Domain IV

Understanding how to govern AI deployment and use

The responsibilities of AI governance professionals with respect to selecting an AI model, then deploying and using it responsibly through ongoing monitoring, maintenance and other key obligations. Applies whether deploying a proprietary model or one from a third party.

Exam weight: 21–25 of 100 3 competencies 48 practice questions
IV.A

Evaluate key factors and risks relevant to the decision to deploy the AI system.

6–8 Q
  • IV.A.1 Understand the context of the AI use case (e.g., business objectives, performance requirements, data availability, ethical considerations and workforce readiness).
  • IV.A.2 Understand the differences in AI model types (e.g., classic vs. generative, proprietary vs. open source, small vs. large, and language vs. multimodal capabilities).
  • IV.A.3 Understand the differences in AI deployment options (e.g., cloud vs. on-premise vs. edge, and using the AI model as is or with fine-tuning, retrieval augmented generation, agentic architectures, or other techniques to improve performance and fit).
Study this topic →
IV.B

Perform key activities to assess the AI system.

5–7 Q
  • IV.B.1 Perform or review an impact assessment on the selected AI system.
  • IV.B.2 Identify and evaluate key terms and risks in the vendor or licensing agreement.
  • IV.B.3 Identify and understand the risks and opportunities that are unique to a company deploying its own proprietary AI model (e.g., increased obligations and higher potential liability).
Study this topic →
IV.C

Govern the deployment and use of the AI system.

9–11 Q
  • IV.C.1 Apply the policies, procedures, best practices and ethical considerations to the deployment of an AI system (e.g., data governance, risk management, issue management, and user training).
  • IV.C.2 Conduct continuous monitoring of the AI model and system, and establish a regular schedule for maintenance, updates and retraining.
  • IV.C.3 Conduct periodic activities to assess the AI system’s performance, reliability and safety (e.g., audits, red teaming, threat modeling and security testing).
  • IV.C.4 Document incidents, issues, risks and post-market monitoring plans.
  • IV.C.5 Forecast and reduce risks of secondary or unintended uses and downstream harms.
  • IV.C.6 Establish external communication plans.
  • IV.C.7 Create and implement a policy and controls to deactivate or localize an AI system as necessary (e.g., due to regulatory requirements or performance issues).
Study this topic →