AI Governance Practice

Scenario training for AI governance practitioners

296 original scenarios that put you in a governance decision and ask what you would do. Progress is saved on your device and works without an account — signing in only adds syncing across devices.

Independent educational product. Not affiliated with the IAPP.

Try one now

A question from the bank

This is a real item, not a simplified demonstration. Nothing you do here is recorded — it will not appear in your progress, your review queue, or anywhere else.

During design review of a resume-screening tool, a reviewer insists hiring managers must be able to understand in plain terms why one candidate ranked above another. Which responsible AI principle does this most directly reflect?

How to read a scenario

The same four passes work on every question in the app, and on real decisions outside it.

How to read a governance scenario

Four passes over the same text. Working in this order stops the common failure: recognising a framework and answering from it before establishing what is actually happening.

  1. Facts

    What is actually described — the system, who it affects, what stage it is at. Separate this from what you assume is going on.

  2. Obligations

    What is required here, and by whom. Obligations attach to roles and contexts, so establish those before reaching for a rule.

  3. Risks

    What could go wrong for the people on the receiving end, ranked by how badly rather than how likely.

  4. Action

    The narrowest step that addresses the risk you identified. A defensible answer names its trade-off rather than pretending there is none.

Practice judgment, not vocabulary

Knowing the terms is the starting point. Knowing what to notice, who is responsible, what could go wrong, and what to do next is the work. Every scenario in this product is built to train that loop.

How a scenario trains judgment

Vocabulary is necessary. The loop is what turns it into practice.

  1. 1Scenario

    Read the facts without jumping to a framework.

  2. 2Decide

    Choose the narrowest defensible next step.

  3. 3Feedback

    See why — including the near-miss distractors.

  4. 4Carry forward

    The key takeaway becomes the portable rule.

A framework you can operate

The NIST AI Risk Management Framework is one of the instruments the scenarios reference. Govern frames the work; Map, Measure, and Manage keep it moving.

NIST AI Risk Management Framework

Govern is continuous. Map, Measure, and Manage form the operational cycle. Select a function to inspect its governance question and controls.

Culture, roles, and policy that make the cycle possible.

Govern

Set culture, roles, and policies that make the other three functions possible.

Governance question
Who is accountable, and what are they allowed to decide?
Example control
AI risk committee with documented escalation authority
Evidence artifact
Charter, RACI, decision log

Same bank. Different pressure.

Study mode teaches the reasoning. Exam mode tests whether it holds when feedback is withheld and the clock is running.

Two modes, one bank

Study trains the reasoning loop. Exam tests whether the reasoning holds under constraint.

Study

Learn the reasoning

  • Immediate feedback after every answer
  • Rationale and near-miss explanation
  • Key takeaway to carry forward
  • Wrong items enter the review queue
  • Self-paced; pause and resume

Exam

Test the reasoning

  • No feedback until you submit
  • Timed sitting under constraint
  • Final score only
  • Does not write to the review queue
  • Designed to feel like the real sitting

Structured against the published outline

Scenarios map to the thirteen competencies across four domains so weak areas can be identified. Structural coverage only — not an endorsement or a prediction of any exam result.

Coverage across the AIGP Body of Knowledge

Thirteen competencies in four domains. Scenarios are mapped so weak areas can be identified. Structural coverage only — not an endorsement or score predictor.

Domain I

Foundations

What AI is, why it needs governance, and how an organisation sets expectations.

  • I.AUnderstand what AI is and why it needs governance
  • I.BEstablish and communicate organizational expectations
  • I.CEstablish policies and procedures across the life cycle

Domain II

Laws & frameworks

How existing privacy law, sector rules, and AI-specific instruments apply.

  • II.AHow existing data privacy laws apply to AI
  • II.BHow other types of existing laws apply to AI
  • II.CMain elements of AI-specific laws
  • II.DMain industry standards and tools

Domain III

Development

Governing design, data, testing, and release of the system itself.

  • III.AGovern the designing and building of the AI system
  • III.BGovern data in training and testing
  • III.CGovern release, monitoring and maintenance

Domain IV

Deployment & use

Deciding to deploy, assessing fitness, and governing ongoing operation.

  • IV.AEvaluate factors and risks in the decision to deploy
  • IV.BPerform key activities to assess the AI system
  • IV.CGovern the deployment and use of the AI system

Source outline: IAPP AIGP Body of Knowledge (publicly published structure). This product is independent and unaffiliated.

Start with a scenario

No account required. Progress stays on this device until you choose to sync.