AIGP - Understanding the foundations of AI governance (21% of the exam) - Section 1.5

Differentiate approaches to AI governance based on company size, maturity, industry, and risk tolerance, and distinguish the roles of AI developers, providers, deployers and users.

Distinguish AI governance approaches suited to different company sizes, maturity levels, industries, and risk tolerances. Recognise the distinct obligations of AI developers, providers, deployers, and end users within a governance programme.

AI developers vs deployersgovernance maturityrisk toleranceAI providers

Practice question for this objective

Free sampleUnderstanding the foundations of AI governancemedium

A fast-growing analytics startup with a deliberately high risk tolerance is building an AI system that scores consumer creditworthiness for lenders across the European Union. Its founders argue that, because the company accepts more risk than a conservative bank would, it may run a lighter governance programme than the objective intensity its competitors choose. A governance adviser is asked what limits how far risk tolerance can shape this organisation's governance. Which principle most accurately states that limit?

  • ARisk tolerance may set the governance intensity freely, because each organisation is the sole judge of how much risk its own AI systems should carry.
  • BRisk tolerance may shape governance intensity above the baseline, but it cannot reduce controls below the mandatory obligations that external law imposes on a high-risk AI system. Correct
  • CRisk tolerance is irrelevant to AI governance design, because every organisation must apply an identical control set regardless of its size, industry, or appetite.
  • DRisk tolerance may lower governance only where the organisation buys liability insurance to transfer the financial consequences of any AI harm to an insurer.
Risk tolerance legitimately shapes governance intensity above the regulatory baseline but cannot reduce controls below the mandatory obligations external law imposes. An organisation's risk appetite governs discretionary choices, yet statutory regimes such as the EU AI Act set a mandatory floor for high-risk AI systems that internal appetite, insurance, or growth pressure cannot override; governance can exceed that floor but never fall beneath it.

Why A is wrong: It is tempting because risk appetite genuinely is an internal board decision that legitimately drives governance intensity. It is wrong because an external mandatory regime such as the EU AI Act for a high-risk credit-scoring system imposes a floor that internal appetite cannot waive.

Why B is correct: It is correct because a credit-scoring AI system is high-risk under the EU AI Act, which fixes a non-negotiable floor of obligations; appetite can add rigour above that floor but never strip the statutory minimum.

Why C is wrong: It is tempting because it sounds rigorous and safe. It is wrong because the objective expressly treats risk tolerance, size, and maturity as legitimate factors that proportionately shape governance above any regulatory baseline.

Why D is wrong: It is tempting because insurance is a recognised risk-transfer treatment in the mitigation toolkit. It is wrong because transferring financial loss does not discharge statutory duties under the EU AI Act, and obligations such as conformity assessment and human oversight remain owed regardless of cover.

See more AIGP practice questions, answers explained.

Exam traps in Understanding the foundations of AI governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • The founders' stated willingness to accept more risk than rivals, which lets the firm scale back governance to match its chosen appetite.

    Why it is wrong: Tempting because risk tolerance does shape governance, but appetite is a subjective preference that cannot reduce the objective intensity the context demands.

  • Replicate the full three-lines-of-defence model with a separate risk committee, an internal audit function, and a dedicated chief AI officer from day one.

    Why it is wrong: This is tempting because it mirrors mature-enterprise best practice, but imposing a heavy structure on ten people consumes scarce resource without matching the firm's actual scale and would likely go unused.

  • The organisation has acquired more advanced AI systems and a larger volume of training data than its less mature competitors hold.

    Why it is wrong: It is tempting because mature firms often run sophisticated systems, but maturity describes the consistency and repeatability of governance practices, not the technical sophistication or data volume of the AI systems themselves.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.