AIGP - Understanding how to govern AI development - Section 3.2

Identify and manage internal and external risks in designing and building AI models, using tools such as probability/severity harm matrices, risk mitigation hierarchies, stakeholder mapping and pre-deployment pilots.

Identify internal and external risks during AI design and build using harm probability and severity matrices, risk mitigation hierarchies, and stakeholder mapping. Apply pre-deployment testing to validate that mitigations are effective before release.

AI risk mitigation hierarchyharm probability and severitystakeholder mappingpre-deployment testing

Practice question for this objective

Free sampleUnderstanding how to govern AI developmenthard

A design team has a probability and severity matrix template and a mitigation hierarchy ready to apply to a new AI system, and asks where stakeholder mapping fits in relation to them. A governance adviser is asked to explain the correct relationship between stakeholder mapping, the harm matrix, and the mitigation hierarchy in the design-stage risk process. Which explanation is correct?

  • AStakeholder mapping helps identify who could be harmed, the harm matrix then ranks those identified risks by likelihood and severity, and the mitigation hierarchy guides how the prioritised risks are treated. Correct
  • BStakeholder mapping and the harm matrix are interchangeable starting points, so a team may begin with either one and reach the same set of prioritised risks.
  • CThe mitigation hierarchy should be applied before stakeholder mapping, because deciding how to treat risks early lets the team limit which stakeholders it then needs to consult.
  • DStakeholder mapping and the harm matrix should each be completed once at the outset and then frozen, because revisiting them after treatment would reopen settled risk decisions.
Sequence design-stage risk tools so identification through stakeholder mapping precedes prioritisation by the harm matrix and treatment by the mitigation hierarchy. The design-stage risk tools form an ordered chain. Stakeholder mapping and context-setting identify who could be affected and what harms could arise. The probability and severity matrix then ranks those identified risks so attention goes where it matters most. The mitigation hierarchy guides how the prioritised risks are treated, from elimination down to acceptance. Because a matrix cannot rank harms that were never identified and treatment presupposes a priority order, the tools are complementary stages rather than interchangeable or fixed steps.

Why A is correct: Identification must precede prioritisation, which must precede treatment, so mapping affected parties feeds the matrix that ranks the risks, and the hierarchy then determines how the highest-priority risks are addressed.

Why B is wrong: The two tools serve different stages and are tempting to treat as equivalent entry points, but a matrix can only rank risks that have first been identified, so they are not interchangeable.

Why C is wrong: Choosing treatments first is appealing as a shortcut, but treating risks before identifying who is affected reverses the logic and risks missing harms to stakeholders the team never mapped.

Why D is wrong: Stability sounds disciplined, but risk work is iterative and new information can change who is affected and how risks rank, so freezing the analysis is poor practice rather than a correct relationship.

See more AIGP practice questions, answers explained.

More in this domain

Back to all Understanding how to govern AI development objectives, or the AIGP cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.