Pre-Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmaspas7

Easiest Solution 2 Pass Your Certification Exams

AIGP IAPP Artificial Intelligence Governance Professional Free Practice Exam Questions (2026 Updated)

Prepare effectively for your IAPP AIGP Artificial Intelligence Governance Professional certification with our extensive collection of free, high-quality practice questions. Each question is designed to mirror the actual exam format and objectives, complete with comprehensive answers and detailed explanations. Our materials are regularly updated for 2026, ensuring you have the most current resources to build confidence and succeed on your first attempt.

Page: 2 / 3
Total 194 questions

The White House Executive Order from November 2023 requires companies that develop dual-use foundation models to provide reports to the federal government about all of the following EXCEPT?

A.

Any current training or development of dual-use foundation models.

B.

The results of red-team testing of each dual-use foundation model.

C.

Any environmental impact study for each dual-use foundation model.

D.

The physical and cybersecurity protection measures of their dual-use foundation models.

A company ' s AI-powered hiring tool is found to be consistently ranking male candidates higher than female candidates with similar qualifications.

Which of the following is the most immediate and critical governance action required to address this issue?

A.

Log the incident in the company ' s central AI incident management system.

B.

Conduct a comprehensive audit of the AI system ' s entire lifecycle.

C.

Notify cross-functional stakeholders.

D.

Initiate a full-scale retraining of the AI model with a more balanced dataset.

According to the GDPR, an individual has the right to have a human confirm or replace an automated decision unless that automated decision?

A.

Is authorized with the data subject s explicit consent.

B.

Is authorized by applicable Ell law and includes suitable safeguards.

C.

Is deemed to solely benefit the individual and includes documented legitimate interests.

D.

Is necessary for entering into or performing under a contract between the data subject and data controller.

CASE STUDY

A company is considering the procurement of an AI system designed to enhance the security of IT infrastructure. The AI system analyzes how users type on their laptops, including typing speed, rhythm and pressure, to create a unique user profile. This data is then used to authenticate users and ensure that only authorized personnel can access sensitive resources.

When prioritizing the updates to its policies, rules and procedures to include the new AI system for user authentication, the organization should:

A.

Update third-party data sharing policies

B.

Update security controls for sensitive data

C.

Ensure that any personal data used is only processed for a specific and lawful purpose

D.

Reduce the complexity of the policy to make it easier for non-technical employees to understand

MULTI-SELECT

Please select 3 of the 5 options below. No partial credit will be given.

In cooperation with an Italian University, a US technology company called Nudge 2078, with no offices or employees in other countries, is developing an AI system which subtly encourages " good " behaviors, such as saving money and exercising. The two companies plan to conduct some experiments on volunteers. However, the study protocol is misleading on the purpose of the study, the experiments that will be conducted and its relevance to the application.

Which regulations are most likely applicable?

A.

The EU AI Act.

B.

The Digital Services Act.

C.

The General Data Protection Act.

D.

The Federal Trade Commission Act.

E.

Payment Card Industry PCI Standards.

A company plans on procuring a tool from an Al provider for its employees to use for certain business purposes.

Which contractual provision would best protect the company ' s intellectual property in the tool, including training and testing data?

A.

The provider willgive privacy notice to individuals before using their personal data to train or test the tool.

B.

The provider willdefend and indemnify the company against infringement claims.

C.

The provider willobtain and maintain insurance to cover potential claims.

D.

The provider willwarrant that the tool will work as intended.

CASE STUDY

Please use the following answer the next question:

Good Values Corporation (GVC) is a U.S. educational services provider that employs teachers to create and deliver enrichment courses for high school students. GVC has learned that many of its teacher employees are using generative Al to create the enrichment courses, and that many of the students are using generative Al to complete their assignments.

In particular, GVC has learned that the teachers they employ used open source large language models (“LLM”) to develop an online tool that customizes study questions for individual students. GVC has also discovered that an art teacher has expressly incorporated the use of generative Al into the curriculum to enable students to use prompts to create digital art.

GVC has started to investigate these practices and develop a process to monitor any use of generative Al, including by teachers and students, going forward.

All of the following may be copyright risks from teachers using generative Al to create course content EXCEPT?

A.

Content created by an LLM may be protectable under U.S. intellectual property law.

B.

Generative Al is generally trained using intellectual property owned by third parties.

C.

Students must expressly consent to this use of generative Al.

D.

Generative Al often creates content without attribution.

The OECD ' s Ethical Al Governance Framework is a self-regulation model that proposes to prevent societal harms by?

A.

Establishing explain ability criteria to responsibly source and use data to train Al systems.

B.

Defining requirements specific to each industry sector and high-risk Al domain.

C.

Focusing on Al technical design and post-deployment monitoring.

D.

Balancing Al innovation with ethical considerations.

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

Which other stakeholder groups should be involved in the selection and implementation of the Al hiring tool?

A.

Finance and Legal.

B.

Marketing and Compliance.

C.

Supply Chain and Marketing.

D.

Litigation and Product Development.

All of the following issues are unique for proprietary AI model deployments EXCEPT?

A.

The acquisition of training data.

B.

The cost of AI chips.

C.

The potential for bias.

D.

The necessity of performing conformity assessments.

Scenario:

A mid-sized tech firm is building its AI governance program and is exploring ISO/IEC standards that could support consistency in terminology and risk assessment processes across teams.

ISO/IEC 22989andISO/IEC 42001can be valuable resources for AI Governance professionals inall of the following ways EXCEPT:

A.

Establishing terminology and describing concepts so that governance team members can communicate with diverse parties and stakeholders from around the world

B.

Being applicable to organizations of any size and industry seeking to use AI responsibly and effectively in their design processes, information systems and controls

C.

Addressing specific issues related to managing procurement processes with third parties that provide or develop AI systems for their organization

D.

Recommending key activities to assess and manage risk: test, evaluate, verify and validate (TEVV)

CASE STUDY

Please use the following answer the next question:

A mid-size US healthcare network has decided to develop an Al solution to detect a type of cancer that is most likely arise in adults. Specifically, the healthcare network intends to create a recognition algorithm that will perform an initial review of all imaging and then route records a radiologist for secondary review pursuant agreed-upon criteria (e.g., a confidence score below a threshold).

To date, the healthcare network has taken the following steps: defined its Al ethical principles: conducted discovery to identify the intended uses and success criteria for the system: established an Al governance committee; assembled a broad, crossfunctional team with clear roles and responsibilities; and created policies and procedures to document standards, workflows, timelines and risk thresholds during the project.

The healthcare network intends to retain a cloud provider to host the solution and a consulting firm to help develop the algorithm using the healthcare network ' s existing data and de-identified data that is licensed from a large US clinical research partner.

Which stakeholder group is most important in selecting the specific type of algorithm?

A.

The cloud provider.

B.

The consulting firm.

C.

The healthcare network ' sdata science team.

D.

The healthcare network ' s Al governance committee.

The best method to ensure a comprehensive identification of risks for a new AI model is?

A.

An environmental scan.

B.

Red teaming.

C.

Integration testing.

D.

An impact assessment.

The planning phase of the Al life cycle articulates all of the following EXCEPT the?

A.

Objective of the model.

B.

Approach to governance.

C.

Choice of the architecture.

D.

Context in which the model will operate.

CASE STUDY

Please use the following answer the next question:

ABC Corp, is a leading insurance provider offering a range of coverage options to individuals. ABC has decided to utilize artificial intelligence to streamline and improve its customer acquisition and underwriting process, including the accuracy and efficiency of pricing policies.

ABC has engaged a cloud provider to utilize and fine-tune its pre-trained, general purpose large language model (“LLM”). In particular, ABC intends to use its historical customer data—including applications, policies, and claims—and proprietary pricing and risk strategies to provide an initial qualification assessment of potential customers, which would then be routed a human underwriter for final review.

ABC and the cloud provider have completed training and testing the LLM, performed a readiness assessment, and made the decision to deploy the LLM into production. ABC has designated an internal compliance team to monitor the model during the first month, specifically to evaluate the accuracy, fairness, and reliability of its output. After the first month in production, ABC realizes that the LLM declines a higher percentage of women ' s loan applications due primarily to women historically receiving lower salaries than men.

What is the best strategy to mitigate the bias uncovered in the loan applications?

A.

Retrain the model with data that reflects demographic parity.

B.

Procure a third-party statistical bias assessment tool.

C.

Document all instances of bias in the data set.

D.

Delete all gender-based data in the data set.

CASE STUDY

Please use the following answer the next question:

A local police department in the United States procured an Al system to monitor and analyze social media feeds, online marketplaces and other sources of public information to detect evidence of illegal activities (e.g., sale of drugs or stolen goods). The Al system works by surveilling the public sites in order to identify individuals that are likely to have committed a crime. It cross-references the individuals against data maintained by law enforcement and then assigns a percentage score of the likelihood of criminal activity based on certain factors like previous criminal history, location, time, race and gender.

The police department retained a third-party consultant assist in the procurement process, specifically to evaluate two finalists. Each of the vendors provided information about their system ' s accuracy rates, the diversity of their training data and how their system works. The consultant determined that the first vendor’s system has a higher accuracy rate and based on this information, recommended this vendor to the police department.

The police department chose the first vendor and implemented its Al system. As part of the implementation, the department and consultant created a usage policy for the system, which includes training police officers on how the system works and how to incorporate it into their investigation process.

The police department has now been using the Al system for a year. An internal review has found that every time the system scored a likelihood of criminal activity at or above 90%, the police investigation subsequently confirmed that the individual had, in fact, committed a crime. Based on these results, the police department wants to forego investigations for cases where the Al system gives a score of at least 90% and proceed directly with an arrest.

Which Al risk would NOT have been identified during the procurement process based on the categories of information requested by the third-party consultant?

A.

Security.

B.

Accuracy.

C.

Explainability.

D.

Discrimination.

During the planning and design phases of the Al development life cycle, bias can be reduced by all of the following EXCEPT?

A.

Stakeholder involvement.

B.

Feature selection.

C.

Human oversight.

D.

Data collection.

A US company has developed an Al system, Crime Buster 9619, that collects information about incarcerated individuals to help parole boards predict whether someone is likely to commit another crime if released from prison.

When considering expanding to the EU market, this type of technology would?

A.

Require the company to register the tool with the EU database.

B.

Be subject approval by the relevant EU authority.

C.

Require a detailed conformity assessment.

D.

Be banned under the EU Al Act.

CASE STUDY

Please use the following answer the next question:

XYZ Corp., a premier payroll services company that employs thousands of people globally, is embarking on a new hiring campaign and wants to implement policies and procedures to identify and retain the best talent. The new talent will help the company ' s product team expand its payroll offerings to companies in the healthcare and transportation sectors, including in Asia.

It has become time consuming and expensive for HR to review all resumes, and they are concerned that human reviewers might be susceptible to bias.

Address these concerns, the company is considering using a third-party Al tool to screen resumes and assist with hiring. They have been talking to several vendors about possibly obtaining a third-party Al-enabled hiring solution, as long as it would achieve its goals and comply with all applicable laws.

The organization has a large procurement team that is responsible for the contracting of technology solutions. One of the procurement team ' s goals is to reduce costs, and it often prefers lower-cost solutions. Others within the company are responsible for integrating and deploying technology solutions into the organization ' s operations in a responsible, cost-effective manner.

The organization is aware of the risks presented by Al hiring tools and wants to mitigate them. It also questions how best to organize and train its existing personnel to use the Al hiring tool responsibly. Their concerns are heightened by the fact that relevant laws vary across jurisdictions and continue to change.

All of the following are potential negative consequences created by using the Al tool when making hiring decisions EXCEPT?

A.

Reputational harm.

B.

Civil rights violations.

C.

Discriminatory treatment.

D.

Intellectual property infringement.

Why is it important that conformity requirements are satisfied before an AI system is released into production?

A.

To ensure the visual design is fit for purpose.

B.

To ensure the AI system is easy for end-users to operate.

C.

To guarantee interoperability of the AI system across multiple platforms and environments.

D.

To comply with legal and regulatory standards, ensuring the AI system is safe and trustworthy.

Page: 2 / 3
Total 194 questions
Copyright © 2014-2026 Solution2Pass. All Rights Reserved