AIGP - Understanding the foundations of AI governance - Section 1.5

Differentiate approaches to AI governance based on company size, maturity, industry, and risk tolerance, and distinguish the roles of AI developers, providers, deployers and users.

Distinguish AI governance approaches suited to different company sizes, maturity levels, industries, and risk tolerances. Recognise the distinct obligations of AI developers, providers, deployers, and end users within a governance programme.

AI developers vs deployersgovernance maturityrisk toleranceAI providers

Practice question for this objective

Free sampleUnderstanding the foundations of AI governancemedium

A fast-growing analytics startup with a deliberately high risk tolerance is building an AI system that scores consumer creditworthiness for lenders across the European Union. Its founders argue that, because the company accepts more risk than a conservative bank would, it may run a lighter governance programme than the objective intensity its competitors choose. A governance adviser is asked what limits how far risk tolerance can shape this organisation's governance. Which principle most accurately states that limit?

  • ARisk tolerance may set the governance intensity freely, because each organisation is the sole judge of how much risk its own AI systems should carry.
  • BRisk tolerance may shape governance intensity above the baseline, but it cannot reduce controls below the mandatory obligations that external law imposes on a high-risk AI system. Correct
  • CRisk tolerance is irrelevant to AI governance design, because every organisation must apply an identical control set regardless of its size, industry, or appetite.
  • DRisk tolerance may lower governance only where the organisation buys liability insurance to transfer the financial consequences of any AI harm to an insurer.
Risk tolerance legitimately shapes governance intensity above the regulatory baseline but cannot reduce controls below the mandatory obligations external law imposes. An organisation's risk appetite governs discretionary choices, yet statutory regimes such as the EU AI Act set a mandatory floor for high-risk AI systems that internal appetite, insurance, or growth pressure cannot override; governance can exceed that floor but never fall beneath it.

Why A is wrong: It is tempting because risk appetite genuinely is an internal board decision that legitimately drives governance intensity. It is wrong because an external mandatory regime such as the EU AI Act for a high-risk credit-scoring system imposes a floor that internal appetite cannot waive.

Why B is correct: It is correct because a credit-scoring AI system is high-risk under the EU AI Act, which fixes a non-negotiable floor of obligations; appetite can add rigour above that floor but never strip the statutory minimum.

Why C is wrong: It is tempting because it sounds rigorous and safe. It is wrong because the objective expressly treats risk tolerance, size, and maturity as legitimate factors that proportionately shape governance above any regulatory baseline.

Why D is wrong: It is tempting because insurance is a recognised risk-transfer treatment in the mitigation toolkit. It is wrong because transferring financial loss does not discharge statutory duties under the EU AI Act, and obligations such as conformity assessment and human oversight remain owed regardless of cover.

See more AIGP practice questions, answers explained.

More in this domain

Back to all Understanding the foundations of AI governance objectives, or the AIGP cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.