IAPP AIGP Exam Prep
Artificial Intelligence Governance Professional (Page 5 )

Updated On: 7-Sep-2026

CASE STUDY
Please use the following to answer the next question: A premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company’s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia. It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias. To address these concerns, the company is considering using a third-party AI tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party AI-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws. The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team’s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company deploy technology solutions into the organization’s operations in a responsible, cost-effective manner. The organization is aware of the risks presented by AI hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the AI hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change. All of the following are potential negative consequences created by using the AI tool to help make hiring decisions EXCEPT:

  1. Automation bias.
  2. Candidate quality.
  3. Privacy violations.
  4. Disparate impacts.

Answer(s): B

Explanation:

The correct answer is B. Candidate quality. Here's why:
Automation Bias: The AI tool is trusted without critically analyzing. Because humans may tend to over rely on output from an automated system, even when it is wrong. Since the AI tool is screening resumes and assisting with hiring, people will be less likely to question the tool's choices, thus causing automation bias. Privacy Violations: The AI hiring tool might collect and process sensitive candidate data (e.g., demographic information, background checks) which may violate privacy laws like GDPR, CCPA, or local regulations in Asian countries where the company is expanding. Data security breaches are also a serious concern, leading to identity theft and regulatory penalties. Disparate Impacts: AI models can inadvertently discriminate against protected groups (e.g., gender, race) if trained on biased data or if the algorithms themselves contain biases. This would then be considered disparate impact. If the AI hiring tool consistently filters out qualified candidates from certain demographic groups, it results in discriminatory hiring practices and legal repercussions. Candidate Quality: Candidate quality refers to the overall skill, experience, and suitability of the candidates who are considered for a job. However, candidate quality isn't a direct negative consequence created by using the AI tool. The AI tool is intended to improve candidate quality by screening for the best talent. Although the AI might have unintentional bad consequences, it cannot make quality of candidates lower.
Supporting Resources:
Equal Employment Opportunity Commission (EEOC) on AI and Algorithmic Bias: https://www.eeoc.gov/artificial-intelligence-and-algorithmic-fairness NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework



CASE STUDY
Please use the following to answer the next question: A premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company’s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia. It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias. To address these concerns, the company is considering using a third-party AI tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party AI-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws. The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team’s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company deploy technology solutions into the organization’s operations in a responsible, cost-effective manner. The organization is aware of the risks presented by AI hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the AI hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.
Which other stakeholder groups should be involved in the selection and implementation of the AI hiring tool?

  1. Finance and Legal.
  2. Marketing and Compliance.
  3. Supply Chain and Marketing.
  4. Litigation and Product Development.

Answer(s): A

Explanation:

The correct answer is A. Finance and Legal.
Here's a detailed justification:
To implement an AI hiring tool responsibly and effectively, several stakeholder groups beyond HR, the procurement team, and deployment teams must be involved. Finance is crucial because they control the budget and need to assess the return on investment (ROI) of the AI tool, ensuring its cost-effectiveness aligns with the company's overall financial strategy. They will analyze pricing models, hidden costs, and potential cost savings compared to the current hiring process.
Legal's involvement is paramount due to the varying and evolving legal landscape surrounding AI, particularly in hiring. The legal team needs to ensure the AI tool complies with anti-discrimination laws (e.g., Title VII in the US, GDPR in Europe, similar legislation in Asia), data privacy regulations, and any local regulations concerning automated decision-making. They must review the vendor's contract, data handling practices, and audit logs to mitigate legal risks and ensure compliance across all relevant jurisdictions where the company operates. Specifically in Asia, legal counsel with experience in the nuances of local data protection and employment law is invaluable. They should also advise on transparency requirements and potential liability if the AI tool produces discriminatory outcomes. Without involving Finance and Legal from the start, the organization risks financial overspending and significant legal repercussions due to non-compliance.
Option B is less relevant, as Marketing and Compliance are not the core stakeholders in the initial selection and implementation phase.
While Compliance is important, Legal is the more immediate need in this context, regarding data privacy and employment law. Option C is also incorrect; Supply Chain is generally not involved in AI software selection for HR, and Marketing's involvement comes later in employer branding and communicating the AI's use to candidates. Option D is less critical; Litigation becomes relevant if issues arise, and Product Development is involved later when integrating the AI tool with other HR systems, not during selection.
Authoritative Links for Further Research:
EEOC (U.S. Equal Employment Opportunity Commission) on AI and Algorithmic Fairness: https://www.eeoc.gov/artificial-intelligence-and-algorithmic-fairness GDPR (General Data Protection Regulation): https://gdpr-info.eu/ OECD Principles on AI: https://www.oecd.org/going-digital/ai/principles/ AI Risk Management Framework - NIST: https://www.nist.gov/itl/ai-risk-management-framework



CASE STUDY
Please use the following to answer the next question: A premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company’s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia. It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias. To address these concerns, the company is considering using a third-party AI tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party AI-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws. The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team’s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company deploy technology solutions into the organization’s operations in a responsible, cost-effective manner. The organization is aware of the risks presented by AI hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the AI hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change. If the company does not deploy and use the AI hiring tool responsibly in the United States, its liability would likely increase under all of the following laws EXCEPT:

  1. Anti-discrimination laws.
  2. Product liability laws.
  3. Accessibility laws.
  4. Privacy laws.

Answer(s): B

Explanation:

Here's a detailed justification for why the answer is B, Product liability laws, along with supporting details and resources:
The question asks which law would not likely increase liability if the AI hiring tool is deployed irresponsibly in the United States. Let's analyze each option:

A: Anti-discrimination laws: AI hiring tools, if not properly designed and monitored, can perpetuate or amplify existing biases in the data they are trained on. This could lead to discriminatory hiring practices based on protected characteristics like race, gender, age, religion, etc., violating anti-discrimination laws such as Title VII of the Civil Rights Act of 1964, the Age Discrimination in Employment Act (ADEA), and the Americans with Disabilities Act (ADA). If the tool screens out qualified candidates based on these biases, the company faces significant legal risk.
EEOC on AI and Algorithmic Fairness
B: Product liability laws: Product liability laws generally concern defects in products that cause physical harm to users.
While an AI hiring tool is a product, its irresponsible use doesn't typically result in physical injury to job applicants in the way a defective machine or consumer product might. The harm it causes is primarily economic and emotional distress due to unfair denial of employment opportunities. Therefore, product liability is less directly applicable in this scenario.
C: Accessibility laws: Accessibility laws, such as the Americans with Disabilities Act (ADA), require that hiring processes be accessible to individuals with disabilities. If the AI hiring tool's interface, assessment methods, or communication methods are not accessible (e.g., lacking screen reader compatibility, using video interviews without captions, or not providing alternative formats for assessments), the company could face liability under accessibility laws.
D: Privacy laws: AI hiring tools often collect and process personal data from resumes and applications. If the company fails to comply with privacy laws, such as state-level laws like the California Consumer Privacy Act (CCPA) or similar laws in other states or countries (if the company receives applications from outside the US), regarding data collection, usage, security, and transparency, it could face significant penalties. Improperly handling personal data collected through the AI tool increases privacy law liability.
Therefore, Product liability laws (B) are the least likely to be the basis for increased liability in this scenario compared to anti-discrimination, accessibility, and privacy laws, which are directly relevant to fair and responsible hiring practices. The main risk arises from the AI's decision-making regarding candidates, not a physical defect causing injury.
Authoritative Links:
California Consumer Privacy Act (CCPA) Title VII of the Civil Rights Act of 1964 Age Discrimination in Employment Act (ADEA) Americans with Disabilities Act (ADA)



What is the primary purpose of an AI impact assessment?

  1. To determine whether a conformity assessment is needed.
  2. To escalate the findings to the appropriate owner(s).
  3. To identify and measure the benefits of an AI system.
  4. To anticipate and manage the potential risks and harms of an AI system.

Answer(s): D

Explanation:

The correct answer, D, focuses on the core objective of an AI impact assessment: to proactively identify and manage potential negative consequences arising from AI systems. An AI impact assessment is a systematic process designed to anticipate and mitigate risks before an AI system is deployed or further developed.
Option A is incorrect because determining whether a conformity assessment is needed is often a result of an impact assessment, not its primary purpose. The impact assessment informs the need for further, more formal evaluation.
Option B, escalating findings, is a step within the overall impact assessment process but not the ultimate goal.
While crucial for accountability, escalation follows the identification and analysis of risks.
Option C, identifying and measuring benefits, is part of a broader AI evaluation, but an impact assessment specifically targets potential harms.
While benefits are considered, the primary emphasis is on understanding and mitigating risks.
The impact assessment allows organizations to proactively address ethical, legal, and societal concerns associated with AI, like bias, discrimination, lack of transparency, and potential job displacement. By carefully analyzing data sets, algorithms, and deployment contexts, organizations can implement safeguards, adjust system design, and ensure responsible AI practices. This aligns with responsible innovation frameworks which emphasize understanding the unintended consequences of new technologies. Effective AI governance requires this proactive approach to mitigate harm and build trust in these powerful systems.
For more information, you can refer to:
NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework EU AI Act: https://artificialintelligenceact.eu/ (Especially relevant to impact assessments required for high-risk AI systems.)



The use of paid generative AI public tools is appealing because? (Choose three.)

  1. They are convenient to adopt.
  2. They have additional privacy and security controls.
  3. They have frequent enhancements of new features.
  4. They provide transparency in models and in decision-making.
  5. They eliminate concerns about the data used to generate outputs.

Answer(s): A,B,C

Explanation:

The answer ABC is correct because paid generative AI public tools often offer:

A: Convenience of Adoption: These tools are designed for easy integration and use. They typically come with user-friendly interfaces and readily available documentation, accelerating the adoption process compared to building a custom AI solution from scratch. Organizations can quickly leverage these tools without significant upfront investment in infrastructure or expertise. Think of them as software-as-a-service (SaaS) offerings, ready to use with minimal configuration.
B: Frequent Enhancements of New Features: Paid services are often actively maintained and improved. Providers invest in research and development, leading to continuous upgrades and the addition of new capabilities. This allows users to benefit from the latest advancements in AI without having to manage the underlying technology. This aligns with the cloud computing model of providing updated services without user intervention, akin to platform-as-a-service (PaaS).
C: They eliminate concerns about the data used to generate outputs: While this is not always the case, a paid service typically ensures that the data used is high quality, well-vetted and has had all the legal and IP considerations met.
Option D is incorrect because public AI tools, even paid ones, often lack transparency regarding the models used and the decision-making processes. The 'black box' nature of these models can raise concerns about bias and accountability.
Option E is incorrect because, even with paid services, users must still be mindful of the data they input. Paid tools do not automatically absolve users of responsibility for ensuring the legality, ethics, and privacy of the data they provide. Users remain responsible for compliance with data protection regulations.
Further Research:
IAPP: https://iapp.org/ NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework



Viewing page 5 of 46
Viewing questions 21 - 25 out of 222 questions


Post your Comments and Discuss IAPP AIGP exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!