Skip to content
CY0-001
AI Governance, Risk, and Compliance
medium
Question 1 of 18

A data privacy officer is reviewing an AI system that processes personal data of EU residents to make automated credit decisions. Which two regulatory frameworks are most directly applicable, and what controls are required at their intersection?

AGDPR (automated decision-making rights under Article 22 requiring human review on request and explanation of decisions) and EU AI Act (high-risk classification requiring documentation and human oversight)
BNIST CSF and SOC 2, requiring annual penetration testing and security certification
CISO 27001 and COBIT, requiring information security management system certification
DPCI DSS and HIPAA, requiring encryption of cardholder data and health records

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion