AIGP - Understanding how laws, standards and frameworks apply to AI (25% of the exam) - Section 2.6

Understand the OECD AI principles, the NIST AI Risk Management Framework and Playbook, and the core ISO AI standards including ISO 22989, 42001 and 42005.

Apply the OECD AI principles, the NIST AI Risk Management Framework and Playbook, and core ISO AI standards including ISO 22989, ISO 42001, and ISO 42005 to an organisation's governance programme. Distinguish the purpose and scope of each framework.

OECD AI principlesNIST AI RMFISO 42001ISO 42005

Practice question for this objective

Free sampleUnderstanding how laws, standards and frameworks apply to AImedium

A governance lead is mapping responsibilities for an AI programme onto the four core functions of the NIST AI Risk Management Framework so that each activity sits under the function it genuinely belongs to. Which TWO statements correctly match a NIST AI RMF core function to the work it is meant to cover? Select TWO.

  • AThe Govern function establishes the culture, policies, accountability lines and oversight that cut across and sustain the other three functions throughout the AI lifecycle. Correct
  • BThe Map function defines the context, intended use and categorisation of a system so its potential risks can be framed before they are measured or treated. Correct
  • CThe Measure function selects the policies and assigns the accountable executive for AI risk across the whole organisation before any system is analysed.
  • DThe Manage function uses quantitative and qualitative tools to assess and benchmark a system's risks against the agreed trustworthiness metrics.
  • EThe four core functions are Identify, Protect, Detect and Respond, applied in that order to each AI system the organisation builds.
Match each NIST AI RMF core function to its purpose, recognising Govern as cross-cutting and distinguishing the framework from the NIST Cybersecurity Framework. The AI RMF is built on Govern, Map, Measure and Manage. Govern is cross-cutting and sustains the others; Map frames context and risk; Measure analyses and benchmarks; Manage prioritises and responds. The Identify-Protect-Detect-Respond set belongs to the separate Cybersecurity Framework.

Why A is correct: Correct: Govern is the cross-cutting function that sets policy, accountability and oversight enabling Map, Measure and Manage to operate.

Why B is correct: Correct: Map gathers context and frames risks, giving the later analysis and response functions something concrete to act on.

Why C is wrong: Tempting because Measure sounds organisation-wide, but setting policy and accountability is the Govern function, not Measure, which analyses and tracks risk.

Why D is wrong: Tempting because Manage handles risk, but assessing and benchmarking against metrics is the Measure function; Manage prioritises and acts on those findings.

Why E is wrong: Tempting because these are real NIST functions, but they belong to the Cybersecurity Framework; the AI RMF functions are Govern, Map, Measure and Manage.

See more AIGP practice questions, answers explained.

Exam traps in Understanding how laws, standards and frameworks apply to AI

Answers that look right on this material and are not. Each one is a distractor from a different question in the AIGP bank for this domain.

  • ISO/IEC 42005, which specifies requirements for an artificial intelligence management system covering leadership, planning and operational control

    Why it is wrong: This option is tempting because the number sits alongside 42001, but 42005 addresses AI system impact assessment rather than a management system, so it is the wrong instrument for organisation-wide governance.

  • Both are voluntary outcome-based frameworks that an external body can certify against, so adopting one makes adopting the other redundant for governance purposes.

    Why it is wrong: This is tempting because both address AI governance, but the NIST AI RMF is not a certifiable standard, so claiming both can be certified and are therefore redundant is wrong on both counts.

  • The four core functions, applied in the fixed sequence Govern, then Map, then Measure, then Manage, with each function gating the next before any gap analysis can begin.

    Why it is wrong: The core functions are real and organise the work, but they are continuous and not a one-time gated sequence, and on their own they do not capture a documented current-versus-target comparison for one use case, which is what the division needs.

Examworthy is not affiliated with or endorsed by IAPP. Original, blueprint-aligned practice material only.