are responsible for ensuring input data is:

a)

Randomised and anonymised

b)

Relevant, representative, error-free and complete

c)

Only collected from public sources

d)

As large as possible regardless of quality

18.

Continuous monitoring purpose. Why must deployers continuously monitor AI operations?

a)

To increase model size over time

b)

To identify and address emerging risks

c)

To avoid documenting limitations

d)

To remove the need for impact assessments

19.

Incident escalation path. When deployers identify risks or serious incidents, they must:

a)

Keep them internal unless media reports occur

b)

Promptly report them to providers

c)

Report only to end users

d)

Wait for annual audits

20.

Logging obligation. Which deployer obligation supports traceability and regulatory expectations for high-risk systems?

a)

Publishing training data publicly

b)

Maintaining detailed logs of AI system usage

c)

Disabling user feedback

d)

Avoiding monitoring to reduce cost

21.

Impact assessments for deployers: What additional activity is described for deployers operating high-risk AI?

a)

Quarterly marketing reviews

b)

Regular impact assessments (as required by legislation in some cases)

c)

Annual staff surveys only

d)

No formal reviews after deployment

22.

Consumer notice obligation: Deployers must notify consumers when:

a)

Any AI system is used for any purpose

b)

A high-risk AI system will be used to make consequential decisions about them

c)

A model is trained on open data

d)

A chatbot is used for routine FAQs only

23.

High-risk risk management program: To further mitigate risks, deployers implement and maintain:

a)

A model leaderboard

b)

A comprehensive risk management policy and program for high-risk AI systems

c)

A sales enablement package

d)

Only a privacy policy

24.

User recognition requirement Why must users recognise when they are engaging with an AI system?

a)

To improve model compression

b)

Because interaction may not be immediately apparent, and recognition supports responsible use and appropriate escalation

c)

Because it is required only for entertainment products

d)

Because it replaces provider documentation

25.

User feedback role Which user obligation directly supports governance feedback loops?

a)

Refusing to use the tool

b)

Offering feedback on AI performance, outcomes, and issues that arise

c)

Publishing outputs on social media

d)

Demanding the source code

26.

User rights awareness Users should understand and exercise rights related to AI-driven decisions such as:

a)

Right to free software upgrades

b)

Right to notice or human review for consequential decisions

c)

Right to retrain the model themselves

d)

Right to remove all logs

27.

What is identified as vital for fostering trust and accountability within AI systems?

a)

Only vendor warranties

b)

Clear communication and collaboration among all stakeholders

c)

Only strong encryption

d)

Only model interpretability tools

28.

Which is an explicitly listed performance indicator topic for this lesson?

a)

Building neural network architectures from scratch

b)

Differentiating approaches to AI governance based on organisational context

c)

Writing model training code

d)

Designing GPU clusters

29.

Which option best matches the intended scope of AI governance policies?

a)

Deployment only

b)

Use case assessment through to incident management across the life cycle

30.

Risk tolerance misconception: Which statement is most accurate about risk tolerance and AI adoption decisions?

a)

If AI reduces one risk, it reduces all risks

b)

AI can ameliorate some risks but almost certainly introduces new risks, so decisions must be use case based

c)

Risk tolerance only applies to model developers

d)

Risk tolerance is irrelevant if the model is bought from a vendor

31.

“Relative score” limitation: Why is a risk assessment score alone insufficient for decision-making?

a)

Scores are always wrong

b)

Scores are relative, so organisations must determine fit with operational position, values, and strategic plans

c)

Scores remove the need for monitoring

d)

Scores eliminate the need for stakeholder analysis

32.

Use case assessment definition: What best defines a use case assessment?

a)

A marketing exercise to justify AI spend

b)

A structured process to evaluate viability, risks and ethical implications of applying AI to a specific problem or opportunity

c)

A security test performed after deployment

d)

A data migration plan

33.

NIST AI RMF core components: Which set are listed as key components of the NIST AI Risk Management Framework in the lesson?

a)

Plan, Build, Ship

b)

Map, Measure, Manage

c)

Define, Code, Deploy

d)

Identify, Patch, Restore

34.

Map phase purpose: What is the primary purpose of the “Map” function?

a)

To write a model card after deployment

b)

To establish context and identify risks related to that context by surveying the operating environment and impacts

c)

To retrain the model weekly

d)

To choose a cloud provider

35.

Map phase key activities: Which is a correct "Map" activity?

a)

Only measuring accuracy on a test set

b)

Identifying stakeholders and impacts, characterising positive and negative impacts

c)

Writing incident reports for historical events only

d)

Selecting marketing channels

36.

System categorisation in Map: Why does the RMF recommend categorising the AI system (tasks and methods such as generative models or recommenders)?

a)

To choose a corporate logo

b)

To understand capabilities, targeted usage, goals, and expected benefits and costs

c)

To reduce the need for measurement

d)

To avoid documentation

37.

Which Map activity addresses overreliance and misuse risk most directly?

a)

Choosing a larger model

b)

Documenting knowledge limits and how humans may use and oversee output

c)

Increasing marketing budget

d)

Removing logs

38.

What does the “Measure” function do?

a)

Only tracks customer satisfaction

b)

Assesses, analyses and tracks mapped risks, quantifying risks across technical, societal and organisational domains

c)

Removes the need for managing risk

d)

Focuses only on cost reduction

39.

Which set matches examples of "trustworthy characteristics" in the Measure phase?

a)

Profit, market share, headcount

b)

Accuracy, robustness, fairness

c)

Brand awareness, NPS, conversion rate

d)

Latency, uptime, sales pipeline

40.

What must be assessed when measuring identified risks?

a)

Only likelihood

b)

Severity, likelihood and scope, including biases and security vulnerabilities

c)

Only severity

d)

Only the cost of mitigation

41.

Which mechanism is explicitly required in Measure?

a)

One-time testing only

b)

Mechanisms to continuously track identified AI risks and gather feedback on measurement efficacy

c)

Only executive sign-off

d)

Only vendor attestations

42.

Manage phase objective: What is the primary aim of “Manage” in NIST AI RMF?

a)

Increase inference speed

b)

Prioritise and act on risks identified and measured during assessment

c)

Replace stakeholder engagement

d)

Prevent any need for documentation

43.

Risk response options: Which set are explicitly listed as possible risk response approaches in Manage?

a)

Ignore, delay, deny, deflect

b)

Mitigate, transfer, avoid, accept

c)

Outsource, automate, monetise, rebrand

d)

Predict, classify, generate, retrieve

44.

Controls and interventions in Manage: Which is a Manage activity?

a)

Implement security controls, safeguards and interventions to reduce risk

b)

Remove all guardrails to improve user experience

c)

Stop monitoring to avoid false alarms

d)

Rely solely on user goodwill

45.

Continuous improvement expectation. Which statement is consistent with Manage?

a)

Governance ends at launch

b)

Regularly monitor system behaviour, update controls as needed, and establish continuous improvement plans

c)

Only measure risk, do not act

d)

Only act on risks once per year

46.

When to perform a use case assessment. Which option is correct?

a)

Only after deployment

b)

Before implementation, early in the life cycle, for new initiatives, throughout the life cycle, and for regulatory compliance

c)

Only for low-risk use cases

d)

Only when a regulator asks

47.

Healthcare image analysis: why assess early. In the medical imaging example, why is a use case assessment needed during the design phase?

a)

To select a marketing slogan

b)

To map risks like life-critical false positives/negatives, bias due to lack of diverse training data, data security, and the need for human oversight

c)

To avoid any testing

d)

To prevent radiologists from reviewing results

48.

Third-party sentiment tool: key evaluation focus Before integrating a third-party sentiment tool, what should a use case assessment evaluate?

a)

Only the vendor’s sales references

b)

Vendor AI governance practices, transparency, performance on relevant data, and compliance with internal policies and external regulations

c)

Only the cloud region location

d)

Only whether the tool is popular on social media

49.

Bank chatbot: the “best solution” test In the customer service chatbot example, what is a key reason to assess before committing resources?

a)

To ensure the chatbot replaces all human staff

b)

To assess whether a chatbot is the best solution versus alternatives, and to identify risks like misinterpreting intent, incorrect information, privacy concerns, and workforce impacts

c)

To avoid defining scope and capabilities

d)

To skip risk management because it is routine enquiries