AIGP - Understanding how to govern AI development (27% of the exam) - Section 3.5

Govern the release of an AI system, including readiness assessment, model card creation, conformity requirements, and preparation of public disclosures to meet transparency obligations.

Govern AI system release by conducting readiness assessments, creating model cards, verifying conformity requirements, and preparing public disclosures that meet AI transparency obligations. Recognise what each artefact must contain to satisfy regulatory and stakeholder expectations.

model cardconformity requirementspost-market monitoringAI transparency obligations

Practice question for this objective

Free sampleUnderstanding how to govern AI developmentmedium

A provider has built a CV-screening system that ranks job applicants, a use listed in Annex III of the EU AI Act. Before it can place the system on the EU market, the governance lead asks what the Act requires as the gateway step that lets the system bear a CE marking. Which requirement is that gateway step?

  • ARegistering the deployer's data protection officer with the national supervisory authority for personal data
  • BObtaining explicit opt-in consent from every applicant before any ranking decision is produced
  • CCompleting a conformity assessment against the high-risk requirements and drawing up the EU declaration of conformity Correct
  • DPublishing the model's full training source code and weights in an open repository for inspection
Recognise that an EU AI Act high-risk system must pass a conformity assessment and gain an EU declaration of conformity before it can carry a CE marking. Under the EU AI Act, high-risk systems such as those used for recruitment ranking cannot be placed on the market until the provider has demonstrated conformity with the high-risk requirements through a conformity assessment and has drawn up the EU declaration of conformity. The CE marking signals that this gateway has been met. GDPR roles, consent, or source-code publication address different obligations and are not the conformity gateway.

Why A is wrong: A data protection officer relates to GDPR governance and may be relevant separately, but registering one is not the AI Act step that authorises a CE marking on a high-risk system.

Why B is wrong: Consent may matter for the lawful processing of applicant data, yet the AI Act does not make applicant consent the precondition for affixing a CE marking to a high-risk system.

Why C is correct: For a high-risk system the provider must run a conformity assessment against the Chapter III requirements and draw up the EU declaration of conformity, which is what permits the CE marking and lawful placement on the market.

Why D is wrong: Open publication can support transparency in some contexts, but the AI Act does not require disclosing source code and weights as the condition for placing a high-risk system on the market.

See more AIGP practice questions, answers explained.

Exam traps in Understanding how to govern AI development

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • A marketing summary highlighting the assistant's fluent writing quality and the productivity gains observed during the internal pilot, framed to encourage adoption across teams

    Why it is wrong: Pilot benefits and writing quality may interest sponsors, but a model card exists to communicate validated behaviour and limits, not promotional framing, so this fails the artefact's purpose and omits the safety-critical information adopters need.

  • The post-market monitoring plan is already running on collected field data, with drift metrics gathered from live recruitment decisions.

    Why it is wrong: Tempting because post-market monitoring is mandatory, but live field data and its drift metrics only exist after deployment, so this cannot be confirmed as in place at the release gate.

  • A model card is a signed legal attestation lodged with a notified body, whereas a declaration of conformity is an informal internal note describing how the system was tested

    Why it is wrong: This inverts the two artefacts, which is tempting because both relate to release documentation, but the model card is not a lodged legal attestation and the declaration of conformity is a formal legal statement, not an informal note.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.