IAPP AIGP Exam Prep
Artificial Intelligence Governance Professional (Page 6 )

Updated On: 10-Sep-2026

Within an established AI governance infrastructure, what might be the most effective governance action to handle third-party AI systems deemed to be high-risk?

  1. Align organizational impact assessment activities with relevant regulatory or legal requirements.
  2. Re-evaluate the purchase of the third-party AI system deemed to be high-risk, and consider other vendors.
  3. Establish policies for handling third-party system failures that include consideration of redundancy mechanisms for vital third-party AI system.
  4. Delegate the power, resources and authorization among executive leadership to perform risk management to each appropriate level throughout the management chain.

Answer(s): A

Explanation:

The most effective governance action within an established AI governance infrastructure to handle high-risk third-party AI systems is aligning organizational impact assessment activities with relevant regulatory or legal requirements (Option A). Here's why:
Compliance Focus: High-risk AI systems often fall under stringent regulatory scrutiny (e.g., GDPR, AI Act). Aligning impact assessments ensures the organization proactively identifies and addresses potential compliance gaps. This reduces the risk of fines, legal challenges, and reputational damage. https://iapp.org/resources/article/european-union-ai-act/
Holistic Risk Management: Impact assessments provide a structured framework for evaluating the AI system's potential impact on individuals, society, and the organization itself. By integrating regulatory requirements, the assessments become more comprehensive, capturing a wider range of potential risks beyond just technical performance.
Vendor Risk Mitigation: Evaluating a third-party system's alignment with regulatory requirements helps to identify potential issues with the vendor's practices and technologies. It allows organizations to demand evidence of compliance, audit reports, and other relevant documentation before deployment.
Data Governance Integration: High-risk AI systems often process sensitive data. Regulatory alignment of impact assessments ensures data governance principles are considered throughout the system's lifecycle, mitigating data security and privacy risks.
Transparency and Accountability: Documented impact assessments provide a clear record of the risk identification and mitigation process, enhancing transparency and accountability in AI governance.
While re-evaluating the purchase (Option B), establishing failure handling policies (Option C), and delegating risk management responsibilities (Option D) are important governance actions, they are secondary to ensuring the initial impact assessment captures and addresses regulatory requirements for high-risk systems. Impact assessments inform these other actions and provide the foundation for responsible AI adoption.
Specifically, a thorough impact assessment may lead to the decision to re-evaluate, or highlight the need for specific failure handling policies or delegation of responsibility. However, these are downstream consequences of, and less fundamentally important than, a regulatory-aligned impact assessment. The impact assessment is the primary mechanism for understanding the depth and breadth of the risks in the first place.



CASE STUDY
Please use the following to answer the next question: A premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company’s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia. It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias. To address these concerns, the company is considering using a third-party AI tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party AI-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws. The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team’s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company deploy technology solutions into the organization’s operations in a responsible, cost-effective manner. The organization is aware of the risks presented by AI hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the AI hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.
Which of the following measures should the company adopt to best mitigate its risk of reputational harm from using the AI tool?

  1. Test the AI tool pre- and post-deployment.
  2. Ensure the vendor provides indemnification for the AI tool.
  3. Require the procurement and deployment teams to agree upon the AI tool.
  4. Continue to require the company’s hiring personnel to manually screen all applicants.

Answer(s): A

Explanation:

The correct answer is A, testing the AI tool pre- and post-deployment, because it directly addresses the risk of reputational harm associated with potentially biased or inaccurate AI-driven hiring decisions. Regular testing allows the company to identify and rectify any unintended biases or discriminatory outcomes embedded in the AI's algorithms. This proactive approach demonstrates a commitment to fairness and ethical AI practices, enhancing the company's reputation by showing that it is taking responsible steps to mitigate potential harm. Indemnification from the vendor (B) offers financial protection but doesn't prevent reputational damage if the tool malfunctions or exhibits bias.
While agreement between procurement and deployment teams (C) is important for operational efficiency, it doesn't directly address the core risk of biased outcomes. Eliminating the AI tool and relying solely on manual screening (D) might avoid AI-related risks but misses the opportunity to improve efficiency and potentially reduce human bias. Moreover, manual screening is precisely what the company is trying to avoid due to its cost and potential for human bias.
Testing pre-deployment allows for baseline evaluation and identification of potential issues before implementation, while post-deployment testing facilitates ongoing monitoring and adjustment to maintain fairness and accuracy over time. This ongoing vigilance is crucial, as AI models can drift or produce unintended results as they're exposed to new data. Ignoring the biases that AI tools may inherit from their training data is a major risk. The constant regulatory evolution in AI also underscores the need for continuous monitoring to ensure compliance with changing legal standards. Demonstrating the use of AI in a responsible way helps to ensure the company's reputation is protected.
Authoritative Links:
AI Risk Management Framework (RMF) - NIST: https://www.nist.gov/itl/ai-risk-management-framework -This framework provides guidance on how to manage the risks associated with AI, including bias and discrimination. EU AI Act: https://artificialintelligenceact.eu/ - This proposed legislation aims to regulate AI systems and minimize the risk of harm. OECD AI Principles: https://oecd.ai/principles - These principles promote responsible and trustworthy AI.



You are a privacy program manager at a large e-commerce company that uses an AI tool to deliver personalized product recommendations based on visitors’ personal information that has been collected from the company website, the chatbot and public data the company has scraped from social media. A user submits a data access request under an applicable US state privacy law, specifically seeking a copy of their personal data, including information used to create their profile for product recommendations.
What is the most challenging aspect of managing this request?

  1. Some of the visitor’s data is synthetic data that the company does not have to provide to the data subject.
  2. The data subject’s data is structured data that can be searched, compiled and reviewed only by an automated tool.
  3. The data subject is not entitled to receive a copy of their data because some of it was scraped from public sources.
  4. Some of the data subject’s data is unstructured data and you cannot untangle it from the other data, including information about other individuals.

Answer(s): D

Explanation:

Here's a detailed justification for why option D is the most challenging aspect of managing the data access request:
Option D highlights the difficulty of extracting a specific individual's data from a complex AI system when that data is intermingled with others' data, especially when dealing with unstructured data. AI-driven recommendation systems often rely on analyzing vast amounts of data, including text, images, and social media posts, which are typically unstructured. The challenge arises because separating one individual's data from the collective dataset used to train the AI model can be exceptionally difficult, sometimes even impossible, without revealing information about other individuals, which would violate their privacy rights.
Unlike structured data (option B), which is organized in a defined format and readily searchable using tools like SQL, unstructured data requires more sophisticated techniques like natural language processing (NLP) and machine learning to identify relevant pieces of information. Even with these techniques, isolating the data relevant to a single individual and ensuring no other individuals' data is inadvertently disclosed is a significant hurdle.
Option A is incorrect because synthetic data, which is artificially created, generally isn't subject to the same privacy regulations as real personal data, but here we are dealing with real personal data used to create the profile. Option C is also incorrect; while scraping public data has its own compliance challenges, many US state privacy laws grant individuals the right to access data collected about them, regardless of the source. Moreover, the data collected from the company's website and chatbot falls squarely under the scope of privacy laws.
The difficulty in option D stems from the nature of AI systems, particularly those using unstructured data and the potential for data commingling. It can lead to significant operational overhead, legal risks, and potential violations of privacy laws if not handled carefully. This challenge is compounded by the "black box" nature of some AI models, making it difficult to understand how specific data points contribute to the model's outputs and how to extract that data safely.
Here are some authoritative links for further research:
NIST Special Publication 800-188, De-Identifying Government Datasets: https://csrc.nist.gov/publications/detail/sp/800-188/final (Discusses de-identification techniques and their limitations) The EU's GDPR Guidelines on Transparency: https://gdpr-info.eu/art-13-gdpr/ (While focused on GDPR, the principles of transparency and data minimization are relevant globally.) California Consumer Privacy Act (CCPA): https://oag.ca.gov/privacy/ccpa (Review the access request requirements)



An artist has been using an AI tool to create digital art and would like to ensure that it has copyright protection in the United States.
Which of the following is most likely to enable the artist to receive copyright protection?

  1. Ensure the tool was trained using publicly available content.
  2. Obtain a representation from the AI provider on how the tool works.
  3. Provide a log of the prompts the artist used to generate the images.
  4. Update the images in a creative way to demonstrate that it is the artist’s.

Answer(s): D

Explanation:

The most likely way for the artist to secure copyright protection for AI-generated art in the US is by updating the images in a creative way to demonstrate that it is the artist's work (Option D). US copyright law currently emphasizes human authorship as a prerequisite for copyright protection. Purely AI-generated content, without significant human input, is unlikely to be granted copyright. The Copyright Office considers the extent of human creative contribution in the final work when determining eligibility.
Options A, B, and C are less relevant to establishing copyright ownership. The source data used to train the AI tool (Option A) is related to fair use and potentially the AI provider's liability, but does not establish the artist's claim to the final artwork. Understanding how the AI tool functions (Option B) doesn't inherently demonstrate the artist's creative input. A log of prompts (Option C) might offer some insight into the artist's intentions, but it alone does not prove the level of creativity and artistic contribution needed for copyright protection.
The artist can add significant, original creative input by editing, modifying, or transforming the AI-generated images using tools and techniques within their control. This human element transforms the AI output into a derivative work, and the copyright would protect the artist's unique contribution to the derivative work. Examples of such creative input include adding artistic elements like brush strokes, textures, color adjustments, composing different AI-generated parts, or creating entirely novel compositions through extensive manipulation. The greater the artist's creative contribution, the stronger the copyright claim.
For more information on copyright law and AI-generated works, research US Copyright Office guidance and relevant court cases. The US Copyright Office provides extensive documentation online. Here are some resources:
US Copyright Office - Copyright and AI: https://www.copyright.gov/ai/ Copyright Office Artificial Intelligence Study: https://www.copyright.gov/policy/ai/
The key is to show that the artwork reflects the artist's originality and creative expression, rather than simply being a product of an AI algorithm.



A French medical research center wishes to develop an AI-based system which will predict the risk of serious diseases based on the patient’s genetic data. In order to do so it contracts with a tech company and provides it with patients’ data previously obtained by the center during the research. To guarantee compliance when processing special categories of personal data, the medical research center must ensure that:

  1. The AI-based system is designed for the purposes of preventive medicine.
  2. The patients’ health and genetic data is anonymized.
  3. The patients have given explicit consent to using the data.
  4. The tech company is located in the EU and is not cloud-based.

Answer(s): C

Explanation:

The correct answer is C: The patients have given explicit consent to using the data. Here's a detailed justification:
Processing special categories of personal data, such as health and genetic data, is heavily restricted under data protection laws like the GDPR. This type of data is considered highly sensitive and requires a specific lawful basis for processing.
While the scenario suggests a research purpose, the involvement of a third-party tech company shifts the context beyond pure academic research, potentially making explicit consent the most reliable and appropriate legal basis.
Explicit consent, meaning a freely given, specific, informed, and unambiguous indication of the data subject's agreement, is generally required when processing special category data. It ensures individuals have a high degree of control over how their sensitive data is used, especially when combined with AI-driven analysis that could reveal unforeseen or highly personal insights.
Option A (preventive medicine purpose) is relevant, but alone it's insufficient.
While preventive medicine can be a legitimate interest or public interest ground for processing health data, it often still requires an additional safeguard like explicit consent, especially with a third party involved.
Option B (anonymization) eliminates the "personal data" aspect altogether. If the data were truly anonymized, GDPR would not apply. However, the scenario implies data is being processed in a way that allows individual predictions, suggesting re-identification is possible. True anonymization is exceedingly difficult, especially with genetic data and AI.
Option D (EU location & no cloud) is incorrect because data residency alone is not a sufficient safeguard under data protection laws.
While data localization may be a factor in overall compliance, it does not negate the fundamental requirement for a valid lawful basis for processing special category data. Cloud computing is also acceptable as long as GDPR regulations are followed.
In summary, given the nature of the data (genetic and health) and the involvement of a third-party (tech company) for AI-based prediction, explicit consent is the most direct and comprehensive way to ensure compliance with data protection principles when processing special category data.
Further research:
GDPR Article 9 (Processing of special categories of personal data): https://gdpr-info.eu/art-9-gdpr/ European Data Protection Board (EDPB) Guidelines on Consent: https://edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en ICO (UK Information Commissioner's Office) Guide to GDPR - Special Category Data: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/lawful-basis-for-processing/special-category-data/



Viewing page 6 of 46
Viewing questions 26 - 30 out of 222 questions


Post your Comments and Discuss IAPP AIGP exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!