Weeks 1–4

Checkpoint 1

AI foundations, responsible AI and harm, GRC basics, and the wider legal landscape — scenario-based questions drawn from real practitioner situations.

Time remaining40:00
01

A bank's contact centre uses a hosted foundation model to draft reply emails, which a general-purpose classifier then routes into one of six queues before a human sends anything. Which statement about this arrangement is most accurate?

Question 1: A bank's contact centre uses a hosted foundation model to draft reply emails, which a general-purpose classifier then routes into one of six queues before a human sends anything. Which statement about this arrangement is most accurate?
02

A vendor pitches a 'small, single-purpose' fraud-scoring model against a 'large, general-purpose' foundation model for the same task. What is the most defensible governance question to ask first?

Question 2: A vendor pitches a 'small, single-purpose' fraud-scoring model against a 'large, general-purpose' foundation model for the same task. What is the most defensible governance question to ask first?
03

A chatbot confidently states a policy that does not exist in any source document. This is best described as:

Question 3: A chatbot confidently states a policy that does not exist in any source document. This is best described as:
04

A retrieval-augmented generation (RAG) system answers questions using a company's internal wiki. Compared to fine-tuning the model on the same wiki, what is the main governance advantage of RAG?

Question 4: A retrieval-augmented generation (RAG) system answers questions using a company's internal wiki. Compared to fine-tuning the model on the same wiki, what is the main governance advantage of RAG?
05

An AI agent is given the ability to call a CRM API and send email on a person's behalf. Compared to a simple chatbot, what new governance concern does this introduce?

Question 5: An AI agent is given the ability to call a CRM API and send email on a person's behalf. Compared to a simple chatbot, what new governance concern does this introduce?
06

A company buys access to a third-party foundation model via API and builds a recruitment product on top of it. In this relationship, the company is best described as:

Question 6: A company buys access to a third-party foundation model via API and builds a recruitment product on top of it. In this relationship, the company is best described as:
07

Which pairing correctly orders these concepts from broadest to narrowest?

Question 7: Which pairing correctly orders these concepts from broadest to narrowest?
08

A model is trained on labelled examples of 'fraudulent' and 'legitimate' transactions. This is an example of:

Question 8: A model is trained on labelled examples of 'fraudulent' and 'legitimate' transactions. This is an example of:
09

During training, a model's weights are adjusted on historical data. During inference, the same model is used live on a new applicant's data. Which statement is correct?

Question 9: During training, a model's weights are adjusted on historical data. During inference, the same model is used live on a new applicant's data. Which statement is correct?
10

A caseworker relies on an AI recommendation without independently reviewing the underlying evidence, even when it looks unusual. This tendency is best described as:

Question 10: A caseworker relies on an AI recommendation without independently reviewing the underlying evidence, even when it looks unusual. This tendency is best described as:
11

A student-support tool assigns a 'risk' label to some learners. Some learners never see the label but tutors change how they treat those learners because of it. Who is an 'affected person' in this scenario?

Question 11: A student-support tool assigns a 'risk' label to some learners. Some learners never see the label but tutors change how they treat those learners because of it. Who is an 'affected person' in this scenario?
12

A hiring tool rejects candidates from one demographic group at twice the rate of others, even though overall accuracy is 90%. What is the most accurate governance conclusion?

Question 12: A hiring tool rejects candidates from one demographic group at twice the rate of others, even though overall accuracy is 90%. What is the most accurate governance conclusion?
13

Which pair correctly distinguishes 'harm' from 'risk'?

Question 13: Which pair correctly distinguishes 'harm' from 'risk'?
14

A frontline decision using an AI score results in an unfair rejection for one applicant. A separate concern is that many such rejections, repeated across a sector, could erode public trust in automated lending generally. The second concern is best classified as:

Question 14: A frontline decision using an AI score results in an unfair rejection for one applicant. A separate concern is that many such rejections, repeated across a sector, could erode public trust in automated lending generally. The second concern is best classified as:
15

A team is deciding whether a moderate-probability, high-severity harm should block a product launch. Using the risk mitigation hierarchy, which option should be considered before 'accept'?

Question 15: A team is deciding whether a moderate-probability, high-severity harm should block a product launch. Using the risk mitigation hierarchy, which option should be considered before 'accept'?
16

Which best distinguishes governance from risk management, in the GRC sense?

Question 16: Which best distinguishes governance from risk management, in the GRC sense?
17

A control owner is different from a risk owner because:

Question 17: A control owner is different from a risk owner because:
18

An AI product team wants to launch generated marketing copy that closely echoes a competitor's trademarked slogan, reuses licensed images without checking terms, and personalises pricing using inferred protected characteristics. Why is a privacy review alone insufficient here?

Question 18: An AI product team wants to launch generated marketing copy that closely echoes a competitor's trademarked slogan, reuses licensed images without checking terms, and personalises pricing using inferred protected characteristics. Why is a privacy review alone insufficient here?
Exam centre