Skip to main content
Deliberate AcademyProfessional AI Education
~30 min left
Lesson 9 of 9
30 min read10 XP

AI Governance and Compliance Capstone Exercise

Deliberate Academy Editorial Team

Reviewed for accuracy and professional relevance

You're 9 lessons in — don't lose your progress.

Sign up free
What you'll learn
  • Apply the classification, documentation, and policy-drafting skills from across this course to a single realistic enterprise AI deployment
  • Produce a defensible, audit-ready risk classification memo for a described AI system
  • Self-assess a governance artifact against the evidentiary standard a real auditor or regulator would apply

This course has covered the operational mechanics of AI governance: EU AI Act risk tiers and conformity requirements, prohibited and high-risk use cases, ISO/IEC 42001's management system structure, internal policy framework design, formal risk classification methodology, audit documentation and evidence, and vendor and third-party AI risk. The capstone brings those skills together in the artifact a compliance officer or AI governance lead is most frequently asked to produce under real time pressure: a risk classification memo for a new AI system, written to a standard that would actually survive scrutiny from an internal auditor, an external certification body, or a regulator.

The exercise is designed to test not just whether you can describe the relevant frameworks, but whether you can apply them to a specific, messy, realistic scenario and produce a document someone else could act on.

Capstone Exercise

Risk Classification Memo: AI-Assisted Employee Performance Scoring Tool

Context

You are the AI Governance Lead at a logistics company with 6,000 warehouse and delivery staff across eight countries, three of which are EU member states. The operations team has piloted an AI tool that analyzes handheld scanner data, delivery timing, and route-completion patterns to generate a weekly performance score for each employee, intended to inform manager coaching conversations and, eventually, input into formal performance reviews. The tool was built by a third-party logistics-technology vendor and is licensed as an add-on to the company's existing route-management software. The pilot has been running for eight weeks with 400 employees at two EU sites, and operations leadership wants to expand it company-wide next quarter. No formal risk classification has been completed. The vendor's contract does not mention data training use, model-change notification, or audit evidence provision. Managers currently review scores before any coaching conversation, but the review is not logged.

Your Task

Draft a risk classification memo of 500 to 700 words covering: (1) a classification of this system's EU AI Act risk tier using the decision-tree approach from this course, with your reasoning stated explicitly; (2) an internal five-factor risk score (regulatory tier, data sensitivity, decision consequence, reversibility, population scale/vulnerability) with a one-sentence justification for each factor and the resulting internal tier; (3) the three most significant conformity or governance gaps you identify in the current pilot, with one sentence naming the specific evidence or control each gap requires; (4) one specific vendor due diligence gap that needs to be closed before company-wide expansion, and why; and (5) a recommendation on whether the pilot should expand company-wide next quarter as planned, or what conditions should be met first.

Your notes (optional)

Deliverable

A 500-to-700-word risk classification memo covering EU AI Act tier classification with reasoning, a five-factor internal risk score with justification, three prioritized conformity gaps with the specific evidence each requires, one vendor due diligence gap, and a conditional recommendation on company-wide expansion.

Quick check

Managers do review every score before a coaching conversation, but the review is not logged. Why does the capstone treat that as a conformity gap rather than a documentation nicety?

Select one answer.

Key takeaways
  • A defensible risk classification memo states its reasoning explicitly at every step — the classification tier alone, without the decision-tree or five-factor reasoning behind it, gives an auditor nothing to verify.
  • A system's classification can and should account for where its use case is heading, not just where it is today — a tool moving from informal coaching input toward formal performance review input carries a materially different risk profile, and that trajectory belongs in the memo.
  • An unlogged human review and a missing vendor model-change notification clause are not minor administrative details — they are the specific, recurring evidence and contract gaps this course has shown to be the most common source of real audit and regulatory exposure.
  • A compliance recommendation does not need to be a binary "stop" or "go" — a conditional recommendation naming specific, closeable gaps and a realistic timeline is usually the more defensible and more useful output of a real classification exercise.

Complete all lessons to take the free exam

Pass the exam to earn your AI Governance and Compliance — Certified AI Practitioner — a verifiable certificate you can share on LinkedIn.