200 QUESTIONS · ALL 24 WEEKS

Complete question bank

The full 200-question bank covering all 24 weeks. Untimed, comprehensive and intended for deep revision. Questions are original practice material aligned to this course syllabus; they are not copied from, endorsed by or represented as questions from an official certification exam.

01
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

Which actor role fits 'the organisation putting a system into use under its own authority, without further marketing it'?

Question 1: Which actor role fits 'the organisation putting a system into use under its own authority, without further marketing it'?
02
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

What is COSO, in one sentence?

Question 2: What is COSO, in one sentence?
03
WEEK 6 · NIST AI RMF · NIST GOVERN

What's a realistic consequence of poor supplier governance?

Question 3: What's a realistic consequence of poor supplier governance?
04
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

What is the purpose of 'monitoring' under Clause 9, distinct from a one-off pre-launch test?

Question 4: What is the purpose of 'monitoring' under Clause 9, distinct from a one-off pre-launch test?
05
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

What does 'AI control maturity' generally describe?

Question 5: What does 'AI control maturity' generally describe?
06
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

Which best distinguishes governance from risk management?

Question 6: Which best distinguishes governance from risk management?
07
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What is the purpose of an 'exceptions and waivers' process?

Question 7: What is the purpose of an 'exceptions and waivers' process?
08
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

What is a 'foundation model'?

Question 8: What is a 'foundation model'?
09
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Clause 4 requires understanding which two categories of issues?

Question 9: Clause 4 requires understanding which two categories of issues?
10
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

A 'localisation/geographic restriction policy' addresses:

Question 10: A 'localisation/geographic restriction policy' addresses:
11
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

What is a shared theme across South Korea, US state-level and Canadian AI governance approaches, per this course?

Question 11: What is a shared theme across South Korea, US state-level and Canadian AI governance approaches, per this course?
12
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What defines an 'AI agent' as distinct from a standard chatbot?

Question 12: What defines an 'AI agent' as distinct from a standard chatbot?
13
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

What is the purpose of 'AIMS processes' as referenced in Clause 4, beyond simply listing issues and parties?

Question 13: What is the purpose of 'AIMS processes' as referenced in Clause 4, beyond simply listing issues and parties?
14
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

A supplier's model was trained on scraped web content without clear licensing. This primarily raises a concern under:

Question 14: A supplier's model was trained on scraped web content without clear licensing. This primarily raises a concern under:
15
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

What does DPIA screening determine?

Question 15: What does DPIA screening determine?
16
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Which is the best way to describe the relationship between Clause 4 scoping work and later Clause 8 operational controls?

Question 16: Which is the best way to describe the relationship between Clause 4 scoping work and later Clause 8 operational controls?
17
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

What's the risk of treating '87% accuracy' as sufficient evidence of fairness in an exam answer?

Question 17: What's the risk of treating '87% accuracy' as sufficient evidence of fairness in an exam answer?
18
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Why does 'regulatory evidence preservation' matter even years after a high-risk system was first placed on the market?

Question 18: Why does 'regulatory evidence preservation' matter even years after a high-risk system was first placed on the market?
19
WEEK 8 · NIST AI RMF · NIST MEASURE

What's the risk of setting acceptance criteria only after seeing initial test results?

Question 19: What's the risk of setting acceptance criteria only after seeing initial test results?
20
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

'Source quality' as a RAG risk refers to:

Question 20: 'Source quality' as a RAG risk refers to:
21
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

Segregation of duties in AI governance most directly reduces the risk of:

Question 21: Segregation of duties in AI governance most directly reduces the risk of:
22
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

What is an 'authorised representative' under the EU AI Act?

Question 22: What is an 'authorised representative' under the EU AI Act?
23
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

What should drive EU AI Act risk classification first?

Question 23: What should drive EU AI Act risk classification first?
24
WEEK 7 · NIST AI RMF · NIST MAP

'Deployment environment' in MAP includes:

Question 24: 'Deployment environment' in MAP includes:
25
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

In financial services AI, what does 'model risk management' specifically address?

Question 25: In financial services AI, what does 'model risk management' specifically address?
26
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

What does the Act's 'cybersecurity' obligation for high-risk systems primarily address?

Question 26: What does the Act's 'cybersecurity' obligation for high-risk systems primarily address?
27
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

A recruitment vendor's fairness testing only used labour-market data from one country. What's the practitioner concern if the tool is deployed elsewhere?

Question 27: A recruitment vendor's fairness testing only used labour-market data from one country. What's the practitioner concern if the tool is deployed elsewhere?
28
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

A control says data will be 'reviewed periodically'. What's missing to make this a real control?

Question 28: A control says data will be 'reviewed periodically'. What's missing to make this a real control?
29
WEEK 8 · NIST AI RMF · NIST MEASURE

'Human oversight testing' evaluates:

Question 29: 'Human oversight testing' evaluates:
30
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

How does this week's syllabus explicitly frame the alignment between ISO Clause 5/6 and NIST AI RMF?

Question 30: How does this week's syllabus explicitly frame the alignment between ISO Clause 5/6 and NIST AI RMF?
31
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

Why is 'governance vs management' a common source of confusion in practice?

Question 31: Why is 'governance vs management' a common source of confusion in practice?
32
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

'Credit and lending fairness' as a legal concern most directly relates to:

Question 32: 'Credit and lending fairness' as a legal concern most directly relates to:
33
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

Which best distinguishes accuracy from fairness?

Question 33: Which best distinguishes accuracy from fairness?
34
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

What does 'evidence' mean in a GRC context?

Question 34: What does 'evidence' mean in a GRC context?
35
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

An AI triage tool helps decide which emergency department patients are seen first. What's the key practitioner question about its accuracy failures?

Question 35: An AI triage tool helps decide which emergency department patients are seen first. What's the key practitioner question about its accuracy failures?
36
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What should an 'assurance dashboard' primarily show?

Question 36: What should an 'assurance dashboard' primarily show?
37
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

How should 'procured' versus 'internally built' AI systems be treated differently, if at all, in Clause 4 scoping?

Question 37: How should 'procured' versus 'internally built' AI systems be treated differently, if at all, in Clause 4 scoping?
38
WEEK 6 · NIST AI RMF · NIST GOVERN

What is the purpose of 'AI literacy and training' as a GOVERN activity?

Question 38: What is the purpose of 'AI literacy and training' as a GOVERN activity?
39
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

'Professional negligence' is most relevant to AI when:

Question 39: 'Professional negligence' is most relevant to AI when:
40
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

Why is 'clinical decision support' distinguished from 'diagnosis' in healthcare AI governance?

Question 40: Why is 'clinical decision support' distinguished from 'diagnosis' in healthcare AI governance?
41
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What is the difference between a control test and a walkthrough?

Question 41: What is the difference between a control test and a walkthrough?
42
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

In LLM application architecture, what's the difference between a system prompt and a user prompt?

Question 42: In LLM application architecture, what's the difference between a system prompt and a user prompt?
43
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

'Overreliance' as an LLM risk means:

Question 43: 'Overreliance' as an LLM risk means:
44
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why do 'agent permissions' and 'tool permissions' need to be scoped narrowly?

Question 44: Why do 'agent permissions' and 'tool permissions' need to be scoped narrowly?
45
WEEK 6 · NIST AI RMF · NIST GOVERN

Why does 'AI ownership' need to be distinct from general IT ownership?

Question 45: Why does 'AI ownership' need to be distinct from general IT ownership?
46
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What is the main risk of an agent being given broad, standing permissions 'just in case' rather than scoped, task-specific ones?

Question 46: What is the main risk of an agent being given broad, standing permissions 'just in case' rather than scoped, task-specific ones?
47
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

A non-EU company's AI product is never sold in the EU, but its output is used by an EU-based customer who receives services generated by it. Could EU AI Act obligations still be relevant?

Question 47: A non-EU company's AI product is never sold in the EU, but its output is used by an EU-based customer who receives services generated by it. Could EU AI Act obligations still be relevant?
48
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

Which sector is most associated with statutory 'equality impact' duties in this course's coverage?

Question 48: Which sector is most associated with statutory 'equality impact' duties in this course's coverage?
49
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

What should a 'final improvement plan' contain to be useful, rather than a generic statement?

Question 49: What should a 'final improvement plan' contain to be useful, rather than a generic statement?
50
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

Why are 'vulnerable groups' given specific attention in AI and privacy guidance?

Question 50: Why are 'vulnerable groups' given specific attention in AI and privacy guidance?
51
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

How should 'information and communication' differ for staff versus the board?

Question 51: How should 'information and communication' differ for staff versus the board?
52
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What's the difference between certification and implementation?

Question 52: What's the difference between certification and implementation?
53
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

An AI product giving unsafe advice (e.g. on medication dosage) primarily engages which combination of legal domains?

Question 53: An AI product giving unsafe advice (e.g. on medication dosage) primarily engages which combination of legal domains?
54
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Why does AI governance exist at all?

Question 54: Why does AI governance exist at all?
55
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

Why might 'geographic restriction' be a more proportionate response than full deactivation?

Question 55: Why might 'geographic restriction' be a more proportionate response than full deactivation?
56
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Why is 'evidence preservation' relevant to both Clause 9 (evaluation) and later external scrutiny (e.g. audit or regulatory review)?

Question 56: Why is 'evidence preservation' relevant to both Clause 9 (evaluation) and later external scrutiny (e.g. audit or regulatory review)?
57
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why do 'tool permissions' need periodic review, not just a one-time setup?

Question 57: Why do 'tool permissions' need periodic review, not just a one-time setup?
58
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

Risk tolerance is best described as:

Question 58: Risk tolerance is best described as:
59
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Which best describes 'needs and expectations' of interested parties in Clause 4 terms?

Question 59: Which best describes 'needs and expectations' of interested parties in Clause 4 terms?
60
WEEK 8 · NIST AI RMF · NIST MEASURE

What is a 'benchmark' in AI testing?

Question 60: What is a 'benchmark' in AI testing?
61
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

The OECD principle 'transparency and explainability' emphasises:

Question 61: The OECD principle 'transparency and explainability' emphasises:
62
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

What's the relationship between control activities and risk appetite?

Question 62: What's the relationship between control activities and risk appetite?
63
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

An AI agent with CRM and email tool access is asked, via a crafted prompt embedded in a customer message, to 'forward this thread to an external address.' What control most directly reduces this risk?

Question 63: An AI agent with CRM and email tool access is asked, via a crafted prompt embedded in a customer message, to 'forward this thread to an external address.' What control most directly reduces this risk?
64
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Which best reflects how 'control maturity' typically progresses across stages such as initial, developing, defined, managed and optimising?

Question 64: Which best reflects how 'control maturity' typically progresses across stages such as initial, developing, defined, managed and optimising?
65
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Why do GPAI providers face obligations around a 'copyright policy'?

Question 65: Why do GPAI providers face obligations around a 'copyright policy'?
66
WEEK 6 · NIST AI RMF · NIST GOVERN

What is the primary purpose of the GOVERN function?

Question 66: What is the primary purpose of the GOVERN function?
67
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

What is the 'second line' in the three lines of defence model?

Question 67: What is the 'second line' in the three lines of defence model?
68
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

How should a confirmed incident feed back into MANAGE's broader risk treatment process?

Question 68: How should a confirmed incident feed back into MANAGE's broader risk treatment process?
69
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Why are affected people treated as interested parties rather than just 'users'?

Question 69: Why are affected people treated as interested parties rather than just 'users'?
70
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What belongs in the 'retirement' stage of the AI lifecycle?

Question 70: What belongs in the 'retirement' stage of the AI lifecycle?
71
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

An umbrella (protection against a likely, low-severity event — rain) is often used to illustrate which risk concept?

Question 71: An umbrella (protection against a likely, low-severity event — rain) is often used to illustrate which risk concept?
72
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

A model quietly moving from 'decision support' to being treated as an automatic decision-maker illustrates a bias/harm risk at which lifecycle stage?

Question 72: A model quietly moving from 'decision support' to being treated as an automatic decision-maker illustrates a bias/harm risk at which lifecycle stage?
73
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

Why should review time be deliberately reserved at the end of a timed exam, not just used for the last question?

Question 73: Why should review time be deliberately reserved at the end of a timed exam, not just used for the last question?
74
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What does 'AIMS' stand for and mean?

Question 74: What does 'AIMS' stand for and mean?
75
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Who is the 'provider' in the AI actor model?

Question 75: Who is the 'provider' in the AI actor model?
76
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

Why does US AI governance activity, per this course, include both federal and state-level components?

Question 76: Why does US AI governance activity, per this course, include both federal and state-level components?
77
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

Why might an outdated document being used in a chatbot's answer be worse than the chatbot admitting it doesn't know?

Question 77: Why might an outdated document being used in a chatbot's answer be worse than the chatbot admitting it doesn't know?
78
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

Why does 'access control' matter specifically for enterprise RAG copilots?

Question 78: Why does 'access control' matter specifically for enterprise RAG copilots?
79
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

What is a realistic early-warning 'risk indicator' MANAGE might monitor after release?

Question 79: What is a realistic early-warning 'risk indicator' MANAGE might monitor after release?
80
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

'Release gates' in MANAGE function as:

Question 80: 'Release gates' in MANAGE function as:
81
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

Which trigger would most likely require a DPIA screening at intake?

Question 81: Which trigger would most likely require a DPIA screening at intake?
82
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Which is a provider obligation for a high-risk system, distinct from a deployer obligation?

Question 82: Which is a provider obligation for a high-risk system, distinct from a deployer obligation?
83
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What is the risk of an organisation writing an AI policy that simply copies another company's publicly available policy verbatim?

Question 83: What is the risk of an organisation writing an AI policy that simply copies another company's publicly available policy verbatim?
84
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

Which best reflects why 'scope' matters as a foundational EU AI Act concept before classification questions?

Question 84: Which best reflects why 'scope' matters as a foundational EU AI Act concept before classification questions?
85
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

Why does this course emphasise that 'AI law is broader than privacy'?

Question 85: Why does this course emphasise that 'AI law is broader than privacy'?
86
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

Why does 'how ISO 42001 supports governance system design' matter for a multi-site organisation?

Question 86: Why does 'how ISO 42001 supports governance system design' matter for a multi-site organisation?
87
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Clause 7 (Support) primarily covers:

Question 87: Clause 7 (Support) primarily covers:
88
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

Which lawful basis is most likely appropriate for processing necessary to decide whether to enter a loan contract a customer has requested?

Question 88: Which lawful basis is most likely appropriate for processing necessary to decide whether to enter a loan contract a customer has requested?
89
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

What should a well-written approval recommendation include?

Question 89: What should a well-written approval recommendation include?
90
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

Why does 'record keeping' matter as a distinct legal concern for AI systems?

Question 90: Why does 'record keeping' matter as a distinct legal concern for AI systems?
91
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What does 'inspection' mean as an evidence-gathering method?

Question 91: What does 'inspection' mean as an evidence-gathering method?
92
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

What would a 'right of access' request typically entitle someone to, regarding an AI-scored decision about them?

Question 92: What would a 'right of access' request typically entitle someone to, regarding an AI-scored decision about them?
93
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

A retailer in the supply chain makes a high-risk AI system available on the EU market without being the original provider or importer. Which role does this describe?

Question 93: A retailer in the supply chain makes a high-risk AI system available on the EU market without being the original provider or importer. Which role does this describe?
94
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

What's the best first step when reading a long scenario question?

Question 94: What's the best first step when reading a long scenario question?
95
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Under the updated timeline enacted via the EU's 'Digital Omnibus' in 2026, when do Annex III high-risk use case obligations generally apply?

Question 95: Under the updated timeline enacted via the EU's 'Digital Omnibus' in 2026, when do Annex III high-risk use case obligations generally apply?
96
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

Between a small, single-purpose model and a large, general-purpose model, which factor most matters for a narrow, well-defined task?

Question 96: Between a small, single-purpose model and a large, general-purpose model, which factor most matters for a narrow, well-defined task?
97
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

What should a plain-language AI privacy notice for an automated decision include?

Question 97: What should a plain-language AI privacy notice for an automated decision include?
98
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What does an 'audit trail' for an agent enable that a simple output log does not?

Question 98: What does an 'audit trail' for an agent enable that a simple output log does not?
99
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

How does 'fairness' as a UK GDPR principle differ from simply having a lawful basis for processing?

Question 99: How does 'fairness' as a UK GDPR principle differ from simply having a lawful basis for processing?
100
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

Which vendor contract term most directly addresses the supplier's right to inspect or verify compliance claims?

Question 100: Which vendor contract term most directly addresses the supplier's right to inspect or verify compliance claims?
101
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

Sector regulation for a financial services AI tool would most likely add requirements around:

Question 101: Sector regulation for a financial services AI tool would most likely add requirements around:
102
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

Why might an organisation use NIST AI RMF even where it isn't legally required?

Question 102: Why might an organisation use NIST AI RMF even where it isn't legally required?
103
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Relying entirely on a supplier's unverified claim of 'no bias' is a gap in which Annex A theme?

Question 103: Relying entirely on a supplier's unverified claim of 'no bias' is a gap in which Annex A theme?
104
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

Which best describes Canada's general direction in AI governance, as covered by this course's global landscape material?

Question 104: Which best describes Canada's general direction in AI governance, as covered by this course's global landscape material?
105
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Which is a practical example of 'documented information' required under Clause 7 for an operating AI system?

Question 105: Which is a practical example of 'documented information' required under Clause 7 for an operating AI system?
106
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What's a reasonable trigger for a 'security review' at intake?

Question 106: What's a reasonable trigger for a 'security review' at intake?
107
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

Which is a leadership responsibility under Clause 5, not a purely operational task?

Question 107: Which is a leadership responsibility under Clause 5, not a purely operational task?
108
WEEK 8 · NIST AI RMF · NIST MEASURE

What is the difference between a false positive and a false negative in a fraud-detection model, and why does MEASURE care about the distinction?

Question 108: What is the difference between a false positive and a false negative in a fraud-detection model, and why does MEASURE care about the distinction?
109
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Why is 'documenting scope' considered a defensibility issue, not just an administrative one?

Question 109: Why is 'documenting scope' considered a defensibility issue, not just an administrative one?
110
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

A control's override log exists but has never been reviewed. What does this most likely indicate?

Question 110: A control's override log exists but has never been reviewed. What does this most likely indicate?
111
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

The 'green apple bias' example is typically used to illustrate:

Question 111: The 'green apple bias' example is typically used to illustrate:
112
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

Which best distinguishes design effectiveness from operating effectiveness?

Question 112: Which best distinguishes design effectiveness from operating effectiveness?
113
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What's the difference between 'risk acceptance' and simply ignoring a risk?

Question 113: What's the difference between 'risk acceptance' and simply ignoring a risk?
114
WEEK 7 · NIST AI RMF · NIST MAP

'External dependencies' in MAP is broader than 'supplier dependencies' because it also includes:

Question 114: 'External dependencies' in MAP is broader than 'supplier dependencies' because it also includes:
115
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

What is the primary purpose of the MANAGE function?

Question 115: What is the primary purpose of the MANAGE function?
116
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Why would 'supplier controls' appear within Clause 8 operation rather than only in Annex A's third-party theme?

Question 116: Why would 'supplier controls' appear within Clause 8 operation rather than only in Annex A's third-party theme?
117
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

Which of these is one of NIST's listed trustworthy AI characteristics?

Question 117: Which of these is one of NIST's listed trustworthy AI characteristics?
118
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What's a key governance trade-off between hosted and self-hosted deployment?

Question 118: What's a key governance trade-off between hosted and self-hosted deployment?
119
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What is the purpose of an integrated AI governance lifecycle?

Question 119: What is the purpose of an integrated AI governance lifecycle?
120
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

How should planning under Clause 6 treat a newly identified AI risk discovered mid-cycle, rather than at the original planning point?

Question 120: How should planning under Clause 6 treat a newly identified AI risk discovered mid-cycle, rather than at the original planning point?
121
WEEK 7 · NIST AI RMF · NIST MAP

Which best reflects the relationship between MAP and MEASURE?

Question 121: Which best reflects the relationship between MAP and MEASURE?
122
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Why does the Act distinguish 'training data', 'validation data' and 'testing data' as separate governance concerns?

Question 122: Why does the Act distinguish 'training data', 'validation data' and 'testing data' as separate governance concerns?
123
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

A leader says: 'We just follow the law, we don't need frameworks.' What's the issue with this view?

Question 123: A leader says: 'We just follow the law, we don't need frameworks.' What's the issue with this view?
124
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What should a management action plan for a finding always include?

Question 124: What should a management action plan for a finding always include?
125
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

An 84% 'overall accuracy' figure for a learner engagement score says what about fairness across student groups?

Question 125: An 84% 'overall accuracy' figure for a learner engagement score says what about fairness across student groups?
126
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

Which best distinguishes the role of an AI governance board from an operational AI ethics working group, where both exist?

Question 126: Which best distinguishes the role of an AI governance board from an operational AI ethics working group, where both exist?
127
WEEK 6 · NIST AI RMF · NIST GOVERN

What distinguishes 'model ownership' from 'product ownership' in AI governance?

Question 127: What distinguishes 'model ownership' from 'product ownership' in AI governance?
128
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

What does 'NIST' stand for?

Question 128: What does 'NIST' stand for?
129
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

A hospital AI tool recommends a treatment priority but a clinician always follows it without independent judgement. What sector-specific issue does this raise?

Question 129: A hospital AI tool recommends a treatment priority but a clinician always follows it without independent judgement. What sector-specific issue does this raise?
130
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

Which two sectors in this week's coverage most explicitly require attention to how automated decisions affect vulnerable or differently-situated groups?

Question 130: Which two sectors in this week's coverage most explicitly require attention to how automated decisions affect vulnerable or differently-situated groups?
131
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

What is an audit trail for, in practical terms?

Question 131: What is an audit trail for, in practical terms?
132
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Which best orders these from broadest to narrowest?

Question 132: Which best orders these from broadest to narrowest?
133
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

Why is 'human review vs rubber-stamping' a recurring theme across both ISO/IEC 42001 oversight controls and UK GDPR ADM safeguards?

Question 133: Why is 'human review vs rubber-stamping' a recurring theme across both ISO/IEC 42001 oversight controls and UK GDPR ADM safeguards?
134
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

Which RMF function establishes intended use, context and risk scenarios?

Question 134: Which RMF function establishes intended use, context and risk scenarios?
135
WEEK 7 · NIST AI RMF · NIST MAP

What does MAP's 'context' work primarily protect against?

Question 135: What does MAP's 'context' work primarily protect against?
136
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

A company documents its AIMS scope, policy and objectives but has never run an impact assessment on any deployed system. Which standard's practice is missing?

Question 136: A company documents its AIMS scope, policy and objectives but has never run an impact assessment on any deployed system. Which standard's practice is missing?
137
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

Why does an evidence-pack index need to state each artefact's relevance to the final decision, not just its title?

Question 137: Why does an evidence-pack index need to state each artefact's relevance to the final decision, not just its title?
138
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

How should 'business context' under Clause 4 reflect a new strategic AI initiative the organisation is about to launch?

Question 138: How should 'business context' under Clause 4 reflect a new strategic AI initiative the organisation is about to launch?
139
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Which best distinguishes a hosted open-source model from a paid vendor API model?

Question 139: Which best distinguishes a hosted open-source model from a paid vendor API model?
140
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Which best reflects the relationship between 'quality management system' (QMS) obligations and technical documentation?

Question 140: Which best reflects the relationship between 'quality management system' (QMS) obligations and technical documentation?
141
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

What does 'AI actor' terminology, as covered under 22989-style vocabulary, help clarify?

Question 141: What does 'AI actor' terminology, as covered under 22989-style vocabulary, help clarify?
142
WEEK 6 · NIST AI RMF · NIST GOVERN

Which is the best example of a 'developer' role, distinct from 'provider'?

Question 142: Which is the best example of a 'developer' role, distinct from 'provider'?
143
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Why does timely 'serious incident reporting' matter beyond simply satisfying a legal box-ticking requirement?

Question 143: Why does timely 'serious incident reporting' matter beyond simply satisfying a legal box-ticking requirement?
144
WEEK 6 · NIST AI RMF · NIST GOVERN

In the developer/provider/deployer/user responsibility mapping, who is the 'deployer'?

Question 144: In the developer/provider/deployer/user responsibility mapping, who is the 'deployer'?
145
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

A cited source doesn't actually support the claim made in the answer. This is a failure of:

Question 145: A cited source doesn't actually support the claim made in the answer. This is a failure of:
146
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

A vector database returns technically similar but contextually wrong content for a query. What RAG risk does this best illustrate?

Question 146: A vector database returns technically similar but contextually wrong content for a query. What RAG risk does this best illustrate?
147
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

When should a harm block a launch?

Question 147: When should a harm block a launch?
148
WEEK 7 · NIST AI RMF · NIST MAP

Why does higher autonomy typically require more attention in MAP?

Question 148: Why does higher autonomy typically require more attention in MAP?
149
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What is the role of internal audit within an AIMS?

Question 149: What is the role of internal audit within an AIMS?
150
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

Why do control gaps need a severity rating, not just a list?

Question 150: Why do control gaps need a severity rating, not just a list?
151
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

What is the relationship between transparency and explainability?

Question 151: What is the relationship between transparency and explainability?
152
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

Which of these is a 'special category' of data under UK GDPR?

Question 152: Which of these is a 'special category' of data under UK GDPR?
153
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

What role does 'management oversight' play in an AI control environment?

Question 153: What role does 'management oversight' play in an AI control environment?
154
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

What does the OECD AI Principles' relationship to human rights and democratic values mean in practice?

Question 154: What does the OECD AI Principles' relationship to human rights and democratic values mean in practice?
155
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

Which best describes the combination of using both OECD Principles and NIST AI RMF together?

Question 155: Which best describes the combination of using both OECD Principles and NIST AI RMF together?
156
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

When classifying a scenario under the EU AI Act, what should a strong answer state alongside the conclusion?

Question 156: When classifying a scenario under the EU AI Act, what should a strong answer state alongside the conclusion?
157
WEEK 7 · NIST AI RMF · NIST MAP

What is the primary purpose of the MAP function?

Question 157: What is the primary purpose of the MAP function?
158
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

Why might 'monitor' be an acceptable treatment for a low-probability, low-severity harm, when it wouldn't be for a high-severity one?

Question 158: Why might 'monitor' be an acceptable treatment for a low-probability, low-severity harm, when it wouldn't be for a high-severity one?
159
WEEK 8 · NIST AI RMF · NIST MEASURE

How does a 'system card' differ from a 'model card'?

Question 159: How does a 'system card' differ from a 'model card'?
160
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

What best describes 'control environment' in COSO terms?

Question 160: What best describes 'control environment' in COSO terms?
161
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What is an 'external communication plan' for AI incidents meant to define?

Question 161: What is an 'external communication plan' for AI incidents meant to define?
162
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

How does ISO/IEC 42005 relate to NIST AI RMF's MAP function?

Question 162: How does ISO/IEC 42005 relate to NIST AI RMF's MAP function?
163
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What's a reasonable assurance conclusion when a control's operating effectiveness could not be evidenced at all?

Question 163: What's a reasonable assurance conclusion when a control's operating effectiveness could not be evidenced at all?
164
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

How should an organisation treat a nonconformity discovered during a management review?

Question 164: How should an organisation treat a nonconformity discovered during a management review?
165
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

How do the three standards relate to each other?

Question 165: How do the three standards relate to each other?
166
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

What does 'data governance' cover in the EU AI Act's high-risk obligations?

Question 166: What does 'data governance' cover in the EU AI Act's high-risk obligations?
167
WEEK 8 · NIST AI RMF · NIST MEASURE

What is the primary purpose of the MEASURE function?

Question 167: What is the primary purpose of the MEASURE function?
168
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Why is 'competence' under Clause 7 relevant specifically to people operating AI systems, not just general staff training?

Question 168: Why is 'competence' under Clause 7 relevant specifically to people operating AI systems, not just general staff training?
169
WEEK 8 · NIST AI RMF · NIST MEASURE

A good acceptance criterion should be set:

Question 169: A good acceptance criterion should be set:
170
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

Why does the Act treat certain manipulative AI techniques as prohibited rather than merely high-risk?

Question 170: Why does the Act treat certain manipulative AI techniques as prohibited rather than merely high-risk?
171
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

How should 'objectives and measurement' under Clause 6 be reviewed after a significant AI incident?

Question 171: How should 'objectives and measurement' under Clause 6 be reviewed after a significant AI incident?
172
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

What's the practical consequence of an organisation having no defined risk appetite for AI?

Question 172: What's the practical consequence of an organisation having no defined risk appetite for AI?
173
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

What role does the 'governance board' typically play under Clause 5, as distinct from day-to-day system owners?

Question 173: What role does the 'governance board' typically play under Clause 5, as distinct from day-to-day system owners?
174
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

In public sector AI, why does 'equality impact' carry particular weight?

Question 174: In public sector AI, why does 'equality impact' carry particular weight?
175
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

What is a 'management system' in the ISO sense, as distinct from a single policy document?

Question 175: What is a 'management system' in the ISO sense, as distinct from a single policy document?
176
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What is a 'release-readiness review' meant to confirm?

Question 176: What is a 'release-readiness review' meant to confirm?
177
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

Why is 'source traceability' particularly important in a compliance or legal RAG use case?

Question 177: Why is 'source traceability' particularly important in a compliance or legal RAG use case?
178
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What is the practical risk of treating 42001 implementation as a one-off project rather than an ongoing system?

Question 178: What is the practical risk of treating 42001 implementation as a one-off project rather than an ongoing system?
179
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

Which of these questions is best answered using ISO/IEC 42005 rather than 42001?

Question 179: Which of these questions is best answered using ISO/IEC 42005 rather than 42001?
180
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

How does a 'risk' differ from an 'incident'?

Question 180: How does a 'risk' differ from an 'incident'?
181
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why does giving an AI agent tool access (like sending email) raise the stakes versus a plain chatbot?

Question 181: Why does giving an AI agent tool access (like sending email) raise the stakes versus a plain chatbot?
182
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

Why does 'senior management responsibilities' under Clause 5 typically include approving risk acceptance, not just policy?

Question 182: Why does 'senior management responsibilities' under Clause 5 typically include approving risk acceptance, not just policy?
183
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Which is a foreseeable example of 'basic AI risk thinking' applied to a fruit-recognition app misclassifying a fruit's ripeness?

Question 183: Which is a foreseeable example of 'basic AI risk thinking' applied to a fruit-recognition app misclassifying a fruit's ripeness?
184
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

Why is a privacy review alone insufficient for a generative marketing tool?

Question 184: Why is a privacy review alone insufficient for a generative marketing tool?
185
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

Processing criminal offence data for an AI-driven vetting tool requires:

Question 185: Processing criminal offence data for an AI-driven vetting tool requires:
186
WEEK 7 · NIST AI RMF · NIST MAP

Why should 'assumptions and constraints' be explicitly documented in MAP?

Question 186: Why should 'assumptions and constraints' be explicitly documented in MAP?
187
WEEK 8 · NIST AI RMF · NIST MEASURE

What should happen if a system fails its defined acceptance criteria during MEASURE?

Question 187: What should happen if a system fails its defined acceptance criteria during MEASURE?
188
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

Which best reflects the relationship between leadership commitment (Clause 5) and Annex A control selection?

Question 188: Which best reflects the relationship between leadership commitment (Clause 5) and Annex A control selection?
189
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why does 'audit trail' design for agents typically need to capture the reasoning or plan, not just the final action taken?

Question 189: Why does 'audit trail' design for agents typically need to capture the reasoning or plan, not just the final action taken?
190
WEEK 7 · NIST AI RMF · NIST MAP

What's the risk of skipping 'assumptions and constraints' documentation in MAP?

Question 190: What's the risk of skipping 'assumptions and constraints' documentation in MAP?
191
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

Why do ISO AI standards matter to a practitioner, beyond academic interest?

Question 191: Why do ISO AI standards matter to a practitioner, beyond academic interest?
192
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

A 'small model' versus a 'large model' distinction primarily refers to:

Question 192: A 'small model' versus a 'large model' distinction primarily refers to:
193
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

Which best reflects a 'reduce' treatment, as distinct from 'avoid'?

Question 193: Which best reflects a 'reduce' treatment, as distinct from 'avoid'?
194
WEEK 6 · NIST AI RMF · NIST GOVERN

How should 'approval gates' differ for a low-risk internal tool versus a high-risk customer-facing system?

Question 194: How should 'approval gates' differ for a low-risk internal tool versus a high-risk customer-facing system?
195
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

How does Clause 5/6 planning relate to NIST's GOVERN and MAP functions?

Question 195: How does Clause 5/6 planning relate to NIST's GOVERN and MAP functions?
196
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What does 'Clause 4 to 10 overview' most usefully give a first-time reader of ISO/IEC 42001?

Question 196: What does 'Clause 4 to 10 overview' most usefully give a first-time reader of ISO/IEC 42001?
197
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

A rollback plan is important because:

Question 197: A rollback plan is important because:
198
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

How should 'wider legal issues' (beyond privacy) be handled in a capstone-style scenario?

Question 198: How should 'wider legal issues' (beyond privacy) be handled in a capstone-style scenario?
199
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Compared to fine-tuning, a key advantage of RAG is:

Question 199: Compared to fine-tuning, a key advantage of RAG is:
200
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What is the primary purpose of assurance planning before testing begins?

Question 200: What is the primary purpose of assurance planning before testing begins?
Self-check centre