🇬🇧 Chartered IT Professional (CITP) · flashcards

Chartered IT Professional (CITP) Professionalism, Ethics and Conduct Flashcards

50 question-and-answer cards covering Professionalism, Ethics and Conduct as it is examined in Chartered IT Professional (CITP). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

50Cards in deck
24Free preview
10Syllabus topics
~262Chars per answer
FreePrice

24 sample cards from the Professionalism, Ethics and Conduct deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What are the core ethical principles commonly applied to data and AI systems?

    Typically: fairness (non-discrimination), accountability, transparency/explainability, privacy, safety/security, human oversight, and beneficence (do good)/non-maleficence (avoid harm) — often summarised as the FAT/FATE principles (Fairness, Accountability, Transparency, Ethics).

  2. What is algorithmic bias and how does it arise in AI systems?

    Systematic, unfair discrimination in an algorithm's outputs against certain groups. It arises mainly from biased or unrepresentative training data, biased feature selection, or biased design choices, causing the model to reproduce or amplify existing societal inequalities.

  3. What does 'explainability' (interpretability) mean for AI, and why does it matter ethically?

    The ability to understand and communicate how an AI system reached a decision. It matters for accountability, contesting decisions, detecting bias, and meeting legal rights (e.g. GDPR's safeguards around automated decision-making).

  4. Under UK GDPR, what right do individuals have regarding solely automated decisions?

    Under Article 22, individuals have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects, except in limited cases, and with safeguards including the right to human intervention and to contest the decision.

  5. What are the data protection principles a professional must apply when handling personal data?

    Under UK GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality (security); and accountability.

  6. What is a Data Protection Impact Assessment (DPIA) and when is it required?

    A structured process to identify and minimise data-protection risks of a project. It is mandatory under UK GDPR for processing likely to result in a high risk to individuals — e.g. large-scale profiling, systematic monitoring, or processing special-category data.

  7. Define 'data minimisation' and 'purpose limitation'.

    Data minimisation: collect only personal data that is adequate, relevant and limited to what is necessary for the purpose. Purpose limitation: collect data for specified, explicit and legitimate purposes and do not further process it in a way incompatible with those purposes.

  8. What ethical concerns are raised by generative AI such as large language models?

    Misinformation/hallucination, intellectual property and training-data consent, bias and toxicity, deepfakes and impersonation, privacy leakage of training data, labour displacement, and lack of transparency/accountability for outputs.

  9. What is 'digital responsibility' for an IT professional?

    The obligation to consider the wider social, ethical and environmental consequences of digital technology — including accessibility, inclusion, the digital divide, sustainability and the wellbeing of users — not just technical and commercial outcomes.

  10. What is the 'digital divide' and why is it an ethical concern?

    The gap between those with effective access to digital technology/skills and those without. It is an ethical concern because reliance on digital services can exclude or disadvantage groups, conflicting with the public-interest duty to avoid discrimination and promote inclusion.

  11. What is 'sustainable IT' (Green IT), and give two example practices.

    Designing, using and disposing of IT to minimise environmental impact. Examples: energy-efficient data centres and code (reducing power and carbon footprint); and responsible e-waste management, hardware reuse/recycling and extending equipment lifecycles.

  12. Why is energy consumption of AI and data centres an ethical/sustainability issue?

    Training and running large models and data centres consume significant electricity and water and generate carbon emissions, contributing to climate impact — so professionals must weigh computational/environmental cost against benefit, supporting the public-interest duty regarding the environment.

  13. What is digital accessibility and what standard underpins it?

    Designing digital products usable by people with disabilities. It is underpinned by the Web Content Accessibility Guidelines (WCAG), with conformance levels A, AA and AAA; AA is the common legal/procurement target (and required by UK public sector accessibility regulations).

  14. Define a 'duty of care' in the context of IT professional negligence.

    A legal obligation to exercise reasonable care and skill to avoid acts or omissions that could foreseeably harm others. An IT professional owes a duty of care to clients and, in some cases, third parties who may foreseeably be harmed by their work.

  15. What three elements must be established to prove the tort of negligence?

    1) A duty of care was owed; 2) that duty was breached (the standard of reasonable care was not met); and 3) the breach caused reasonably foreseeable loss or damage (causation and remoteness).

  16. What standard of care applies to a professional, per Bolam, in a negligence claim?

    The Bolam test: a professional is judged against the standard of a reasonably competent member of that profession. They are not negligent if acting in accordance with a practice accepted as proper by a responsible body of professional opinion in that field.

  17. How does negligence differ from breach of contract?

    Breach of contract is failure to perform an obligation expressly or impliedly agreed between the parties (liability defined by the contract). Negligence is a tort — breach of a general legal duty of reasonable care owed independently of any contract, which can extend to third parties.

  18. What is 'reasonable skill and care' as an implied contractual term for IT services?

    Under the Supply of Goods and Services Act 1982 / Consumer Rights Act 2015, a service supplier must perform with reasonable care and skill. This is an implied term, so failing to meet competent professional standards can be both a contractual breach and negligence.

  19. Distinguish express terms, implied terms, and statutory obligations in an IT contract.

    Express terms are explicitly agreed (written or spoken). Implied terms are not stated but read in by law or custom (e.g. reasonable care and skill). Statutory obligations are imposed by legislation regardless of the contract (e.g. data protection, consumer rights) and generally cannot be excluded.

  20. Name key UK statutes an IT professional must comply with and their focus.

    Data Protection Act 2018 / UK GDPR (personal data); Computer Misuse Act 1990 (unauthorised access/modification); Copyright, Designs and Patents Act 1988 (IP/software); Equality Act 2010 (non-discrimination); Health and Safety at Work Act 1974; Bribery Act 2010; Consumer Rights Act 2015.

  21. What does a 'limitation of liability' clause do in an IT contract, and what are its limits?

    It caps or excludes a party's liability for losses. Under the Unfair Contract Terms Act 1977 / Consumer Rights Act 2015, such clauses must be reasonable/fair, and liability for death or personal injury caused by negligence cannot be excluded.

  22. Outline the typical stages of the BCS disciplinary process for a member.

    A complaint/allegation is received; an initial assessment/investigation determines whether there is a case to answer; the case goes before a disciplinary panel/committee for a hearing; a decision on whether the Code was breached is made; and if upheld, a sanction is imposed. Members usually have a right of appeal.

  23. What sanctions can a professional body such as BCS impose for misconduct?

    Sanctions range from no action or advice/reprimand, through formal warning or censure, to suspension of membership, withdrawal of professional/chartered status, and ultimately expulsion (exclusion) from the institution.

  24. On what standard of proof and principles are professional disciplinary decisions typically made?

    They are generally decided on the civil 'balance of probabilities' standard, applying principles of natural justice/fairness — the member is informed of the allegations, given a chance to respond at a hearing, and has a right of appeal; sanctions should be proportionate to the misconduct.

What this deck covers

The Professionalism, Ethics and Conduct deck follows the Chartered IT Professional (CITP) Professionalism, Ethics and Conduct syllabus — 3 chapters and 10 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 16.7 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 262 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Professionalism, Ethics and Conduct flashcards FAQ

How many Professionalism, Ethics and Conduct flashcards are in this Chartered IT Professional (CITP) deck?

50 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Chartered IT Professional (CITP) flashcards free?

Yes. The preview here is free to read with no signup, and the full 50-card deck is free inside the Examius app.

What do the Professionalism, Ethics and Conduct cards cover?

They follow the Chartered IT Professional (CITP) Professionalism, Ethics and Conduct syllabus — 3 chapters and 10 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.