Free IAPP AI Governance Professional (AIGP) practice — 6 questions on AI Laws, Regulations, and Standards, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 5: AI Laws, Regulations, and Standards
A multinational pharmaceutical company is deploying an AI system to analyze patient data across facilities in the EU, US, and Japan. The system will process health records to predict treatment outcomes. Under the EU AI Act's risk classification system, how should this AI system be categorized, and what is the primary compliance obligation that differs from lower-risk categories?
Healthcare AI systems used for treatment decisions fall under Annex III of the EU AI Act as high-risk systems. High-risk systems require mandatory conformity assessment (either internal control or third-party notified body assessment), CE marking, registration in the EU database, human oversight mechanisms, and ongoing post-market monitoring—obligations not required for lower-risk categories.
Question 2 of 6 · Domain 5: AI Laws, Regulations, and Standards
A financial services firm operating under both GDPR and the NIST AI Risk Management Framework is implementing an AI-based credit scoring system. During a regulatory audit, auditors request documentation demonstrating how the system handles concept drift. Which specific artifacts would BEST demonstrate compliance with both frameworks' requirements for ongoing system validity?
Concept drift monitoring requires continuous evidence of model performance tracking over time. NIST AI RMF's 'Manage' function requires ongoing monitoring and GDPR Article 22 requirements for automated decision-making demand accuracy maintenance. Retraining schedules, drift detection, and version control demonstrate systematic approaches to maintaining model validity as data distributions change—a critical technical and compliance requirement.
Question 3 of 6 · Domain 5: AI Laws, Regulations, and Standards
An AI vendor is preparing to sell a facial recognition system to law enforcement agencies in multiple jurisdictions. The system will be used to match suspects against criminal databases. Which combination of regulatory frameworks creates the MOST restrictive deployment constraints that the vendor must navigate?
EU AI Act Article 5 prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions), creating hard deployment barriers. The US Algorithmic Accountability Act (proposed/enacted in some jurisdictions) requires impact assessments for high-risk systems. This combination creates both prohibition risks and mandatory disclosure requirements—the most restrictive scenario presented.
Question 4 of 6 · Domain 5: AI Laws, Regulations, and Standards
A global retailer is implementing an AI system to automate hiring decisions across its European and Canadian operations. The system analyzes video interviews using emotion recognition technology. Under current Canadian AI regulations (AIDA - Artificial Intelligence and Data Act) and EU AI Act, what is the KEY compliance difference the company must address?
EU AI Act explicitly lists recruitment and worker management as high-risk (Annex III), triggering mandatory conformity assessment. Canada's AIDA takes a harm-based approach, requiring impact assessments when systems could cause 'material harm'—focusing on outcomes rather than sectoral categorization. This fundamental difference in risk classification methodology is the key compliance distinction organizations must navigate.
Question 5 of 6 · Domain 5: AI Laws, Regulations, and Standards
An insurance company using AI to detect fraudulent claims discovers that its model disproportionately flags claims from a protected demographic group. Under the US Equal Credit Opportunity Act (ECOA) as interpreted for AI systems and the EU Non-Discrimination Directive, what is the company's BEST defense strategy if challenged by regulators?
Under disparate impact legal theory applicable to both US and EU anti-discrimination law, statistical proof of discrimination shifts burden to the organization to show business necessity AND that no less discriminatory alternative exists. Comprehensive documentation of testing, mitigation efforts, exclusion of protected variables, and alternative exploration demonstrates due diligence and good faith compliance—the strongest legal defense position.
Question 6 of 6 · Domain 5: AI Laws, Regulations, and Standards
A healthcare AI company receives a Subject Access Request (SAR) under GDPR Article 15 from a patient whose cancer diagnosis recommendation was generated by an AI diagnostic system. The patient requests 'meaningful information about the logic involved' in the AI decision. Which response BEST satisfies the legal obligation while protecting legitimate trade secrets?
GDPR Article 15(1)(h) and Recital 71 require 'meaningful information about the logic involved' in automated decisions—but this does not mean full algorithmic disclosure. Case law and regulatory guidance establish that patient-specific explanations (feature importance, confidence, model type, validation) satisfy transparency while protecting IP. This balances individual rights with commercial interests, which is the legally correct approach.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
$109.99$34.99 with code FREETEST33 — valid through August 22.