Weeks 5–9

Checkpoint 2

OECD AI Principles and NIST AI RMF — Govern, Map, Measure and Manage — tested through realistic governance decisions.

Time remaining45:00
01

How should NIST AI RMF best be described to a business stakeholder?

Question 1: How should NIST AI RMF best be described to a business stakeholder?
02

A committee is deciding who can approve exceptions to the AI policy and how model ownership is assigned. Which NIST AI RMF function does this belong to?

Question 2: A committee is deciding who can approve exceptions to the AI policy and how model ownership is assigned. Which NIST AI RMF function does this belong to?
03

A team documents the intended use, foreseeable misuse, affected people and deployment environment of a new claims-triage system before building controls. This work sits primarily in:

Question 3: A team documents the intended use, foreseeable misuse, affected people and deployment environment of a new claims-triage system before building controls. This work sits primarily in:
04

A red-teaming exercise probes a chatbot for prompt-injection vulnerabilities and records the pass/fail results against a threshold. This activity sits primarily in:

Question 4: A red-teaming exercise probes a chatbot for prompt-injection vulnerabilities and records the pass/fail results against a threshold. This activity sits primarily in:
05

After testing reveals a high residual risk, the organisation decides to add a mandatory human review step and sets a monitoring threshold for post-launch drift. This decision sits primarily in:

Question 5: After testing reveals a high residual risk, the organisation decides to add a mandatory human review step and sets a monitoring threshold for post-launch drift. This decision sits primarily in:
06

Which OECD AI Principle is most directly reflected by publishing a model card with intended use, limitations and evaluation results?

Question 6: Which OECD AI Principle is most directly reflected by publishing a model card with intended use, limitations and evaluation results?
07

A senior leader says 'we don't need NIST, ISO or OECD — we only care about the law.' What is the most accurate response?

Question 7: A senior leader says 'we don't need NIST, ISO or OECD — we only care about the law.' What is the most accurate response?
08

A company sets its AI risk appetite as 'no automated decision may adversely affect a customer's access to credit without a documented human review path.' This statement is best described as defining:

Question 8: A company sets its AI risk appetite as 'no automated decision may adversely affect a customer's access to credit without a documented human review path.' This statement is best described as defining:
09

In the MAP function, which of the following is a 'foreseeable misuse' scenario for a public-facing HR chatbot, as opposed to intended use?

Question 9: In the MAP function, which of the following is a 'foreseeable misuse' scenario for a public-facing HR chatbot, as opposed to intended use?
10

Which is the strongest example of a MEASURE-stage acceptance criterion?

Question 10: Which is the strongest example of a MEASURE-stage acceptance criterion?
11

A model's accuracy is degrading over time as real-world claims patterns shift away from the training data. This phenomenon is best described as:

Question 11: A model's accuracy is degrading over time as real-world claims patterns shift away from the training data. This phenomenon is best described as:
12

During MANAGE, a residual risk remains 'high' even after controls are applied. Who should make the final acceptance decision?

Question 12: During MANAGE, a residual risk remains 'high' even after controls are applied. Who should make the final acceptance decision?
13

Which best distinguishes a 'profile' from the 'core' in NIST AI RMF?

Question 13: Which best distinguishes a 'profile' from the 'core' in NIST AI RMF?
14

An organisation wants to demonstrate 'accountability' in the OECD sense for an automated loan-decision tool. Which action best supports this?

Question 14: An organisation wants to demonstrate 'accountability' in the OECD sense for an automated loan-decision tool. Which action best supports this?
15

A benchmark shows a model performs well on a public test set but the deployment team has not tested it on the organisation's real, messier data. What is the primary governance concern?

Question 15: A benchmark shows a model performs well on a public test set but the deployment team has not tested it on the organisation's real, messier data. What is the primary governance concern?
16

Which statement best reflects the relationship between NIST AI RMF and ISO/IEC 42001?

Question 16: Which statement best reflects the relationship between NIST AI RMF and ISO/IEC 42001?
17

A supplier changes the underlying model behind an API with no advance notice, and downstream accuracy drops. Which NIST AI RMF weakness does this best illustrate?

Question 17: A supplier changes the underlying model behind an API with no advance notice, and downstream accuracy drops. Which NIST AI RMF weakness does this best illustrate?
18

Which of these best reflects OECD's 'human-centred values and fairness' principle in a real deployment?

Question 18: Which of these best reflects OECD's 'human-centred values and fairness' principle in a real deployment?
19

A team wants to reuse the same MEASURE test plan for every AI system regardless of risk level or context. What is the main problem with this approach?

Question 19: A team wants to reuse the same MEASURE test plan for every AI system regardless of risk level or context. What is the main problem with this approach?
20

A company documents a full risk register but has no evidence that mitigations were actually implemented or that anyone checks whether they still work. Which MANAGE-related weakness does this show?

Question 20: A company documents a full risk register but has no evidence that mitigations were actually implemented or that anyone checks whether they still work. Which MANAGE-related weakness does this show?
Exam centre