Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Page 1

Total questions: 54

Worksheet time: 27mins

Name
Class
Date
1.

Readiness and release into production — Purpose of a readiness assessment: A readiness assessment is best understood as:

a)

A final performance benchmark

b)

A structured determination of whether the AI system is safe, compliant and suitable for production use

c)

A marketing approval step

d)

A replacement for testing

2.

Readiness and release into production — Readiness assessment scope: Which question is least appropriate for a readiness assessment?

a)

Does the system achieve its intended goal?

b)

Were all required tests completed successfully?

c)

Has conformity been verified?

d)

Will the model improve revenue projections?

3.

Readiness and release into production — Data quality as a release gate: Why is data quality explicitly included in readiness assessments?

a)

Data quality only affects speed

b)

Poor data quality can undermine performance, fairness and reliability even if testing appears successful

c)

Data quality is only a privacy issue

d)

Data quality is fixed at training

4.

Model card timing: Why must the model card exist before release?

a)

It is only for regulators

b)

It consolidates purpose, limits, risks and intended use needed for deployers, users and audits

c)

It replaces technical documentation

d)

It is optional unless required by law

5.

Conformity verification: What does "satisfying conformity requirements" most directly mean?

a)

The model is accurate

b)

The system meets applicable legal, regulatory and internal governance requirements for its risk class

c)

The vendor approved deployment

d)

The system passed a pilot

6.

Periodic assessment purpose: Why does the module emphasise periodic assessments rather than one-time reviews?

a)

Models never change

b)

AI behaviour, data and usage contexts evolve after deployment

c)

Audits are required monthly

d)

Periodic reviews reduce documentation

7.

Performance assessment focus. A performance assessment primarily answers:

a)

Is the model explainable?

b)

Does the system achieve its intended purpose using defined metrics?

c)

Is the system secure?

d)

Is the data lawful?

8.

Reliability assessment focus. Reliability assessments focus on whether the system:

a)

Is accurate at launch

b)

Performs consistently and robustly over time and under real-world conditions

c)

Is fair by design

d)

Meets privacy obligations

9.

Safety assessment focus. Safety assessments primarily evaluate:

a)

UI usability

b)

Whether the system can cause harm and how operational context affects that risk

c)

Licensing compliance

d)

Vendor pricing

10.

User feedback as an input Why is user feedback included in performance and reliability assessments?

a)

It replaces metrics

b)

Users can surface real-world failure modes not visible in controlled testing

c)

It is required by all AI laws

d)

It guarantees fairness

11.

Red teaming definition Red teaming is best described as:

a)

A marketing exercise

b)

Simulating adversarial attacks to expose vulnerabilities, biases and misinformation risks

c)

Accuracy testing only

d)

Legal review

12.

Governance value of red teaming Why is red teaming especially valuable before public release?

a)

It improves brand perception

b)

It identifies vulnerabilities that conventional testing may not reveal

c)

It eliminates the need for audits

d)

It guarantees compliance

13.

A challenger model is used to:

a)

Replace the champion immediately

b)

Compare against the champion to detect drift, regressions or unexpected behaviours

c)

Increase compute efficiency

d)

Avoid documentation

14.

Stress tests are most useful for:

a)

Measuring average performance

b)

Evaluating behaviour under extreme or unexpected conditions

c)

Reducing bias

d)

Meeting transparency obligations

15.

Threat modeling contributes to governance by:

a)

Predicting future profits

b)

Systematically identifying and communicating security risks and attack paths

c)

Replacing incident response

d)

Eliminating adversarial risk

16.

Automation bias risk: What is automation bias in this context?

a)

Bias in training data

b)

Over-reliance on AI outputs because users assume machines are always correct

c)

Bias against automation

d)

Security vulnerability

17.

Governance response to automation bias: Which control best mitigates automation bias?

a)

Disable human oversight

b)

Require human interpretation, review and challenge of outputs

c)

Increase model autonomy

d)

Remove metrics

18.

Anticipating unintended harms: Which method best helps anticipate unintended outputs?

a)

Accuracy testing only

b)

Challenger models and scenario-based analysis

c)

Vendor assurances

d)

UI disclaimers

19.

Why does the module warn about misuse reflection becoming a “roadmap”?

a)

It reduces transparency

b)

Overly detailed misuse analysis can unintentionally guide malicious actors

c)

It violates IP law

d)

It replaces threat modeling

20.

Monitoring is fundamentally about:

a)

Improving UI

b)

Tracking whether the system continues to meet documented purpose and risk assumptions

c)

Reducing documentation

d)

Increasing speed

21.

Which is not listed as a monitoring signal?

a)

Deviations in accuracy

b)

Irregular decisions

c)

Data drift

d)

Marketing engagement metrics

22.

AI system inventory: Why maintain an inventory of AI systems with risk scores?

a)

To reduce audits

b)

To allocate monitoring, review frequency and audit resources proportionally

c)

To eliminate third-party tools

d)

To centralise marketing

23.

Snapshot practice: Why keep snapshots of models and outputs?

a)

For debugging only

b)

To compare versions, identify what changed and support incident analysis

c)

To avoid retraining

d)

To comply with IP law

24.

Purpose drift detection: Why is “new purpose use” a predictable risk?

a)

Users never repurpose tools

b)

AI systems are often applied beyond original scope, invalidating prior risk assessments

c)

Laws prohibit new uses

d)

Purpose drift improves safety

25.

Incident response and issue management — Incident treatment principle: How should AI issues be treated according to the module?

a)

Case-by-case discretion

b)

As incidents, using the organisation’s incident response plan

c)

Only if harm occurs

d)

Only if regulators ask

26.

Incident response and issue management — First step when AI underperforms: When AI performance deviates significantly, the first step should be:

a)

Retrain immediately

b)

Treat it as an incident and invoke the response plan

c)

Ignore until next audit

d)

Disable monitoring

27.

Incident response and issue management — Incident documentation requirement: What must be documented during AI incidents?

a)

Only technical logs

b)

Issue identification, mitigation actions, and communications

c)

Only user complaints

d)

Only vendor responses

28.

Incident response and issue management — AI registrar purpose: Why keep incident information in an AI registrar?

a)

To enable traceability, accountability, and audits

b)

To reduce data storage costs by archiving quickly

c)

To market the AI system to potential customers

d)

To avoid any need for regulatory reporting

29.

Incident root causes — Which set best matches listed reasons incidents may occur?

a)

Vendor failure only

b)

Brittleness, lack of robustness, poor data quality, insufficient testing, model or data drift

c)

UI design errors

d)

User negligence only

30.

Third-party notification — Why must third-party tool users sometimes be notified during incidents?

a)

Courtesy only

b)

Incidents can propagate across integrated systems, affecting partners and internal users

c)

Contracts always require it

d)

To shift liability

31.

Third-party dependency risk — What governance risk arises from integrated third-party tools?

a)

Reduced transparency

b)

Incident impact may extend beyond the primary system

32.

Remote shutdown requirement: Why should humans be able to shut down an AI remotely?

a)

Convenience

b)

Rapid containment of harmful behaviour without physical access

c)

Performance optimisation

d)

Legal symbolism

33.

Threshold disclosure requirement: What disclosure is common across almost all AI laws?

a)

Source code publication

b)

Disclosure that AI is being used or influencing decisions

c)

Full training data lists

d)

Algorithm accuracy

34.

“One notice fits all” fallacy: Why is there no single disclosure that satisfies all transparency obligations?

a)

Laws conflict

b)

Different contexts (finance, health, employment) impose additional, specific notice requirements

c)

Disclosures are optional

d)

AI systems are too complex

35.

Provider–deployer disclosure chain: Under regimes like the EU AI Act, what is required between providers and deployers?

a)

One-time notice

b)

Bidirectional information flow about incidents, monitoring and use context

c)

No communication

d)

Marketing alignment

36.

Disclosure purpose: Why are disclosures tied to appeal and redress rights?

a)

For UX consistency

b)

Users must know AI is involved to exercise legal rights effectively

c)

To reduce litigation

d)

To improve accuracy

37.

Timing of disclosures: Why does timing matter in communications?

a)

Earlier is always better

b)

Users need information when it is relevant to decision-making and risk

c)

Timing is irrelevant

d)

Only regulators care

38.

Risk-level communication: How should communication vary by risk level?

a)

All disclosures identical

b)

Higher-risk systems require more detailed, proactive communication

39.

Why are audits and assessments considered accountability mechanisms?

a)

They replace regulation

b)

They provide evidence that controls exist and function

c)

They guarantee no harm

d)

They reduce cost

40.

Why does audit scope vary by system?

a)

Auditor preference

b)

Risk level, sector, use case and legal requirements differ

c)

All audits are identical

d)

Cost considerations only

41.

Why are AI audits challenging today?

a)

No tools exist

b)

Widely adopted precedents are still emerging

c)

Audits are banned

d)

Models cannot be tested

42.

Why is human review still required even with automation?

a)

Automation is illegal

b)

Humans must validate, challenge and override machine outputs where harm is possible

c)

Machines cannot log actions

d)

Reviews eliminate bias

43.

Deactivation policy purpose Why must organisations have deactivation or localisation policies?

a)

For convenience

b)

Regulatory changes or performance issues may require rapid restriction or withdrawal

c)

To reduce compute

d)

To meet marketing goals

44.

Localisation scenario Which situation best justifies localisation?

a)

UI translation

b)

Jurisdiction-specific legal requirements limiting use or data flows

c)

Latency optimisation

d)

Cost reduction

45.

Graceful shutdown Why emphasise “graceful” shutdown?

a)

For aesthetics

b)

To prevent cascading failures, data loss or safety incidents

c)

To improve performance

d)

To meet IP obligations

46.

Why must governance professionals collaborate with technologists during monitoring?

a)

Technologists own compliance

b)

Root causes of incidents often involve technical brittleness, data issues or drift

c)

Lawyers cannot understand models

d)

Monitoring is purely legal

47.

Which is not a typical root cause listed?

a)

Brittleness

b)

Lack of robustness

c)

Insufficient testing

d)

Strong governance

48.

Why is learning from incidents critical?

a)

To assign blame

b)

To improve system design, monitoring and future risk mitigation

c)

To justify shutdown

d)

To avoid transparency

49.

End-to-end governance logic: Which statement best captures Module 7 Part 2?

a)

Deployment ends governance

b)

Release is a transition point into continuous oversight, not the end of responsibility

c)

Monitoring replaces planning

d)

Transparency is optional

50.

Predictable vs emergent risks: Why distinguish predictable from emergent risks?

a)

To reduce testing

b)

Predictable risks can be mitigated in advance; emergent risks require monitoring and response capacity

c)

To limit documentation

d)

To shift liability

51.

False sense of safety: What creates a “false sense of safety” per the module?

a)

Too much testing

b)

One-time evaluations without continuous monitoring

c)

Excessive documentation

d)

User feedback

52.

Communication failure risk: What is the main risk of poor communication about AI updates?

a)

Delayed model training schedules

b)

Misaligned stakeholders leading to unsafe or incorrect system behavior

c)

Reduced compute costs

d)

Automatic compliance with all policies

53.

Documentation as mitigation: Why does documentation mitigate predictable risks?

a)

It replaces testing

b)

It clarifies purpose, changes and assumptions, enabling detection of misuse and drift

c)

It improves compute

d)

It reduces bias automatically

54.

Exam-level takeaway: Which statement best reflects AIGP expectations for release and post-deployment governance?

a)

Deploy fast, fix later

b)

Continuous monitoring, accountability, transparency and readiness to intervene are core obligations

c)

Governance ends at launch

d)

Incidents are unavoidable