Domain 4 of 4

AI Governance, Risk, and Compliance

Domain · 19% of the CY0-001 exam

Three questions decide every AI governance answer, and the trap is answering the wrong one

A product team wants to swap the CV-screening model for a newer version on Friday, and three objections arrive that are not the same objection. Legal asks whether the system is high risk under the EU AI Act (Regulation (EU) 2024/1689) and whether your company is acting as its provider, the party that puts it on the market under its own name, or merely as its deployer, the party that uses it. The governance lead asks which register entry the change reopens and who signs the release. The person who will send the rejection letters asks whether a candidate can still be told why. Those three are the whole domain, and they compose in that order: the obligation (who outside your company can require something of you), the machinery (the inventory, register, gates and reviews that turn a duty into a record someone else can read) and the behaviour the system owes the people it decides about. The trap that costs marks is offering one as an answer to another. Saying you follow the NIST AI Risk Management Framework (AI RMF) answers the machinery question and no obligation question, because that framework is voluntary and carries no penalty at all; an ISO/IEC 42001 certificate proves an accredited body found a working management system, and tells the rejected candidate nothing.

The domain unfolds in three steps: what is required, how you prove it, what the system owes people

One question, one step, one page: read them in order and the chain builds itself. AI Regulatory Frameworks is the obligation step: it sorts each instrument by force (what happens if you ignore it) and by reach (what pulls this deployment into it), then works through the AI Act's risk tiers and the provider and deployer roles, the General Data Protection Regulation (GDPR) questions an AI deployment walks into, from the lawful basis for the training set to the right not to be subject to a solely automated decision, and the difference between a regulation, a certifiable standard, a voluntary framework and government guidance. Reach for it when a question names a rule or asks whether you are allowed to ship. Its structure has held since 2024 while its calendar has not, since a deferral of the high-risk deadlines was adopted in 2026 but had not been published in the Official Journal at the time of writing, so that page teaches the structure and tells you to re-check any date against the current consolidated text. AI Lifecycle GRC Integration is the machinery step, built on the AI RMF's four functions (GOVERN, MAP, MEASURE and MANAGE, with GOVERN running across the other three): the inventory that finds the systems nobody registered, the risk appetite and tolerance you must set yourself, the risk register with one named owner per entry, the test, evaluation, verification and validation work (TEVV) that feeds the release gate, third-party due diligence, change control, incident reporting and decommissioning. Reach for it when the question is about running the programme rather than reading the rule. Responsible AI Use is the behaviour step: the seven trustworthiness characteristics and the trade-offs between them, bias that arrives with nobody intending it, the transparency artefacts and their different audiences, oversight a reviewer could actually exercise, acceptable use, and how far a provenance mark gets you. Those characteristics come from the same AI RMF, which supplies vocabulary for two steps and obligations for none. Reach for it when an output lands on a named person.

Govern the deployment, not the company and not the model

The unit that carries a governance answer is one system in one use, with one intended purpose, one affected population and one accountable owner. The AI Act classifies a system by what it is built to do rather than by who owns it, so the same model can be high risk inside a hiring workflow and unremarkable inside a document-search tool, and a register holding one entry per model rather than one per use case describes your software estate instead of your exposure. The instinct to carry into the exam: when one option states a company-wide position and another is scoped to this deployment, the scoped one is almost always the governance answer, and the company-wide policy is what the scoped answer inherits from. It also means every conclusion here has an expiry condition rather than an expiry date, because changing the purpose, the population, the model version or the data behind it gives you a different deployment to answer for.

The deliverable is evidence someone outside the room can read

Across all three pages, the answer that survives is the one leaving a record a stranger can check: a register entry with an owner, a treatment and a date; a test result measured against a threshold fixed before the test ran; an evaluation broken out per subgroup instead of one aggregate accuracy number; a reason given to the person the decision went against. Intent counts for very little, and this domain leans on that hard. A completed supplier questionnaire is the supplier's own account of itself, not independent assurance. A policy proves a programme was designed, never that it runs, which is why an assessor asks for records and not for the policy binder. The sentence "nobody here is biased" answers a question about motive when the question was about outcomes. So when two options both sound conscientious, prefer the one that ends in an artefact with a name and a date on it.

This is the domain about being defensible, not about being attacked

Nothing on these three pages stops an adversary. AI Systems Security, the largest domain at 40%, owns the controls, the deployment environment and the defences against attacks on models, data and inference; AI-Assisted Security, at 24%, owns AI put to work inside the security operations centre. This domain, 19% of CY0-001, asks the different question: when a regulator, an auditor, a buyer or the person your system decided against comes asking, what can you show them? The two meet at one point worth remembering, because secure and resilient is one of the seven trustworthiness characteristics, so your security controls become evidence in a governance file, and a governance obligation can require a control nobody would have funded on threat grounds alone. If the scenario has an attacker in it, you are in another domain. If it has someone who is not attacking you but is entitled to an answer, you are here.

Obligation, machinery and behaviour: what each question settles and where it is taught

The questionWhat it settlesEvidence it leaves behindDrill into
Obligation: who outside your company can require this?Which regimes reach this deployment, what force each one carries, and which role you occupy in itA per-deployment list of applicable regimes, the role you hold in each and the duties that follow from itAI Regulatory Frameworks
Machinery: how do you produce the proof?How a duty becomes repeatable practice: inventory, risk register, TEVV gates, supplier checks, change control, incidents and retirementRegister entries with owners and dates, evaluation records, gate decisions, incident reports and an audit trail an assessor can readAI Lifecycle GRC Integration
Behaviour: what does the system owe the people it affects?What trustworthy behaviour demands in practice, and which trade-offs between the characteristics you consciously acceptedPer-subgroup evaluations, model and system documentation, AI disclosures, explanations owed to affected people and oversight recordsResponsible AI Use

Subtopics in this domain