Lesson 26 / 26
Revision: Cheat Sheet and Self-Check
Review the strategy, ethics, risk, governance and regulation essentials of the whole course.
Cheat sheet
Strategy: start from measurable business goals; score use cases on value, feasibility, data readiness and low risk; prefer "assist" first; record a baseline. Business case: count full cost; NPV and payback; compare TCO for build/buy/partner; one accountable owner per decision. Ethics: principles become questions; list all stakeholders; measure fairness by group (disparate impact, TPR gap); be transparent and allow contesting. Risk: register (likelihood × impact), tiers, impact assessments before launch. Governance: short policy, review board with authority, inventory + lifecycle gates, vendor due diligence, linked evidence. Regulation: risk-based laws plus data-protection laws; use NIST AI RMF (Govern, Map, Measure, Manage) and ISO/IEC 42001; control matrix. Operations: incident runbook, blameless reviews, balanced KPIs.
Questions interviewers ask
Be ready to explain: how you would pick and prioritise AI use cases, how to build an honest business case, how you would check an AI system for bias, what a risk-tiered governance process looks like, how the NIST AI RMF functions work, and what you would do in the first hour of an AI incident.
Quick check: Which is the best first AI use case for a cautious organisation?
- Human-reviewed drafting of routine documents
- Fully automatic decisions on loan approvals
- Automatic hiring rejection
- An unmonitored public chatbot with account access
Answer
Human-reviewed drafting of routine documents — Assistive, reviewable, low-severity work is the safest place to build skills and trust.
Quick check: A screening tool selects group A at 50% and group B at 30%. What does the disparate impact ratio suggest?
- Ratios cannot be computed
- 1.67, so all is well
- 0.2, so it is fair
- 0.6, below 0.8, so investigate
Answer
0.6, below 0.8, so investigate — 30 divided by 50 is 0.6, under the 0.8 rule of thumb, which calls for investigation of data, features and process.
Quick check: Why can a "silent" vendor model update be a governance problem?
- Updates are always improvements
- It can change behaviour and invalidate earlier evaluation and approvals
- It makes the policy shorter
- It has no effect on risk
Answer
It can change behaviour and invalidate earlier evaluation and approvals — Approval rests on tested behaviour, so a change in the model means testing and approval must be repeated.