wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 6 Part 1

Total questions: 45

Worksheet time: 23mins

Name
Class
Date
1.

AI life cycle and planning fundamentals — Life cycle ordering: Which ordering best reflects the iterative AI development life cycle described?

a)

Deployment → Testing → Monitoring → Data prep → Decommissioning

b)

Planning/design → Data collection/preparation → Model development → Testing/evaluation → Deployment → Monitoring/maintenance → Decommissioning

c)

Data prep → Planning/design → Deployment → Testing → Monitoring

d)

Planning/design → Deployment → Data prep → Model development → Decommissioning

2.

AI life cycle and planning fundamentals — “Planning is critical” rationale: Why does the module treat planning and design as a critical step?

a)

It is where the model weights are set

b)

It defines objectives, evaluates use cases and data, and establishes governance structures before building decisions become costly

c)

It is required only for high-risk AI

d)

It replaces monitoring and maintenance

3.

AI life cycle and planning fundamentals — Business context definition: Which statement best matches “define the business context and use case”?

a)

Choose the best-performing model on a benchmark

b)

Specify the mission goal, what decision/output is needed, who is affected, and whether AI is suitable for that purpose

c)

Start collecting as much data as possible

d)

Write the privacy policy first

4.

AI life cycle and planning fundamentals — Suitability decision: Which governance step most directly addresses “should we use AI at all”?

a)

Benchmarking

b)

Use case evaluation

c)

Harms matrix

d)

Pre-deployment pilot

5.

AI life cycle and planning fundamentals — Requirements gathering trap: Which choice is most likely to be a governance failure during requirements gathering?

a)

Documenting trade-offs between privacy and accuracy

b)

Defining success metrics and thresholds

c)

Starting model training before agreeing on goals, risk tolerance and oversight ownership

d)

Identifying sector-specific compliance requirements

6.

Stakeholder engagement and accountability — Timing of stakeholder engagement: The module’s stakeholder guidance implies stakeholder engagement should occur:

a)

Only at deployment

b)

After model selection, before pilots

c)

Early and continuously through the life cycle

d)

Only after an incident

7.

Stakeholder engagement and accountability — Stakeholder group’s first job: What is the most defensible “first output” of a stakeholder group?

a)

A list of model vendors

b)

Agreement on the goal and whether AI is suitable for the mission/purpose

c)

A pilot schedule

d)

A marketing plan

8.

Stakeholder engagement and accountability — Accountability assignment: Why does the stakeholder group need to establish who is ultimately responsible for risks and mitigations?

a)

To reduce cost

b)

To clarify accountability for failures and risk acceptance before implementation

c)

Because regulators require a single person be blamed

d)

Because models cannot be audited

9.

Stakeholder engagement and accountability — Stakeholder membership: Which stakeholder set best matches the module’s examples of common stakeholders?

a)

Only engineers and data scientists

b)

AI governance officers, privacy experts, security experts, procurement, subject matter experts and legal

c)

Only legal and marketing

d)

Only leadership and HR

10.

Operational controls and “who owns what” — Sector-specific compliance cue: The module uses HIPAA as an example of what practice?

a)

Benchmarking

b)

Sector-specific compliance evaluation tied to training data and system use

c)

Vendor certification

d)

Kill switch ownership

11.

Stakeholder engagement and accountability — Meeting frequency purpose: Why does the module suggest deciding how frequently the stakeholder group meets?

a)

To satisfy procurement

b)

To continuously evaluate progress toward goals and surface risks early

c)

To finalise model architecture

d)

To reduce documentation needs

12.

Stakeholder engagement and accountability — Competing values scenario: The guidance says there may not be “one perfect answer” when values compete (for example accuracy vs privacy). What is the best governance expectation?

a)

Always prioritise privacy

b)

Always prioritise accuracy

c)

Decide priorities explicitly, obtain stakeholder agreement, and document the trade-off decision

d)

Let engineering decide silently

13.

Operational controls and “who owns what” — Stakeholder input and governance framework alignment: Why must stakeholders who wrote general governance policies also advise on specific AI systems?

a)

They are legally required to do so

b)

To ensure the project aligns with established governance frameworks and organisational objectives

c)

Because they own model development

d)

Because audits are optional

14.

Operational controls and “who owns what” — Operational controls scope: Which list best represents the operational control ownership decisions the module highlights?

a)

Model selection, feature engineering, dataset labelling

b)

Real-time operational responsibility, audits/reviews, feedback/appeals, escalation, kill switch ownership

c)

Marketing claims, pricing, branding

d)

Data retention schedules only

15.

Operational controls and “who owns what” — Kill switch ownership: Why is “own the kill switch” an explicit governance decision?

a)

Because kill switches improve accuracy

b)

Because someone must have authority to stop or suspend the system

16.

Appeals mechanism relevance: Why do feedback and appeals mechanisms matter in planning/design?

a)

They are only for customer support

b)

They operationalise accountability by enabling challenge and remediation of harmful outcomes

c)

They replace benchmarking

d)

They eliminate legal risk

17.

Escalation criteria: What is the strongest reason to define how issues are elevated in emergent or emergency situations?

a)

It improves system speed

b)

It reduces ambiguity and delays when rapid action is needed to prevent harm

c)

It increases training data availability

d)

It eliminates privacy requirements

18.

Impact assessments: AIA vs PIA vs DPIA — Impact assessment definition: In this module, an impact assessment is best described as:

a)

A marketing review

b)

A lifecycle risk management tool assessing benefits, risks and limitations

c)

A model benchmark score

d)

A procurement checklist

19.

Algorithmic impact assessment content: Which item is most appropriate within an algorithmic impact assessment based on the module?

a)

Only model accuracy

b)

Data issues, stakeholder decisions, risk identification/mitigation, and who approves or accepts risk

c)

Only privacy notices

d)

Only vendor pricing

20.

Using existing processes: What does the module recommend regarding PIAs/DPIAs?

a)

Avoid them because they are not AI-specific

b)

Use them where possible as a starting point, but identify gaps for a comprehensive algorithmic impact assessment

c)

Replace them entirely with benchmarking

d)

Use a PIA only and skip DPIAs

21.

DPIA vs PIA difference: Which distinction best matches the module’s descriptions?

a)

DPIA is about financial risk; PIA is about model risk

b)

DPIA focuses on risks from processing personal data; PIA analyses how PII is handled and privacy compliance

c)

DPIA is only for government; PIA is only for private sector

d)

DPIA is optional under privacy law; PIA is mandatory

22.

Limitation of relying solely on PIA/DPIA: The module’s stated limitation of relying only on a PIA or DPIA is that:

a)

They are illegal for AI

b)

They are not tailored specifically for AI applications and may miss AI-specific governance requirements

c)

They are too expensive

d)

They cover too much

23.

Training data assessment nuance: The module suggests considering a PIA on underlying training data. Why?

a)

Training data is never personal data

b)

Training data processing can create privacy risks and must be evaluated independently of deployment processing

c)

It replaces data minimisation

d)

It is only relevant for benchmarking

24.

Gap identification: When adapting PIAs/DPIAs into an algorithmic impact assessment, what is the key governance task?

a)

Remove all privacy sections

b)

Identify gaps between existing templates and AI project needs (such as human oversight, model limits, monitoring and appeal paths)

c)

Add marketing messaging

d)

Focus only on data retention

25.

Risk assessment strategies (order matters) — Sequence test: Which sequence matches the module’s recommended order of risk assessment strategies?

a)

Harms matrix → benchmarking → stakeholder mapping → pilots → mitigation hierarchy

b)

Use case evaluation → stakeholder mapping → probability/severity harms matrix → risk mitigation hierarchy → benchmarking → pre-deployment pilots

c)

Stakeholder mapping → pilots → benchmarking → mitigation hierarchy → harms matrix

d)

Benchmarking → use case evaluation → harms matrix → stakeholder mapping → pilots

26.

Use case evaluation goal: Use case evaluation is primarily intended to:

a)

Decide whether the model should be open source

b)

Determine whether AI is warranted and what type of model suits the need, while flagging risks

c)

Assign kill switch ownership

d)

Replace stakeholder mapping

27.

Stakeholder mapping purpose: Stakeholder mapping is best described as:

a)

A technical test

b)

A project management step ensuring correct decision-makers are involved and communication channels exist

c)

A compliance filing

d)

A pilot environment configuration

28.

Harms matrix calculation logic: What does the probability/severity harms matrix do?

a)

Adds probability to severity

b)

Multiplies probability score by severity score to rate risk

c)

Chooses benchmarks

d)

Assigns stakeholders

29.

Matrix misuse trap: Which is the most defensible critique of a harms matrix used alone?

a)

It is too technical

b)

It identifies and ranks risk but does not specify what to do next

c)

It is illegal

d)

It replaces stakeholder mapping

30.

Mitigation hierarchy role: Why is the risk mitigation hierarchy described as the “now what” portion?

a)

It generates benchmark scores

b)

It provides structured options: avoid, minimise, remediate and offset impacts

c)

It assigns compliance budgets

d)

It replaces DPIAs

31.

Avoid vs minimise: Which option best reflects "avoid" in a mitigation hierarchy?

a)

Improve accuracy

b)

Remove or redesign the use case so the risk no longer exists

c)

Provide user notice

d)

Buy insurance

32.

Benchmarking purpose: Why is benchmarking especially useful for less transparent models?

a)

It reveals source code

b)

It provides standardised comparative testing to evaluate performance characteristics when interpretability is limited

c)

It replaces pilots

d)

It guarantees fairness

33.

Benchmark choice: Which benchmarking approach best matches the module?

a)

Only speed testing

b)

Standardised tests for accuracy, speed and complex task handling, including targeted evaluation such as language understanding for LLMs

c)

Only privacy testing

d)

Only usability testing

34.

Pre-deployment pilot definition: A pre-deployment pilot is best defined as:

a)

A post-incident review

b)

A trial phase before go-live, ideally matching production conditions closely, used to confirm behaviour and update before deployment

c)

A legal audit

d)

A marketing beta

35.

Pilot environment trap: Why does the module emphasise pilots matching production conditions as closely as possible?

a)

It increases marketing value

b)

It reduces the risk that the system behaves differently under real constraints, distributions, and operational pressures

c)

It removes privacy obligations

d)

It makes benchmarking unnecessary

36.

Documentation purpose: Why does the module emphasise documenting design and build processes?

a)

Documentation is optional but nice

b)

Documentation supports compliance evidence, risk management, and traceability of decisions and trade-offs

c)

Documentation improves model accuracy directly

d)

Documentation replaces governance

37.

Documenting trade-offs: Which trade-off decision is most important to document according to the stakeholder guidance?

a)

Font choice in UI

b)

Competing values trade-off decisions, for example privacy vs accuracy thresholds

c)

Whether to use Python

d)

Employee preferences

38.

Evidence of risk acceptance: Where should "who approved or accepted the risk" most appropriately be recorded?

a)

Only in email

b)

In the algorithmic impact assessment and governance documentation

c)

Only in the code repository

d)

Only in a vendor brochure

39.

Communication audiences: The stakeholder guidance suggests communicating risks and mitigations to different audiences. Why?

a)

Everyone needs the same detail

b)

Different audiences need different formats and levels of detail to act appropriately

c)

Communication increases model performance

d)

Communication removes liability

40.

Compliance vs governance artefacts: Why might a PIA be insufficient as the only governance document for an AI system?

a)

It covers too much technical content

b)

It may not cover operational controls, model behaviour limits, stakeholder trade-offs, and oversight arrangements required for AI governance

c)

It is not recognised legally

d)

It is always optional

41.

Choosing the right method: A team is deciding whether to automate a decision that impacts individuals. Which two methods should be initiated earliest?

a)

Benchmarking and pilots

b)

Use case evaluation and stakeholder mapping

c)

Pilots and harms matrix

d)

Benchmarking and mitigation hierarchy

42.

Harms matrix to mitigation: A harms matrix shows a high-severity, moderate-probability risk. What is the next most appropriate governance step?

a)

Skip mitigation and proceed to deployment

b)

Apply the risk mitigation hierarchy to choose avoidance, minimisation, remediation or offsetting measures

c)

Replace the model vendor

d)

Publish transparency notices

43.

Operational control failure mode: An AI system causes harm and the organisation cannot quickly suspend it because authority is unclear. Which planning control was missed?

a)

Benchmarking selection

b)

Kill switch ownership and escalation processes

c)

Data preparation

d)

Model selection

44.

Governance under uncertainty: A stakeholder group cannot agree whether to prioritise privacy or accuracy. Which response best matches module guidance?

a)

Let engineering decide privately

b)

Escalate to leadership, decide risk tolerance for scenarios, document the decision and revisit periodically

c)

Choose whichever is cheaper

d)

Delay indefinitely

45.

Late-stage validation choice: A black box model performs well internally, but stakeholders worry it may fail in real-world conditions. Which combination best addresses this concern late in design?

a)

Stakeholder mapping and DPIA

b)

Benchmarking and pre-deployment pilots

c)

Use case evaluation and harms matrix

d)

PIA and procurement review