Scenario training for AI governance practitioners
296 original scenarios that put you in a governance decision and ask what you would do. Progress is saved on your device and works without an account — signing in only adds syncing across devices.
Independent educational product. Not affiliated with the IAPP.
Try one now
A question from the bank
This is a real item, not a simplified demonstration. Nothing you do here is recorded — it will not appear in your progress, your review queue, or anywhere else.
During design review of a resume-screening tool, a reviewer insists hiring managers must be able to understand in plain terms why one candidate ranked above another. Which responsible AI principle does this most directly reflect?
How to read a scenario
The same four passes work on every question in the app, and on real decisions outside it.
How to read a governance scenario
Four passes over the same text. Working in this order stops the common failure: recognising a framework and answering from it before establishing what is actually happening.
Facts
What is actually described — the system, who it affects, what stage it is at. Separate this from what you assume is going on.
Obligations
What is required here, and by whom. Obligations attach to roles and contexts, so establish those before reaching for a rule.
Risks
What could go wrong for the people on the receiving end, ranked by how badly rather than how likely.
Action
The narrowest step that addresses the risk you identified. A defensible answer names its trade-off rather than pretending there is none.
Practice judgment, not vocabulary
Knowing the terms is the starting point. Knowing what to notice, who is responsible, what could go wrong, and what to do next is the work. Every scenario in this product is built to train that loop.
How a scenario trains judgment
Vocabulary is necessary. The loop is what turns it into practice.
1Scenario
Read the facts without jumping to a framework.
2Decide
Choose the narrowest defensible next step.
3Feedback
See why — including the near-miss distractors.
4Carry forward
The key takeaway becomes the portable rule.
A framework you can operate
The NIST AI Risk Management Framework is one of the instruments the scenarios reference. Govern frames the work; Map, Measure, and Manage keep it moving.
NIST AI Risk Management Framework
Govern is continuous. Map, Measure, and Manage form the operational cycle. Select a function to inspect its governance question and controls.
Culture, roles, and policy that make the cycle possible.
Govern
Set culture, roles, and policies that make the other three functions possible.
- Governance question
- Who is accountable, and what are they allowed to decide?
- Example control
- AI risk committee with documented escalation authority
- Evidence artifact
- Charter, RACI, decision log
Same bank. Different pressure.
Study mode teaches the reasoning. Exam mode tests whether it holds when feedback is withheld and the clock is running.
Two modes, one bank
Study trains the reasoning loop. Exam tests whether the reasoning holds under constraint.
Study
Learn the reasoning
- Immediate feedback after every answer
- Rationale and near-miss explanation
- Key takeaway to carry forward
- Wrong items enter the review queue
- Self-paced; pause and resume
Exam
Test the reasoning
- No feedback until you submit
- Timed sitting under constraint
- Final score only
- Does not write to the review queue
- Designed to feel like the real sitting
Structured against the published outline
Scenarios map to the thirteen competencies across four domains so weak areas can be identified. Structural coverage only — not an endorsement or a prediction of any exam result.
Coverage across the AIGP Body of Knowledge
Thirteen competencies in four domains. Scenarios are mapped so weak areas can be identified. Structural coverage only — not an endorsement or score predictor.
Domain I
Foundations
What AI is, why it needs governance, and how an organisation sets expectations.
- I.AUnderstand what AI is and why it needs governance
- I.BEstablish and communicate organizational expectations
- I.CEstablish policies and procedures across the life cycle
Domain II
Laws & frameworks
How existing privacy law, sector rules, and AI-specific instruments apply.
- II.AHow existing data privacy laws apply to AI
- II.BHow other types of existing laws apply to AI
- II.CMain elements of AI-specific laws
- II.DMain industry standards and tools
Domain III
Development
Governing design, data, testing, and release of the system itself.
- III.AGovern the designing and building of the AI system
- III.BGovern data in training and testing
- III.CGovern release, monitoring and maintenance
Domain IV
Deployment & use
Deciding to deploy, assessing fitness, and governing ongoing operation.
- IV.AEvaluate factors and risks in the decision to deploy
- IV.BPerform key activities to assess the AI system
- IV.CGovern the deployment and use of the AI system
Source outline: IAPP AIGP Body of Knowledge (publicly published structure). This product is independent and unaffiliated.
Start with a scenario
No account required. Progress stays on this device until you choose to sync.