SAI-250 knowledge check
Verify control traceability, evidence quality, passport completeness, exceptions, reviews, and change triggers.
How to use this assessment
Complete the questions without referring to the chapter text. Then review the guidance and update your evidence-pack artifacts where your answer exposes a gap.
This public knowledge check supports learning. It is not a professional certification examination.
Scenario questions
1. Traceability chain
A team says a control objective is "assured" because a policy document references it. Name the additional links required before that objective is actually traceable to evidence.
2. Ownership versus operation
A managed service provider configures and runs an access-control mechanism for your AI workload. Explain why "the provider handles security" is not a complete ownership model, and what the adopting organization must still decide.
3. Inherited controls
A platform team states that its container-scanning control covers "all workloads on the platform." What assumptions and scope details must be confirmed before an AI workload team can rely on that inherited control?
4. Evidence quality
An operations dashboard shows a green checkmark next to "policy enforced" for the last release. List the properties this evidence is missing before it can support a release decision.
5. System passport
Explain why a system passport should link to authoritative evidence rather than copy it, and what happens to a copied passport when the source evidence changes.
6. Exceptions
A team has an approved exception for a missing control, with no expiry date recorded. Explain why this is a risk in itself, independent of the original unmet control.
7. Material change
A deployed AI assistant's underlying model is swapped for a newer version with no other change. Explain why this alone can be enough to trigger reassessment, and name two other events that should trigger it.
8. Continuous assurance versus review
A team argues that because its observability dashboards show no policy violations in six months, it no longer needs a periodic independent review. Evaluate this argument.
Answer guidance
- Strong answers name the chain from obligation to control objective, implementation, test, evidence record, owner, reviewer, and review frequency — a policy reference alone establishes intent, not verification.
- Ownership requires naming who accepts the risk if the control fails and who verifies the provider's evidence is sufficient, in addition to who operates the control day to day.
- The workload team must confirm which components, tenants, environments, and versions the inherited scan actually covers, and independently verify any portion it does not.
- The dashboard record lacks identity, integrity, source, and retention, and is not linked to the specific version it was evaluated against — a status indicator is not itself verifiable evidence.
- A passport that links to sources always reflects current evidence; a copied passport silently goes stale the moment the source changes, misleading a later reviewer.
- Without an expiry, the exception becomes a permanent, unreviewed risk acceptance — the original gap and the absence of a review deadline are two separate, compounding risks.
- A model swap can change behavior, outputs, and risk profile even with no code change, so it must trigger reassessment; policy, identity, tool, infrastructure, or supplier changes, and new incidents or findings, should trigger it too.
- Continuous signals show that approved properties currently hold; they do not test assumptions, sampling, or independence the way a periodic review does, and cannot catch failures the monitored signals were never designed to detect.
Completion rubric
Mark the assurance package complete only when:
- Every control objective in the traceability matrix has a named owner and at least one evidence producer.
- Evidence records carry identity, scope, time, source, integrity, and retention — not just a pass or fail status.
- The system passport links to authoritative sources and names one specific release candidate.
- Every exception has a compensating control, an owner, an approver, and an expiry date.
- Material-change triggers are defined and distinct from rollback triggers.
- The release recommendation names a decision authority and a monitoring window.
- A reviewer unfamiliar with the project can reconstruct the decision from the package alone.
Completion outcome
SAI-250 is complete when the learner can explain why traceable evidence differs from a policy statement, and can produce the assurance package from the AI evidence-pack workshop.