# Revision: Cheat Sheet and Self-Check — AI Strategy, Ethics and Governance

Source: https://www.geekswithgeeks.com/en/ai-strategy-governance/wrap-revision

> Review the strategy, ethics, risk, governance and regulation essentials of the whole course.

## Cheat sheet

**Strategy**: start from measurable business goals; score use cases on value, feasibility, data readiness and low risk; prefer "assist" first; record a baseline. **Business case**: count full cost; NPV and payback; compare TCO for build/buy/partner; one accountable owner per decision. **Ethics**: principles become questions; list all stakeholders; measure fairness by group (disparate impact, TPR gap); be transparent and allow contesting. **Risk**: register (likelihood × impact), tiers, impact assessments before launch. **Governance**: short policy, review board with authority, inventory + lifecycle gates, vendor due diligence, linked evidence. **Regulation**: risk-based laws plus data-protection laws; use NIST AI RMF (Govern, Map, Measure, Manage) and ISO/IEC 42001; control matrix. **Operations**: incident runbook, blameless reviews, balanced KPIs.

## Questions interviewers ask

Be ready to explain: how you would pick and prioritise AI use cases, how to build an honest business case, how you would check an AI system for bias, what a risk-tiered governance process looks like, how the NIST AI RMF functions work, and what you would do in the first hour of an AI incident.

**Quiz:** Which is the best first AI use case for a cautious organisation?

- [x] Human-reviewed drafting of routine documents
- [ ] Fully automatic decisions on loan approvals
- [ ] Automatic hiring rejection
- [ ] An unmonitored public chatbot with account access

*Answer:* Human-reviewed drafting of routine documents. Assistive, reviewable, low-severity work is the safest place to build skills and trust.

**Quiz:** A screening tool selects group A at 50% and group B at 30%. What does the disparate impact ratio suggest?

- [ ] Ratios cannot be computed
- [ ] 1.67, so all is well
- [ ] 0.2, so it is fair
- [x] 0.6, below 0.8, so investigate

*Answer:* 0.6, below 0.8, so investigate. 30 divided by 50 is 0.6, under the 0.8 rule of thumb, which calls for investigation of data, features and process.

**Quiz:** Why can a "silent" vendor model update be a governance problem?

- [ ] Updates are always improvements
- [x] It can change behaviour and invalidate earlier evaluation and approvals
- [ ] It makes the policy shorter
- [ ] It has no effect on risk

*Answer:* It can change behaviour and invalidate earlier evaluation and approvals. Approval rests on tested behaviour, so a change in the model means testing and approval must be repeated.
