AI foundations, responsible AI and harm, GRC basics, and the wider legal landscape — scenario-based questions drawn from real practitioner situations.
Time remaining40:00
01
A bank's contact centre uses a hosted foundation model to draft reply emails, which a general-purpose classifier then routes into one of six queues before a human sends anything. Which statement about this arrangement is most accurate?
02
A vendor pitches a 'small, single-purpose' fraud-scoring model against a 'large, general-purpose' foundation model for the same task. What is the most defensible governance question to ask first?
03
A chatbot confidently states a policy that does not exist in any source document. This is best described as:
04
A retrieval-augmented generation (RAG) system answers questions using a company's internal wiki. Compared to fine-tuning the model on the same wiki, what is the main governance advantage of RAG?
05
An AI agent is given the ability to call a CRM API and send email on a person's behalf. Compared to a simple chatbot, what new governance concern does this introduce?
06
A company buys access to a third-party foundation model via API and builds a recruitment product on top of it. In this relationship, the company is best described as:
07
Which pairing correctly orders these concepts from broadest to narrowest?
08
A model is trained on labelled examples of 'fraudulent' and 'legitimate' transactions. This is an example of:
09
During training, a model's weights are adjusted on historical data. During inference, the same model is used live on a new applicant's data. Which statement is correct?
10
A caseworker relies on an AI recommendation without independently reviewing the underlying evidence, even when it looks unusual. This tendency is best described as:
11
A student-support tool assigns a 'risk' label to some learners. Some learners never see the label but tutors change how they treat those learners because of it. Who is an 'affected person' in this scenario?
12
A hiring tool rejects candidates from one demographic group at twice the rate of others, even though overall accuracy is 90%. What is the most accurate governance conclusion?
13
Which pair correctly distinguishes 'harm' from 'risk'?
14
A frontline decision using an AI score results in an unfair rejection for one applicant. A separate concern is that many such rejections, repeated across a sector, could erode public trust in automated lending generally. The second concern is best classified as:
15
A team is deciding whether a moderate-probability, high-severity harm should block a product launch. Using the risk mitigation hierarchy, which option should be considered before 'accept'?
16
Which best distinguishes governance from risk management, in the GRC sense?
17
A control owner is different from a risk owner because:
18
An AI product team wants to launch generated marketing copy that closely echoes a competitor's trademarked slogan, reuses licensed images without checking terms, and personalises pricing using inferred protected characteristics. Why is a privacy review alone insufficient here?