1. AI Risk Tiering advanced

    The business wants to deploy a model that ranks loan applications, with a credit officer making the final decision. What must the architecture provide, and what will you insist on before go-live?

    2 min answer ai-governancemodel-riskfairnesshuman-oversight
  2. Audit Evidence intermediate

    Your organisation is preparing for its first SOC 2 audit. The security team is asking engineers for screenshots of configurations. What would you change, and what is the architectural argument?

    2 min answer complianceevidenceautomationcertification
  3. Certification Impact on Architecture intermediate

    Your organisation is starting SOC 2. Someone proposes scoping it to the whole estate "to be safe". What is your advice?

    2 min answer certificationscopecompliancearchitecture
  4. Continuous Controls Monitoring advanced

    Quarterly access reviews take two weeks of manager time and everyone approves everything. How do you make this a real control?

    2 min answer accesscontrolsautomationassurance
  5. Exception & Waiver Management intermediate

    Your exception register has grown from 12 to 90 waivers in eighteen months and none have been closed. What does this tell you and what do you do?

    2 min answer governanceexceptionsstandardsrisk
  6. Model Risk Management advanced

    A deployed model performed well in validation and its business metric has declined over four months. Nothing has been deployed. What do you investigate?

    2 min answer aimonitoringdriftmodel-risk
  7. Model Risk Management advanced

    A vendor SaaS product embeds a model that scores customers, and its output drives an automated decision in your process. Your model governance framework covers models you build. What do you do?

    2 min answer model-riskthird-partygovernanceai