IAPP Artificial Intelligence Governance Professional AIGP Exam Questions

Page: 1 / 14
Total 194 questions
Question 1

CASE STUDY

Please use the following answer the next question:

ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.

ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (''LLM''). In particular, ABC intends to use its historical customer data---including applications, policies, and claims---and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed t



Answer : B

Providing the loan applicants with information about the model capabilities and limitations would not directly support fairness testing by the compliance team. Fairness testing focuses on evaluating the model's decisions for biases and ensuring equitable treatment across different demographic groups, rather than informing applicants about the model.


Question 2

Scenario:

An organization is developing a powerful general-purpose AI (GPAI) model that has systemic impact. The compliance team is assessing what legal obligations apply under the EU AI Act.

Under the EU AI Act, which of the following compliance actions appliesonly to General Purpose AI models with systemic risk?



Answer : A

The correct answer isA. Only GPAI modelswith systemic riskmustpublish a detailed summary of training datato meet transparency and accountability standards under the EU AI Act.

From the AI Governance in Practice Report 2025 (EU AI Act Section):

''For GPAI systems with systemic risk, providers must publish sufficiently detailed summaries of the content used to train the model.''

Also, the AIGP ILT Guide confirms:

''The obligation to disclose summaries of training data applies only to systemic-risk GPAI models, not all general-purpose models or high-risk systems.''

This unique requirement is part of the Act's effort to increasetransparency and auditabilityfor powerful foundational models.

===========


Question 3

An EU bank intends to launch a multi-modal Al platform for customer engagement and automated decision-making assist with the opening of bank accounts. The platform has been subject to thorough risk assessments and testing, where it proves to be effective in not discriminating against any individual on the basis of a protected class.

What additional obligations must the bank fulfill prior to deployment?



Answer : D

Under the EU regulations, particularly the GDPR, banks using AI for decision-making must inform users about the use of AI and provide mechanisms for users to contest decisions. This is part of ensuring transparency and accountability in automated processing. Explicit consent under the privacy directive (A) and disclosing under the Digital Services Act (B) are not specifically required in this context. An adequacy decision is related to data transfers outside the EU (C).


Question 4

A U.S. mortgage company developed an Al platform that was trained using anonymized details from mortgage applications, including the applicant's education, employment and demographic information, as well as from subsequent payment or default information. The Al platform will be used automatically grant or deny new mortgage applications, depending on whether the platform views an applicant as presenting a likely risk of default.

Which of the following laws is NOT relevant to this use case?



Answer : D

The U.S. mortgage company's AI platform relates to housing and credit, making the Fair Housing Act (A), Fair Credit Reporting Act (B), and Equal Credit Opportunity Act (C) relevant. Title VII of the Civil Rights Act of 1964 deals with employment discrimination and is not directly relevant to the mortgage application context (D).


Question 5

Decreasing the complexity of a machine learning model reduces variance and?



Answer : A

The correct answer is A because of the fundamental bias-variance tradeoff in machine learning. When model complexity is reduced, the model becomes simpler and less flexible, which decreases variance because it is less sensitive to fluctuations in the training data. However, this simplification comes at the cost of increased bias, meaning the model may oversimplify relationships and fail to capture underlying patterns accurately. This tradeoff is a core concept in AI fundamentals and directly impacts model performance, reliability, and governance decisions. From an AI governance perspective, understanding this balance is critical when evaluating model risk, as high bias can lead to systematic errors and fairness issues, while high variance can result in instability and unpredictability in outputs. Proper model tuning aims to balance both for optimal and responsible performance.


Question 6

According to the GDPR, what is an effective control to prevent a determination based solely on automated decision-making?



Answer : D

The GDPR requires that individuals have the right to not be subject to decisions based solely on automated processing, including profiling, unless specific exceptions apply. One effective control is to establish a human-in-the-loop procedure (D), ensuring human oversight and the ability to contest decisions. This goes beyond just-in-time notices (A), data safeguarding (B), or review rights (C), providing a more robust mechanism to protect individuals' rights.


Question 7

Which of the following are subjects covered by a typical impact assessment?



Answer : D

The correct answer is D because typical AI impact assessments focus on evaluating risks to individuals and society, particularly in areas such as fundamental rights, data protection, and safety. Frameworks like Data Protection Impact Assessments and Fundamental Rights Impact Assessments are designed to assess how AI systems may affect privacy, fairness, human rights, and potential harm to users. These assessments are core components of AI governance and are often required or recommended by regulations such as the GDPR and the EU AI Act. While options A, B, and C reference technical or operational considerations, they do not capture the broader societal and legal impacts that impact assessments are intended to address. AI governance emphasizes a human-centric approach, ensuring systems are safe, lawful, and respectful of individual rights before deployment.


Page:    1 / 14   
Total 194 questions