Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

A bank is aiming to comply with ISO/IEC 42005:2025, and is studying how to adopt the standard in light of a new AI customer service system that it would like to implement.

In addition to the risk management process the bank already has in place to assess the risks of any potential new systems, which of the following actions is the most effective in adopting the ISO/IEC 42005:2025 standard?

A.

Collecting information on the AI system ' s performance to document additional AI risks.

B.

Adding AI risks to the risk register and continuing to leverage the existing risk management process.

C.

Defining a standalone AI impact assessment procedure to supplement the existing risk management process.

D.

Instructing AI developers to perform an AI impact assessment before development in addition to the existing risk management process.

Which of the following is NOT required to be included in an AI impact assessment for a narrow AI use case?

A.

The AI model ' s potential impact on privacy rights.

B.

The data sources used for training the AI model.

C.

The potential bias in the outputs of the AI model.

D.

The AI model ' s energy consumption during processing.

Scenario:

An organization is developing a powerful general-purpose AI (GPAI) model that has systemic impact. The compliance team is assessing what legal obligations apply under the EU AI Act.

Under the EU AI Act, which of the following compliance actions appliesonly to General Purpose AI models with systemic risk?

A.

Publishing a detailed summary of the data used to train the model

B.

Maintaining up-to-date technical documentation, including testing details

C.

Implementing an intellectual property policy to comply with EU copyright laws

D.

Making information available to downstream providers who integrate the model into their AI systems

What type of organizational risk is associated with Al ' s resource-intensive computing demands?

A.

People risk.

B.

Security risk.

C.

Third-party risk.

D.

Environmental risk.

After initially deploying a third-party AI model, you learn the developer has released a new version.

As deployer of this third-party model, what should you do?

A.

Audit the model.

B.

Retrain the model.

C.

Seek input from data scientists.

D.

Communicate necessary updates to your users.

The OECD ' s Ethical Al Governance Framework is a self-regulation model that proposes to prevent societal harms by?

A.

Establishing explain ability criteria to responsibly source and use data to train Al systems.

B.

Defining requirements specific to each industry sector and high-risk Al domain.

C.

Focusing on Al technical design and post-deployment monitoring.

D.

Balancing Al innovation with ethical considerations.

CASE STUDY

Please use the following to answer the next question:

You have recently assumed the role of AI Governance leader for a California-based medical technology company. The organization primarily serves hospitals and has recently expanded to include walk-in clinics located within local pharmacies.

The company ' s core business focuses on diagnostic assistance powered by a large language model LLM and back-office process optimization using Agentic AI, including chatbots, medical record request handling, scheduling and billing.

In preparation for its next round of funding, the board has asked you to prepare an AI Risk report to demonstrate to investors how the company is addressing AI-related risks. In preparing the report you learn that last year the company generated 30 million dollars in gross revenue across the US, EU, India, and South Korea and that vendors are engaged for various activities, including model testing and providing third-party AI solutions for chatbots.

Which of the following would provide you the best information addressing quality principles pertaining to the functioning of the AI agents and LLM?

A.

A monthly log of all input data validation checks showing:

the percentage of anomalous or missing data points that were cleaned

the average time it takes for the LLM to generate a response.

B.

The aggregate count of user feedback:

flagged as Negative or Unsatisfactory over the past 30 days

categorized by language preference.

C.

Real-time system diagnostics tracking:

the total number of model predictions processed daily

the percentage of high-certainty predictions

a summary of code quality scores from internal software testing tools before deployment.

D.

Monthly statistical measures showing:

the percentages of accuracy by user group

the response category

real world change data.

A Canadian company is developing an Al solution to evaluate candidates in the course of job interviews.

Before offering the Al solution in the EU market, the company must take all of the following steps EXCEPT?

A.

Register the Al solution in a public EU database.

B.

Establish a risk and quality management system.

C.

Engage a third-party auditor to perform a bias audit.

D.

Draw up technical documentation and instructions for use.

Training data is best defined as a subset of data that is used to?

A.

Enable a model to detect and learn patterns.

B.

Fine-tune a model to improve accuracy and prevent overfitting.

C.

Detect the initial sources of biases to mitigate prior to deployment.

D.

Resemble the structure and statistical properties of production data.

All of the following are elements of establishing a global Al governance infrastructure EXCEPT?

A.

Providing training to foster a culture that promotes ethical behavior.

B.

Creating policies and procedures to manage third-partyrisk.

C.

Understanding differences in norms across countries.

D.

Publicly disclosing ethical principles.