Regulatory Compliance & Legal Framework Flashcards
7 cards from real AML practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
The Fair Housing Act (FHA) is relevant to ML models used in real estate platforms because it:
Answer: Prohibits discriminatory practices in housing based on protected class membership
The FHA prohibits housing discrimination based on race, color, religion, sex, national origin, disability, or familial status, and applies to algorithmic recommendation and pricing systems.
Which of the following best describes 'regulatory sandboxes' in the context of AI governance?
Answer: Controlled frameworks allowing companies to test AI products under relaxed rules with regulatory oversight
Regulatory sandboxes let companies pilot innovative AI systems in live environments under temporary regulatory relaxation and direct supervisory oversight.
Under HIPAA, which of the following would most likely constitute a violation when using patient data for ML model training?
Answer: Training on PHI without a valid Business Associate Agreement with the cloud provider
Processing Protected Health Information (PHI) for ML training using a cloud provider without a valid Business Associate Agreement (BAA) violates HIPAA's Privacy and Security Rules.
The term 'disparate impact' in algorithmic fairness law means:
Answer: A facially neutral policy that disproportionately harms a protected group
Disparate impact refers to neutral policies or systems that produce statistically disproportionate adverse outcomes for protected groups, regardless of intent.
Which international standard provides a framework specifically for AI management systems that aligns with ISO 9001 quality management principles?
Answer: ISO/IEC 42001
ISO/IEC 42001 is the international standard for AI management systems, providing requirements and guidance for organizations developing or using AI responsibly.
An ML practitioner must perform a Data Protection Impact Assessment (DPIA) under GDPR when:
Answer: Processing is likely to result in high risk to individuals' rights and freedoms
GDPR Article 35 mandates a DPIA when processing operations are likely to result in high risk to data subjects, such as large-scale profiling or processing sensitive data.
Under the Executive Order on Safe, Secure, and Trustworthy AI (EO 14110), which category of AI models must submit safety test results to the US government before public release?
Answer: Dual-use foundation models posing serious national security risks above defined compute thresholds
EO 14110 requires developers of powerful dual-use foundation models—defined by compute thresholds—to share safety test results with the federal government before release.