50 QUESTIONS · ALL 24 WEEKS

Standard mixed check

A balanced cross-syllabus session with at least two questions drawn from every syllabus week. Questions are original practice material aligned to this course syllabus; they are not copied from, endorsed by or represented as questions from an official certification exam.

01
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

A retailer in the supply chain makes a high-risk AI system available on the EU market without being the original provider or importer. Which role does this describe?

Question 1: A retailer in the supply chain makes a high-risk AI system available on the EU market without being the original provider or importer. Which role does this describe?
02
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

A recruitment vendor's fairness testing only used labour-market data from one country. What's the practitioner concern if the tool is deployed elsewhere?

Question 2: A recruitment vendor's fairness testing only used labour-market data from one country. What's the practitioner concern if the tool is deployed elsewhere?
03
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

When should a harm block a launch?

Question 3: When should a harm block a launch?
04
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

Which best reflects the relationship between leadership commitment (Clause 5) and Annex A control selection?

Question 4: Which best reflects the relationship between leadership commitment (Clause 5) and Annex A control selection?
05
WEEK 13 · ISO AI management · ISO/IEC 42001 Foundations

What's the difference between certification and implementation?

Question 5: What's the difference between certification and implementation?
06
WEEK 7 · NIST AI RMF · NIST MAP

What does MAP's 'context' work primarily protect against?

Question 6: What does MAP's 'context' work primarily protect against?
07
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

What does 'evidence' mean in a GRC context?

Question 7: What does 'evidence' mean in a GRC context?
08
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

How does 'fairness' as a UK GDPR principle differ from simply having a lawful basis for processing?

Question 8: How does 'fairness' as a UK GDPR principle differ from simply having a lawful basis for processing?
09
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Which is the best way to describe the relationship between Clause 4 scoping work and later Clause 8 operational controls?

Question 9: Which is the best way to describe the relationship between Clause 4 scoping work and later Clause 8 operational controls?
10
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

A company documents its AIMS scope, policy and objectives but has never run an impact assessment on any deployed system. Which standard's practice is missing?

Question 10: A company documents its AIMS scope, policy and objectives but has never run an impact assessment on any deployed system. Which standard's practice is missing?
11
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

What is a 'foundation model'?

Question 11: What is a 'foundation model'?
12
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

'Release gates' in MANAGE function as:

Question 12: 'Release gates' in MANAGE function as:
13
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

Which is a leadership responsibility under Clause 5, not a purely operational task?

Question 13: Which is a leadership responsibility under Clause 5, not a purely operational task?
14
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

Why do 'tool permissions' need periodic review, not just a one-time setup?

Question 14: Why do 'tool permissions' need periodic review, not just a one-time setup?
15
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

Between a small, single-purpose model and a large, general-purpose model, which factor most matters for a narrow, well-defined task?

Question 15: Between a small, single-purpose model and a large, general-purpose model, which factor most matters for a narrow, well-defined task?
16
WEEK 8 · NIST AI RMF · NIST MEASURE

'Human oversight testing' evaluates:

Question 16: 'Human oversight testing' evaluates:
17
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

Why does an evidence-pack index need to state each artefact's relevance to the final decision, not just its title?

Question 17: Why does an evidence-pack index need to state each artefact's relevance to the final decision, not just its title?
18
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Why would 'supplier controls' appear within Clause 8 operation rather than only in Annex A's third-party theme?

Question 18: Why would 'supplier controls' appear within Clause 8 operation rather than only in Annex A's third-party theme?
19
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Which best describes 'needs and expectations' of interested parties in Clause 4 terms?

Question 19: Which best describes 'needs and expectations' of interested parties in Clause 4 terms?
20
WEEK 14 · ISO AI management · ISO/IEC 42001 Clause 4: Context of the Organisation

Clause 4 requires understanding which two categories of issues?

Question 20: Clause 4 requires understanding which two categories of issues?
21
WEEK 15 · ISO AI management · ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

How should 'objectives and measurement' under Clause 6 be reviewed after a significant AI incident?

Question 21: How should 'objectives and measurement' under Clause 6 be reviewed after a significant AI incident?
22
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

Segregation of duties in AI governance most directly reduces the risk of:

Question 22: Segregation of duties in AI governance most directly reduces the risk of:
23
WEEK 11 · GenAI & agent security · Agentic AI, Prompt Injection and AI Security Controls

What defines an 'AI agent' as distinct from a standard chatbot?

Question 23: What defines an 'AI agent' as distinct from a standard chatbot?
24
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

A leader says: 'We just follow the law, we don't need frameworks.' What's the issue with this view?

Question 24: A leader says: 'We just follow the law, we don't need frameworks.' What's the issue with this view?
25
WEEK 9 · NIST AI RMF · NIST MANAGE and Risk Treatment

A 'localisation/geographic restriction policy' addresses:

Question 25: A 'localisation/geographic restriction policy' addresses:
26
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

Why does this course emphasise that 'AI law is broader than privacy'?

Question 26: Why does this course emphasise that 'AI law is broader than privacy'?
27
WEEK 24 · Controls, operations & judgement · Mock Exam, Capstone Evidence Pack and Final Viva

How should 'wider legal issues' (beyond privacy) be handled in a capstone-style scenario?

Question 27: How should 'wider legal issues' (beyond privacy) be handled in a capstone-style scenario?
28
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

How does ISO/IEC 42005 relate to NIST AI RMF's MAP function?

Question 28: How does ISO/IEC 42005 relate to NIST AI RMF's MAP function?
29
WEEK 12 · ISO AI management · ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

What is a 'management system' in the ISO sense, as distinct from a single policy document?

Question 29: What is a 'management system' in the ISO sense, as distinct from a single policy document?
30
WEEK 3 · Foundations, harm & law · Governance, Risk, Compliance & Assurance Basics

How does a 'risk' differ from an 'incident'?

Question 30: How does a 'risk' differ from an 'incident'?
31
WEEK 16 · ISO AI management · ISO/IEC 42001 Clauses 7–10 and Annex A Controls

Why is 'competence' under Clause 7 relevant specifically to people operating AI systems, not just general staff training?

Question 31: Why is 'competence' under Clause 7 relevant specifically to people operating AI systems, not just general staff training?
32
WEEK 20 · Controls, operations & judgement · COSO Internal Control Foundations for AI

What role does 'management oversight' play in an AI control environment?

Question 32: What role does 'management oversight' play in an AI control environment?
33
WEEK 23 · Controls, operations & judgement · Sector Case Studies and Practitioner Judgement

A hospital AI tool recommends a treatment priority but a clinician always follows it without independent judgement. What sector-specific issue does this raise?

Question 33: A hospital AI tool recommends a treatment priority but a clinician always follows it without independent judgement. What sector-specific issue does this raise?
34
WEEK 6 · NIST AI RMF · NIST GOVERN

What's a realistic consequence of poor supplier governance?

Question 34: What's a realistic consequence of poor supplier governance?
35
WEEK 5 · NIST AI RMF · NIST AI RMF Overview and OECD AI Principles

The OECD principle 'transparency and explainability' emphasises:

Question 35: The OECD principle 'transparency and explainability' emphasises:
36
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

Under the updated timeline enacted via the EU's 'Digital Omnibus' in 2026, when do Annex III high-risk use case obligations generally apply?

Question 36: Under the updated timeline enacted via the EU's 'Digital Omnibus' in 2026, when do Annex III high-risk use case obligations generally apply?
37
WEEK 18 · AI law & privacy · EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

What does the Act's 'cybersecurity' obligation for high-risk systems primarily address?

Question 37: What does the Act's 'cybersecurity' obligation for high-risk systems primarily address?
38
WEEK 7 · NIST AI RMF · NIST MAP

What's the risk of skipping 'assumptions and constraints' documentation in MAP?

Question 38: What's the risk of skipping 'assumptions and constraints' documentation in MAP?
39
WEEK 19 · AI law & privacy · UK GDPR, DUAA, DPIA and AI Privacy

Which lawful basis is most likely appropriate for processing necessary to decide whether to enter a loan contract a customer has requested?

Question 39: Which lawful basis is most likely appropriate for processing necessary to decide whether to enter a loan contract a customer has requested?
40
WEEK 17 · AI law & privacy · EU AI Act Foundations and Global AI Law Landscape

Why does US AI governance activity, per this course, include both federal and state-level components?

Question 40: Why does US AI governance activity, per this course, include both federal and state-level components?
41
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What should an 'assurance dashboard' primarily show?

Question 41: What should an 'assurance dashboard' primarily show?
42
WEEK 21 · Controls, operations & judgement · AI Control Testing, Assurance and Audit Readiness

What should a management action plan for a finding always include?

Question 42: What should a management action plan for a finding always include?
43
WEEK 8 · NIST AI RMF · NIST MEASURE

How does a 'system card' differ from a 'model card'?

Question 43: How does a 'system card' differ from a 'model card'?
44
WEEK 10 · GenAI & agent security · GenAI, RAG and LLM Application Risk

A cited source doesn't actually support the claim made in the answer. This is a failure of:

Question 44: A cited source doesn't actually support the claim made in the answer. This is a failure of:
45
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What's a key governance trade-off between hosted and self-hosted deployment?

Question 45: What's a key governance trade-off between hosted and self-hosted deployment?
46
WEEK 1 · Foundations, harm & law · AI Foundations for Governance

Which best orders these from broadest to narrowest?

Question 46: Which best orders these from broadest to narrowest?
47
WEEK 2 · Foundations, harm & law · Responsible AI, Trustworthy AI & Harm

An umbrella (protection against a likely, low-severity event — rain) is often used to illustrate which risk concept?

Question 47: An umbrella (protection against a likely, low-severity event — rain) is often used to illustrate which risk concept?
48
WEEK 4 · Foundations, harm & law · AI and the Wider Legal Landscape

A supplier's model was trained on scraped web content without clear licensing. This primarily raises a concern under:

Question 48: A supplier's model was trained on scraped web content without clear licensing. This primarily raises a concern under:
49
WEEK 22 · Controls, operations & judgement · Integrated AI Governance Operating Model

What is an 'external communication plan' for AI incidents meant to define?

Question 49: What is an 'external communication plan' for AI incidents meant to define?
50
WEEK 6 · NIST AI RMF · NIST GOVERN

Why does 'AI ownership' need to be distinct from general IT ownership?

Question 50: Why does 'AI ownership' need to be distinct from general IT ownership?
Self-check centre