AI Compliance Foundations Capstone Exercise
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 9 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Apply the technical model, risk vocabulary, regulatory orientation, and inventory-triage skills from across this course in a single realistic scenario
- Produce a well-reasoned, appropriately hedged first-pass AI inventory triage
- Self-assess your output against the foundational judgment standard this course has built
This course has covered how AI systems actually work at a compliance-relevant level, the model-risk vocabulary of bias, drift, hallucination, and explainability, an orientation to the EU AI Act, GDPR Article 22, the NIST AI RMF, and ISO/IEC 42001, vendor due-diligence questions, how to build a first AI system inventory, and when to escalate to specialist expertise. The capstone brings all of it together in the scenario most newcomers to this field encounter in their first few months: making sense of an unclassified inventory under real time pressure.
Capstone Exercise
Triaging an Unclassified AI Inventory
Context
You are a compliance analyst at a mid-size consumer lending company, three months into a newly created AI compliance role. An internal survey has identified six AI systems currently in active use: (1) an AI-powered chatbot answering basic loan-application FAQ questions on the public website; (2) a third-party AI tool that scores loan applications and recommends approve or decline, with a loan officer reviewing each recommendation in an average of 12 seconds before confirming it; (3) an internal AI tool used only by the finance team to summarize monthly expense reports; (4) an AI-powered resume-screening tool used by HR to rank job applicants; (5) a vendor-provided AI fraud-detection tool flagging suspicious transactions for manual investigator review, with investigators reporting the flagged transaction volume has been rising steadily for the past two quarters without an obvious explanation; (6) an AI writing assistant used by the marketing team to draft social media captions. None of the six currently has a documented risk classification.
Your Task
Produce a written triage covering all six systems. For each system: (1) assign a first-pass EU AI Act tier using the orientation framework from Lesson 5 (prohibited, high-risk, limited-risk, or minimal-risk) with a one-sentence domain-based justification; (2) note whether GDPR Article 22 plausibly applies, applying the meaningful-human-involvement test from Lesson 4 where a human review step exists; (3) name any model-risk term from Lesson 2 (bias, drift, hallucination, explainability) that the scenario specifically suggests may be present, and for which system; (4) identify which one or two systems most urgently need escalation to specialist expertise, and to which role from Lesson 8, with a one- or two-sentence escalation summary for each. Close with a one-paragraph honest statement of what you cannot yet determine from the information given, and what you would ask for next.
Your notes (optional)
Deliverable
A written triage of all six systems covering EU AI Act tier with justification, Article 22 applicability, relevant model-risk terms, prioritized escalation targets with specific summaries, and an honest closing statement of open questions.
System 2 scores loan applications and a loan officer confirms each recommendation in an average of twelve seconds. Why does the capstone highlight that timing rather than treating the review step as settling the Article 22 question?
Select one answer.
- Classification follows domain and decision impact, not how impressive or sophisticated a system seems — apply that discipline consistently across every system in an inventory, not selectively.
- A nominal human review step does not resolve an Article 22 question on its own — the review time, override frequency, and reviewer authority all matter.
- An unexplained shift in a system's real-world output pattern, like a steadily rising flagged-transaction rate, is a plausible drift signal worth investigating before it is dismissed as routine.
- A specific, well-scoped escalation to the right specialist is more valuable than either attempting to resolve every question personally or a vague request for someone else to "take a look."
- An honest statement of what you do not yet know is a stronger professional output than a confident but under-supported conclusion — this course has built the judgment to tell the difference.
Where to Go Next
If your role involves the operational execution of AI governance at scale — formal EU AI Act conformity assessment, ISO/IEC 42001 management-system implementation, defensible risk classification methodology, and audit-ready evidence practice — the natural next step is AI Governance and Compliance, this catalog's advanced certificate course for compliance officers, AI governance leads, and legal and risk teams who already have the foundation this course builds and are ready to execute governance at the depth a regulator or auditor expects.
If your role sits closer to strategic AI sponsorship and adoption decisions rather than compliance execution, AI Strategy for Leaders and its own beginner on-ramp, AI for Executives and Senior Leaders, may be the more relevant next step.
Complete all lessons to take the free exam
Pass the exam to earn your AI Compliance Foundations — Certified AI Practitioner — a verifiable certificate you can share on LinkedIn.