# AIGP interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | Walk me through how you would decide whether a new AI use case needs a governance review. | An intake step, a risk tier, a named owner and a written decision. Vague answers about "best practice" without a process are a flag. | |
| 2 | How would you explain our AI policy to the board in five minutes? | Risk appetite, who is accountable, the top three risks and how progress is measured. Short and specific beats complete. | |
| 3 | How does data protection law reach the data we use to train or tune a model? | Lawful basis, purpose limitation, data minimization, a data protection impact assessment where the risk is high, and how data subject rights still apply. | |
| 4 | Which EU AI Act duties apply to us, and from when? | First our role (provider or deployer) and the risk category. Then dates: Article 4 literacy and the Article 5 bans since 2 February 2025, and Annex III high-risk duties from 2 December 2027 after Regulation (EU) 2026/1744. | |
| 5 | What does ISO/IEC 42001 give us that the law does not? | A certifiable management system with continual improvement. Not a substitute for meeting legal duties. | |
| 6 | How would you govern a model after it is released? | Monitoring with set thresholds, an incident route, change control for retraining, and a record of decisions. | |
| 7 | A team wants a vendor's generative AI tool. What do you check before we sign? | Intended use, data terms, the vendor's documentation, whether our use is high-risk, transparency duties, and who owns the decision to deploy. | |
| 8 | Tell me about a time you changed or stopped an AI deployment. | The evidence used, who was involved, what changed afterward. Candidates new to the field can use a project or case study. | |

Source: https://credentialpress.com/guides/aigp-interview-questions
