From use case to production, proved — question bank
50 standalone questions going deep on the governance intake, the six risk domains, lifecycle gates, assurance, the one-page case and the forces that bend a GenAI number.
Audience: senior business leaders and anyone running a GenAI programme. No technical background assumed.
Source: the eighty-five-question reference — the eleven gates that carry an idea from a candidate list to a governed, measured, defensible production system.
How to use this: every question stands alone. Pick an option, then read the answer. The sections follow the gates in order.
A · Step 1 — Why the order of the gates is load-bearing
Q1Three orderings in the method are non-negotiable. Which is not one of them?
Answer: (4)Vendor choice is downstream of everything. The three that matter: you do not cost a thing you are not permitted to build; a baseline is a photograph you can take only once; and the people work starts immediately even though it is easiest to explain last.
Q2What is a "gate," in this method?
Answer: (2)That is the entire economic argument for the method: each gate costs less than the one after it, so every idea killed early is money you did not spend badly.
B · Step 2 — The governance intake
Q3Most organisations have a Responsible AI Principles document. Why does it govern almost nothing?
Answer: (2)It is the difference between a company that says it checks food for allergens and one that has a kitchen with a labelled process every dish passes through. One is a sentiment; the other is a system you can inspect.
Q4What is the single most useful governance mechanism, and what does it do?
Answer: (2)Picture the security line at an airport. Everyone passes the same door; most move quickly; something that trips the scanner gets pulled aside; a few items are simply not allowed on the plane. The sorting is proportionate.
Q5What happens if you apply mortgage-grade scrutiny to every AI request?
Answer: (2)And the opposite failure is just as fatal: apply the light touch to everything and the loan-approval system ships with no more oversight than the email polisher. The intake is what makes governance proportionate rather than either paralysing everything or checking nothing.
Q6What is the single most important question to ask about any proposed AI system?
Answer: (2)Everything downstream flows from the answer. An AI that only writes text can, at worst, be wrong. An AI that can move money can cause immediate, irreversible loss — including if someone tricks it. And you must answer for what it does when nobody is watching, not what it does in the demo.
Q7A support assistant only drafts replies for a human to send. Assessors still asked whether a draft could ever contain a number affecting a customer's entitlement. Why ask that?
Answer: (2)Naming it now prevents an accidental, illegal upgrade later. Systems rarely get reclassified deliberately; they drift across the line one feature at a time.
C · Step 3 — Risk tiers and what they oblige
Q8The EU AI Act sorts systems into four tiers. Which pairing is correct?
Answer: (2)And note it applies extraterritorially — it binds any provider or deployer whose AI output is used in the EU, regardless of where they sit.
Q9"Limited risk" is the most misunderstood point in AI governance. Why?
Answer: (2)In the worked case study, a Limited-risk system still carried four Critical risks — they simply came from data-protection law and accuracy, not from the AI Act. Limited risk is not low risk.
Q10An agentic system investigates payment disputes, decides approve or reject, and executes refunds up to €500 with no human review. Why is it High-risk?
Answer: (2)And the "simple helper" exemption that saved the drafting assistant fails on every count: the system makes a real decision, replaces human judgment entirely, executes the outcome, and profiles people.
Q11Which obligation requires verification of everything else before market placement?
Answer: (3)It is the primary deployment gate. Alongside it: a continuous risk-management system, data governance and bias examination, a full technical dossier, automatic logging, transparency to deployers, genuine human oversight, proven accuracy and robustness, a fundamental-rights assessment, registration before going live, post-market monitoring and incident reporting.
Q12Article numbering moved between the draft and final text of the regulation — serious-incident reporting was one number in drafts and another in the Regulation. Why does that matter beyond pedantry?
Answer: (2)A cheap, fast signal about how current someone's compliance work really is. And treat every date you are given as a prompt to check the primary regulation — these have been debated, delayed and adjusted, and will shift again.
Q13Penalties scale with the breach. Which is the highest band?
Answer: (3)Seven percent of global revenue is not a cost of doing business you quietly absorb. The middle band — 3% for breaching most obligations — is the one most high-risk gaps fall into.
D · Step 4 — The other laws in the room
Q14A GenAI system rarely triggers one law. Which layer usually becomes dominant the moment personal data leaves your walls?
Answer: (2)It is often heavier than the AI-specific rules, and it is the layer most likely to be underestimated because it feels like a solved, familiar problem.
Q15Where do data-protection and AI-specific obligations genuinely conflict?
Answer: (2)Resolving it needs a documented lawful basis, not a shrug. Note the reinforcing case too: the right to human review and the human-oversight obligation push the same control — build it once, satisfy both.
Q16What is the governance instruction that follows from laws stacking on one system?
Answer: (2)The classic mistake is a stand-alone AI policy disconnected from a mature privacy programme. The two must be a single control fabric, or you will double-build and still miss the seams.
E · Step 5 — Policies, controls and evidence
Q17In one worked case, the organisation's AI Governance Policy is owned by the CTO and sits "Under Review" — never ratified. Yet it is the parent of all twelve AI controls. What follows?
Answer: (2)That single governance gap cascades into every compliance failure downstream. Ratify the policy first; everything else inherits its authority from an active mandate.
Q18A policy states what must be true. What is a control?
Answer: (2)A policy on its own is a promise. Read the relationship as "the rule, and the machine that enforces it" — and if you cannot name a control for a policy, that policy is not real yet.
Q19Controls classify by function. With high-risk AI, which type dominates and why?
Answer: (3)Conformity assessment, human-oversight gates, consent filters, refusal guardrails. Detective controls then catch the drift the gates cannot foresee, and corrective controls limit damage after.
Q20A human-oversight policy becomes what specific control?
Answer: (2)Specificity is what separates a control from an intention. Note what the recording is for: it is how you later prove the review was genuine rather than a rubber stamp.
Q21A control is marked "Implemented" but its compliance mapping has no evidence location. To an auditor, what is it?
Answer: (3)Compliance is not what you do — it is what you can prove. Think of evidence as the receipt. Compliance = requirement × control × evidence; drop any factor and the product is zero.
Q22Scoring risks as likelihood × impact is described as a forcing function rather than a formula. Why?
Answer: (2)Two people who both call a risk "bad" may be a full band apart on impact, and scoring drags that disagreement into the open where it can be settled.
Q23"Operating without a human below €500 is the intended feature." What does that do to the likelihood score?
Answer: (2)This is the sharpest scoring insight in the method. Most risks are about malfunction; this one is about design. Nothing has to go wrong for the harm to occur.
F · Step 6 — The six cross-cutting domains
Q24Several important GenAI risks are not really about a specific statute. Which set describes them?
Answer: (2)They are baked into how generative AI works and cut across every system regardless of tier. A programme that only asks "does this pass the AI Act?" will sail straight past them.
Q25In the privacy domain, which mechanism is specific to generative systems rather than to data handling generally?
Answer: (2)Along with prompts and retrieved context carrying personal data outside your walls to a third-party model, logs quietly capturing personal data, and models being used to re-identify supposedly anonymous data.
Q26When must bias testing happen?
Answer: (3)A model update can reintroduce a bias that a previous version had been corrected for, and nothing about the interface will indicate it. Testing across demographic groups is a standing control family, not a launch task.
Q27What is an "AI bill of materials," and which domain does it belong to?
Answer: (2)You inherit what you cannot see inside: unknown training data, licence obligations restricting commercial use, tampered weights, unmaintained models — and the fact that calling a hosted API sends your data to someone else.
Q28In the hallucination domain, which mitigation is most often missing from a design?
Answer: (2)Systems are usually built to always produce an answer. Designing in the ability to decline is what converts a confident-falsehood risk into a routed escalation — and in some systems, refusing well is the most important thing the tool does.
Q29The copyright domain has a third angle organisations routinely miss. What is it?
Answer: (3)Copyright is usually discussed as an inbound risk — what the model was trained on — and as an output risk. The outbound leak from your own people is the one with no vendor to negotiate with.
G · Step 7 — The genuinely new threats
Q30For thirty years security has been about guarding a perimeter. What is different now?
Answer: (2)Keep the wall — but understand that it was never designed to imagine this. The model is like a very literal, very eager new employee carrying out any order written on a memo that lands on their desk, without asking whether it came from their boss or a stranger.
Q31Indirect prompt injection is the sneakier variant. Where does the malicious instruction come from?
Answer: (2)And here is the sting: the filters you put on what users type will never catch it, because the instruction never came through the front door.
Q32Guards go at three points, not one. Which rail is most often forgotten — and which threat does it stop?
Answer: (3)Picture a building's water system: you screen what comes in from the main, you put valves on what flows out to the taps, and you check the tank you draw from — because contamination there poisons everything downstream no matter how clean the incoming supply.
Q33What is the precise difference between quality testing and red-teaming?
Answer: (2)You need both, and the second is the one almost everybody skips. Organisations routinely report that they "tested thoroughly" while never having asked a single adversarial question.
Q34Where must an autonomous system's permission to act be enforced?
Answer: (2)Permission belongs at the boundary the AI is asking to cross, not in the text it was asked to obey. An instruction in the prompt is a request, and a well-crafted input can talk a model out of following it.
H · Step 8 — Human oversight, lifecycle and assurance
Q35Name the three postures of human oversight, weakest to strongest.
Answer: (2)And the design question is which one your consequence justifies. Reserve in-the-loop for anything hard to undo.
Q36A "human in the loop" exists on paper, but agents under time pressure skim and accept. What is this called, and why does it matter?
Answer: (2)It quietly converts a design you assessed as low-risk into one you never assessed at all. The fix is the control from Q20: a screen that requires an edit and records what changed.
Q37Governance runs as seven lifecycle gates from intake to retirement. What does the lifecycle view make visible that a control list does not?
Answer: (2)Each gate is a stop, not a suggestion. The governance body's power is the authority to refuse passage to the next gate — which only exists if the policy was ratified. Everything connects back.
Q38Which two named backbones let an outsider verify your governance, and what is the difference between them?
Answer: (2)A principle is something you assert. A certifiable management system is something someone else can verify. That is the leap from vibe to proof — and four plain verbs are something any leader can hold in their head and ask of any project.
Q39In the three-lines model, why can an AI ethics board that also builds the models provide no governance?
Answer: (2)Builders own controls at the point of risk; risk and compliance set policy and challenge; independent audit assures that the other two lines actually work. Collapsing lines one and two into the same body removes the challenge function entirely.
Q40What distinguishes an audit finding from a complaint?
Answer: (2)A finding with no owner and no date is a complaint; a finding with both is a commitment. Assurance value comes from the tracking, not the discovery.
Q41What is the reframe that turns governance from a brake into an enabler?
Answer: (2)Compliance asks "are we allowed to?" Sovereignty asks "are we in control?" — and governance done well is the thing that finally lets you take your foot off the brake and say yes to scaling, because you at last know what you are saying yes to.
I · Step 9 — The one-page case
Q42The one-pager has seven rooms. Which two "gatekeepers" stand at the door of the first?
Answer: (2)The first room opens with the business symptom before the word "AI" appears — then screens whether the task is inside what today's AI does well, and captures the current-state number while it still exists.
Q43The strongest page ends with two registers. What are they, and why do they strengthen rather than weaken it?
Answer: (2)A plan with no listed unknowns tells the reader one of two things — you did not look, or you are hiding something — and neither gets funded twice. The unknown you name today, with an owner beside it, is the very thing your pilot exists to measure.
Q44The page is graded on four questions. Which is not one of them?
Answer: (3)The page is not graded on how good the number looks. It is graded on how honest it is — and the fourth question is whether every productivity gain is actually captured. The person who should ask all four first is you, alone with the draft.
Q45What is the one-pager's deepest value, according to the practitioner quoted at the end?
Answer: (2)The discipline of building it — the baseline you were forced to capture, the counterfactual you were forced to name, the cost you were forced to count in full — fences the project in. A project with a one-pager cannot run amok, because someone wrote down, in advance, what "working" would have to mean.
J · Step 10 — Why these are GenAI numbers
Q46A sceptic says this is just ordinary business-case arithmetic. Are they right?
Answer: (2)The arithmetic is generic; the adjustments are not. Learn the forces and you can read or build any AI business case honestly.
Q47Of the seven GenAI-specific forces, how do they split?
Answer: (2)And the point worth stating: none of them exists in a deterministic automation case — which is exactly why a GenAI number needs them written down rather than assumed away.
Q48Which force is rooted in "felt ≠ measured"?
Answer: (3)It removes both the share other changes caused and the gains that were only felt. The correction it forces is a holdout or staged rollout, and measured throughput rather than surveyed hours.
Q49Which force produces the "AI floor, human ceiling" design?
Answer: (3)Let the machine take the high-volume, simple, forgiving tier; keep humans on the complex, emotional, high-stakes cases where a confident wrong answer is a disaster. The failure in the best-known reversal was not that the AI was bad — it was drawing that line in the wrong place.
Q50A $10.8M headline walks down to $1.79M through measured deflection, attribution, realization and cost of poor quality. What is the lesson?
Answer: (2)Every adjustment pushes the number down, and that is not pessimism — it is the difference between a headline that survives contact with a CFO and one that collapses in month nine. Under-promising here was not modesty; it was survival.