AIGP - Understanding how laws, standards and frameworks apply to AI - Section 2.6

Understand the OECD AI principles, the NIST AI Risk Management Framework and Playbook, and the core ISO AI standards including ISO 22989, 42001 and 42005.

Apply the OECD AI principles, the NIST AI Risk Management Framework and Playbook, and core ISO AI standards including ISO 22989, ISO 42001, and ISO 42005 to an organisation's governance programme. Distinguish the purpose and scope of each framework.

OECD AI principlesNIST AI RMFISO 42001ISO 42005

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AImedium

A governance lead is mapping responsibilities for an AI programme onto the four core functions of the NIST AI Risk Management Framework so that each activity sits under the function it genuinely belongs to. Which TWO statements correctly match a NIST AI RMF core function to the work it is meant to cover? Select TWO.

  • AThe Govern function establishes the culture, policies, accountability lines and oversight that cut across and sustain the other three functions throughout the AI lifecycle. Correct
  • BThe Map function defines the context, intended use and categorisation of a system so its potential risks can be framed before they are measured or treated. Correct
  • CThe Measure function selects the policies and assigns the accountable executive for AI risk across the whole organisation before any system is analysed.
  • DThe Manage function uses quantitative and qualitative tools to assess and benchmark a system's risks against the agreed trustworthiness metrics.
  • EThe four core functions are Identify, Protect, Detect and Respond, applied in that order to each AI system the organisation builds.
Match each NIST AI RMF core function to its purpose, recognising Govern as cross-cutting and distinguishing the framework from the NIST Cybersecurity Framework. The AI RMF is built on Govern, Map, Measure and Manage. Govern is cross-cutting and sustains the others; Map frames context and risk; Measure analyses and benchmarks; Manage prioritises and responds. The Identify-Protect-Detect-Respond set belongs to the separate Cybersecurity Framework.

Why A is correct: Correct: Govern is the cross-cutting function that sets policy, accountability and oversight enabling Map, Measure and Manage to operate.

Why B is correct: Correct: Map gathers context and frames risks, giving the later analysis and response functions something concrete to act on.

Why C is wrong: Tempting because Measure sounds organisation-wide, but setting policy and accountability is the Govern function, not Measure, which analyses and tracks risk.

Why D is wrong: Tempting because Manage handles risk, but assessing and benchmarking against metrics is the Measure function; Manage prioritises and acts on those findings.

Why E is wrong: Tempting because these are real NIST functions, but they belong to the Cybersecurity Framework; the AI RMF functions are Govern, Map, Measure and Manage.

See more AIGP practice questions, answers explained.

More in this domain

Back to all Understanding how laws, standards and frameworks apply to AI objectives, or the AIGP cert hub.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.