Skip to content
BytePatterns

AIB-C01 · Domain 3: AI Governance and Responsible AI Leadership · 24% of the exam

Task 3.2: Establish AI governance structures and ensure regulatory compliance.

Cross-functional governance bodies with clear accountability, regulatory risks in AI-driven processes, access control and data security for AI systems, and risk classification that scales oversight to the stakes of each use case.

Study it

  • Governance bodies, accountability and the regulatory picture

    Lesson coming

  • Access control, data security and the shared responsibility model for AI

    Partly covered by: Shared Responsibility & IAM

  • Risk classification across the AI lifecycle

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

A pharmaceutical company has a dozen AI pilots, each approved informally by whichever executive sponsored it. Nobody can say who is accountable when a pilot causes a problem. The CEO asks for a governance structure. What should the company establish?

  1. AAn approval process run by the IT department alone, because AI is a technology
  2. BA rule that each pilot's executive sponsor approves its own pilot as before
  3. CA cross-functional AI oversight committee with defined roles and a RACI matrix
  4. DAn external auditor who reviews every AI system once a year
Show the answer and why
  • AAn approval process run by the IT department alone, because AI is a technology

    Incorrect

    AI decisions involve legal, compliance, security and business risk. An IT-only body lacks the representation those decisions need.

  • BA rule that each pilot's executive sponsor approves its own pilot as before

    Incorrect

    This is the current informal arrangement that leaves accountability unclear when something goes wrong.

  • CA cross-functional AI oversight committee with defined roles and a RACI matrix

    Correct

    AWS's maturity guidance calls for a cross-functional oversight committee for AI implementation reviews and a signed-off RACI matrix that makes responsibilities explicit.

  • DAn external auditor who reviews every AI system once a year

    Incorrect

    External audits provide assurance, but an annual review is not an internal structure that decides and owns AI matters day to day.

Effective AI governance brings together the functions affected by AI, including business, technology, legal, compliance and security, and makes accountability explicit. A cross-functional committee plus a RACI matrix answers the question of who decides and who is accountable.

Question 2 · choose 1

A national bank is early in its AI journey and operates under strict regulatory oversight. It is choosing between centralized, federated and hybrid governance for AI agents. Which model fits its situation best?

  1. ACentralized governance with a single enterprise authority for policies and approvals
  2. BFederated governance, letting each business unit set its own rules under shared standards
  3. CHybrid governance, mixing central standards with local autonomy
  4. DNo formal governance until the first agents reach production
Show the answer and why
  • ACentralized governance with a single enterprise authority for policies and approvals

    Correct

    AWS guidance says centralized governance provides strong control, consistent enforcement and simpler compliance, and works well for highly regulated industries or organizations early in their AI journey.

  • BFederated governance, letting each business unit set its own rules under shared standards

    Incorrect

    Federated governance suits large enterprises with diverse business units and mature IT governance. Early in the journey it risks inconsistent interpretation of strict regulations.

  • CHybrid governance, mixing central standards with local autonomy

    Incorrect

    Hybrid governance suits many enterprises, but it requires a clear delineation of responsibilities that an organization early in its AI journey has not built yet, and AWS points highly regulated or early-stage organizations to centralized control.

  • DNo formal governance until the first agents reach production

    Incorrect

    Deferring governance in a strictly regulated bank invites compliance failures and shadow AI before controls exist.

The governance model should fit the organization's culture, risk tolerance and maturity. For a highly regulated organization at the start of its AI journey, centralized control and consistent policy enforcement outweigh the speed that distributed models offer.

Question 3 · choose 1

A hiring-software company will offer an AI candidate-screening feature to employers in several countries. Product managers assume that compliance with the laws of the company's home country is enough. What should the product leader do before launch?

  1. AComply with the home country's laws only, because the company is registered there
  2. BMap where data is collected and used; have legal identify each location's rules
  3. CRely on the employers to check compliance, because they make the hiring decisions
  4. DUse the Responsible AI Lens as the compliance checklist for all countries
Show the answer and why
  • AComply with the home country's laws only, because the company is registered there

    Incorrect

    The geographic scope of operation determines which laws apply. An international feature can be subject to rules in each market.

  • BMap where data is collected and used; have legal identify each location's rules

    Correct

    AWS guidance is to identify the specific geographic locations where the system operates, including where data is collected and processed and where decisions apply, and to work with legal on AI-specific, data protection and industry rules in each.

  • CRely on the employers to check compliance, because they make the hiring decisions

    Incorrect

    Customers' obligations do not remove the provider's own, and approvals for the use case must be obtained by the team building it.

  • DUse the Responsible AI Lens as the compliance checklist for all countries

    Incorrect

    AWS states that the lens is advisory and should not be used as a compliance or assurance checklist; legal counsel interprets the regulations that apply.

AI regulations, data protection laws and industry rules differ by location, and an AI system may be subject to several at once. Mapping the geographic footprint and engaging legal early, including on upcoming regulations, prevents a launch that is compliant at home and exposed abroad.

Question 4 · choose 1

A company is building an AI assistant that answers employees' questions from internal documents, including HR files and board papers that only some employees may read. The security officer wants to prevent the assistant from revealing restricted content. Which control matters most?

  1. AInstruct the model in its prompt never to reveal confidential information
  2. BLet the assistant retrieve only documents the asking user is allowed to read
  3. CGive the assistant read access to every document so that answers are complete
  4. DEncrypt the documents at rest and give the assistant the keys
Show the answer and why
  • AInstruct the model in its prompt never to reveal confidential information

    Incorrect

    Prompt instructions can be bypassed and do not control what data is retrieved. Access must be enforced in the data layer, not requested of the model.

  • BLet the assistant retrieve only documents the asking user is allowed to read

    Correct

    AWS's data strategy guidance says generative AI models should only retrieve information that the user is authorized to access, and managed knowledge bases support document-level permission filtering at retrieval time.

  • CGive the assistant read access to every document so that answers are complete

    Incorrect

    Broad access lets any user reach restricted content through the assistant, because it can answer from everything it is able to read.

  • DEncrypt the documents at rest and give the assistant the keys

    Incorrect

    Encryption at rest protects stored data, but an assistant that can decrypt everything can still show restricted content to any user.

An AI assistant must not become a way around existing permissions. Enforcing each user's access rights at retrieval keeps restricted documents restricted even when the question is asked in natural language.

Question 5 · choose 1

An insurer's AI committee has a list of 30 potential harms across its AI use cases and limited capacity to review them. It wants to decide which harms get the strongest controls first. How should it classify them?

  1. ARank the harms by how often they have appeared in news coverage of AI
  2. BTreat all 30 harms as equally important and address them in list order
  3. CRate each harm's likelihood and severity and combine them into a risk level
  4. DRank the harms only by severity, because likelihood is hard to estimate
Show the answer and why
  • ARank the harms by how often they have appeared in news coverage of AI

    Incorrect

    Media attention is not a measure of the likelihood or severity of a harm in the insurer's own use cases.

  • BTreat all 30 harms as equally important and address them in list order

    Incorrect

    Treating every harm alike spreads limited capacity evenly instead of focusing it where risk is highest.

  • CRate each harm's likelihood and severity and combine them into a risk level

    Correct

    AWS guidance uses a risk matrix that combines likelihood (probability of occurrence) and severity (degree of consequences) to assign an overall risk level such as low, medium, high or critical.

  • DRank the harms only by severity, because likelihood is hard to estimate

    Incorrect

    Severity alone ignores how probable a harm is. AWS's approach rates both and sets standardized scales so that likelihood can be estimated consistently.

Risk classification turns a long list of concerns into priorities. A consistent matrix of likelihood and severity gives every harm a risk level, so governance and controls go first where the expected impact is greatest.

Question 6 · choose 1

A manufacturer's risk office is building its first AI risk framework from scratch, with categories invented internally. Auditors and partners find it hard to compare with other companies' approaches. The board wants a framework that auditors can work with this year, before any AI-specific regulation applies to the company, and that fits the manufacturer's own AI uses. What does AWS's security guidance recommend?

  1. AKeep the internal categories and document them in more detail
  2. BAlign it with an established framework such as the NIST AI RMF
  3. CAdopt a peer company's framework unchanged, since auditors know it
  4. DWait until regulators publish a mandatory AI risk framework
Show the answer and why
  • AKeep the internal categories and document them in more detail

    Incorrect

    More detail does not give auditors and partners a shared reference; AWS recommends aligning with an established standard such as the NIST AI Risk Management Framework.

  • BAlign it with an established framework such as the NIST AI RMF

    Correct

    AWS's guidance is to align the risk framework with established standards like the NIST AI Risk Management Framework while adapting controls for AI-specific challenges.

  • CAdopt a peer company's framework unchanged, since auditors know it

    Incorrect

    A peer's framework reflects its own risks; AWS advises calibrating the risk strategy to the deployment context and adapting controls to the organization's AI-specific challenges.

  • DWait until regulators publish a mandatory AI risk framework

    Incorrect

    AWS encourages organizations to use NIST ahead of regulatory action rather than wait, and the board needs a framework this year.

Governance structures are easier to explain and audit when they build on recognized frameworks. Aligning with an established AI risk framework, then adapting it to the organization, gives a common language for compliance.

Question 7 · choose 1

A bank's central security team reviews every AI project and has become a bottleneck; data scientists see security as the team that says "no". Which governance structure does AWS's security guidance suggest?

  1. AMore reviewers added to the central security team's review board
  2. BLetting data scientists skip security reviews for AI
  3. CTrained security guardians embedded in the data science teams
  4. DMoving security reviews to the end of each project
Show the answer and why
  • AMore reviewers added to the central security team's review board

    Incorrect

    More central reviewers keep the gatekeeping model that creates the bottleneck.

  • BLetting data scientists skip security reviews for AI

    Incorrect

    Skipping reviews removes security instead of scaling it.

  • CTrained security guardians embedded in the data science teams

    Correct

    AWS suggests scaling security rather than consolidating it, for example by training guardians who embed security in data science teams, shifting security left with fast feedback and an enabling "yes, but" approach.

  • DMoving security reviews to the end of each project

    Incorrect

    Late reviews increase rework and do not provide the fast feedback the teams need.

Governance structures should scale with demand. Embedding trained security expertise in teams keeps control close to the work and speeds delivery instead of creating a queue.

Question 8 · choose 1

A US retailer plans to give its data science team European customers' purchase records for AI work. Following the method it uses for US data, it removes names and email addresses but keeps birth dates, postcodes and detailed purchase histories, and its US counsel accepts the result as deidentified. The records will stay in the company's governed cloud environment. What should the compliance lead conclude?

  1. AThe records may still count as personal data under GDPR, so its rules apply
  2. BThe US method is sufficient, since deidentification is defined alike everywhere
  3. CSharing is fine as long as every access is logged and audited
  4. DSharing is fine because the data stays in the governed cloud environment
Show the answer and why
  • AThe records may still count as personal data under GDPR, so its rules apply

    Correct

    AWS notes that definitions of PII differ by country, and in the EU, if a person can be re-identified, the GDPR does not recognize the data as deidentified. Removing names and email addresses does not settle that question when detailed personal attributes remain.

  • BThe US method is sufficient, since deidentification is defined alike everywhere

    Incorrect

    The United States and other countries define PII differently, so a method accepted in one jurisdiction may not satisfy another.

  • CSharing is fine as long as every access is logged and audited

    Incorrect

    Auditing helps maintain appropriate use of data, but it does not change whether the records count as deidentified under the GDPR.

  • DSharing is fine because the data stays in the governed cloud environment

    Incorrect

    Keeping data in a governed cloud environment protects against leaks, but it does not make re-identifiable records deidentified.

Regulatory compliance in AI depends on local definitions. What counts as deidentified in one jurisdiction may still be personal data in another, and security controls around the data do not change that status.

Question 9 · choose 1

A wealth manager's AI assistant pulls client data from several systems, sends it through a model and writes summaries into a CRM. The security team cannot say where sensitive client data travels or is stored along the way. Which practice should come first?

  1. AEncrypt only the final summaries stored in the CRM
  2. BAssume the model provider protects every step of the data flow end to end
  3. CStop the assistant from writing to the CRM
  4. DMap the data flows from input to output across trust boundaries
Show the answer and why
  • AEncrypt only the final summaries stored in the CRM

    Incorrect

    Protecting one endpoint leaves the rest of the unmapped flow unexamined.

  • BAssume the model provider protects every step of the data flow end to end

    Incorrect

    Responsibility for how the application moves and stores data stays with the organization building it.

  • CStop the assistant from writing to the CRM

    Incorrect

    Removing one output does not reveal or protect the other places data travels.

  • DMap the data flows from input to output across trust boundaries

    Correct

    AWS's security guidance recommends comprehensive data flow analysis from input to output to make sure sensitive data is safeguarded and to identify weak points where it could be exposed.

You cannot protect data flows you have not mapped. Tracing where sensitive data enters, moves and rests in an AI application is the basis for placing the right access controls and protections.

Question 10 · choose 1

A retailer's AI agent reads supplier documents that could contain malicious instructions, and it runs on the same network as the finance systems. Its task never requires finance data. The security architect wants to limit how far the agent could reach if a document compromised it. Which control does AWS's security guidance recommend for this?

  1. ARead-only access to the finance systems instead of write access
  2. BIsolating the agent in a sandbox away from sensitive systems
  3. CA web application firewall placed in front of the agent
  4. DA weekly review of a sample of the agent's actions
Show the answer and why
  • ARead-only access to the finance systems instead of write access

    Incorrect

    Read-only access still leaves the finance systems within reach, so a compromised agent could read sensitive records it never needs.

  • BIsolating the agent in a sandbox away from sensitive systems

    Correct

    AWS recommends agent isolation, using sandboxing to keep agents from directly accessing sensitive parts of the system and to minimize the impact of a compromised agent.

  • CA web application firewall placed in front of the agent

    Incorrect

    AWS notes that traditional methods such as a WAF do not go far enough against instructions hidden in inputs, and a firewall does not limit what a compromised agent can reach.

  • DA weekly review of a sample of the agent's actions

    Incorrect

    Regular audits help find problems, but a review after the fact does not limit how far a compromised agent can reach in the meantime.

Containment limits damage. When an agent handles untrusted content, isolating it from sensitive systems means a successful attack has far less to reach.

Practise domain 3 →Practise all domains →