Domain III
Understanding how to govern AI development
The responsibilities of AI governance professionals with respect to designing, building, training, testing and maintaining AI systems.
Exam weight: 21–25 of 100
3 competencies
51 practice questions
III.A
6–8 Q
Govern the designing and building of the AI system.
- III.A.1 Define the business context and use case of the AI system.
- III.A.2 Perform or review an impact assessment on the AI system.
- III.A.3 Apply the policies, procedures, best practices and ethical considerations to designing and building the AI system (e.g., purpose of AI, requirements gathering, architecture and model selection, human oversight, data analysis, metric and threshold evaluation, stakeholder engagement and feedback, and operational controls).
- III.A.4 Identify and manage the internal and external risks and contributing factors related to designing and building the AI model and system (e.g., using probability/severity harms matrix, using a risk mitigation hierarchy, stakeholder mapping, use-case evaluation, benchmarking, and pre-deployment pilots and testing).
- III.A.5 Document the designing and building process (e.g., to establish compliance and manage risks).
III.B
6–8 Q
Govern the collection and use of data in training and testing the AI model and system.
- III.B.1 Establish and follow the requirements for data governance (e.g., assess and document lawful rights to collect and use data, and assess data quality, quantity, integrity and fit-for-purpose).
- III.B.2 Establish and document data lineage and provenance.
- III.B.3 Plan and perform training and testing of the AI model and system (e.g., unit, integration, validation, performance, security, bias and interpretability).
- III.B.4 Identify and manage issues and risks during training and testing of the AI model and system.
- III.B.5 Document the training and testing process (e.g., to validate results, establish compliance and manage risks).
III.C
8–10 Q
Govern the release, monitoring and maintenance of the AI system.
- III.C.1 Assess readiness, and prepare for release into production (e.g., creating the model card and satisfying conformity requirements).
- III.C.2 Conduct continuous monitoring of the AI system, and establish a regular schedule for maintenance, updates and retraining.
- III.C.3 Conduct periodic activities to assess the AI system’s performance, reliability and safety (e.g., audits, red teaming, threat modeling and security testing).
- III.C.4 Manage and document incidents, issues and risks.
- III.C.5 Collaborate with cross-functional stakeholders to understand why incidents arise from AI systems (e.g., brittleness, lack of robustness, lack of quality data, insufficient testing, and model or data drift).
- III.C.6 Make public disclosures to meet transparency obligations (e.g., technical documentation, instructions for use to deployers and post-market monitoring plans).