Skip to content
BytePatterns

AIB-C01 · Domain 3: AI Governance and Responsible AI Leadership · 24% of the exam

Task 3.1: Apply responsible AI principles to business decisions.

The responsible AI dimensions applied to real decisions, trade-offs when a business goal pulls against a principle, governance by design from the first planning meeting, and where human oversight, guardrails and escalation are required.

Study it

  • The responsible AI dimensions applied to business decisions

    Lesson coming

  • Trade-offs and governance by design

    Lesson coming

  • Human oversight, guardrails and escalation

    Partly covered by: Guardrails

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A lender's credit-limit model is accurate overall, but a review shows it wrongly declines applicants over 60 about twice as often as younger applicants with similar finances. Which responsible AI dimension does this finding primarily concern?

  1. AFairness
  2. BExplainability
  3. CRobustness
  4. DVeracity
Show the answer and why
  • AFairness

    Correct

    Fairness is about considering impacts on different groups of stakeholders. Performance that varies across demographic groups, such as more wrongful denials for one age group, is a fairness harm.

  • BExplainability

    Incorrect

    Explainability concerns mechanisms to understand why the system produced an output. It would help investigate the problem, but the harm itself is unequal treatment of a group.

  • CRobustness

    Incorrect

    The applicants' inputs are ordinary credit files. The finding is not about how the model copes with its inputs but about different outcomes for groups of people.

  • DVeracity

    Incorrect

    Nothing in the review concerns the content of the model's outputs. The issue here is unequal error rates between groups.

AWS defines fairness as considering impacts on different groups of stakeholders. A fairness assessment looks at harms to individuals, such as wrongful denials, and to groups, such as performance that varies across demographic groups, which is exactly what the review found.

Question 2 · choose 1

A utility company plans to let a generative AI system answer billing questions in its web chat. Research shows that many customers would assume they are talking to an employee and would treat every answer as an official commitment. Which action addresses the responsible AI dimension most at stake?

  1. ARetrain the system on more billing conversations so that its answers become official
  2. BMake the replies sound as human as possible to keep customer satisfaction high
  3. CAdd a content filter that blocks insults in customer messages
  4. DTell customers they are using an AI system and explain its limits
Show the answer and why
  • ARetrain the system on more billing conversations so that its answers become official

    Incorrect

    More training data can improve answers, but it does not tell customers what they are dealing with, which is the gap the research found.

  • BMake the replies sound as human as possible to keep customer satisfaction high

    Incorrect

    Imitating a person deepens the misunderstanding that creates the risk instead of removing it.

  • CAdd a content filter that blocks insults in customer messages

    Incorrect

    A content filter addresses safety. It does not help customers understand that they are interacting with AI.

  • DTell customers they are using an AI system and explain its limits

    Correct

    Transparency means enabling stakeholders to make informed choices about their engagement with an AI system. Harms arise when users are unaware an AI is present or do not understand its probabilistic nature.

When people do not know an AI is involved, or do not understand that its answers can be wrong, they cannot make informed choices. Disclosing the AI and its intended use and limitations, for example in user-facing guidance, is the transparency response.

Question 3 · choose 1

A retailer's product team plans to add a responsible AI review two weeks before launch of its AI pricing assistant, after the design is final. The chief risk officer objects. According to AWS's responsible AI guidance, when should responsible AI practices enter the project?

  1. ATwo weeks before launch, as the team planned, because the design is then stable
  2. BAfter launch, once real customer data shows whether problems exist
  3. COnly if regulators ask for a review of the assistant
  4. DAt the start, when the use case is defined and designed
Show the answer and why
  • ATwo weeks before launch, as the team planned, because the design is then stable

    Incorrect

    A late review finds issues when changing the design is most expensive, and it can only accept or reject what has already been built.

  • BAfter launch, once real customer data shows whether problems exist

    Incorrect

    Waiting for production harm exposes customers first. Monitoring after launch complements design-time work; it does not replace it.

  • COnly if regulators ask for a review of the assistant

    Incorrect

    Responsible AI aims to maximize benefits and minimize risks for the use case whether or not a regulator asks; external demand is not the trigger.

  • DAt the start, when the use case is defined and designed

    Correct

    AWS's Responsible AI Lens is built on being responsible by design: practices are embedded across the lifecycle with the emphasis on identifying and resolving potential issues during design.

Governance by design means the use case, its stakeholders, its potential harms and its release criteria are worked out before the system is built. Design-time decisions are where risks are cheapest to remove, which is why AWS emphasizes resolving issues in design.

Question 4 · choose 1

A health insurer wants a generative AI system to process prior authorization requests. Approvals are routine, but a wrong denial can delay a patient's treatment. Operations wants full automation to meet a cost target. What should the responsible AI lead require?

  1. AAutomate all decisions and audit a random sample of them each month
  2. BLet AI draft every decision, with a clinician reviewing any proposed denial
  3. CLet the AI decide, but add a disclaimer that decisions may contain errors
  4. DDo not use AI for prior authorization at all, because health decisions are sensitive
Show the answer and why
  • AAutomate all decisions and audit a random sample of them each month

    Incorrect

    Sampling after the fact catches patterns but leaves individual patients exposed to wrong denials before anyone reviews them.

  • BLet AI draft every decision, with a clinician reviewing any proposed denial

    Correct

    AWS guidance places human review where errors have significant consequences or quality is hard to judge, and where human expertise adds unique value to consequential decisions.

  • CLet the AI decide, but add a disclaimer that decisions may contain errors

    Incorrect

    A disclaimer informs, but it does not prevent the consequential harm of a wrongful denial.

  • DDo not use AI for prior authorization at all, because health decisions are sensitive

    Incorrect

    A blanket ban gives up value on routine approvals. Placing human review at the high-stakes point keeps the benefit and controls the risk.

Human oversight belongs where mistakes are costly and judgment matters. Letting AI handle routine work while routing consequential outcomes, such as denials, to qualified people balances efficiency with protection for the people affected.

Question 5 · choose 1

A streaming company's marketing team wants its recommendation system to use viewers' inferred health interests to increase engagement. The privacy team says this conflicts with its privacy commitments. Several similar disputes are expected this year. What should the AI governance lead put in place?

  1. AA rule that the business objective always wins when the revenue impact exceeds a threshold
  2. BA rule that privacy always wins, so the team never revisits such requests
  3. CExplicit trade-off criteria from company policy, applied and documented per decision
  4. DLet each product team settle conflicts informally to avoid slowing delivery
Show the answer and why
  • AA rule that the business objective always wins when the revenue impact exceeds a threshold

    Incorrect

    A revenue threshold settles conflicts in one direction only. It ignores the stakeholder harms the trade-off is meant to weigh.

  • BA rule that privacy always wins, so the team never revisits such requests

    Incorrect

    Blanket rules avoid the decision instead of weighing it. Some uses may be acceptable with mitigations, and the criteria should show why.

  • CExplicit trade-off criteria from company policy, applied and documented per decision

    Correct

    AWS guidance is to evaluate trade-offs between benefits and risks and, where they are missing, to develop explicit trade-off criteria (like tenets) that reflect organizational policies and stakeholder needs.

  • DLet each product team settle conflicts informally to avoid slowing delivery

    Incorrect

    Informal, case-by-case outcomes are inconsistent and leave no record of how competing objectives were balanced.

Conflicts between business goals and responsible AI principles are normal. Agreeing on explicit criteria in advance, applying them consistently and documenting each decision make the trade-offs transparent, repeatable and defensible.

Question 6 · choose 2

A bank is adding a generative AI feature to its website that answers each customer question by retrieving passages from its product terms. Leadership has two worries: answers that the product terms do not support reaching customers, and customers who need a person being left with the AI. It wants safeguards that act while the customer is still on the site. Which safeguards should the bank require? (Choose TWO.)

  1. AA check that blocks answers not grounded in the retrieved product terms
  2. BDefined criteria for handing a customer over to a human agent
  3. CA content filter that blocks insults and abusive language in customers' messages
  4. DEncryption of stored chat transcripts with keys that the bank manages
  5. EA monthly compliance review of a sample of past conversations
Show the answer and why
  • AA check that blocks answers not grounded in the retrieved product terms

    Correct

    Contextual grounding checks in Amazon Bedrock Guardrails score each answer against the source passages and the question, and block answers below the threshold before they reach the customer.

  • BDefined criteria for handing a customer over to a human agent

    Correct

    Escalation criteria hand off the cases the AI should not handle. AWS describes escalating to live agents when confidence falls below set thresholds and routing by complexity and customer preference.

  • CA content filter that blocks insults and abusive language in customers' messages

    Incorrect

    Content filters protect against harmful language, but filtering customer input neither checks whether answers are supported by the product terms nor connects anyone to a person.

  • DEncryption of stored chat transcripts with keys that the bank manages

    Incorrect

    Encrypting stored transcripts protects the data at rest. It does nothing about unsupported answers or customers who need a person.

  • EA monthly compliance review of a sample of past conversations

    Incorrect

    Periodic sampled reviews find quality problems over time, but they act weeks after the conversation and cannot stop an answer or hand a waiting customer to a person.

Each safeguard should match the risk it is meant to control. A grounding check stops unsupported answers before customers act on them, and escalation criteria put a person in the loop when the AI should not continue. Filters, encryption and periodic reviews are worthwhile controls, but they address other risks or act too late for these two.

Question 7 · choose 1

A city is launching an AI system that prioritizes road repair requests. Residents, city engineers and council members all need different information about how it works and where it falls short. What should the responsible AI lead create?

  1. AOne technical document published on the city's developer portal for everyone
  2. BNo public information, to avoid confusing residents
  3. CA press release at launch and nothing afterward
  4. DA transparency plan matching formats and channels to each group
Show the answer and why
  • AOne technical document published on the city's developer portal for everyone

    Incorrect

    A single technical document suits engineers but not residents or council members, who need other formats and channels.

  • BNo public information, to avoid confusing residents

    Incorrect

    Withholding information prevents stakeholders from making informed choices about their engagement with the system.

  • CA press release at launch and nothing afterward

    Incorrect

    A one-off announcement does not give each group the detail and ongoing access it needs.

  • DA transparency plan matching formats and channels to each group

    Correct

    AWS guidance is to choose, for each stakeholder group, a transparency strategy such as a user guide, FAQs or system documentation, and an appropriate distribution channel.

Transparency works when information reaches each audience in a form it can use. Matching content, format and channel to each stakeholder group turns a principle into practice.

Question 8 · choose 1

A bank published user documentation for its AI credit assistant at launch. Since then, the system has had three updates, but the documentation still describes the original version. The assistant will keep changing every few months, and the bank wants users to always have accurate information that has been reviewed before it is published. Which practice achieves this?

  1. ARegenerate the docs from release notes and publish them unreviewed
  2. BAn owner and a plan to update, review and republish docs
  3. CA note on the documentation that it may not match the current version
  4. DA scheduled documentation review once a year
Show the answer and why
  • ARegenerate the docs from release notes and publish them unreviewed

    Incorrect

    Automated triggers help, but AWS guidance also calls for a review process with an approval chain before updates are published, which this skips.

  • BAn owner and a plan to update, review and republish docs

    Correct

    AWS guidance is to create a plan for publishing and updating documentation, with a dedicated owner, update criteria and triggers, versioning, review and approval chains.

  • CA note on the documentation that it may not match the current version

    Incorrect

    A disclaimer admits the gap without closing it; users still lack accurate information about the system they are using.

  • DA scheduled documentation review once a year

    Incorrect

    With updates every few months, a yearly review leaves the documentation out of date for most of the year; AWS ties updates to new system releases and stakeholder feedback.

Transparency is not a one-time publication. Documentation needs an owner and a process tied to system changes, with review before release, so that users always have accurate information.

Question 9 · choose 1

Two weeks before release, a bank's team adds a feature to its customer assistant that remembers details from past conversations, such as stated income and family events, to personalize later answers. The release criteria and risk assessment were written for the version without this memory. The product owner wants to keep the release date. What should the responsible AI lead require before release?

  1. AReassess the risks the memory adds and update the release criteria
  2. BRelease on the existing criteria, since the use case is unchanged
  3. CRelease on schedule and watch for privacy complaints afterward
  4. DRestart the full responsible AI review from the use case definition
Show the answer and why
  • AReassess the risks the memory adds and update the release criteria

    Correct

    AWS guidance is to check whether design choices introduce new risks or change their likelihood, update the risk assessment, and decide whether the release criteria must change so the new risks are tested before release.

  • BRelease on the existing criteria, since the use case is unchanged

    Incorrect

    The use case is the same, but the design now keeps personal details across sessions, a risk the original criteria were never written to test.

  • CRelease on schedule and watch for privacy complaints afterward

    Incorrect

    Monitoring after launch has its place, but AWS guidance is to cover newly identified risks in the release criteria and test them before release, not to discover them through customers.

  • DRestart the full responsible AI review from the use case definition

    Incorrect

    The guidance targets the design decision that changed the risk profile; repeating every step from the start would miss the release date without adding protection for the specific new risk.

Responsible AI review is not a gate passed once. A design change can bring risks the original assessment never covered, so the assessment and the release criteria should be updated for that change and the new risks tested before the system ships.

Question 10 · choose 1

A housing agency's team is assessing the benefits and harms of its AI eligibility screener. Its list of contributors and overseers, from the software vendor to the compliance officers who approve deployment, is complete. On the affected side it lists only applicants and caseworkers, yet the screener uses data about household members and affects neighborhoods' access to services. What should the responsible AI lead ask the team to add?

  1. AThe IT team that runs the screener and the vendor that built it
  2. BHousehold members only, since their data is used as input
  3. CSecondary users, indirect stakeholders and vulnerable groups
  4. DThe agency's board and the funding body that approve the budget
Show the answer and why
  • AThe IT team that runs the screener and the vendor that built it

    Incorrect

    Operators and suppliers are upstream stakeholders, which the team has already covered; the gap is the people affected by the system's operation.

  • BHousehold members only, since their data is used as input

    Incorrect

    Household members are secondary users, but stopping there leaves out the indirect stakeholders, such as affected neighborhoods, and vulnerable groups.

  • CSecondary users, indirect stakeholders and vulnerable groups

    Correct

    AWS guidance is to consider primary users, secondary users such as those whose data is used as input, indirect stakeholders affected by the system, and vulnerable populations across categories.

  • DThe agency's board and the funding body that approve the budget

    Incorrect

    Bodies that approve and fund the system are oversight stakeholders on the upstream side, which the team's list already covers.

Benefits and harms can only be assessed for people who have been identified. Including secondary users, indirect stakeholders and vulnerable groups makes the responsible AI analysis reflect everyone the system affects, not only those who use it.

Question 11 · choose 1

An insurer's AI underwriting assistant is ready for a release decision. The evidence is spread across emails, test logs and slide decks, and reviewers cannot see whether all risks were addressed. What should the responsible AI lead prepare?

  1. AA launch announcement draft for the marketing team to review and approve
  2. BThe raw test logs, sent to every reviewer for interpretation
  3. CA verbal briefing to the sponsor, without written records
  4. DOne evidence package for stakeholder review, with the decision recorded
Show the answer and why
  • AA launch announcement draft for the marketing team to review and approve

    Incorrect

    Marketing approval of an announcement is not a review of the release evidence.

  • BThe raw test logs, sent to every reviewer for interpretation

    Incorrect

    Unsummarized logs make it harder, not easier, to see whether risks are addressed.

  • CA verbal briefing to the sponsor, without written records

    Incorrect

    A verbal briefing leaves no record of what was reviewed and decided.

  • DOne evidence package for stakeholder review, with the decision recorded

    Correct

    AWS guidance is to organize evidence from the use case, risk assessments, release criteria tests, datasets and system design into a single source of truth, review it with stakeholders and record the go/no-go decision.

Governance by design ends in a documented decision. A consolidated evidence package lets the right people verify that risks across responsible AI dimensions are mitigated before release.

Practise domain 3 →Practise all domains →