Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free IAPP Artificial Intelligence Governance Professional AIGP Exam Questions

Page: 1 / 15 Total 215 questions

Want more questions? Get Premium Access.

Question 1

CASE STUDY

Please use the following to answer the next question:

You have recently assumed the role of AI Governance leader for a California-based medical technology company. The organization primarily serves hospitals and has recently expanded to include walk-in clinics located within local pharmacies.

The company's core business focuses on diagnostic assistance powered by a large language model LLM and back-office process optimization using Agentic AI, including chatbots, medical record request handling, scheduling and billing.

In preparation for its next round of funding, the board has asked you to prepare an AI Risk report to demonstrate to investors how the company is addressing AI-related risks. In preparing the report you learn that last year the company generated 30 million dollars in gross revenue across the US, EU, India, and South Korea and that vendors are engaged for various activities, including model testing and providing third-party AI solutions for chatbots.

Which of the following best exemplifies human oversight capabilities you should enable under the relevant AI laws?

Correct Answer: A. The tool requires a medical doctor to approve a diagnosis before the diagnosis is entered into the patient's medical record.
Explanation:

The correct answer is A because it directly demonstrates meaningful human oversight over AI-generated outcomes, which is a key requirement in AI governance frameworks and regulations such as the EU AI Act. Human oversight requires that a qualified human can review, intervene, and override AI decisions before they produce legal or significant real-world effects. In high-risk contexts like healthcare diagnostics, governance frameworks emphasize ''human-in-the-loop'' controls to prevent harm and ensure accountability. Option A ensures a licensed medical professional validates the AI output before it is finalized, aligning with safety, accountability, and risk mitigation principles. Other options describe training, system design, or monitoring, which are important governance measures but do not constitute direct oversight of individual AI decisions at the point of impact, making them insufficient under strict regulatory expectations.


Question 2

All of the following are reasons to deploy a challenger Al model in addition a champion Al model EXCEPT to?

Correct Answer: D. Retrain the champion model.
Explanation:

Deploying a challenger AI model alongside a champion model is a strategy used to compare the performance of different models in a real-world environment. This approach helps in providing a framework to consider alternatives to the champion model, automating real-time monitoring of the champion model, and performing testing on the champion model. However, retraining the champion model is not a reason to deploy a challenger model. Retraining is a separate process that involves updating the champion model with new data or techniques, which is not related to the use of a challenger model.


Question 3

The processes and methods that allow human users to understand and trust the outputs produced by AI are important in addressing which key regulatory concern?

Correct Answer: C. Explainable AI
Explanation:

The correct answer is Explainable Ai because it specifically refers to the ability of a system to describe the logic behind its decisions or output in a way that is understandable to humans. This is a key part of regulatory and ethical frameworks and is directly related to addressing the black-box problem in AI.

From the AIGP ILT Participant Guide (Module on Transparency and Explainability):

''Explainability refers to the understanding of how a black-box model works. The black-box problem exists because some models are too complex for human interpretation. Explainability methods aim to provide meaningful insight into the logic and decision-making of AI systems.''

Also, according to the AI Governance in Practice Report 2025:

''Explainability refers to the representation of the underlying mechanisms of the AI system's operation... a key tenet of AI governance due to the desire to understand how AI systems are built, managed and maintained.''

Thus, while Trustworthy and Responsible AI are broader concepts,explainabilityspecifically targets the regulatory concern about understanding outputs.


Question 4

Which of the following most encourages accountability over Al systems?

Correct Answer: C. Defining the roles and responsibilities of Al stakeholders.
Explanation:

Defining the roles and responsibilities of AI stakeholders is crucial for encouraging accountability over AI systems. Clear delineation of who is responsible for different aspects of the AI lifecycle ensures that there is a person or team accountable for monitoring, maintaining, and addressing issues that arise. This accountability framework helps in ensuring that ethical standards and regulatory requirements are met, and it facilitates transparency and traceability in AI operations. By assigning specific roles, organizations can better manage and mitigate risks associated with AI deployment and use.


Question 5

What is the most important reason to document the results of AI testing?

Correct Answer: C. To create a verifiable audit trail.
Explanation:

Testing results need to bedocumented thoroughlyto ensuretraceability, accountability, and compliance. This is central to enabling audits, investigations, or regulatory inquiries into the system's development and performance.

From theAI Governance in Practice Report 2025:

''Documentation and recordkeeping are essential components... to demonstrate AI system compliance, trace system behavior, and support audits and conformity assessments.'' (p. 34--35)

''Maintaining audit trails across development and deployment enables transparency and accountability.'' (p. 12)

AandBare benefits, but not theprimary governance justification.

D-- Limiting future testing is not a recommended goal.


Question 6

Scenario:

A large multinational organization is rolling out a company-wide AI governance initiative. To build awareness and support adoption, they are evaluating different ways to train employees and stakeholders across departments, including legal, technical, marketing, and customer-facing roles.

Which of the following typical approaches is a large organization least likely to use to responsibly train stakeholders on AI terminology, strategy and governance?

Correct Answer: A. Providing all technical employees education on AI development so they can retool and participate in the development of AI systems
Explanation:

The correct answer isA. While educating technical staff is important, expectingall technical employees to be retooled as AI developersis unrealistic and not aligned with scalable governance practices.

From the AIGP ILT Guide:

'Training approaches should berole-specificand align with the individual's function and responsibilities... Organizations typically do not expect every technical role to participate in model development.'

The AI Governance in Practice Report 2025 supports tailored approaches:

''Cross-functional training should be specific to the individual's role and exposure to AI risk... Role-based education supports scalability and comprehension.''

Thus,broad development training for all technical employeesis the least practical and least likely approach.


Question 7

Why is it important that conformity requirements are satisfied before an AI system is released into production?

Correct Answer: D. To comply with legal and regulatory standards, ensuring the AI system is safe and trustworthy.
Explanation:

Conformity assessmentsare a core requirement under theEU AI Actfor high-risk systems and serve to confirm that the AI meetsregulatory, safety, and ethical standardsbefore it is put into production.

From theAI Governance in Practice Report 2025:

''Conformity assessments... ensure that systems comply with legal requirements, safety criteria, and intended purpose before being placed on the market.'' (p. 34)

''They are a critical step to demonstrate safety and trustworthiness in AI deployment.'' (p. 35)


Question 8

Your management consulting firm is planning to use an AI system to support its employees.

Which category of operator applies to the firm in this context?

Correct Answer: D. Deployer.
Explanation:

Under the EU AI Act, a deployer is a natural or legal person, public authority, agency, or other body that uses an AI system under its authority, except where the system is used in a personal, non-professional activity. The consulting firm is using an existing AI system to support its employees and is therefore acting as a deployer. It is not a provider because the scenario does not state that the firm develops the AI system, has it developed, or places it on the market under its own name or trademark. It is not a distributor because it is not making the system available in the supply chain. An authorized representative acts on behalf of a provider established outside the EU. Consequently, D correctly describes the firm's role.


Question 9

According to the GDPR's transparency principle, when an Al system processes personal data in automated decision-making, controllers are required to provide data subjects specific information on?

Correct Answer: A. The existence of automated decision-making and meaningful information on its logic and consequences.
Explanation:

The GDPR's transparency principle requires that when personal data is processed for automated decision-making, including profiling, data subjects must be informed about the existence of such automated decision-making. Additionally, they must be provided with meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for them. This requirement ensures that data subjects are fully aware of how their personal data is being used and the potential impacts, thereby promoting transparency and trust in the processing activities.


Question 10

Why is it important that conformity requirements are satisfied before an AI system is released into production?

Correct Answer: D. To comply with legal and regulatory standards, ensuring the AI system is safe and trustworthy.
Explanation:

The correct answer is D because conformity requirements are primarily intended to ensure that AI systems meet applicable legal, regulatory, and safety standards before deployment. AI governance frameworks, including the EU AI Act and international standards, require conformity assessments to verify that systems are safe, reliable, and compliant with risk management, documentation, and performance obligations. These assessments help identify and mitigate risks prior to market release, particularly for high-risk AI systems that may impact individuals' rights, health, or safety. Conformity ensures accountability, transparency, and trustworthiness, which are central principles of responsible AI governance. The other options relate to usability or technical considerations, but they do not address the primary purpose of conformity assessments, which is regulatory compliance and risk mitigation prior to deployment.


Question 11

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company's product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team's goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization's operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

Which other stakeholder groups should be involved in the selection and implementation of the Al hiring tool?

Correct Answer: A. Finance and Legal.
Explanation:

In the selection and implementation of the AI hiring tool, involving Finance and Legal is crucial. The Finance team is essential for assessing cost implications, budget considerations, and financial risks. The Legal team is necessary to ensure compliance with applicable laws and regulations, including those related to data privacy, employment, and anti-discrimination. Involving these stakeholders ensures a comprehensive evaluation of both the financial viability and legal compliance of the AI tool, mitigating potential risks and aligning with organizational objectives and regulatory requirements.


Question 12

Scenario:

A European AI technology company was found to be non-compliant with certain provisions of the EU AI Act. The regulator is considering penalties under the enforcement provisions of the regulation.

According to the EU AI Act, which of the following non-compliance examples could lead to fines of up to 15 million or 3% of annual worldwide turnover(whichever is higher)?

Correct Answer: B. In case of breach of a provider's obligations for high-risk AI systems
Explanation:

The correct answer isB. The EU AI Act assigns atiered penalty systembased on the severity of the violation. A breach ofobligations related to high-risk AI systemsfalls into the mid-tier category, triggering fines of 15 million or 3% of annual global turnover.

From the AIGP ILT Guide -- EU AI Act Module:

''Providers of high-risk AI systems must comply with strict documentation, testing, monitoring, and registration obligations. Breaches of these result in significant fines of up to 15 million or 3% of turnover.''

AI Governance in Practice Report 2025 supports this:

''Non-compliance with obligations under Title III (high-risk systems) leads to financial penalties under Article 71(3) of the EU AI Act.''

Note: Thehighest penalty (35 million or 7%)applies toprohibited AI uses, not to obligations for high-risk systems.


Question 13

A deployer discovers that a high-risk AI recruiting system has been making widespread errors, resulting in harms to the rights of a considerable number of EU residents who are denied consideration for jobs for improper reasons such as ethnicity, gender and age.

According to the EU AI Act, what should the company do first?

Correct Answer: A. Notify the provider, the distributor, and finally the relevant market authority of the serious incident.
Explanation:

Under theEU AI Act, serious incidents involvinghigh-risk AI systemsmust be reported. The deployer is required topromptly inform the provider and relevant authoritiesabout the issue.

From theAI Governance in Practice Report 2025:

''Serious incidents involving high-risk systems... must be reported to the provider and relevant market surveillance authority.'' (p. 35)

''Timely reporting is required when AI systems result in or may result in violations of fundamental rights.'' (p. 35)


Question 14

You are the chief privacy officer of a medical research company that would like to collect and use sensitive data about cancer patients, such as their names, addresses, race and ethnic origin, medical histories, insurance claims, pharmaceutical prescriptions, eating and drinking habits and physical activity.

The company will use this sensitive data to build an Al algorithm that will spot common attributes that will help predict if seemingly healthy people are more likely to get cancer. However, the company is unable to obtain consent from enough patients to sufficiently collect the minimum data to train its model.

Which of the following solutions would most efficiently balance privacy concerns with the lack of available data during the testing phase?

Correct Answer: C. Utilize synthetic data to offset the lack of patient data.
Explanation:

Utilizing synthetic data to offset the lack of patient data is an efficient solution that balances privacy concerns with the need for sufficient data to train the model. Synthetic data can be generated to simulate real patient data while avoiding the privacy issues associated with using actual patient data. This approach allows for the development and testing of the AI algorithm without compromising patient privacy, and it can be refined with real data as it becomes available. Reference: AIGP Body of Knowledge on Data Privacy and AI Model Training.


Question 15

What is the best method to proactively train an LLM so that there is mathematical proof that no specific piece of training data has more than a negligible effect on the model or its output?

Correct Answer: C. Differential privacy.
Explanation:

Differential privacy is a technique used to ensure that the inclusion or exclusion of a single data point does not significantly affect the outcome of any analysis, providing a way to mathematically prove that no specific piece of training data has more than a negligible effect on the model or its output. This is achieved by introducing randomness into the data or the algorithms processing the data. In the context of training large language models (LLMs), differential privacy helps in protecting individual data points while still enabling the model to learn effectively. By adding noise to the training process, differential privacy provides strong guarantees about the privacy of the training data.