44 practice questions for Domain 3 of the AWS Certified AI Business Strategist (AIB-C01) exam, which makes up 24% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 3: AI Governance and Responsible AI Leadership
97. A recruitment AI tool is found to score candidates from certain postcodes lower, and postcode correlates with a protected characteristic. Which response is most appropriate?
Answer and explanation
Answer: B. A feature that correlates with a protected characteristic acts as a proxy and can produce discriminatory outcomes even though the characteristic is not used directly, so the feature's contribution must be assessed and mitigated before further use. Arguing that postcode is not itself protected ignores how proxy discrimination works. More data does not remove a systematic proxy relationship. Disclosure does not make a discriminatory outcome acceptable.
98. An organization is establishing AI governance. Which structure most effectively balances innovation with risk control?
Answer and explanation
Answer: C. Risk-tiered governance concentrates scrutiny where consequences are greatest while allowing low-risk experimentation to proceed quickly, and cross-functional membership brings legal, business, and technical perspectives. A universal executive gate becomes a bottleneck that drives shadow adoption. No governance leaves high-risk uses unreviewed. Engineering-only ownership omits the legal, ethical, and business judgement high-risk decisions require.
99. Under the AWS shared responsibility model applied to a generative AI application on Amazon Bedrock, which responsibility belongs to the customer?
Answer and explanation
Answer: D. Customers control their data, the guardrail configuration, and the identity and access model for their application, which is security in the cloud. Physical infrastructure patching, facility security, and hypervisor maintenance are all AWS responsibilities for security of the cloud and are not customer-configurable.
100. Which governance structure best balances speed with control across many AI initiatives?
Answer and explanation
Answer: B. Tiering concentrates scrutiny where consequences are greatest while letting low-risk work proceed quickly, which prevents governance becoming a bottleneck that drives shadow adoption. A universal detailed review creates that bottleneck. Self-certification leaves high-risk uses unreviewed. Post-production review arrives after harm is possible.
101. An AI system will influence decisions about individuals' access to a service. Which control should be mandatory?
Answer and explanation
Answer: B. Decisions affecting individuals require a person able to examine and change the outcome, with the reasoning recorded for challenge or audit. A disclaimer informs without providing recourse. Quarterly sampling reviews decisions already acted upon. A higher threshold changes behaviour without introducing human judgement.
102. A model uses a feature that correlates strongly with a protected characteristic although the characteristic itself is excluded. What is the governance concern?
Answer and explanation
Answer: B. A proxy variable transmits the protected characteristic's influence into the outcome, so excluding the characteristic formally does not prevent discriminatory effect. This is a fairness and legal concern rather than merely a performance or intellectual property matter.
103. Which documentation most helps a reviewer decide whether a model is appropriate for a proposed new use?
Answer and explanation
Answer: B. A model card states what the model was built for, where it fails, and how it was evaluated, which is what determines fitness for a new purpose. Source code describes implementation without stating intended use. Cost reports and parameter counts carry no information about suitability.
104. A third-party AI vendor processes customer data on the company's behalf. Which governance step is essential?
Answer and explanation
Answer: A. Third-party processing extends the company's data risk to the vendor, so retention, usage, and training practices must be established contractually and verified. The underlying model, interface quality, and marketing claims do not address data handling obligations.
105. An organization must prepare for regulatory scrutiny of its AI systems. Which practice most improves its position?
Answer and explanation
Answer: C. Regulators ask what systems exist, what they do, who owns them, and what evidence supports their use, so a maintained inventory with risk classification is the foundation of any response. Confidentiality does not remove obligations. Responsibility cannot be delegated to a vendor. Publishing weights is unrelated and may create other risks.
106. An AI incident occurs when a customer-facing assistant gives harmful advice. What should the organization have in place beforehand?
Answer and explanation
Answer: B. AI incidents differ from outages because the system is available but behaving harmfully, so a defined process for detection, containment, and communication is required. An outage runbook addresses unavailability. A retraining schedule does not handle a live incident. A disclaimer does not constitute a response capability.
107. Which measure best supports transparency with customers interacting with an AI assistant?
Answer and explanation
Answer: D. Transparency for an end user means knowing what they are dealing with and having recourse to a person. Architecture details, uptime figures, and infrastructure locations are not meaningful to a customer deciding whether to trust an interaction.
108. Which risk is specific to generative AI and requires explicit management in a customer-facing deployment?
Answer and explanation
Answer: A. Confidently stated but unfounded output is characteristic of generative systems and requires grounding, guardrails, and review to manage. Capacity, licensing, and latency are general IT concerns rather than risks arising from the technology's nature.
109. A company is concerned about intellectual property in content produced by a generative system. What should it establish?
Answer and explanation
Answer: A. Intellectual property exposure is addressed through policy on what may be used as input, clarity on ownership of output, and contractual indemnities from the provider. Mandatory rewriting does not resolve ownership. A blanket prohibition forgoes the capability. Publishing output does not address ownership at all.
110. A model in production was trained two years ago and the provider has announced its deprecation. What governance practice should have anticipated this?
Answer and explanation
Answer: B. Models are dependencies with lifecycles, so the inventory should record versions and deprecation exposure with a plan to migrate and re-evaluate. Providers do not maintain models indefinitely. Avoiding managed models substitutes a much larger burden. Freezing an application does not prevent the underlying model being withdrawn.
111. Which practice most reduces the risk that employees paste confidential information into external AI tools?
Answer and explanation
Answer: C. Shadow use is driven by unmet need, so providing sanctioned tools that do the job, alongside policy and controls, is what actually reduces leakage. Prohibition without alternatives drives use underground. Monitoring without alternatives detects rather than prevents. Judgement alone is not a control.
112. A board asks for regular reporting on AI risk. What content is most useful?
Answer and explanation
Answer: B. A board needs exposure, incidents, control effectiveness, and outstanding actions to discharge oversight. Model counts and spend are activity measures. A technology summary is educational rather than a risk report.
113. Which control addresses the risk that an AI system's performance degrades silently after deployment?
Answer and explanation
Answer: B. Degradation happens after launch as data and conditions change, so it is detected by ongoing monitoring rather than by pre-deployment testing alone. An annual review is far too infrequent for gradual drift. A disclaimer transfers perception of risk without detecting anything.
114. An AI system will make recommendations that materially affect individuals in more than one country. What should governance establish first?
Answer and explanation
Answer: B. Regulatory obligations shape design, documentation, and oversight requirements, so establishing which apply is prerequisite to building. Inference cost, benchmark scores, and interface language are downstream choices.
115. Which statement about consent and data use is most accurate for training or customizing an AI model on customer data?
Answer and explanation
Answer: A. Data collected for one stated purpose generally cannot be repurposed freely, and training is a distinct purpose that may require a fresh basis. Holding data does not confer unlimited rights. The constraint applies regardless of technique. Anonymization helps but is rarely complete and does not remove every obligation.
116. Which approach best manages the risk of over-reliance on an AI system by the people using it?
Answer and explanation
Answer: C. Over-reliance is a human factors problem addressed by surfacing uncertainty and provenance and by teaching users where the system fails. No achievable accuracy removes the need for judgement. Hiding AI involvement worsens miscalibrated trust. A waiver shifts liability without changing behaviour.
117. An AI vendor will not disclose how its model was trained or evaluated. What should the strategist conclude?
Answer and explanation
Answer: C. Opacity limits the organization's ability to assess fitness and risk, which is a real factor in the decision and can be partly offset by contractual terms and independent testing. It is neither automatically benign nor proof of a defect. Purchased systems still carry risk the buyer is accountable for.
118. Which practice supports accountability when an AI system contributes to a decision that is later challenged?
Answer and explanation
Answer: B. Answering a challenge requires reconstructing what the system was given, what it produced, and what the human did with it. The final decision alone omits the basis. Thirty days is often shorter than the challenge window. Provider logs do not capture the organization's own decision context.
119. Which consideration belongs in an AI governance framework but is often omitted?
Answer and explanation
Answer: A. Governance frameworks commonly cover approval to deploy while omitting a defined path to withdraw a system, which leaves underperforming or inappropriate systems running by default. Vendor lists, budget thresholds, and naming conventions are useful but routinely included.
120. An AI governance body is being formed. Which composition is most appropriate?
Answer and explanation
Answer: C. AI decisions span business value, technical feasibility, legal exposure, and compliance, so the body needs all four represented with accountability defined. Any single function sees only part of the risk. One executive deciding alone concentrates judgement without the necessary breadth.
121. Why does an organization apply a risk classification framework to its AI systems?
Answer and explanation
Answer: D. Risk classification prioritises oversight where consequences are greatest, since uniform governance across all systems is neither affordable nor proportionate. Compute consumption, build order, and vendor selection are separate decisions.
122. A business process that uses AI is subject to sector regulation. What should be established before the system is deployed?
Answer and explanation
Answer: B. Regulatory obligations and the evidence of compliance must be established before deployment, because retrofitting them is costly and may be impossible. User count, model choice, and latency are design decisions rather than compliance preconditions.
123. At which stages of the AI lifecycle can bias be introduced?
Answer and explanation
Answer: D. Bias can enter through how data is collected, how it is labelled, how the model is trained, and how the system is used, which is why monitoring is continuous. Attributing it to a single stage leads to controls that miss the others.
124. An organization uses a generative AI system to produce marketing copy. Which intellectual property risk should be managed?
Answer and explanation
Answer: C. The principal IP risks are that output may reproduce protected material and that ownership of generated content can be uncertain. Model weights do not transfer to the customer. Brand copyright is unaffected. Customer data ownership is a separate contractual matter rather than an IP risk of generation.
125. A business decision must balance a model's accuracy against its explainability. Which consideration should drive the decision?
Answer and explanation
Answer: C. Consequence and regulation determine whether explainability is mandatory. Recency, cost, and preference do not resolve the trade-off.
126. An AI system's outputs affect individuals differently depending on their demographic group. Which responsible AI principle is engaged?
Answer and explanation
Answer: C. Differential outcomes across groups engage fairness. Robustness concerns behaviour on unexpected input, privacy concerns personal data, and transparency concerns disclosure.
127. A generative AI system must be prevented from producing content that breaches the organization's policy. Which control belongs in the design?
Answer and explanation
Answer: B. Automated evaluation with human escalation enforces the policy at the point of generation. A circulated policy, quarterly review, and prompt instruction are all advisory or retrospective.
128. An organization must decide where human oversight is required in an AI-enabled process. Which approach is appropriate?
Answer and explanation
Answer: B. Risk-proportionate oversight concentrates scarce human attention where errors matter most. Universal oversight does not scale, complaint-driven oversight is reactive, and removing it on an accuracy threshold ignores that errors still occur.
129. An AI governance framework must define accountability for a deployed system. Which element is required?
Answer and explanation
Answer: B. Accountability requires a named owner and escalation paths. Technology lists, dates, and user counts are inventory rather than accountability.
130. An AI system processes personal data in several jurisdictions with differing requirements. Which approach is appropriate?
Answer and explanation
Answer: A. Multi-jurisdiction processing requires per-flow analysis against the applicable rules. A single home standard, the least restrictive standard, and deferral all risk non-compliance.
131. An AI system's risk classification must determine the governance applied to it. Which factors should the classification consider?
Answer and explanation
Answer: C. Consequence, data sensitivity, and autonomy determine risk. User count, cost, and technology describe the system without indicating its risk.
132. Which governance practice applies across the whole AI lifecycle rather than at a single point?
Answer and explanation
Answer: B. Lifecycle governance reviews at checkpoints throughout. Launch approval, annual audit, and decommission review each cover one point.
133. An AI system's performance has degraded since deployment although its code has not changed. Which risk does this describe?
Answer and explanation
Answer: B. Degradation without a code change indicates drift in the underlying relationship. Defects follow releases, capacity shortages affect throughput, and licensing produces access failures.
134. Employees are using public generative AI tools with company information. Which risk is most significant?
Answer and explanation
Answer: B. Uncontrolled disclosure of confidential information to a third party is the principal shadow AI risk. Cost, productivity, and latency are minor by comparison.
135. An AI system's training data is found to contain content the organization does not have rights to use. Which risk does this create?
Answer and explanation
Answer: B. Unlicensed training content creates legal exposure extending to derived outputs. Accuracy, cost, and speed are not the consequence.
136. An organization must decide what to monitor to detect emerging AI risks after deployment. Which combination is appropriate? (Select TWO.)
Answer and explanation
Answer: B, D. Quality degradation and misuse patterns are the risk signals. Request counts, model counts, and infrastructure cost describe scale and spend rather than risk.
137. An AI governance framework must define how exceptions to policy are handled.
Answer and explanation
Answer: C. Defined approval, basis, duration, and review make exceptions controlled. Prohibition drives them underground, unit-level approval is inconsistent, and informal handling is unauditable.
138. Which element must an AI governance framework define for a system that makes decisions affecting customers?
Answer and explanation
Answer: A. A contest and review route is required where decisions affect customers. Infrastructure, architecture, and authorship are implementation facts.
139. Which enterprise risk arises when several business units deploy AI independently without coordination?
Answer and explanation
Answer: C. Uncoordinated deployment produces inconsistent controls and no aggregate risk view. Cost, latency, and accuracy are narrower consequences.
140. An AI system's supplier has changed the underlying model without notice. Which risk does this create?
Answer and explanation
Answer: B. An unannounced model change can alter behaviour and invalidate the evaluation the approval rested on. Cost, total failure, and data loss are not the characteristic risk.