AIGP - Understanding the foundations of AI governance (21% of the exam) - Section 1.6

Create and implement policies to ensure oversight and accountability across all AI life cycle stages, including use case assessment, risk management, data governance, model development, and incident management.

Design policies that establish oversight and accountability across every AI life cycle stage, from use case assessment and data governance through to incident management. Recognise how acceptable use policies and third-party risk controls apply at each stage.

AI life cycleAI policiesthird-party riskacceptable use policy

Practice question for this objective

Free sampleUnderstanding the foundations of AI governancehard

A manufacturer is drafting an AI policy to ensure oversight and accountability as high-risk models progress through the life cycle, from use case assessment into development, deployment and ongoing monitoring. Leadership wants the policy itself to assign clear ownership and to force human oversight at the moments that most affect affected individuals. Which TWO provisions most directly embed life cycle oversight and accountability in the policy? Select TWO.

  • AName a single accountable owner for each AI system who answers for its outcomes across every life cycle stage, even where delivery work is delegated to other teams. Correct
  • BRequire a documented risk assessment and a defined human review gate before a high-risk system may move from one life cycle stage to the next, such as into production. Correct
  • CMandate that every model achieve at least ninety-five percent accuracy on a held-out test set before it is approved for deployment to production users.
  • DDirect the security operations team to retain server access logs for the inference environment for a minimum of twelve months for forensic purposes.
  • ERequire the data science team to publish a model card describing the system's intended use and known limitations once development is complete.
An AI life cycle policy embeds oversight and accountability chiefly by naming an accountable owner per system and gating stage transitions with risk assessment and human review. Oversight and accountability across the life cycle come from structural provisions: a single answerable owner ties outcomes to a person regardless of delegation, and a stage gate forces a documented risk assessment plus human review before a high-risk system advances. Technical thresholds, log retention and model cards are useful artefacts but each governs one slice and none of them assigns ownership or compels oversight at the transitions.

Why A is correct: Naming one accountable owner per system who answers for outcomes across all stages is the core accountability mechanism a life cycle policy must establish.

Why B is correct: Stage-gated risk assessment with a human review checkpoint embeds proportionate oversight at the transitions that most affect individuals, which is exactly the policy's purpose.

Why C is wrong: A fixed accuracy threshold is tempting as a quality bar, but it is a narrow technical metric set in a standard, not a policy provision that establishes oversight or accountability across stages.

Why D is wrong: Log retention sounds like governance and aids later forensics, but it is an operational security control that neither assigns life cycle ownership nor forces human oversight at decision points.

Why E is wrong: A model card aids transparency and is tempting, but it documents one stage after the fact and does not by itself assign accountability or compel oversight across the life cycle.

See more AIGP practice questions, answers explained.

Exam traps in Understanding the foundations of AI governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • It applies only at the data collection stage, because once a dataset has been gathered and labelled the data governance obligations are discharged and later stages are matters for model engineering alone.

    Why it is wrong: Confining the policy to collection is tempting because acquisition is where data first enters scope, but it is wrong because data governance obligations such as quality, lineage and lawful-basis controls continue to apply through training, validation, deployment and retraining.

  • It replaces the supplier security review with a single contractual warranty in which the vendor confirms the AI system is safe, removing the need for the acquirer to assess the system itself.

    Why it is wrong: A vendor warranty is tempting because it appears to shift liability cleanly, but accountability stays with the organisation that puts the AI system into use, and a warranty cannot substitute for the acquirer's own assessment of the system in its intended context.

  • Rely on the supplier's purge of its own copy of the dataset and consider the bank's obligation discharged, because the unlawful data originated outside the bank's own collection processes.

    Why it is wrong: Treating the supplier's purge as sufficient is tempting because the data came from a third party, but the bank processed that data in its own AI system and remains a controller for that processing, so the supplier deleting its copy does not address the bank's downstream obligations.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.