AIGP - Understanding the foundations of AI governance (21% of the exam) - Section 1.4

Define roles and responsibilities for AI governance stakeholders and establish cross-functional collaboration within the AI governance programme.

Define the roles and responsibilities of stakeholders in an AI governance programme, from executive sponsors to technical practitioners. Describe how cross-functional collaboration between legal, data science, risk, and compliance teams enables effective oversight.

AI governance stakeholderscross-functional collaborationAI governance programme

Practice question for this objective

Free sampleUnderstanding the foundations of AI governancemedium

An organisation is defining the concept of cross-functional collaboration within its AI governance programme. Which statement best captures why such collaboration is treated as a structural requirement rather than an optional courtesy between teams?

  • ACross-functional collaboration exists primarily to speed up product delivery, so governance committees should defer to engineering timelines whenever a release deadline is at stake.
  • BIt is needed because data protection law requires every AI project to be approved unanimously by all departments before any development work may begin.
  • CIt mainly allows the executive sponsor to delegate accountability for AI outcomes across the participating functions, so that responsibility is shared and no individual carries it.
  • DAI systems raise risks spanning legal, technical, ethical and business domains, so no single function holds all the expertise needed to govern them, making coordinated input across functions essential. Correct
Cross-functional collaboration is structural because governing AI systems needs combined legal, technical, ethical and business expertise no single function holds. AI systems create interconnected legal, technical, ethical and commercial risks that exceed any one function's expertise, so governance frameworks treat coordinated input as a structural necessity. Collaboration aligns these perspectives without dissolving the single-owner accountability that governance still requires.

Why A is wrong: This is tempting because collaboration can reduce friction, but subordinating governance to delivery deadlines inverts its purpose; the point is to surface risk across functions, not to clear the path for faster shipping.

Why B is wrong: This is plausible because data protection regimes such as the GDPR do impose assessment duties, but no framework mandates unanimous all-department approval before development; the claim overstates a real obligation into an invented one.

Why C is wrong: This is tempting because committees do distribute work, but collaboration does not dissolve accountability; sound governance keeps a single accountable owner even when many functions contribute, so diffusing answerability is wrong.

Why D is correct: This is correct because the risks of AI systems cut across data protection, security, fairness, engineering and commercial concerns, and effective governance requires the relevant functions to contribute and align rather than acting in isolation.

See more AIGP practice questions, answers explained.

Exam traps in Understanding the foundations of AI governance

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • Encrypting the training datasets at rest and in transit so that unauthorised parties cannot read them

    Why it is wrong: Encryption is tempting because it is a core data protection control, but it secures data confidentiality and says nothing about where the data came from or whether the organisation was permitted to use it for training.

  • The Chief AI Officer, because that executive owns the AI strategy and is therefore the natural single point for all advice relating to the organisation's AI systems.

    Why it is wrong: It is tempting because the Chief AI Officer leads AI strategy, but independent data protection advice and compliance monitoring is the specialist remit of the Data Protection Officer, not the AI strategy lead.

  • Let the data science team that built the system set the tool permissions and value limits, since it understands the system's behaviour better than any other function.

    Why it is wrong: It is tempting because the builders do know the system's mechanics best, but the first line that builds a system should not unilaterally set the risk boundaries on its own autonomous actions, as that removes the independent challenge the cross-functional design is meant to provide.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.