TechNuggets Academy

AI Governance and Risk

Free Advanced in AI Audit practice — 6 questions on AI Governance and Risk, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · AI Governance and Risk
An auditor is reviewing conformity assessment documentation for a high-risk AI-powered recruitment/CV-screening system (an Annex III use case) placed on the EU market by its provider. No harmonized standards deviation or biometric identification component is involved. Which conformity assessment route did the EU AI Act require the provider to follow?
For most Annex III high-risk AI systems, including employment/recruitment tools, the EU AI Act permits providers to use the internal control procedure under Annex VI (self-assessment against harmonized standards or common specifications), reserving mandatory notified-body assessment (Annex VII) for specific categories such as remote biometric identification systems.
Question 2 of 6 · AI Governance and Risk
During a governance audit, the auditor finds that the organization has no documented statement of acceptable risk levels for its AI portfolio, and business units are each independently deciding what AI risk is 'tolerable' without any enterprise-level benchmark. Under the NIST AI Risk Management Framework, which function's outcomes are most directly deficient?
GOVERN establishes the organizational culture, policies, and structures for AI risk management, including defining and documenting organizational risk tolerance (GOVERN 1.2) so that risk decisions are consistent across the enterprise rather than made ad hoc by individual business units.
Question 3 of 6 · AI Governance and Risk
An organization is preparing for its first ISO/IEC 42001 certification audit of its AI management system (AIMS). Which of the following is a required input to top management's AIMS management review under Clause 9.3?
ISO/IEC 42001 Clause 9.3 mirrors the management review structure of other ISO management system standards, requiring inputs such as the status of actions from prior reviews, changes in internal/external issues, AIMS performance data, audit results, and the status of AI risk assessment and treatment plans.
Question 4 of 6 · AI Governance and Risk
An auditor reviewing AI model risk governance finds that the same data science team that builds and validates its own machine learning models is also solely responsible for approving those models for production deployment, with no independent review by a risk function. This arrangement primarily represents a failure to observe which governance principle?
In a three lines model applied to AI, the model developers constitute the first line, while an independent model risk management or validation function should serve as the second line, reviewing and challenging models before deployment; allowing developers to self-approve collapses this separation and creates a conflict of interest.
Question 5 of 6 · AI Governance and Risk
An organization deploys a voice-assistant AI system that uses subliminal audio techniques beyond a person's conscious perception to materially distort a user's behavior in a manner that causes psychological harm. How must an AI auditor classify this system under the EU AI Act?
Article 5 of the EU AI Act bans AI systems that deploy subliminal, manipulative, or deceptive techniques materially distorting behavior and causing significant harm; this is classified as unacceptable risk, meaning the practice must stop entirely and cannot be remediated through controls, documentation, or conformity assessment.
Question 6 of 6 · AI Governance and Risk
A company integrates a third-party general-purpose AI (GPAI) foundation model classified as having systemic risk into its own high-risk AI product. Under the EU AI Act, which party bears primary responsibility for fulfilling the GPAI systemic-risk obligations, including model evaluation, adversarial testing, and serious incident reporting for that foundation model?
Under the EU AI Act's obligations for general-purpose AI models with systemic risk (Article 55), the upstream GPAI provider is responsible for model-level evaluations, adversarial testing, cybersecurity measures, and reporting serious incidents related to the foundation model itself; the downstream integrator has separate, distinct obligations tied to its own high-risk system.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →