Skip to content

ITIL 5 Foundation : ITIL and Artificial Intelligence (Domain 6)

ITIL 5 – Foundation : Certified ITIL Foundation - Domain 6 - ITIL and Artificial Intelligence

30 questionsmedium

Introduction to ITIL 5 and the AI-Native Framework

The release of ITIL (Version 5) in early 2026 marks a transformative shift in the landscape of technology service administration. Moving away from the traditional focus on IT Service Management (ITSM), the framework now embraces a comprehensive Digital Product and Service Management (DPSM) paradigm. This evolution is necessitated by the realities of Industry 5.0, where high-velocity, cloud-hosted, and automated environments are the norm.

Domain 6 of the ITIL 5 Foundation syllabus specifically addresses the integration of Artificial Intelligence (AI). In previous iterations, such as ITIL 4, the framework focused primarily on deterministic systems—those that perform exactly as programmed. However, the rise of probabilistic, adaptive, and often opaque AI systems has required ITIL to become “AI-native by design.” While Domain 6 accounts for 2.5% of the Foundation exam weighting (targeting approximately one specific question), its principles are woven throughout the entire Product and Service Lifecycle Model (PSLM).

This study guide explores how ITIL 5 provides a structured governance approach to ensure AI-enabled capabilities create value responsibly, remain human-centric, and operate within acceptable risk levels.


The Role of AI and Automation in Service Management

Artificial intelligence is no longer merely a technology investment; it is a strategic capability. In modern service management, AI serves as an active partner in value streams rather than a passive tool. Organizations leverage AI to automate repetitive data, analytics, and decision workflows, allowing human personnel to focus on strategy and innovation.

Transformation of Efficiency

Automation and AI-powered tools transform operational efficiency, particularly within incident management. Automated workflows can distribute tickets to appropriate teams, reducing resolution times. Organizations implementing structured automation within ITSM report measurable improvements in service quality. Proactive tools, such as service health monitoring and alert management, allow teams to address issues before they escalate.

Strategic Capability in DPSM

AI facilitates a shift toward “high-velocity service delivery.” By integrating AI into the Information and Technology dimension of service management, organizations can:

  • Enhance Decision-Making: AI algorithms categorize and prioritize incidents based on predefined criteria.
  • Predictive Operations: Systems can predict incident severity and suggest likely root causes before human intervention is required.
  • Continuous Improvement: AI-powered analytics process large volumes of data to reveal patterns that inform enhancements to the broader service value system.

Classifying AI Capabilities: The 6C Model

ITIL 5 introduces the 6C Model to provide a structured method for classifying, understanding, and governing AI capabilities. This model helps organizations assess their maturity and develop specific controls based on the nature of the AI’s function.

CapabilityDefinition and ApplicationExample in Service Management
CreationGenerating new digital assets or content.Drafting incident summaries, postmortems, or service level agreement (SLA) drafts.
CurationOrganizing, filtering, and correlating information.Alert correlation and deduplicating incidents to reduce operational “noise.”
ClarificationExplaining or simplifying technical data for stakeholders.Translating technical log data into plain-language business impact updates.
CognitionMaking decisions, predictions, or identifying signals.Predicting likely root causes or forecasting future resource capacity demands.
CommunicationInteracting with human stakeholders through natural language.Using Slack-integrated virtual assistants to interact with users or responders.
CoordinationOrchestrating workflows and automating routing decisions.Assigning on-call personnel or triggering automated rollback scripts.

Why Traditional IT Governance is Insufficient for AI

A core argument of ITIL 5 is that traditional IT governance (such as ITIL 4 or COBIT) was built for static, deterministic systems. These older frameworks assume that requirements are defined, tested, and deployed in a controlled, predictable manner. AI systems introduce four unique challenges that traditional governance cannot solve:

  1. Autonomy in Decision-Making: AI systems can execute multi-step workflows without human approval at each individual step.
  2. Lack of Transparency: Many AI models (particularly Large Language Models) are “black boxes,” making it difficult to understand why a specific decision was reached.
  3. Model Drift and Evolution: Unlike static software, an AI model evolves as it ingests new data. Its risk profile can change over time without any manual code changes.
  4. Emergent Behavior: AI may produce outputs or actions that were not explicitly programmed and could not be predicted during the design phase.

Consequently, ITIL 5 demands a move from periodic audits to continuous monitoring and a new relationship between technical and compliance teams.


The Four AI Governance Perspectives

To manage the risks associated with data privacy, opacity, and ethical bias, ITIL 5 divides AI governance into four distinct perspectives. These perspectives ensure that AI adoption is responsible, ethical, and compliant.

1. Decision Authority and Risk Management

This perspective defines who has the authority to approve automated actions. It establishes clear operational boundaries and confidence thresholds.

  • Accountability: It ensures there is a named owner for model outcomes rather than “shared responsibility,” which often leads to no one being responsible.
  • Escalation: It defines human-in-the-loop thresholds, determining when an AI must hand off a decision to a human.

2. Ethical Principles and Responsible AI

Organizations must ensure AI use aligns with corporate values. This includes implementing testing procedures to detect and mitigate algorithmic bias and ensuring fairness in how AI prioritizes work or selects candidates.

3. Data Governance and Performance Management

Because AI performance is dependent on data integrity, this perspective regulates the quality of training data.

  • Lineage: Tracking data origins to ensure compliance and accuracy.
  • Drift Monitoring: Continuous monitoring of live models to detect distributional shifts where model accuracy begins to degrade.

4. Regulatory Compliance and Operational Standards

This involves aligning AI operations with international frameworks, such as the EU AI Act or Singapore’s MAS FEAT Principles. Organizations must categorize AI systems by risk level (Low, Medium, High) to meet documentation and monitoring obligations.


The ITIL AI Governance Improvement Model

To establish and adapt governance effectively, ITIL 5 proposes a four-step improvement model. This model is iterative, acknowledging that as AI capabilities evolve, governance must adapt.

  1. Assess: Evaluate the organization’s current AI governance maturity and stress-test existing frameworks. This includes auditing “Shadow AI” (unauthorized tools) and identifying gaps where human judgment is being replaced by AI.
  2. Design: Define specific requirements and controls. This includes setting confidence thresholds, designing approval workflows for AI actions, and establishing audit logging requirements.
  3. Implement: Deploy governance policies and technical controls. This might involve building monitoring dashboards and automated alerts to catch model drift.
  4. Maintain: This is an ongoing operational capability. It involves continuous monitoring, assurance, and the use of the Continual Improvement Model to refine governance as regulations and technologies change.

AI Governance Maturity Levels

Governance maturity is not binary; it exists on a spectrum. The ITIL 5 context utilizes a five-level maturity model to help organizations benchmark their progress.

  • Level 1: Ad Hoc: Uncoordinated AI experimentation across different teams. This is characterized by “invisible exposure” and duplicated efforts.
  • Level 2: Controlled: Pilot programs exist with limited documentation, but there is no clear path to enterprise-wide scale or formal sign-off.
  • Level 3: Structured: Formal policies and designated AI ownership exist. A framework is in place, though it may lack consistent enforcement across all departments.
  • Level 4: Enterprise Operating Model: Standardized governance is integrated across all departments. AI is managed as a core part of the digital product lifecycle.
  • Level 5: Governance Advantage: Governance becomes a strategic differentiator and a “trust signal” to customers and regulators.

AI Governance Patterns and Decision Rights

In the AI era, Decision Rights refers to the clear assignment of who has the authority to approve, override, or retire an AI system’s actions. ITIL 5 identifies four primary governance patterns used to manage these rights:

The Human-in-the-Loop Pattern

A human reviews every recommendation made by the AI before it is executed. This is typical for high-risk systems, such as medical triage or high-value procurement approvals.

The Human-on-the-Loop Pattern

The AI acts autonomously, but a human monitors the process and has the authority to intervene or override actions in real-time.

The Human-out-of-the-Loop Pattern

The AI is authorized to make and execute decisions within predefined boundaries without manual intervention. Governance here relies on “detective controls” and automated “kill switches.”

The Stewardship vs. Control Balance

Effective governance must balance the need for control (stability) with stewardship (innovation). If governance is too restrictive, it leads to Shadow AI; if it is too loose, it creates unmanaged risk.


Controls for Shadow AI

Shadow AI refers to the adoption of AI tools by employees without formal IT or governance review. It is often a symptom of slow internal approval processes.

Risks of Shadow AI

  • Data Leakage: Sensitive company data may be shared with external LLMs that have not been vetted for security.
  • Inconsistency: Different teams may use different tools, leading to inconsistent outputs and uncoordinated decision-making.
  • Compliance Breaches: Using ungoverned tools often violates regulatory requirements like the EU AI Act.

Governance Controls

To manage Shadow AI, ITIL 5 suggests:

  • Auditing: Inventorying every AI tool currently in use, regardless of official status.
  • Approval Gates: Streamlining the internal approval process so employees do not feel the need to bypass official channels.
  • Education: Ensuring staff understand the risks of data sovereignty and the importance of using governed platforms.
  • Detective Controls: Using technology to identify unauthorized AI API calls within the corporate network.

AI Integration with DevOps and PRINCE2

ITIL 5 does not operate in isolation; it emphasizes interoperability with other modern methodologies to ensure end-to-end governance.

AI and DevOps

Within DevOps continuous delivery pipelines, AI governance is integrated into the “Build” and “Transition” activities. Automated testing for bias and performance drift is embedded directly into the CI/CD loop. This ensures that a model is not just accurate at launch but remains “governable” across its operational life.

AI and PRINCE2

AI governance within PRINCE2 focuses on project-level oversight. It ensures that when AI is a component of a project delivery, the business case accounts for the ongoing costs of model maintenance, monitoring, and regulatory compliance.


Practical Application in Incident Management

To prepare for the ITIL 5 Foundation exam, it is useful to see how Domain 6 concepts apply to a high-pressure scenario, such as a SEV-1 Incident.

Capability (6C)Governance ConsiderationAction in an Incident
CognitionConfidence ThresholdsThe AI suggests a hypothesis for a database failure. The team only sees the suggestion if the AI’s confidence is >85%.
CommunicationTransparencyThe AI drafts a status page update. The governance policy requires a human “owner” to review it for “hallucinations” before publishing.
CoordinationDecision BoundariesThe AI is authorized to automatically restart a non-critical service but must page a human before running a script that deletes data.
CurationAudit TrailsThe AI correlates 1,000 alerts into one incident. The governance framework requires an immutable log of which alerts were included in that correlation for postmortem review.

Glossary of Key Terms

  • Agentic AI: AI systems that act autonomously across multi-step tasks without requiring per-action human approval.
  • AI Transformation Governance: The enterprise-wide framework of policies and controls ensuring AI systems are deployed responsibly and aligned with regulations.
  • AI Model Drift: The phenomenon where an AI model’s performance degrades over time as the data it encounters in the real world deviates from its training data.
  • Algorithm Bias: Systematic errors in an AI system that lead to unfair outcomes, often reflecting historical discrimination present in training data.
  • Champion-Challenger Testing: A lifecycle control where a new “challenger” model is tested against the current “champion” model to ensure better performance before deployment.
  • Decision Rights: The clear assignment of authority to approve, override, or retire an AI system’s recommendations.
  • Deterministic System: A system that produces the same output for a given input, following fixed business logic (unlike probabilistic AI).
  • Digital Product and Service Management (DPSM): The paradigm shift in ITIL 5 that unifies product creation and operational support.
  • EU AI Act: A comprehensive regulatory framework that classifies AI systems by risk level and imposes documentation and monitoring obligations.
  • Explainability: The ability for stakeholders or regulators to understand and trace how an AI system reached a specific decision.
  • Hallucination: An error where an AI (typically a generative model) produces a confident output that is factually incorrect or nonsensical.
  • MAS FEAT: A set of principles (Fairness, Ethics, Accountability, and Transparency) issued by the Monetary Authority of Singapore for AI use in finance.
  • Model Risk Management (MRM): The practice of identifying and mitigating the risks associated with using mathematical models in decision-making.
  • P.E.S.T.L.E Factors: An external analysis tool (Political, Economic, Social, Technological, Legal, Environmental) used in the Four Dimensions of ITIL 5.
  • Probabilistic System: A system (like AI) that produces outputs based on likelihoods and patterns rather than fixed rules.
  • Product and Service Lifecycle Model (PSLM): The eight-activity model in ITIL 5 that replaces the ITIL 4 Service Value Chain.
  • Sovereignty (Data): The concept that data is subject to the laws and governance of the country in which it is located.
  • Value Co-Creation: The central theme of ITIL 5, where providers and consumers work together to realize value from services.

Short-Answer Questions

1. What is the primary purpose of the ITIL 5 6C Model? Answer: The 6C Model provides a structured way to classify AI capabilities within the Information and Technology dimension, helping organizations understand and govern AI capabilities responsibly.

2. Why is traditional IT governance considered insufficient for AI systems? Answer: Traditional frameworks are designed for static, deterministic systems and cannot account for AI’s autonomy, lack of transparency, and ability to evolve (model drift).

3. Define “Shadow AI” and its primary risk. Answer: Shadow AI refers to AI tools adopted by employees without formal review; its primary risk is the exposure of sensitive company data to ungoverned external systems.

4. What does the “Cognition” capability in the 6C model involve? Answer: Cognition involves AI making decisions, predictions, or identifying signals, such as predicting incident severity or forecasting resource capacity demands.

5. Name the four perspectives of the ITIL AI Governance Model. Answer: The four perspectives are Decision Authority and Risk Management, Ethical Principles and Responsible AI, Data Governance and Performance Management, and Regulatory Compliance.

6. What is the difference between “Creation” and “Clarification” in the 6C model? Answer: Creation involves generating new content like postmortems, while Clarification involves simplifying technical data for stakeholder updates.

7. In the ITIL AI Governance Improvement Model, what occurs during the “Assess” step? Answer: Organizations evaluate their current governance maturity, identify Shadow AI, and stress-test existing frameworks to find gaps.

8. What is “Model Drift” and how should it be managed? Answer: Model drift is the degradation of AI performance over time; it should be managed through continuous monitoring and defined retraining triggers.

9. How does ITIL 5 define “Decision Rights” in an AI context? Answer: Decision rights are the clear assignments of authority to approve, override, or retire the recommendations or actions of an AI system.

10. What role do “Guiding Principles” play in AI decision-making? Answer: Guiding principles (like “Focus on value” and “Collaborate and promote visibility”) must be evaluated in context to ensure AI decisions remain aligned with organizational values.


Open-Ended / Design Questions

  1. Scenario Design: You are tasked with implementing an AI agent that automatically resolves “Password Reset” requests and “Access Permission” requests. Design a governance strategy using the 6C model. Which capabilities apply, and what are the specific human-in-the-loop thresholds you would establish?
  2. Maturity Assessment: An organization currently has various departments using ChatGPT for internal reporting with no official policy. Using the ITIL 5 Maturity Model, determine their current level and outline the specific steps required to move them to Level 3 (Structured).
  3. Governance vs. Innovation: Debate the “Stewardship vs. Control” balance. How can a Chief AI Officer implement enough control to satisfy the EU AI Act without stifling the speed of an Agile development team? Provide examples of “detective” versus “preventive” controls.
  4. Data Integrity: Given that AI governance inherits from data governance, design a “Data Governance and Performance Management” checklist for a new AI model that predicts customer churn. What specific lineage and quality SLAs must be enforced at the platform layer?
  5. Incident Lifecycle Integration: Analyze the Product and Service Lifecycle Model (PSLM). In which of the eight activities (Discover, Design, Acquire, Build, Transition, Operate, Deliver, Support) is AI governance most critical, and how does “Shadow AI” potentially disrupt the “Transition” activity?

Leaderboard

No scores saved yet. Be the first!

30 Questions — ITIL 5 – Foundation : Certified ITIL Foundation - Domain 6 - ITIL and Artificial Intelligence

Expand any question to reveal the correct answer and explanation.

  1. 1 Which specific '6C' AI capability is responsible for translating technical log data into a format that stakeholders can understand to assess business impact?

    This capability bridges the gap between raw data and human-centric understanding.

    Clarification

    Clarification focuses on simplifying or explaining complex technical information, such as logs, for broader organizational use.

    • Communication

      While related, communication refers more specifically to the natural language interaction between the AI and human stakeholders.

    • Curation

      Curation involves filtering and organizing existing information, such as correlating alerts, rather than explaining it.

    • Cognition

      Cognition is centered on high-level decision-making, predictions, and forecasting based on data patterns.

  2. 2 Under the ITIL 5 AI Governance Model, which perspective addresses the authority to approve an AI agent's ability to trigger an automated remediation script?

    Consider which perspective deals specifically with 'who decides' and the limits of autonomy.

    Decision Authority and Risk Management

    This perspective defines who has the power to approve autonomous actions and sets operational boundaries for those agents.

    • Ethical Principles and Responsible AI

      This perspective is more concerned with bias, fairness, and alignment with organizational values.

    • Regulatory Compliance and Operational Standards

      While it touches on operational standards, its primary focus is on external legal frameworks like the EU AI Act.

    • Data Governance and Performance Management

      This perspective monitors model drift and training data quality rather than the delegation of authority.

  3. 3 An organization discovers that its marketing team is using a third-party GenAI tool without formal IT approval to draft campaign copy. According to ITIL 5, what is the primary structural driver of this 'Shadow AI'?

    Think about the friction between business speed and governance oversight.

    Inefficient internal approval processes

    ITIL 5 identifies that slow internal governance or approval workflows are the most common cause for employees seeking unauthorized tools.

    • Intentional avoidance of ethical standards

      Source material indicates that shadow AI is rarely malicious and is instead usually a symptom of a need for speed.

    • A lack of advanced engineering resources

      The adoption of external SaaS AI tools often happens precisely because they do not require internal engineering resources.

    • High costs of approved enterprise models

      While cost can be a factor, the primary barrier cited is the agility gap created by legacy governance structures.

  4. 4 Which characteristic fundamentally distinguishes Agentic AI from Generative AI in the context of ITIL 5?

    Look for the difference between 'creating content' and 'performing actions'.

    The ability to execute multi-step tasks autonomously

    Agentic AI is defined by its capacity to act across a sequence of tasks to achieve a goal without per-action human approval.

    • The capacity to produce natural language responses

      Both Generative and Agentic AI can utilize natural language, so this is not a distinguishing factor.

    • The use of large language models for reasoning

      Both types often rely on the same underlying model architectures for their processing.

    • The focus on data privacy and encryption

      Privacy and encryption are standard requirements for all enterprise AI and do not define the specific type of intelligence.

  5. 5 In the 6C model, which capability is most likely involved in predicting which server is most likely to fail based on current resource utilization trends?

    This capability involves using data to understand what might happen next.

    Cognition

    Cognition encompasses predictive analytics, forecasting, and suggesting root causes based on data.

    • Curation

      Curation is about organizing and deduplicating current data alerts rather than predicting future state changes.

    • Coordination

      Coordination involves the orchestration of workflows and routing, not the analytical prediction of failures.

    • Clarification

      Clarification focuses on explaining current data rather than generating forecasts or predictive insights.

  6. 6 The ITIL 5 AI Governance perspective 'Data Governance and Performance Management' primarily aims to mitigate which risk?

    This involves the ongoing monitoring of the model's 'health' and accuracy.

    Model performance drift

    This perspective monitors how models evolve over time and ensures that the data they ingest maintains quality and accuracy.

    • Algorithmic bias against users

      While data-related, bias mitigation is specifically categorized under the Ethical Principles perspective.

    • Unauthorized budget expenditure

      Financial oversight is a broader management function and not the primary focus of this specific governance perspective.

    • Lack of human-in-the-loop triggers

      Approval thresholds and human escalation fall under the Decision Authority and Risk Management perspective.

  7. 7 Which of the following describes the 'Stewardship' level of the ITIL 5 AI Governance maturity model?

    It is the level where governance is seen as a supportive responsibility rather than just a set of guardrails.

    Active support for people to navigate compliance and implement measures

    Stewardship represents the highest maturity where governance actively assists stakeholders rather than just enforcing rules.

    • Formalized policies and designated executive owners for all AI

      This describes lower levels of maturity, such as the Structured Framework or Operating Model stages.

    • Ad hoc use of AI tools without centralized oversight

      This is Level 1 maturity, where AI use is uncoordinated and risky.

    • Successful pilot programs with limited documentation

      This corresponds to the Controlled Experiments level of maturity.

  8. 8 Under the 6C model, 'Curation' is specifically used in incident management for which purpose?

    This capability focuses on sorting through data to find what is relevant.

    Correlating alerts and reducing operational noise

    Curation is the act of organizing raw data, such as deduplicating monitoring alerts to find the primary incident.

    • Triggering a rollback script automatically

      Triggering actions and orchestrating workflows is the domain of the Coordination capability.

    • Summarizing an incident for a post-mortem report

      Generating new text or summaries falls under the Creation capability.

    • Paging the on-call engineer based on expertise

      Routing and assigning tasks is part of the Coordination capability.

  9. 9 Which AI governance perspective would be most concerned with ensuring an AI recruitment tool does not favor one demographic over another?

    Look for the perspective that focuses on fairness and social values.

    Ethical Principles and Responsible AI

    This perspective manages fairness and bias testing to ensure AI alignment with organizational ethics.

    • Decision Authority and Risk Management

      This perspective is more about who approves the system rather than the inherent fairness of its logic.

    • Data Governance and Performance Management

      This deals with the quality and drift of data, while the social impact of the logic is an ethical concern.

    • Regulatory Compliance

      While regulations may mandate fairness, the internal focus on organizational values belongs to the Ethical perspective.

  10. 10 How does ITIL 5 define 'Narrow AI' in comparison to other types?

    This type of AI is focused on a 'single-purpose' function.

    AI designed to perform a specific, limited set of tasks

    Narrow AI is task-specific, whereas Generative or Agentic AI often handle more creative or autonomous multi-step operations.

    • AI that has achieved human-level general intelligence

      Human-level intelligence (AGI) is currently theoretical and not how ITIL 5 classifies current systems.

    • AI that primarily acts without any human oversight

      This describes high-autonomy Agentic AI, not necessarily the scope of the AI's intelligence.

    • AI that is only used for data visualization

      Data visualization is just one possible use case; the term refers to the specificity of the function.

  11. 11 According to the ITIL 5 AI Governance Model, what is the role of 'Human-in-the-loop' (HITL) oversight?

    It serves as a checkpoint for critical decisions made by an algorithm.

    A mechanism for review thresholds in high-risk systems

    HITL is a sign of mature governance where humans must review or approve certain consequential AI decisions.

    • A fallback for when AI models fail to generate an output

      HITL is a proactive governance requirement for risk management, not just a technical redundancy.

    • A method to train the AI by manual data entry

      While humans do train AI, 'oversight' specifically refers to the control and monitoring of live systems.

    • A temporary measure only used during the pilot stage

      HITL is an ongoing operational requirement for systems classified as high-risk.

  12. 12 Which of the following is a step in the ITIL AI Governance Improvement Model?

    The first step involves evaluating the current state and identifying breaking points.

    Assess and Stress-Test

    The model's four steps include Assess, Design, Implement, and Maintain.

    • Procure and Deploy

      These are general operational steps, but not the specific steps of the AI Governance Improvement Model.

    • Code and Debug

      These are technical development activities rather than governance improvement activities.

    • Categorize and Route

      These are incident management activities, though they can be enabled by AI.

  13. 13 Which 6C capability is primarily utilized when an AI agent automatically assigns an incident to the correct support team based on their current availability and skillset?

    This capability is about 'orchestrating' how work flows through the system.

    Coordination

    Coordination involves orchestrating workflows and the automated routing of tasks between parties.

    • Communication

      Communication is about the interface and message exchange, not the underlying routing logic.

    • Curation

      Curation filters data but does not necessarily trigger the operational workflow of assigning it to a person.

    • Creation

      Creation would involve drafting the ticket content, while Coordination handles the movement of that ticket.

  14. 14 What does the 'Opacity' characteristic of AI refer to in governance discussions?

    Think about the challenges of 'Explainability'.

    The difficulty in explaining the internal logic of a model's output

    Opacity describes the 'black box' nature of complex AI, making it hard to audit the exact reasoning for a decision.

    • The inability of AI to work with unstructured data

      AI is actually often used specifically for unstructured data; opacity is about transparency of logic.

    • The physical security of the data center housing the AI

      Opacity is a logical and ethical characteristic of the software, not a physical security state.

    • The lack of user interface options for a model

      A model can have a clear interface but still have opaque internal reasoning.

  15. 15 In the context of the EU AI Act mentioned in ITIL 5, AI systems affecting critical infrastructure are likely to be categorized as:

    These systems have the highest impact on safety and societal functioning.

    High-risk

    High-risk systems under the Act include those used in critical infrastructure due to the potential severity of failure.

    • Unacceptable risk

      Unacceptable risks are usually those that violate fundamental rights and are banned, rather than just high-stakes infrastructure.

    • Low-risk

      Critical infrastructure has high impact potential, making it the opposite of low-risk.

    • Non-regulated

      Critical infrastructure systems are a primary focus of AI regulatory frameworks.

  16. 16 Which AI governance perspective focuses on implementing testing procedures to detect and mitigate algorithmic bias?

    It is about making sure the AI 'behaves' fairly and according to human values.

    Ethical Principles and Responsible AI

    This perspective embeds values like fairness into the testing lifecycle to catch biases before production.

    • Decision Authority and Risk Management

      This perspective deals with the delegation of power rather than the social fairness of the logic.

    • Regulatory Compliance

      Regulation may require these tests, but the operational practice of ensuring ethics belongs to the specific Ethical perspective.

    • Data Governance and Performance Management

      This deals with technical accuracy and drift, whereas bias is a sociocultural ethical risk.

  17. 17 According to ITIL 5, why is traditional IT governance like COBIT or ITIL 4 insufficient for AI?

    Traditional systems do exactly what they are programmed to do, every time.

    It was designed for deterministic systems with predictable outputs

    AI is probabilistic and adaptive, whereas older frameworks assumed systems would follow fixed, predictable code paths.

    • It requires too much manual documentation

      AI governance actually increases documentation requirements; the issue is the 'nature' of the system behavior.

    • It focuses solely on hardware and infrastructure

      Traditional frameworks also focused on services and software, but they assumed those systems were static and predictable.

    • It is only applicable to on-premise environments

      Traditional governance adapted to the cloud; the issue is specifically the 'learning' and 'autonomous' nature of AI.

  18. 18 What is the primary function of the 'Coordination' capability in the 6C model?

    It acts like a traffic controller for organizational processes.

    Automating routing decisions and orchestrating workflows

    Coordination handles the movement of work and the triggering of automated responses or assignments.

    • Summarizing log data for human review

      Summarizing is a function of Clarification or Creation, not workflow orchestration.

    • Identifying and removing duplicate data alerts

      This is Curation, which cleans and organizes data before it is routed.

    • Predicting resource demands for the next quarter

      Prediction and forecasting are functions of the Cognition capability.

  19. 19 The 'Decision Authority and Risk Management' perspective is responsible for defining:

    It ensures that a person can still take control when the machine is wrong.

    Human escalation paths for automated decisions

    This perspective ensures there is a clear human path to override or handle anomalies in automated systems.

    • The toxicity score of Generative AI outputs

      Toxicity scoring is part of performance management and ethical monitoring.

    • The accuracy of training datasets

      Training data quality is the domain of Data Governance.

    • The alignment of AI with sustainability goals

      Sustainability is a broader strategic value rather than a specific decision authority control.

  20. 20 Under ITIL 5's 'AI-native' philosophy, AI should be viewed as:

    It is no longer just a 'tool' on the side.

    An active partner in value streams

    ITIL 5 shifts from viewing AI as a tool to seeing it as a core participant in the product and service lifecycle.

    • A replacement for low-skilled service desk staff

      The framework emphasizes human-technology collaboration rather than simple replacement.

    • A separate infrastructure layer for IT only

      AI is integrated across the enterprise, including roles in HR, Finance, and Legal.

    • An optional extension for high-maturity teams

      ITIL 5 assumes AI is unavoidable and 'native' to the standard operating environment.

  21. 21 Which 6C capability is most likely used to draft the initial version of a Service Level Agreement (SLA)?

    This capability involves 'producing' a new digital asset.

    Creation

    Creation involves generating new assets, reports, or drafts based on inputs.

    • Cognition

      Cognition might predict the needed targets, but the act of drafting the document is Creation.

    • Curation

      Curation organizes existing data rather than drafting new content.

    • Communication

      Communication is about the exchange with people, while Creation is about the production of the asset itself.

  22. 22 What is 'Model Drift' in the context of ITIL 5 AI Governance?

    It is a performance issue that happens when the model gets 'out of sync' with reality.

    The degradation of model accuracy over time as it ingests new data

    Drift occurs when the model's performance shifts away from its intended parameters due to evolving data patterns.

    • The movement of a model from a local server to the cloud

      This is a deployment activity, not a governance risk like performance drift.

    • The change in ownership of a model between departments

      This is an organizational change; drift refers to the technical behavior of the model.

    • The process of a model learning a second language

      Learning is a feature; drift is specifically a risk associated with unintended changes in output quality.

  23. 23 Which 6C capability helps organizations move from 'manual hand-offs' to 'high-velocity' value streams?

    This capability handles the orchestration of actions within a process.

    Coordination

    Coordination automates the flow of work, eliminating the delays found in traditional manual hand-offs.

    • Clarification

      Clarification explains the work, but Coordination is what actually moves it through the stream.

    • Curation

      Curation organizes the data being handed off, but it doesn't perform the 'hand-off' itself.

    • Cognition

      Cognition decides 'what' to do, but Coordination is the mechanism for 'doing' it at high velocity.

  24. 24 The ITIL 5 AI Governance perspective on 'Regulatory Compliance' is uniquely challenging because:

    Think about how often AI laws and standards are changing right now.

    The legal landscape is evolving as rapidly as the technology

    Frameworks like the EU AI Act are new and frequently updated, requiring dynamic rather than static compliance.

    • Most AI systems are exempt from traditional laws

      AI is increasingly subject to specific and rigorous legal frameworks globally.

    • It requires lawyers to learn to write machine code

      Compliance is about oversight and policy alignment, not technical coding by legal staff.

    • It only applies to companies based in the United States

      Regulatory frameworks like the EU AI Act have global reach for any firm with European exposure.

  25. 25 In the 'Assess' step of the ITIL AI Governance Improvement Model, what is meant by 'Stress-Testing'?

    It involves finding the limits of your 'rules' and 'oversight'.

    Identifying breaking points in current governance and performance

    Stress-testing evaluates where the existing governance might fail under pressure or at scale.

    • Running a model until the hardware overheats

      This is a physical hardware test; governance stress-testing is about policy and oversight limits.

    • Testing the AI with a massive amount of spam data

      While related to data robustness, governance stress-testing is specifically about the 'oversight' logic.

    • Simulating a complete data center power failure

      This is disaster recovery testing; AI governance focuses on the responsible use and decision-making logic.

  26. 26 Which 6C capability is used by a virtual assistant to interact with a user in natural language to resolve a service request?

    This is the primary 'interface' capability for human stakeholders.

    Communication

    Communication involves the natural language interaction between humans and AI systems.

    • Clarification

      Clarification simplifies data, but Communication is the specific interface of exchange.

    • Coordination

      Coordination would fulfill the request in the background, but the assistant's dialogue is Communication.

    • Curation

      Curation might find the answer, but the act of 'talking' to the user is Communication.

  27. 27 The ITIL 5 perspective 'Ethical Principles' includes 'Fairness.' How is this operationalized in governance?

    It involves checking if the 'math' treats everyone the same.

    By implementing testing to mitigate algorithmic bias

    Fairness is turned into an operational control by testing models for discriminatory patterns.

    • By ensuring the AI model is free to use for all employees

      This is an access policy; ethical fairness is about the quality and equity of the model's outcomes.

    • By providing a user manual for every automated tool

      Documentation is important, but fairness specifically addresses the bias and equity of the logic.

    • By setting a maximum price for AI-enabled services

      This is a commercial or financial decision, not a core ethical fairness control for model behavior.

  28. 28 What is the primary risk of an 'Ungoverned Model Portfolio' according to ITIL 5?

    Consider the 'hidden' costs of taking risks that no one is monitoring.

    Liability that cannot be priced

    Without governance, the organization is exposed to risks (legal, reputational, financial) that it cannot accurately assess or control.

    • Slow deployment of new features

      Ungoverned portfolios often move 'too fast,' creating risk because they lack necessary gates and reviews.

    • A lack of computing power for training

      Computing power is a technical resource issue; governance is about the oversight and accountability of what is built.

    • Lower employee engagement with AI

      Employees often embrace ungoverned 'Shadow AI'; the risk is the liability, not the lack of use.

  29. 29 Which 6C capability enables 'high-velocity' teams to automatically assign on-call personnel when a critical event is detected?

    This capability functions as the 'orchestrator' of human resources during an incident.

    Coordination

    Coordination automates routing and task assignment, which is essential for high-velocity incident response.

    • Creation

      Creation might draft the alert, but it doesn't handle the logistical assignment of a person.

    • Clarification

      Clarification helps the person understand the alert once they are assigned.

    • Cognition

      Cognition identifies that the alert is critical, but Coordination performs the act of assigning the responder.

  30. 30 In ITIL 5, what does 'AI Governance Maturity' level 5 (Governance Advantage) represent?

    It is when 'doing the right thing' helps you win in the market.

    Governance is a trust signal and a competitive differentiator

    At the highest level, mature governance builds so much trust that it becomes a strategic advantage for the business.

    • All AI systems are fully automated with zero human oversight

      Full automation without oversight is actually a sign of poor governance, not high maturity.

    • The organization has the largest AI budget in its industry

      Budget is a measure of investment, while maturity is a measure of oversight, control, and value alignment.

    • Every employee is required to be certified in ITIL 5 Foundation

      Certifications are a capability builder, but maturity level 5 is about the 'strategic outcome' of the governance itself.