A standalone, integrated practice exam of multi-concept scenarios spanning the complete 24-week syllabus and testing practitioner judgement.
Time remaining90:00
01
A multilingual benefits-enquiry assistant uses enterprise RAG over policy and claimant documents, summarises uploaded evidence, and recommends a case routing that a caseworker can accept or change. Who most clearly counts as an 'affected person' in this scenario?
02
In the same scenario, the caseworker remains formally responsible for the final decision but always accepts the AI's routing without reviewing the underlying evidence. What governance risk does this illustrate?
03
The retrieval corpus for this assistant contains both official policy and claimant-submitted documents, and performance varies noticeably by language. What is the most appropriate immediate governance response before scaling?
04
A supplier plans to update the underlying model during the pilot phase. What is the strongest contractual and governance safeguard against this introducing unassessed risk?
05
A credit union's AI affordability tool recommends 'decline' for an applicant with no human review before the applicant is notified. Under UK GDPR Article 22A–22D, what must be assessed first?
06
A recruitment platform operating in the EU auto-rejects candidates below a configurable score threshold with no human review. Under the EU AI Act, this use case most likely falls into which category, and why?
07
For that same recruitment platform, the company that built and markets it under its own name is best classified as which actor?
08
A claims-triage insurer wants one proportionate AI governance operating model across financial, healthcare-adjacent and internal-copilot use cases. What is the most defensible design principle?
09
During due diligence, a vendor cannot confirm whether customer prompts are used to further train its model, nor its data retention period. What should this gap trigger?
10
A model card for a deployed fraud-triage model is six months old and does not reflect a recent supplier-side update. An assurance reviewer is asked whether the system is ready to scale from 2 to 12 sites. What is the most defensible conclusion?
11
A HR chatbot occasionally invents a policy that does not exist in the source handbook when asked an edge-case question. What is the most direct control to reduce this specific risk?
12
A public housing authority's AI tool prioritises repair requests using tenant descriptions and uploaded images. Analysis shows the tool may infer urgency partly from writing style, which correlates with English proficiency. What is the most appropriate next step?
13
An internal audit team wants to confirm that a claimed monthly control — 'a reviewer checks a sample of AI-assisted decisions' — actually happened for the last quarter. Which evidence is strongest?
14
A generative copilot used internally by customer-service staff is found to have received pasted customer personal data directly into free-text prompts. Which is the most complete governance response?
15
A model is measured with 91% overall accuracy but a 3x higher false-decline rate for one age group in a lending use case. Applying the risk mitigation hierarchy, what should be evaluated before considering 'accept'?
16
An AI agent embedded in a finance workflow can initiate payments above a threshold without further approval. A red-team test shows a crafted document can manipulate the agent into approving a fraudulent payment. What combination of controls is most appropriate?
17
A DPIA screening for a new AI-driven eligibility tool concludes the processing is likely high risk due to profiling of a large-scale, vulnerable population. What is the correct next step?
18
Which statement best reflects how ISO/IEC 42001, NIST AI RMF and the EU AI Act relate to each other in practice for an organisation operating internationally?
19
A vendor's contract is silent on what happens if the organisation needs to exit the relationship and migrate to another AI provider. What risk does this create?
20
A model card states the system's intended use is 'general customer support' but the deployment team is using it for medical symptom triage. What is the most accurate governance conclusion?
21
Which best distinguishes an inherent risk from a residual risk in a risk register entry for an AI system?
22
A company's AI incident response plan has never been tested. During a live incident where a chatbot leaked another customer's data, the team is unsure who has authority to trigger a kill switch. What does this reveal?
23
A practitioner is asked in a viva: 'Why not just rely on the vendor's claim that their model is unbiased?' What is the strongest answer?
24
A scenario question describes a system with many technical details but the actual decision turns on who is accountable for a launch decision under incomplete evidence. What is the best exam strategy here?
25
Which best describes the relationship between 'transparency' and 'explainability' as distinct but related concepts?
26
A company wants evidence that its 'human review' step is not just theatre. Which test result would most convincingly demonstrate meaningful oversight?
27
A regulator asks why an organisation classified its recruitment tool as 'limited risk' rather than 'high-risk' under the EU AI Act. Which answer reflects sound practitioner judgement?
28
Comparing an open-source self-hosted model to a proprietary hosted API for a sensitive internal use case, which factor most favours self-hosting?
29
A capstone evidence pack is being assembled for a final approval decision. Which combination best reflects what a defensible pack should contain?