Connecting the needy | A Team of Changemakers | President of India appreciated No-to profit organization (NGO)| Inspired by ISO 26000
Home » Master Class
September 26, 2026
0% 11 12345678910111213141516171819202122232425262728 6th TPRM Masterclass 6th TPRM Masterclass Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%. 1 / 28 Category: 6th TPRM Masterclass 1. The “Eight diligence gates” group gates 5–6 under which theme? A. Test the inputs B. Establish control C. Test resilience D. Define and map 2 / 28 Category: 6th TPRM Masterclass 2. What was the outcome of EEOC v. iTutor Group, Inc., et al.? A. A 2023 consent decree providing USD 365,000 for affected applicants, anti-discrimination policies, training and EEOC monitoring B. A five-year ban on using any recruitment software C. A court judgment finding no discrimination occurred D. A criminal indictment against the company's founders 3 / 28 Category: 6th TPRM Masterclass 3. Under “Audit, evidence and regulatory cooperation,” what must the supplier secure from material subcontractors? A. Exclusive rights to negotiate with regulators on the Customer's behalf B. A right to unilaterally terminate the subcontractor's own customer contracts C. Direct payment of regulatory fines on the Customer's behalf D. Corresponding cooperation through enforceable contractual obligations 4 / 28 Category: 6th TPRM Masterclass 4. Which four questions does the masterclass propose to keep regulatory mapping from becoming a static list of law names? A. What is new? What is old? What changed? What stayed the same? B. What is legal? What is ethical? What is optimal? What is required? C. What is the cost? Who pays? What is covered? What is excluded? D. What is in scope? Who is accountable? What flows upstream? What proves it? 5 / 28 Category: 6th TPRM Masterclass 5. In “Structuring the AI contract,” which party is described as remaining answerable for the contracted delivery chain? A. The online terms B. The data processing agreement (DPA) C. The AI schedule D. The primary vendor 6 / 28 Category: 6th TPRM Masterclass 6. Under APRA's CPS 230, how is a “fourth party” expressly defined? A. Any AI vendor operating outside the customer's home jurisdiction B. A party the regulator directly licenses to supply AI models C. A party a service provider relies on in delivering services to an APRA-regulated entity D. Any subcontractor named in a vendor's public privacy policy 7 / 28 Category: 6th TPRM Masterclass 7. What illustrative maximum notification window is suggested for an AI-related or security incident? A. 72 hours B. 48 hours C. 24 hours D. 12 hours 8 / 28 Category: 6th TPRM Masterclass 8. Under “IP, indemnities and liability,” who retains all rights in Customer Data and other inputs supplied by or on the Customer's behalf? A. The Customer B. The Supplier C. Whichever party's cloud infrastructure physically stores the data D. Jointly the Customer and Supplier 9 / 28 Category: 6th TPRM Masterclass 9. What best defines a “Third party” in the tiering of AI supply-chain relationships? A. A provider deeper in the chain than the vendor B. A regulator overseeing your vendor C. A provider your vendor relies on D. Your directly contracted vendor 10 / 28 Category: 6th TPRM Masterclass 10. Contract terms across the chain” lists four themes. Which theme covers “Notice, assessment rights, remediation and proportionate suspension A. Disclosure B. Flow-down C. Change control D. Evidence and exit 11 / 28 Category: 6th TPRM Masterclass 11. In FTC v. Rite Aid Corporation, what restriction did the stipulated order impose? A. A one-year suspension of Rite Aid's retail operations B. A requirement to publicly disclose its facial-recognition source code C. A five-year ban on facial recognition for security or surveillance D. A permanent ban on all AI use by Rite Aid 12 / 28 Category: 4TPRMMasterclass How would you rate the overall experience of the event? 12. Highly insightful and engaging Informative and valuable Average / satisfactory Lengthy but useful Too long and less engaging Not relevant / could be improved Check 13 / 28 Category: 6th TPRM Masterclass 13. Under “Continuity, termination and exit,” what must the supplier's business continuity and disaster recovery arrangements be consistent with? A. The regulator's standard audit calendar B. The supplier's internal marketing SLAs C. The agreed recovery time and recovery point objectives (RTO/RPO) D. The Customer's annual budget cycle 14 / 28 Category: 6th TPRM Masterclass 14. Per the “Material changes and model substitution” clause, what illustrative minimum notice period is suggested for a material change? A. 15 days B. 7 days C. 30 days D. 60 days 15 / 28 Category: 6th TPRM Masterclass 15. Which pairing correctly matches a risk path with its example, per “Six ways risk reaches the business”? A. Resilience and proof – prompt injection and excessive access B. Security and IP – prompt injection, excessive access, provenance and licensing gaps C. Data and outcomes – concentrated dependencies and service failure D. Resilience and proof – privacy failures and unlawful data use 16 / 28 Category: 6th TPRM Masterclass 16. Under “Evaluation and human oversight,” what must the supplier provide before deployment and after any material change affecting acceptance criteria? A. Proof that the Customer independently re-coded the model before go-live B. Documented evaluation results demonstrating compliance with the agreed acceptance criteria, model/system versions, methodology, limitations and conditions of use C. A third-party certification obtained before every release D. A written guarantee that the AI is error-free and bias-free 17 / 28 Category: 6th TPRM Masterclass 17. Under the “Dependency disclosure and subcontracting” clause, what must the supplier maintain? A. A schedule limited to model providers only, excluding cloud and data providers B. A confidential internal audit accessible only to the supplier C. A current schedule of all material dependencies, including AI models, data sources, tools and hosting infrastructure D. A monthly public report of all subcontractors filed with regulators 18 / 28 Category: 6th TPRM Masterclass 18. Which four functions does the NIST AI Risk Management Framework organize around, as cited in the masterclass? A. Govern, Monitor, Measure and Mitigate B. Map, Measure, Mitigate and Monitor C. Govern, Map, Model and Manage D. Govern, Map, Measure and Manage 19 / 28 Category: 6th TPRM Masterclass 19. According to the AI roles terminology, what is an “AI model”? A. The organization supplying a usable AI product B. The person operating or interacting with AI C. The organization using AI in its operations D. A system trained on data to generate text, predictions or recommendations 20 / 28 Category: 6th TPRM Masterclass 20. The “Data use, training and processing location” clause restricts the supplier from doing what, absent the Customer's prior written authorization? A. Using Customer Data, including prompts and outputs, to train, fine-tune or improve any AI model or develop other products/services B. Sharing Customer Data with any subcontractor under any circumstances C. Processing Customer Data at all, even to provide the contracted Services D. Retaining Customer Data for the full duration of the agreement 21 / 28 Category: 6th TPRM Masterclass 21. Who is defined as a “Data provider”? A. A party supplying AI computing, hosting or storage B. The team connecting models, data and tools into a solution C. A party supplying data to train, test or operate AI D. A party supplying a capability that AI can access 22 / 28 Category: 6th TPRM Masterclass 22. Which of the following is NOT one of the four elements of the “operating model for AI dependencies”? A. Assessment unit B. Evidence C. Review cycle D. Certification 23 / 28 Category: 6th TPRM Masterclass 23. Which pairing correctly matches a “Contractual guardrails for AI use” theme with its own description? A. Continuity and exit – Define evaluation thresholds, human approval and permitted agent actions B. Data and training – Secure recovery, transition support, data return and verified deletion C. Safety and authority – Restrict purposes, training, retention, access and processing locations D. Incident and liability – Set prompt notice, cooperation, remedies and proportionate risk allocation 24 / 28 Category: 4TPRMMasterclass 24. Please share your feedback on the event What did you find most valuable? What could be improved? Any suggestions for future sessions? Check 25 / 28 Category: 4TPRMMasterclass Which topics would you like to see covered in future roundtables or masterclasses? e.g., 25. Third-Party Cyber Risk & Continuous Monitoring AI Risk in Vendor Ecosystems Cloud & SaaS Risk Management Regulatory Compliance (e.g., outsourcing, data protection) Fourth-Party / Concentration Risk Incident & Breach Management involving vendors Other (please specify): __________ Check 26 / 28 Category: 6th TPRM Masterclass 26. Per the 2026 AI Omnibus timing referenced in the masterclass, when do the EU AI Act's Annex III high-risk rules and Annex I product-linked high-risk rules respectively begin to apply? A. 2 August 2027 and 2 December 2028 B. 2 December 2027 and 2 August 2028 C. 2 August 2028 and 2 December 2027 D. 2 December 2026 and 2 August 2027 27 / 28 Category: 6th TPRM Masterclass 27. In the agentic banking assistant case walkthrough, what triggered the unauthorized tool call? A. A cloud outage B. A data broker breach C. Prompt injection D. An expired API key 28 / 28 Category: 6th TPRM Masterclass 28. In the “Dependencies behind an AI service”, which layer most directly affects availability and location of the service? A. Model and data B. Solution vendor C. Infrastructure D. Enterprise Your score is LinkedIn Facebook Twitter 0% Restart quiz Exit
6th TPRM Masterclass
Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.
1 / 28
Category: 6th TPRM Masterclass
1. The “Eight diligence gates” group gates 5–6 under which theme?
2 / 28
2. What was the outcome of EEOC v. iTutor Group, Inc., et al.?
3 / 28
3. Under “Audit, evidence and regulatory cooperation,” what must the supplier secure from material subcontractors?
4 / 28
4. Which four questions does the masterclass propose to keep regulatory mapping from becoming a static list of law names?
5 / 28
5. In “Structuring the AI contract,” which party is described as remaining answerable for the contracted delivery chain?
6 / 28
6. Under APRA's CPS 230, how is a “fourth party” expressly defined?
7 / 28
7. What illustrative maximum notification window is suggested for an AI-related or security incident?
8 / 28
8. Under “IP, indemnities and liability,” who retains all rights in Customer Data and other inputs supplied by or on the Customer's behalf?
9 / 28
9. What best defines a “Third party” in the tiering of AI supply-chain relationships?
10 / 28
10. Contract terms across the chain” lists four themes. Which theme covers “Notice, assessment rights, remediation and proportionate suspension
11 / 28
11. In FTC v. Rite Aid Corporation, what restriction did the stipulated order impose?
12 / 28
Category: 4TPRMMasterclass
How would you rate the overall experience of the event?
13 / 28
13. Under “Continuity, termination and exit,” what must the supplier's business continuity and disaster recovery arrangements be consistent with?
14 / 28
14. Per the “Material changes and model substitution” clause, what illustrative minimum notice period is suggested for a material change?
15 / 28
15. Which pairing correctly matches a risk path with its example, per “Six ways risk reaches the business”?
16 / 28
16. Under “Evaluation and human oversight,” what must the supplier provide before deployment and after any material change affecting acceptance criteria?
17 / 28
17. Under the “Dependency disclosure and subcontracting” clause, what must the supplier maintain?
18 / 28
18. Which four functions does the NIST AI Risk Management Framework organize around, as cited in the masterclass?
19 / 28
19. According to the AI roles terminology, what is an “AI model”?
20 / 28
20. The “Data use, training and processing location” clause restricts the supplier from doing what, absent the Customer's prior written authorization?
21 / 28
21. Who is defined as a “Data provider”?
22 / 28
22. Which of the following is NOT one of the four elements of the “operating model for AI dependencies”?
23 / 28
23. Which pairing correctly matches a “Contractual guardrails for AI use” theme with its own description?
24 / 28
24. Please share your feedback on the event
25 / 28
Which topics would you like to see covered in future roundtables or masterclasses? e.g.,
26 / 28
26. Per the 2026 AI Omnibus timing referenced in the masterclass, when do the EU AI Act's Annex III high-risk rules and Annex I product-linked high-risk rules respectively begin to apply?
27 / 28
27. In the agentic banking assistant case walkthrough, what triggered the unauthorized tool call?
28 / 28
28. In the “Dependencies behind an AI service”, which layer most directly affects availability and location of the service?
Your score is
Restart quiz Exit
June 27, 2026
The quiz has expired!
May 23, 2026
May 9, 2026