AIGP - Understanding how to govern AI deployment and use - Section 4.4

Perform or review an impact assessment on a selected AI system, identify and evaluate key terms and risks in vendor or licensing agreements, and assess risks unique to proprietary model deployment.

Perform or review an AI impact assessment for a selected system and evaluate key terms and risks in vendor and licensing agreements. Recognise the governance risks unique to proprietary AI model deployment, including lock-in, auditability limits, and data handling obligations.

AI vendor risklicensing agreementAI impact assessmentproprietary AI model

Practice question for this objective

Free sampleUnderstanding how to govern AI deployment and usehard

A logistics firm routes time-critical operational decisions through a proprietary foundation model consumed entirely through one vendor's hosted API, with no rights to the weights and no fallback provider. The governance team is documenting the deployment risks that are distinctive to this proprietary, single-vendor arrangement rather than to AI deployment in general. Which two risks are most distinctive to this arrangement? Select TWO.

  • AThe vendor can silently update the model behind the same endpoint, shifting behaviour in production and invalidating the firm's earlier validation results. Correct
  • BConcentration on one provider with no portable weights leaves the firm exposed to outages, price moves, or discontinuation it cannot mitigate by switching. Correct
  • CThe model could produce a biased or inaccurate output that harms an affected individual if the system is not adequately tested before launch.
  • DStaff might over-rely on the system's recommendations and approve them without the scrutiny the oversight design assumed they would apply.
  • EThe firm must keep training data accurate and representative so the model does not degrade as input patterns shift over its operational life.
Proprietary single-vendor hosted deployment carries distinctive risks of silent model updates and concentration or lock-in that generic AI deployment risks do not. Because the firm holds neither the weights nor a fallback, it cannot pin a model version or exit the provider, so opaque updates and concentration become risks specific to this closed, hosted arrangement.

Why A is correct: Correct: opaque vendor-side updates to a hosted proprietary model are a distinctive risk because the firm cannot pin a version it does not control.

Why B is correct: Correct: vendor lock-in and concentration risk are distinctive here because the closed weights and lack of a fallback remove any practical exit.

Why C is wrong: Tempting and real, but output bias is a general risk of any AI deployment, not one distinctive to a proprietary single-vendor hosted arrangement.

Why D is wrong: Tempting as a deployment concern, but automation bias arises in any human-oversight setup regardless of whether the model is proprietary or vendor-hosted.

Why E is wrong: Tempting because drift is a live concern, but a firm consuming a closed hosted model does not control its training data, and drift is a general deployment risk.

See more AIGP practice questions, answers explained.

More in this domain

Back to all Understanding how to govern AI deployment and use objectives, or the AIGP cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.