This sample moves from AI terminology into Annex A, the Statement of Applicability and the distinction between organisational risk and AI system impact assessment. Reveal each answer to see the reasoning and why the other options fail.
What this exact sample covers
AIMS implementation decisions
AI and machine-learning relationships
Annex A and SoA decisions
Risk versus impact assessment
Question 01Domain 1 · evaluation
MedAssist's product team has validated triage accuracy. Its hospital customers nevertheless report that the wording of automated prompts changes whether patients request review. The current service description records inputs, model scores and clinician decisions, but omits prompts. Before revising acceptance criteria, which description best supports assessment of the delivered AI service?
ADescribe the predictor and prompts as components, using their individual intended functions to define separate impact boundaries.
BDescribe the predictor, prompts and review pathway together, tracing how their interaction changes patient and clinician actions.
CDescribe the clinician's final decision process, attributing upstream predictor and prompt effects through its recorded clinical outcomes.
the answer and reasoning
Correct answerB. Describe the predictor, prompts and review pathway together, tracing how their interaction changes patient and clinician actions.
The question concerns the delivered service before criteria are revised. Prompt-mediated reliance changes the route from model output to action even if accuracy is unchanged. A functional account must capture those interactions rather than let a component or final decision boundary hide them. This does not establish a particular legal classification or a clinical treatment requirement.
Why the other options fail
A. Separate component functions do not capture effects that emerge when a correct prediction is presented through an influential prompt.
C. Final clinical outcomes can miss changed review requests and intermediary effects; they are not a complete account of service behaviour.
MedAssist replaces hand-written symptom categories with a deep neural embedding trained without outcome labels. A separate classifier is then trained on labelled triage outcomes. The release board proposes reusing the previous classifier's validation because its target labels and final output categories are unchanged. Which technical analysis most directly challenges that reuse?
AThe embedding is a new data representation within the learned pipeline; unchanged targets do not establish that the downstream classifier receives equivalent inputs.
BThe classifier remains supervised, so its original outcome validation can be reused if the embedding passes an unsupervised reconstruction test.
CThe added neural layers increase model capacity, so comparing training loss before and after the change establishes whether earlier validation remains applicable.
the answer and reasoning
Correct answerA. The embedding is a new data representation within the learned pipeline; unchanged targets do not establish that the downstream classifier receives equivalent inputs.
A new learned representation can change what the classifier receives. The embedding's training objective and the downstream classifier's labelled objective must be distinguished, but they operate as a connected pipeline. Reuse requires relevant evidence of equivalence or current validation; unchanged output labels do not provide it.
Why the other options fail
B. A representation test does not establish unchanged downstream behaviour; retaining a supervised target is not equivalence evidence.
C. Training loss addresses fit to its objective, not whether changed representation preserves service performance under intended conditions.
MedAssist selects a custom safeguard that gives patients a second route to request review. A reviewer finds no Annex A control with exactly that name. The team has mapped its risks but has not compared its selected safeguards with Annex A. Which next step makes its control-selection decision defensible?
AMap the custom safeguard to the nearest Annex A title and treat that match as the evidence that control selection is complete.
BRetain the custom safeguard when it meets an Annex C objective and use that objective match to complete the applicability record.
CCompare the necessary safeguards with Annex A for omissions, retaining justified custom measures and relevant implementation guidance.
the answer and reasoning
Correct answerC. Compare the necessary safeguards with Annex A for omissions, retaining justified custom measures and relevant implementation guidance.
Custom controls are possible; naming does not determine necessity. The outstanding comparison is intended to detect missing necessary controls, while the treatment rationale supports inclusion of the custom measure. Annex B assists implementation but is not a list of separately mandatory implementation steps to exclude from the SoA.
Why the other options fail
A. A title match does not test the rest of Annex A for missing necessary controls or demonstrate the safeguard's adequacy.
B. Annex C can inform relevant objectives and risks, but satisfying one objective does not complete the Annex A omission check.
MedAssist's SoA excludes data-preparation controls because a supplier performs preparation. Its contract specifies transformations, while MedAssist approves suitability and accepts or rejects deliveries. A new patient-review safeguard is necessary but not yet funded. Which revision best separates applicability from delivery responsibility and progress?
AReassess preparation against retained responsibilities and document justified control decisions; record the unfunded necessary safeguard with its inclusion rationale.
BKeep preparation excluded as outsourced, attach the contract as assurance, and list the patient safeguard once implementation funding is released.
CInclude both measures provisionally and postpone their inclusion rationales until operational evidence shows which controls can be effective.
the answer and reasoning
Correct answerA. Reassess preparation against retained responsibilities and document justified control decisions; record the unfunded necessary safeguard with its inclusion rationale.
The supplier's operational role does not resolve MedAssist's retained preparation-related obligations. Applicability requires the risk and responsibility analysis, not a universal outsourced exclusion. A necessary safeguard remains necessary while implementation is pending. Recording its rationale must not wait for funding or operational completion.
Why the other options fail
B. Outsourcing does not remove the stated retained responsibilities, and implementation funding does not determine necessity.
C. Provisional planning can be useful, but postponing the basis of necessity leaves the SoA unable to explain current decisions.
MedAssist's integrated register scores loss to the company. Adding a patient-impact field identifies that delayed review can affect carers' work and access to services, even where expected financial loss to MedAssist is small. Which integration design best preserves that result when deciding treatment priorities?
AKeep the patient-impact narrative and convert its consequences into MedAssist's reputational-loss scale before applying the common ranking.
BRetain differentiated impact findings and link them to risk evaluation criteria capable of escalating material effects despite low enterprise loss.
CRefer external effects to the hospital customers and rank MedAssist's treatment actions from losses within its own contractual responsibilities.
the answer and reasoning
Correct answerB. Retain differentiated impact findings and link them to risk evaluation criteria capable of escalating material effects despite low enterprise loss.
Integration can use one register, but must preserve what impact assessment found and how it affects risk decisions. The material external effects cannot disappear through financial conversion, a detached appendix or a transfer of analytical responsibility. Differentiated criteria allow relevant effects to influence evaluation without assuming that every related risk has the same significance.
Why the other options fail
A. Converting every consequence into enterprise reputation can remove the significance of effects on carers or patients when enterprise loss is low.
C. Customers' responsibilities matter, but do not remove MedAssist's need to assess the effects of its service and use the results in its own risk process.
Casual mode shows feedback as you answer. Full access adds the complete weighted bank, exam mode, saved results and domain-level analysis for this exact qualification.