certslothcertsloth
AIB-C01/Topic 04

AWS / Business

Responsible AI, Governance and Risk Decisions

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Assign accountability before delegating a consequential decision.

Must remember

Responsible AI considers fairness, explainability, privacy, security, robustness, transparency and human oversight. The required safeguards depend on impact and context; an internal drafting assistant and an automated eligibility decision do not have identical risk profiles. Define prohibited uses and escalation criteria.

Governance assigns business ownership, technical responsibility, risk acceptance and independent review. Maintain an inventory of AI systems, intended uses, data/model dependencies, evaluation evidence and approvals. Embed review into procurement and delivery rather than creating a committee that only sees finished systems.

Assess data rights, consent, retention, residency and intellectual-property concerns with the responsible specialists. Supplier contracts should address security, data use, incident support, change notification and exit. A vendor assurance statement does not replace the organization’s own deployment assessment.

Common risks include hallucination, biased outcomes, privacy leakage, prompt injection, overreliance, unsafe tool actions and model/data drift. Mitigations include scoped access, authorized retrieval, output validation, human review, monitoring and restricted actions. Filters reduce some risks but cannot guarantee correctness. Provide an appeal/override path for consequential outcomes and a way to stop unsafe operation.

Choose under exam pressure

Requirement Choice and reason
High-impact automated decision Risk-based approval, meaningful oversight and appeal mechanisms.
Agent can change business records Authorize each action and constrain tool scope.
New model/provider version Re-evaluate quality, risk and contractual implications.

Traps

  • Compliance is not proof of fairness or safety in every use case.
  • A human nominally present is not meaningful oversight if they cannot understand or intervene.

Active recall

1. Why inventory AI systems?

To identify ownership, dependencies, risk and review obligations.

2. What is meaningful human oversight?

A capable authorized person can understand, challenge and stop or correct the outcome.

3. Why constrain agent tools?

Malicious or mistaken instructions can otherwise cause real external effects.

4. Why retain evaluation evidence?

To justify decisions and investigate changes or failures.

5. Who accepts residual risk?

The authorized accountable business/governance owner.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.