View Full IAPP AIGP Exam Dumps and Practice Test Dumps.
Question 101
Which activity is most important when establishing an AI system inventory?
- Recording only the systems that generate revenue
- Identifying and documenting AI systems used across the organization
- Removing all legacy AI systems immediately
- Allowing every employee to register systems independently
Correct Answer: 2
Explanation
An AI system inventory provides an organization with visibility into where and how AI is being used. It should identify relevant AI systems, their business purposes, owners, data sources, vendors, deployment environments, and risk characteristics. Recording only revenue-generating systems can overlook important internal or experimental systems. Likewise, immediately removing legacy systems is not an inventory activity, and unrestricted employee registration may produce incomplete or inconsistent information. A centralized inventory process helps governance teams understand the organization’s AI landscape and determine which systems require additional assessments, controls, monitoring, or approval. Maintaining accurate inventory information also supports accountability and makes it easier to respond to audits, incidents, regulatory inquiries, and changes in organizational risk.
Question 102
What is the primary benefit of conducting an AI impact assessment before deployment?
- To eliminate the need for human oversight
- To guarantee that an AI model will never fail
- To identify potential impacts and risks before the system is used
- To increase the amount of data collected
Correct Answer: 3
Explanation
An AI impact assessment is designed to identify and evaluate potential effects of an AI system before deployment or during significant changes. It can consider issues involving privacy, fairness, safety, security, transparency, affected individuals, and organizational responsibilities. The assessment cannot guarantee that a system will never fail, nor does it eliminate the need for human oversight. Increasing data collection is also not its purpose. Instead, the assessment gives decision-makers structured information about possible harms and helps determine whether mitigation measures are necessary. Conducting this work early can allow an organization to modify the system, restrict its use, improve controls, or decide that deployment should not proceed under the proposed conditions.
Question 103
Which control best supports accountability for an AI system?
- Assigning a clearly identified owner responsible for the system
- Allowing anonymous changes to production models
- Removing documentation after deployment
- Giving all employees unrestricted administrative access
Correct Answer: 1
Explanation
Clear ownership is a fundamental accountability control for AI governance. An identified system owner or responsible business function can coordinate risk assessments, approvals, monitoring, documentation, incident response, and periodic reviews. Without ownership, it can be difficult to determine who is responsible for decisions made about the AI system or who should respond when problems occur. Anonymous production changes, removal of documentation, and unrestricted administrative access weaken accountability and increase operational risk. Ownership does not mean that one person performs every governance activity; instead, it establishes responsibility and helps coordinate relevant technical, legal, compliance, security, privacy, and business stakeholders throughout the AI system lifecycle.
Question 104
An organization discovers that an AI system is being used for a purpose that was not included in its original approval. What should happen first?
- Ignore the change if the system is performing well
- Expand access to additional employees
- Remove all historical records
- Review the changed use against governance and risk requirements
Correct Answer: 4
Explanation
A change in an AI system’s purpose can introduce new risks even when the underlying model has not changed. The organization should therefore review the new use against its governance requirements, approved scope, risk assessment, data practices, and applicable controls. Performance alone does not demonstrate that the new purpose is appropriate. Expanding access could increase exposure, while removing historical records would make governance and accountability more difficult. A proper review may determine that additional testing, impact assessment, privacy analysis, stakeholder approval, or documentation is necessary. Organizations should treat material changes in intended use as lifecycle events requiring appropriate governance rather than assuming that the original approval automatically covers every future application.
Question 105
Why is data provenance important in AI governance?
- It identifies where data originated and how it was handled
- It guarantees that every prediction is correct
- It eliminates the need for data quality testing
- It prevents all cybersecurity incidents
Correct Answer: 1
Explanation
Data provenance provides information about the origin, history, transformations, and handling of data used by an AI system. This information can help organizations evaluate whether data was obtained appropriately, understand how it changed over time, investigate quality problems, and support accountability. Provenance does not guarantee prediction accuracy, eliminate the need for data quality testing, or prevent cybersecurity incidents. However, it can make those areas easier to investigate and manage. When an unexpected model behavior occurs, knowing which datasets were used and how they were processed can help teams identify potential causes. Strong provenance practices therefore contribute to transparency, reproducibility, governance, and responsible lifecycle management.
Question 106
Which situation is most likely to require additional human oversight of an AI system?
- An AI tool generating internal formatting suggestions
- An AI system making recommendations that could significantly affect individuals
- A calculator performing basic arithmetic
- A program sorting files alphabetically
Correct Answer: 2
Explanation
The need for human oversight generally increases when an AI system can produce decisions or recommendations with significant consequences for individuals. Examples may include employment, financial access, education, healthcare, safety, or other high-impact contexts. Human review can provide an opportunity to challenge outputs, identify errors, consider context that the system may not understand, and prevent inappropriate reliance on automated recommendations. Low-impact tasks such as formatting suggestions, basic arithmetic, or alphabetical sorting generally present much lower consequences. The appropriate level of oversight should be based on factors such as potential harm, system capability, uncertainty, affected populations, and the importance of the decisions being supported.
Question 107
What is the purpose of maintaining an AI system change log?
- To prevent employees from using AI
- To replace all system documentation
- To record significant modifications made to the system
- To guarantee regulatory approval
Correct Answer: 3
Explanation
An AI system change log records meaningful modifications made during the system lifecycle. Depending on the organization and system, this may include model updates, data changes, configuration changes, new integrations, changes to intended use, security modifications, or updates to governance controls. A change log supports traceability by allowing teams to understand what changed, when it changed, who authorized it, and potentially why the change was made. It does not replace broader documentation or guarantee regulatory approval. Instead, it complements other governance processes by helping organizations investigate incidents, compare system versions, perform audits, and determine whether a change should trigger additional testing or risk assessment.
Question 108
Which practice is most appropriate when an organization uses an external AI provider?
- Assume the provider manages every organizational risk
- Avoid documenting the provider relationship
- Perform appropriate vendor and AI risk due diligence
- Give the provider unrestricted access to internal information
Correct Answer: 3
Explanation
Using an external AI provider does not automatically transfer all governance responsibilities away from the organization. Appropriate vendor due diligence can help evaluate the provider’s security practices, data handling, model governance, reliability, privacy commitments, incident response capabilities, contractual terms, and relevant controls. Organizations should understand what the provider does with submitted data, how information is retained, and what responsibilities each party has. Assuming the provider manages every risk can create significant gaps. Similarly, undocumented relationships and unrestricted access can increase exposure. Contracts and ongoing monitoring should reflect the organization’s risk requirements. Vendor governance should therefore be treated as an important component of the AI system lifecycle.
Question 109
What is the best reason to establish criteria for AI system retirement?
- To ensure outdated or unsuitable systems are appropriately decommissioned
- To prevent all future AI development
- To avoid keeping any documentation
- To increase the number of active AI systems
Correct Answer: 1
Explanation
AI systems may eventually become outdated, unreliable, unnecessary, too costly, incompatible with new requirements, or inappropriate for continued use. Retirement criteria help an organization determine when a system should be decommissioned rather than allowing it to remain active indefinitely. A retirement process should address issues such as data retention, access removal, dependencies, contractual obligations, records, security, and communication with affected stakeholders. Retiring a system does not mean stopping future AI development, and it should not involve simply deleting documentation without considering recordkeeping requirements. Effective retirement governance reduces risks associated with abandoned systems and ensures that decommissioning is deliberate, documented, and appropriately controlled.
Question 110
Which metric would be most useful for monitoring AI governance effectiveness?
- Number of office meetings held
- Number of governance reviews completed on schedule
- Number of employees with personal smartphones
- Amount of office space occupied
Correct Answer: 2
Explanation
Governance metrics should provide meaningful evidence about whether governance processes are operating as intended. Tracking the number of AI governance reviews completed on schedule can help determine whether required assessments and oversight activities are being performed consistently. Other useful metrics might include unresolved AI incidents, completion of required training, overdue risk assessments, policy exceptions, monitoring coverage, or remediation timelines. Office meetings, smartphone ownership, and office space do not directly demonstrate AI governance effectiveness. Well-designed metrics should be connected to defined governance objectives and should help leadership identify weaknesses, trends, and areas requiring corrective action. Metrics are most valuable when they support decisions rather than simply measuring activity.
Question 111
What should an organization consider when defining AI system access controls?
- Whether access is appropriate for each user’s role and responsibilities
- Whether every employee should receive administrator privileges
- Whether authentication can be eliminated
- Whether sensitive information can be shared without restrictions
Correct Answer: 1
Explanation
AI system access should generally follow principles such as least privilege, role-based access, authentication, authorization, and appropriate segregation of duties. Users should receive the level of access necessary to perform their responsibilities, rather than broad administrative privileges by default. This is particularly important when AI systems process confidential information, influence important decisions, or connect to other organizational resources. Eliminating authentication or allowing unrestricted sharing of sensitive information can create significant security and privacy risks. Access controls should also be reviewed periodically because employee roles, system functions, and organizational requirements can change. Effective access governance helps reduce unauthorized use, inappropriate disclosure, and accidental or malicious modifications.
Question 112
Which approach best supports trustworthy AI system documentation?
- Document only successful test results
- Keep documentation limited to technical model specifications
- Maintain relevant information about purpose, data, risks, controls, and lifecycle decisions
- Delete documentation after deployment
Correct Answer: 3
Explanation
Useful AI documentation should provide enough information for appropriate stakeholders to understand how a system is intended to operate and how it is governed. Depending on the system, documentation may cover its purpose, scope, users, data sources, model characteristics, limitations, testing, risks, mitigations, approvals, monitoring, changes, incidents, and retirement decisions. Documenting only successful tests creates an incomplete picture and may hide known weaknesses. Technical specifications alone may not address governance concerns, while deleting documentation after deployment undermines traceability. Documentation should be maintained throughout the lifecycle and updated when meaningful changes occur. Good records support accountability, audits, troubleshooting, oversight, and informed decision-making.
Question 113
An AI model begins producing less accurate results after a significant change in its operating environment. What is the most appropriate response?
- Ignore the change because the model was previously approved
- Investigate performance deterioration and determine whether remediation is required
- Delete all monitoring records
- Automatically increase the model’s access privileges
Correct Answer: 2
Explanation
AI performance can change when data distributions, user behavior, operational conditions, integrations, or other environmental factors change. A decline in performance should therefore trigger investigation rather than being ignored because the model was previously approved. The organization may need to examine monitoring results, compare current performance with established thresholds, identify possible causes, test the system, and implement remediation. Depending on the severity, it may also be necessary to restrict use or escalate the issue through incident or governance procedures. Deleting monitoring records would reduce visibility, while increasing access privileges does not address the underlying performance problem. Continuous monitoring helps organizations identify these issues before they become more serious.
Question 114
Why should AI governance policies define escalation procedures?
- To ensure significant risks or incidents reach appropriate decision-makers
- To prevent employees from reporting problems
- To eliminate the need for monitoring
- To guarantee that every issue is handled by one person
Correct Answer: 1
Explanation
Escalation procedures help ensure that important AI risks, incidents, policy violations, or unexpected system behaviors are communicated to the appropriate people or functions. A clear escalation path can define when an issue should be reported, who should receive it, what information should be included, and what actions may be required. This is particularly valuable for high-impact systems where delays can increase potential harm. Escalation does not prevent reporting or eliminate monitoring. It also does not require every issue to be handled by one person. Instead, it connects operational teams with appropriate governance, legal, privacy, security, risk, compliance, or executive stakeholders when an issue exceeds predefined thresholds.
Question 115
Which activity is most useful for evaluating an AI vendor before entering into a contract?
- Reviewing only the vendor’s marketing materials
- Asking whether the vendor has any competitors
- Assessing relevant security, privacy, governance, and contractual practices
- Allowing unrestricted testing with production data
Correct Answer: 3
Explanation
Vendor evaluation should provide evidence about whether an external provider can meet the organization’s requirements. Depending on the AI service, due diligence may examine security controls, privacy and data-use practices, model governance, reliability, incident response, subcontractors, data retention, intellectual property terms, audit rights, regulatory responsibilities, and business continuity. Marketing materials may be useful background information but are not sufficient evidence for a meaningful risk assessment. Giving a vendor unrestricted access to production data before appropriate safeguards are established can create unnecessary risk. A structured evaluation helps the organization identify weaknesses, negotiate appropriate contractual protections, and determine whether the provider is suitable for the intended use case.
Question 116
What is the primary purpose of AI literacy training for employees?
- To make every employee an AI engineer
- To help employees understand appropriate AI use, limitations, and risks
- To eliminate organizational AI policies
- To ensure employees never question AI outputs
Correct Answer: 2
Explanation
AI literacy helps employees understand how AI systems are used, what their capabilities and limitations are, and what risks may arise from inappropriate use. Employees do not need to become AI engineers to benefit from appropriate training. Depending on their roles, training may address responsible use, confidentiality, privacy, security, bias, human oversight, verification of outputs, reporting procedures, and organizational policies. Effective AI literacy should encourage employees to recognize uncertainty and question outputs when appropriate rather than blindly trusting automated results. Training can therefore support responsible adoption by giving employees practical knowledge for making informed decisions when interacting with or relying on AI systems.
Question 117
What should an organization do when an AI system has a known limitation that could affect important decisions?
- Hide the limitation from users
- Document the limitation and establish appropriate controls or warnings
- Increase reliance on the system
- Remove all human review
Correct Answer: 2
Explanation
Known limitations should be documented and communicated to the stakeholders who need that information to use the system responsibly. Appropriate controls may include human review, warnings, restricted use cases, additional testing, confidence thresholds, user training, or requirements to verify outputs independently. Hiding a known limitation can lead users to develop an inaccurate understanding of system capabilities and increase the chance of harmful reliance. Increasing reliance or removing human review would generally make the situation worse when the limitation is relevant to important decisions. Transparent documentation helps organizations and users understand where an AI system should and should not be relied upon.
Question 118
Which principle is most relevant when an organization collects only the information necessary for a defined AI purpose?
- Data minimization
- Unlimited data retention
- Maximum data collection
- Unrestricted secondary use
Correct Answer: 1
Explanation
Data minimization refers to limiting the collection or use of data to what is necessary and appropriate for a defined purpose. In AI governance, this principle can reduce privacy, security, compliance, and operational risks associated with collecting unnecessary information. Collecting as much data as possible is not automatically beneficial, particularly when additional information introduces greater exposure without improving the system’s legitimate purpose. Data minimization should be considered alongside purpose definition, retention, access controls, data quality, and applicable legal or organizational requirements. Applying it consistently can help organizations avoid unnecessary data accumulation while encouraging more disciplined decisions about what information an AI system actually needs.
Question 119
Which practice best supports continuous improvement in AI governance?
- Conducting periodic reviews and updating controls based on lessons learned
- Freezing governance processes permanently
- Ignoring incident findings after resolution
- Preventing stakeholders from providing feedback
Correct Answer: 1
Explanation
AI governance should evolve as systems, risks, regulations, organizational practices, and stakeholder expectations change. Periodic reviews can help organizations evaluate whether policies and controls remain effective. Lessons from incidents, audits, monitoring results, user feedback, testing, and new risks can then be used to improve governance processes. Permanently freezing policies can leave organizations unprepared for changing conditions. Similarly, ignoring incident findings or preventing stakeholder feedback removes valuable information that could reveal weaknesses. Continuous improvement does not necessarily mean changing every control frequently; rather, it means using evidence to determine when changes are appropriate and ensuring that governance remains aligned with the organization’s AI risk environment.
Question 120
Which statement best describes a risk-based approach to AI governance?
- Apply identical controls to every AI system regardless of risk
- Focus governance resources according to the potential impact and likelihood of risks
- Approve every AI system automatically
- Assess risks only after an incident occurs
Correct Answer: 2
Explanation
A risk-based approach recognizes that AI systems can have very different levels of potential impact and likelihood of harm. Governance resources and controls should therefore be proportionate to the characteristics and risks of each system. A high-impact system may require stronger testing, human oversight, documentation, monitoring, approval, and incident procedures than a low-risk administrative tool. Applying identical controls everywhere can waste resources or provide insufficient protection for higher-risk applications. Waiting until an incident occurs is also reactive rather than preventive. A risk-based approach allows organizations to prioritize attention where it is most needed while maintaining baseline governance requirements across the broader AI environment.