IAPP AIGP Exam Prep
Artificial Intelligence Governance Professional (Page 4 )

Updated On: 7-Sep-2026

CASE STUDY
Please use the following to answer the next question: A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources. The data processed by the AI system would be classified as:

  1. Non-sensitive personal data, since it does not reveal information about health, gender or race.
  2. Organizational data, since it is part of the authentication process.
  3. Non-personal data, as long as it is not linked to a user ID.
  4. Special category data, if it can be used to uniquely identify a person.

Answer(s): D

Explanation:

The correct answer is D, Special category data, if it can be used to uniquely identify a person . Here's why:
While seemingly innocuous, typing biometrics like typing speed, rhythm, and pressure, collected and analyzed by the AI system, create a unique identifier for each user. This data, when processed to establish a "unique user profile," moves beyond general operational data. The ability to uniquely identify an individual is the key factor that elevates this data into a more sensitive category.
Consider the General Data Protection Regulation (GDPR).
While typing biometrics isn't explicitly listed as special category data (formerly sensitive personal data), Article 9 of the GDPR prohibits processing biometric data for the purpose of uniquely identifying a natural person unless certain exemptions apply. The fact that the AI system is designed to uniquely identify users through their typing patterns brings it into the orbit of special category data.
Even in the absence of explicit legislation like GDPR, many privacy laws and frameworks emphasize the heightened protection required for data that can be used for individual identification. This principle is rooted in the potential for misuse, discrimination, or profiling. Once biometric data, like typing patterns, is used to uniquely identify an individual, it carries increased risks of misuse compared to anonymized or aggregated data. The potential for function creep, where the data is used for purposes beyond security authentication, further elevates the risk.
Therefore, classifying the typing biometric data as special category data (contingent on its capacity to uniquely identify) is the most prudent approach, necessitating stronger security measures, enhanced transparency, and explicit user consent for its processing. Options A and C are incorrect because the data's ability to uniquely identify makes it personal and necessitates greater protection than non-sensitive data. Option B is partially correct in that it is part of an organizational authentication process. However, the unique identifiers make it special category data.
Further Research:
GDPR Article 9 (Processing of special categories of personal data): https://gdpr-info.eu/art-9-gdpr/ NIST Special Publication 800-63-3 (Digital Identity Guidelines): https://pages.nist.gov/800-63-3/ (While not directly addressing typing biometrics, it provides context on biometric authentication and identity assurance levels.) Information Commissioner's Office (ICO) Guide to Data Protection: https://ico.org.uk/for-organisations/guide-to-data-protection/key-definitions/what-is-personal-data/



Which of the following typical approaches is a large organization least likely to use to responsibly train stakeholders on AI terminology, strategy and governance?

  1. Providing all technical employees education on AI development so they can retool and participate in the development of AI systems.
  2. Providing training on AI ethics, based on the extent to which the organization seeks to promote a responsible AI culture.
  3. Providing role-specific training, based on whether the organization uses a centralized, federated or decentralized governance mode.
  4. Providing information and education to customers and users to understand the capabilities and limitations of the AI tools with which they interact.

Answer(s): A

Explanation:

Option A is the least likely approach for a large organization to take when responsibly training stakeholders on AI due to several reasons related to practicality, cost-effectiveness, and relevance.
While upskilling technical staff is beneficial, requiring all technical employees to become proficient in AI development is unrealistic and inefficient. Not all technical roles require deep AI expertise. This broad approach represents a significant investment in time and resources that may not yield proportional returns. Most tech employees have specialized skillsets that are crucial to other parts of the organization. Disrupting that by forcing AI training would be hugely disruptive.
Options B, C, and D, on the other hand, are more targeted and directly address responsible AI implementation. Ethics training (B) fosters a responsible AI culture. Role-specific training (C) aligns governance structures with practical application. Educating customers (D) promotes transparency and trust. These approaches provide training where it's most directly needed.
Further, AI development is a specialized field that requires dedicated expertise. Attempts to broadly retool the workforce would likely result in superficial understanding and lower quality of AI systems. More effective AI governance training would prioritize training the relevant stakeholders rather than attempting to turn all technical employees into AI developers.
The optimal approach for a large organization would prioritize specialized training for those directly involved in AI development and governance, coupled with broader awareness programs for other stakeholders.
Supporting Resources:
OECD AI Principles: https://oecd.ai/ (Guides responsible AI development and deployment.) AI Governance Guidebook by World Economic Forum: https://www.weforum.org/reports/ai-governance-guidebook (Provides practical guidance on implementing AI governance frameworks.)



All of the following are elements of establishing a global AI governance infrastructure EXCEPT:

  1. Providing training to foster a culture that promotes ethical behavior.
  2. Creating policies and procedures to manage third-party risk.
  3. Understanding differences in norms across countries.
  4. Publicly disclosing ethical principles.

Answer(s): B

Explanation:

The correct answer is B.
Establishing a global AI governance infrastructure necessitates a holistic approach that considers ethical, cultural, and transparency aspects. Options A, C, and D directly contribute to this overarching goal. Providing ethics training (A) builds awareness and promotes responsible AI development and deployment. Understanding cultural nuances (C) is critical as ethical considerations and legal requirements surrounding AI vary across different nations. Publicly disclosing ethical principles (D) fosters transparency and accountability, signaling an organization's commitment to responsible AI practices.
While third-party risk management (B) is undoubtedly important in a broader business context, it is not specifically a foundational element for establishing a global AI governance infrastructure. Third-party risk management is a component of overall risk management which applies to all activities, not exclusively AI. A global AI governance infrastructure requires that AI risks, whether developed internally or through third parties, are understood and mitigated appropriately.
While third-party risk management is a part of the operationalization of AI governance, it is not one of its core principles.Therefore, while a governance infrastructure would likely incorporate third-party management, its essence lies in ethics, cultural sensitivity, and transparency.
Here are some resources for further exploration:
OECD AI Principles: https://www.oecd.org/going-digital/ai/principles/ - Offers guidance on responsible and trustworthy AI. UNESCO Recommendation on the Ethics of AI: https://unesdoc.unesco.org/ark:/48223/pf0000381137 -Provides a global framework for ethical AI development. NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework - provides a framework for assessing and managing risks associated with AI.



In the context of increasing use of AI in business operations, your company seeks to update its data privacy policies. You are tasked with evaluating the current policies and proposing necessary updates to address AI-specific risks regarding protection of personal data.
Which of the following would be the most effective addition to the company’s data privacy policies?

  1. Request final review of the policy by senior management.
  2. Request regular audits of the AI Models.
  3. Prohibit the use of AI tools within the company.
  4. Require security training to employees before using AI systems.

Answer(s): B

Explanation:

The most effective addition to a company's data privacy policies to address AI-specific risks concerning personal data protection is (B) Request regular audits of the AI Models. Here's why:
AI models, especially those utilizing machine learning, can inadvertently create privacy risks. They can ingest vast amounts of personal data during training, potentially exposing sensitive information. Regular audits help to identify and mitigate these risks. Audits examine how data is used in AI models, ensuring compliance with privacy regulations (like GDPR or CCPA). They reveal whether the model is unfairly biased against certain groups or if it’s inadvertently leaking private data, even when anonymization techniques are applied.
Audits can also assess the security of the AI model itself, including its resilience to adversarial attacks that might expose sensitive information. Furthermore, they promote accountability and transparency. Understanding how an AI model processes data enables the company to inform individuals about their rights and the model's impact. This includes rights of access, correction, and deletion.
While (A) is important for general governance, it doesn't specifically address AI-driven privacy risks. Option (C), prohibiting AI, is overly restrictive and limits the potential benefits of AI. Option (D) is crucial but not sufficient. Security training is necessary, but it doesn't replace the need for model-specific assessments.
Therefore, regular AI model audits provide the most comprehensive approach to identify, assess, and mitigate
AI-related privacy risks, ensuring ongoing compliance and responsible AI development. This fosters trust with stakeholders and protects personal data in the age of AI.
For further research, consider resources from these organizations:
NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework The Algorithmic Accountability Act: (if available in your region - research current legislation) European Union's AI Act: https://artificialintelligenceact.eu/



Your management consulting firm is planning to use an AI system to support its employees.
Which category of operator applies to the firm in this context?

  1. Authorized representative.
  2. Distributor.
  3. Provider.
  4. Deployer.

Answer(s): D

Explanation:

The correct answer is D, Deployer. Here's a detailed justification:
In the context of AI governance frameworks (like those emerging from the EU AI Act and various national standards), the term "operator" broadly refers to entities involved in the AI system's lifecycle. The categories represent different roles with corresponding responsibilities. A management consulting firm using an AI system internally falls squarely under the definition of a "deployer".
A deployer is the entity that uses an AI system under its authority to achieve a specific purpose. The firm isn't providing the AI system to others (that would be the Provider). They aren’t distributing it in a supply chain. The firm uses the AI system as a tool within their internal operations. The firm takes responsibility for how the AI system impacts its employees and clients regarding the consulting work.
Consider the firm's role regarding data input, monitoring, and risk management associated with using AI to support their consulting staff. These responsibilities are characteristic of a deployer, who determines how the AI system's outputs influence decision-making processes.
An Authorized Representative would generally act on behalf of a provider outside a specific jurisdiction (like the EU) but whose system is placed on that market. A Distributor puts a system on the market that was developed by a provider. A Provider develops the AI system and puts it on the market or puts it into service.
Therefore, because the firm is using an existing AI system to support its employees and achieve their business objectives, the correct operator category is Deployer.
Relevant resources for further reading:
EU AI Act: https://artificialintelligenceact.eu/ (This is the primary source for understanding AI operator roles in a regulatory context) NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework (Though US-focused, it discusses responsible AI system usage and management, which is highly relevant for deployers)



Viewing page 4 of 46
Viewing questions 16 - 20 out of 222 questions


Post your Comments and Discuss IAPP AIGP exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!