wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Page 1

Total questions: 55

Worksheet time: 28mins

Name
Class
Date
1.

Planning for deployment: core scoping questions “Who developed it?” as a governance trigger An organisation is preparing to deploy an AI system. Why is “Who developed it?” a key planning question?

a)

It determines whether the model can be benchmarked

b)

It affects role-based obligations, visibility into design choices, and the organisation’s liability posture

c)

It decides whether the UI needs a disclaimer

d)

It only impacts cloud costs

2.

Planning for deployment: core scoping questions Customisation scope Which scenario most increases the likelihood that a “deployer” begins to resemble a “provider” from a governance burden perspective?

a)

Using an off-the-shelf model with no changes

b)

Making substantive modifications that change risk profile, behaviour, or intended use of the system

c)

Running the vendor’s model with default settings

d)

Adding a chatbot disclaimer to the UI

3.

Planning for deployment: core scoping questions “Who will use it?” Why does identifying whether users are internal staff or external customers materially change deployment planning?

a)

It changes the colour scheme

b)

It alters risk exposure, transparency expectations, incident impact, and compliance duties (especially for consumer-facing contexts)

4.

Which set of questions best reflects the module’s “planning for deployment” essentials?

a)

GPU brand, marketing copy, competitor roadmap

b)

Who developed it, how customisable it is, and who will use it

c)

The model’s parameter count and training epoch number only

d)

Whether the vendor offers a mobile app

5.

When the module says “review existing policy framework to determine gaps,” what is the main objective?

a)

Replace all policies with AI-specific law

b)

Identify where current privacy, security, data governance and IP policies do not address AI’s distinct risks and lifecycle needs

c)

Reduce the number of policies for simplicity

d)

Avoid procurement reviews

6.

Why does a strong existing data governance framework help with AI deployment governance?

a)

It provides established processes for data quality, lineage, access controls and accountability that can be extended to AI workflows

b)

It eliminates the need for model monitoring and incident response

c)

It guarantees legal compliance without additional controls or documentation

d)

It focuses primarily on storage costs, which are the main governance concern

7.

Security policy updates for AI Which AI-specific security issue most directly motivates updating security policies for AI deployment?

a)

Phishing email volume

b)

Adversarial attacks and ML-specific vulnerabilities that can distort outputs or exfiltrate sensitive information

c)

Password rotation rules

d)

Printer firmware updates

8.

Intellectual property policy gaps Which is the most AI-relevant reason to update IP policies before deployment?

a)

IP only matters for patents

b)

AI outputs and proprietary algorithms raise questions of ownership, reuse rights and licensing constraints

c)

IP policies apply only to open source code

d)

IP is irrelevant to deployment

9.

Engineering/model ops policy purpose: Which outcome is an engineering or model ops policy most aimed at for AI deployment?

a)

Determining lawful basis for processing

b)

Establishing lifecycle best practices, release controls, monitoring, retraining triggers and rollback procedures

c)

Creating marketing claims

d)

Setting employee leave entitlements

10.

Open source and platform policies: Why does the module suggest open source and platform policies (for example AWS or Model Garden)?

a)

Platforms remove compliance risk

b)

Organisations need explicit positions on acceptable platforms and models, including risk acceptance, provenance expectations and integration constraints

c)

Open source models are always safer

d)

Platform choice never affects governance

11.

Key principles for adapting policies — Risk-centric approach rationale: Why does the module advocate a risk-centric approach to policy adaptation?

a)

It ensures the fastest deployment

b)

Organisations have limited resources, so governance effort should focus on the highest-risk deployments and harm potential

c)

It reduces need for security testing

d)

It ensures all systems are treated equally

12.

Cutting-edge intent meaning: What does “evaluate cutting-edge intent” practically require from an organisation?

a)

Always adopt frontier models

b)

Decide how far to push advanced AI while explicitly managing privacy/security trade-offs and formal risk acceptance

c)

Avoid any automation

d)

Treat vendor assurances as sufficient

13.

Holistic integration of policies: What does it mean to integrate AI governance policies “holistically”?

a)

Write separate policies for each team with no overlap

b)

Align AI governance with existing processes so policies apply across laws, industries and technologies where feasible

c)

Use a single policy for everything without exceptions

d)

Focus only on privacy policies

14.

Procurement explicitness: Why must procurement of external AI models be explicitly addressed within governance policies?

a)

Procurement teams do not need guidance

b)

Third-party AI introduces distinct risks and contractual dependencies that require screening, ongoing monitoring and acceptable use controls

15.

Cloud-based deployment advantage Which is the best governance-relevant advantage of cloud-based deployment as described?

a)

It eliminates third-party risk

b)

It scales easily and reduces upfront hardware investment, which can enable controlled experimentation and resource elasticity

c)

It guarantees low latency

d)

It ensures data never leaves the organisation

16.

Cloud-based deployment disadvantage Which is the most accurate disadvantage for cloud-based deployments in the module?

a)

Cannot monitor models

b)

Potential latency and added security risks because a third party handles infrastructure and potentially sensitive data flows

c)

Requires no contracts

d)

Only works for edge devices

17.

Why might on-premise deployment be preferred for sensitive data or regulated sectors?

a)

It always improves model accuracy

b)

It offers greater control over infrastructure and data handling, supporting stricter governance and compliance requirements

c)

It eliminates the need for audits

d)

It makes models explainable

18.

Which disadvantage of on-premise deployment is most consistent with the module?

a)

It cannot be monitored

b)

It typically demands higher upfront hardware investment and internal expertise to operate safely

c)

It is illegal

d)

It prevents fine-tuning

19.

Which is the most plausible governance-oriented advantage of edge deployment?

a)

Unlimited compute

b)

Reduced latency and improved privacy because data can remain on-device

c)

Centralised control is stronger

d)

Model behaviour never changes

20.

What is the key constraint for edge deployment in the module?

a)

The model cannot be audited

b)

Edge devices may have limited hardware, constraining computational power and therefore model choice and performance

c)

Edge always increases latency

d)

Edge eliminates the need for policies

21.

Why does choosing between “as-is,” fine-tuning, RAG, and agentic architectures matter for governance?

a)

Only changes UI design

b)

These approaches change system behaviour, data exposure, control points and failure modes, altering assurance needs

c)

Only impacts marketing strategy

d)

Does not affect risk

22.

Which governance difference is most important between using a model “as-is” versus fine-tuning?

a)

Fine-tuning always decreases risk

b)

Fine-tuning can increase obligations by materially altering behaviour, requiring new testing, documentation and potentially different compliance classification

c)

As-is models require no monitoring

d)

As-is models cannot be used externally

23.

RAG-specific risk lens Which risk is particularly relevant to Retrieval Augmented Generation (RAG) in deployment planning?

a)

Only GPU overheating

b)

Data access control, leakage of retrieved content, and provenance/accuracy of retrieved sources influencing outputs

c)

Eliminating need for knowledge bases

d)

Guaranteed factual accuracy

24.

Agentic architectures: distinct requirements Defining feature of agentic systems Which statement best reflects the module’s definition of agentic AI systems?

a)

They only classify images

b)

They actively interact with and influence digital environments through multi-step actions rather than remaining passive

c)

They cannot be monitored

d)

They are identical to static chatbots

25.

Infrastructure requirements for agentic AI Which infrastructure requirement is highlighted as particularly important for agentic AI?

a)

Only serverless compute

b)

Support for autonomy, long-term memory and multi-step actions

c)

No need for logging

d)

No need for access controls

26.

Risk model requirements for agentic AI: Which set of risk controls best aligns with the module’s agentic risk model discussion?

a)

One-time assessment only

b)

Real-time monitoring, audit trails, explainability, human-in-the-loop and override mechanisms, accounting for emergent behaviour

c)

Only privacy notices

d)

Only encryption at rest

27.

Managing emergent behaviours: Why are behavioural simulations and scenario-based risk modelling recommended for agentic AI?

a)

They replace human oversight

b)

Agentic systems can produce unexpected multi-step outcomes, so simulations stress-test behaviours not captured in simple unit tests

c)

They guarantee legal compliance

d)

They remove the need for audit trails

28.

MAESTRO reference purpose: The module references multi-agent risk frameworks (for example MAESTRO). What is the governance intent of such frameworks?

a)

Increasing token limits

b)

Structuring risk assessment and controls for interacting autonomous agents across complex environments

29.

Three-tier guardrails for agentic AI. Which mapping of guardrails tiers is correct?

a)

Tier 1: societal; Tier 2: foundational; Tier 3: risk-based

b)

Tier 1: foundational; Tier 2: risk-based; Tier 3: societal

c)

Tier 1: legal only; Tier 2: marketing; Tier 3: finance

d)

Tier 1: none; Tier 2: minimal; Tier 3: optional

30.

Best practice: constrain action space. Why does “constraining the action space and requiring human approval” matter for agentic safety?

a)

It makes models smaller

b)

It reduces the set of possible harmful actions and introduces friction for high-impact steps, improving controllability

c)

It eliminates the need for monitoring

d)

It guarantees fairness

31.

Best practice: least disruptive defaults. What is the governance rationale for “default behaviours the least disruptive”?

a)

It improves latency

b)

Defaults act as the baseline when uncertainty occurs, so conservative behaviours reduce harm in ambiguous situations

32.

Why is “reliable attribution of agent actions” critical?

a)

It increases model creativity

b)

It supports accountability, incident investigation, auditability and appropriate remediation when actions cause harm

c)

It reduces compute

d)

It prevents all errors

33.

What does “interruptibility (graceful shutdown)” primarily address?

a)

Higher throughput

b)

The ability to stop or contain unsafe agent behaviour without causing uncontrolled failures or data corruption

c)

Better personalisation

d)

Faster fine-tuning

34.

Why does deploying a proprietary model increase obligations and potential liability?

a)

Proprietary models are always high-risk by law

b)

The organisation is both building the technology and using it operationally, increasing responsibility across design, testing, monitoring

35.

Proprietary model opportunity: data transparency. Which opportunity is most directly linked to proprietary model ownership?

a)

Avoiding monitoring

b)

Better transparency about training data origin and provenance because the organisation can source and document it

c)

Eliminating all copyright risk

d)

Removing need for assessments

36.

Proprietary model opportunity: governance reporting. Why might governance reporting be easier with proprietary models?

a)

Reports can be ignored

b)

Ownership can provide access to documentation, test results and design rationale needed for regulatory and internal reporting

c)

Reporting is not required

d)

External vendors prohibit reporting

37.

Proprietary model security posture claim. The module notes proprietary models may be less susceptible to some open source and third-party issues. What is the best interpretation?

a)

Proprietary models cannot be attacked

b)

Controlling the supply chain can reduce provenance and dependency risks

38.

Purpose fit advantage: Why can proprietary models offer better "purpose fit"?

a)

They always outperform frontier models

b)

They can be built for exact requirements rather than retrofitting generic third-party models, improving alignment to constraints and controls

c)

They avoid documentation

d)

They remove need for human oversight

39.

Third-party AI products: contexts and risk management — Two common third-party contexts: Which pair best matches the module’s "two contexts" for third-party AI products?

a)

Research use and personal use

b)

Integration into business operations and employee tool use

c)

Public sector and private sector

d)

Open source and proprietary

40.

Visibility problem: Why is third-party risk management "very challenging" according to the transcript?

a)

Limited visibility into vendor architectures, updates, and data handling across the AI supply chain

b)

Guaranteed regulatory violations for any third-party AI use

c)

Absence of documentation in open-source tools prevents auditing

d)

Employee productivity tools have no operational impact

41.

Internal policy alignment for third-party use — What is the core requirement for policies governing third-party AI products?

a)

Vendor policies override internal policies

b)

Internal policies should align with organisational AI governance expectations and explicitly apply to vendor products and services

c)

Policies should be informal

d)

Only procurement needs policies

42.

“Intentional strategy ahead of time” — What is the most accurate interpretation of an “intentional strategy ahead of time” for third-party AI?

a)

Choose the cheapest vendor

b)

Define screening criteria, expand vendor programs for AI-specific risks, and review acceptable use policies before adoption

c)

Test only after an incident

d)

Let employees decide tool usage

43.

Why does integrating vendor AI into business operations generally demand a more comprehensive risk assessment than employee tool use?

a)

Employee tools have no risks

b)

Integration can directly affect products, customers, and core processes, increasing exposure and the consequences of failures

c)

Employee tools are always internal

d)

Integration always uses anonymised data

44.

Employee tools still matter: Why are off-the-shelf employee tools still governance-relevant?

a)

Employees never use outputs externally

b)

Employees may incorporate tool outputs into client-facing or operational work, transferring risks into organisational decisions and communications

c)

Employee tools are exempt from policy

d)

Employee tools cannot process sensitive data

45.

Risks introduced by third-party models — Data lineage and traceability risk: Which is the best example of a data lineage and traceability issue in third-party AI?

a)

The model runs slowly

b)

The vendor cannot clearly explain where training data originated or whether rights and minimisation practices were applied

c)

The UI is outdated

d)

The vendor offers an API

46.

Downstream “take offline” risk — Which scenario best matches the module’s “downstream issue” example requiring a model to be taken offline?

a)

Minor UI bug

b)

A copyright lawsuit or regulatory action tied to the original training data, forcing suspension of the model’s use

c)

A model gets more accurate

d)

A vendor adds documentation

47.

Output ownership and control — Why does model output ownership become a risk with third-party tools?

a)

Ownership is always the customer’s

b)

Licensing terms may assign ownership or reuse rights to the vendor, restrict publication, or allow vendor training on your prompts and outputs

c)

Outputs are never copyrighted

d)

Ownership only matters for images

48.

Data handling and security risks by environment — Why is “development environment” relevant to third-party risk?

a)

It determines UI features

b)

Cloud or vendor-hosted environments change data exposure, access controls and incident response responsibilities

c)

It guarantees bias reduction

d)

It prevents misuse

49.

Which is the most governance-relevant reason that “quality and model performance may not be a good fit for the task” is a risk?

a)

Performance only matters for user satisfaction

b)

Poor fit can create operational errors, unfair outcomes, and compliance failures if the model is applied outside validated scope

c)

Fit can be ignored if the vendor is large

d)

Fit is solved by disclaimers

50.

Why does the module emphasise contracts to manage third-party AI risk?

a)

Contracts guarantee model accuracy

b)

Contracts allocate responsibilities for data handling, incident response, acceptable use, IP/output rights, and evidence provision

c)

Contracts replace internal policy

d)

Contracts are only for pricing

51.

Which is the best explanation for why procurement, supply chain, HR and acceptable use are mentioned explicitly?

a)

They are unrelated to AI

b)

AI deployment risk spans organisational functions: acquisition (procurement), dependencies (supply chain), workforce use (HR), and constraints on usage (acceptable use)

c)

Only HR matters

d)

Only procurement matters

52.

Vendor or licensing agreement: key evaluation areas — Data rights clause scrutiny: Which is the most critical reason to evaluate whether the vendor has legal rights to training data?

a)

It only impacts model speed

b)

Lack of rights can create legal exposure, forced discontinuation, and reputational harm for the deploying organisation

c)

It improves explainability

d)

It reduces compute needs

53.

Minimisation and deidentification in vendor training: Why does asking whether personal data was minimised and deidentified matter?

a)

It is only a technical preference

b)

It signals maturity of privacy engineering and reduces risk of privacy violations and sensitive data leakage in outputs

c)

It guarantees no bias

d)

It makes RAG unnecessary

54.

Security and safety: misuse and high-risk activities: Why does the agreement review ask about potential misuse or use for high-risk activity?

a)

Because high-risk use is always allowed

b)

Models can be repurposed, and governance must anticipate misuse pathways, safety controls, and vendor incident readiness

55.

Terms of use: fine-tuning and IP outputs — Why are "allowed to fine-tune" and "IP and outputs" specifically high-stakes agreement terms?

a)

They only affect pricing

b)

Fine-tuning changes responsibility and may alter risk profile; output terms determine whether you can legally use, publish, or protect generated content

c)

They are irrelevant if the model is accurate

d)

They only matter for internal tools