Algorithms Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under the EU AI Act, which risk category applies to algorithms used in credit scoring decisions that affect individuals?
- Minimal risk
- Limited risk
- High risk (Correct answer)
- Unacceptable risk
Correct answer: High risk
Credit scoring algorithms fall under the high-risk category because they can significantly impact individuals' access to financial services.
Question 2: Which U.S. regulation requires financial institutions to provide adverse action notices when an algorithm denies a loan application?
- GDPR
- Equal Credit Opportunity Act (ECOA) (Correct answer)
- HIPAA
- CCPA
Correct answer: Equal Credit Opportunity Act (ECOA)
ECOA requires creditors to provide specific reasons for adverse credit decisions, which applies to algorithmic lending decisions.
Question 3: What does 'algorithmic accountability' primarily require organizations to demonstrate?
- That their algorithms run faster than competitors
- That decisions made by algorithms can be explained and audited (Correct answer)
- That all algorithms are open source
- That algorithms never make errors
Correct answer: That decisions made by algorithms can be explained and audited
Algorithmic accountability means organizations must be able to explain how automated systems make decisions and allow for auditing of those decisions.
Question 4: Which principle in GDPR directly limits how long data used to train algorithms can be retained?
- Data minimization
- Storage limitation (Correct answer)
- Purpose limitation
- Accuracy
Correct answer: Storage limitation
GDPR's storage limitation principle requires that personal data not be kept longer than necessary for its stated purpose.
Question 5: A sorting algorithm is used to prioritize job applicants. Under U.S. law, which legal theory applies if the algorithm disproportionately screens out a protected class?
- Disparate treatment
- Disparate impact (Correct answer)
- Strict liability
- Tortious interference
Correct answer: Disparate impact
Disparate impact theory applies when a facially neutral practice (like an algorithm) has a disproportionately negative effect on a protected group.
Question 6: Which standard framework is commonly used to audit algorithmic fairness in U.S. employment screening tools?
- ISO 27001
- NIST AI RMF (Correct answer)
- SOC 2 Type II
- PCI DSS
Correct answer: NIST AI RMF
The NIST AI Risk Management Framework provides guidelines for managing risks including fairness and bias in AI and algorithmic systems.
Question 7: What is the primary purpose of a 'model card' in the context of algorithmic compliance?
- To store model weights securely
- To document a model's intended uses, limitations, and fairness metrics (Correct answer)
- To generate API keys for model access
- To compress model files for deployment
Correct answer: To document a model's intended uses, limitations, and fairness metrics
Model cards provide structured documentation of a machine learning model's performance, intended use cases, limitations, and ethical considerations.
Under the EU AI Act, which risk category applies to algorithms used in credit scoring decisions that affect individuals?