Domain I
Understanding the foundations of AI governance
What AI governance is, including the common principles and pillars to build an AI governance program. Covers best practices regardless of industry, sector or size.
Exam weight: 16–20 of 100
3 competencies
40 practice questions
I.A
4–6 Q
Understand what AI is and why it needs governance.
- I.A.1 Know the generally accepted definitions and types of AI.
- I.A.2 Identify the types of risks and harms posed by AI to individuals, groups, organizations and society (e.g., misalignment with objectives, ethics and bias risk, and complexity and scalability).
- I.A.3 Identify the unique characteristics of AI that require a comprehensive approach to governance (e.g., complexity, opacity, autonomy, speed and scale, potential for harm or misuse, data dependency, and probabilistic versus deterministic outputs).
- I.A.4 Identify and apply the common principles of responsible AI (e.g., fairness, safety and reliability, privacy and security, transparency and explainability, accountability and human-centricity).
I.B
5–7 Q
Establish and communicate organizational expectations for AI governance.
- I.B.1 Define roles and responsibilities for AI governance stakeholders.
- I.B.2 Establish cross-functional collaboration in the AI governance program (e.g., for efficacy and diversity of expertise and perspective).
- I.B.3 Create and deliver a training and awareness program to all stakeholders on AI terminology, strategy and governance.
- I.B.4 Differentiate approaches to AI governance based upon company size, maturity, industry, products and services, objectives and risk tolerance.
- I.B.5 Identify differences among AI developers, providers, deployers and users from a governance perspective (e.g., with respect to responsibilities, opportunities and needs).
I.C
6–8 Q
Establish policies and procedures to apply throughout the AI life cycle.
- I.C.1 Create and implement policies to ensure oversight and accountability across all AI life cycle stages (e.g., use case assessment, risk management, ethics by design, data acquisition and use, model and system development, training and testing, deployment and monitoring, documentation and reporting, and incident management).
- I.C.2 Evaluate and update existing policies (e.g., data privacy, security, data governance and intellectual property) for AI.
- I.C.3 Create, update and implement policies, assessments and contracts to manage third-party risk (e.g., procurement, supply chain, human resources and acceptable use).