Isaca AAISM Practice Test Questions and Exam Dumps Part12 Q221-240

View Full Isaca AAISM Exam Dumps and Practice Test Dumps

 

Question 221. What is the primary purpose of establishing an AI governance escalation threshold?

  1. To ensure every AI issue is treated as a critical incident
  2. To define when an AI-related issue requires higher-level review or intervention
  3. To eliminate business-unit responsibility
  4. To prevent employees from reporting AI concerns

Correct Answer: 2. To define when an AI-related issue requires higher-level review or intervention

Explanation:

An AI governance escalation threshold establishes objective conditions under which an issue must be referred to a higher authority, specialized team, or governance committee. Examples may include significant privacy exposure, unacceptable model performance, regulatory concerns, material business impact, security incidents, or changes that exceed approved risk limits. Clear thresholds prevent both under-escalation and unnecessary escalation. Without defined criteria, employees may handle similar situations inconsistently or delay important decisions. Thresholds should be aligned with the organization’s risk appetite, approval authority, incident procedures, and business impact criteria. They should also be periodically reviewed because AI use cases, regulations, dependencies, and organizational risk tolerance can change over time.

Question 222. Which metric would provide the most useful evidence that AI governance remediation is progressing?

  1. Number of AI systems owned by the organization
  2. Total number of employees
  3. Number of meetings held by the governance committee
  4. Percentage of high-risk findings remediated within the required timeframe

Correct Answer: 4. Percentage of high-risk findings remediated within the required timeframe

Explanation:

Governance metrics should demonstrate whether important risks and control weaknesses are actually being addressed. The percentage of high-risk findings remediated within an established timeframe provides meaningful evidence because it measures both the importance of the findings and the organization’s responsiveness. Metrics such as the number of meetings held or the total number of AI systems may describe activity or scale but do not necessarily demonstrate governance effectiveness. A useful remediation metric should have a defined population, risk classification, target timeframe, responsible owner, and reporting period. Trends can then be analyzed to determine whether remediation performance is improving, deteriorating, or remaining stable and whether additional management intervention is necessary.

Question 223. Why should AI governance include defined risk acceptance authority?

  1. To establish who is authorized to accept residual AI risk
  2. To ensure all risks are automatically accepted
  3. To transfer all responsibility to the technical team
  4. To eliminate the need for risk assessments

Correct Answer: 1. To establish who is authorized to accept residual AI risk

Explanation:

Residual risk may remain even after appropriate controls have been implemented. AI governance should clearly establish who has the authority to accept such risk and under what conditions. The appropriate authority may depend on the risk level, business impact, regulatory requirements, and organizational policy. Defining acceptance authority prevents employees from informally accepting risks beyond their responsibilities and creates an auditable decision trail. Risk acceptance should normally be supported by documented rationale, identified controls, known limitations, and an understanding of potential consequences. It should not be confused with eliminating the risk or transferring all accountability to technical personnel. Clear authority supports consistent and accountable governance decisions.

Question 224. What should an AI governance committee do when a proposed use case exceeds the organization’s approved risk appetite?

  1. Approve it automatically because it provides business value
  2. Ignore the risk classification
  3. Require appropriate escalation, risk treatment, or formal risk acceptance before approval
  4. Allow the development team to decide independently

Correct Answer: 3. Require appropriate escalation, risk treatment, or formal risk acceptance before approval

Explanation:

A use case that exceeds the organization’s approved risk appetite should not proceed through ordinary approval simply because it offers potential business benefits. Governance should require the risk to be addressed through additional controls, redesign, reduction of scope, escalation to an authorized decision-maker, or formal acceptance by an authority permitted to accept that level of residual risk. The decision should be documented with sufficient evidence to demonstrate why the risk was considered acceptable or how it was reduced. This process preserves the connection between risk appetite and actual decision-making. It also prevents business pressure from informally overriding governance requirements without appropriate accountability and oversight.

Question 225. Which control best supports accountability for decisions made using an AI system?

  1. Removing human review from all high-impact decisions
  2. Maintaining documented decision ownership and relevant audit evidence
  3. Allowing anonymous use of the system
  4. Deleting decision records immediately after use

Correct Answer: 2. Maintaining documented decision ownership and relevant audit evidence

Explanation:

Accountability requires the organization to identify who is responsible for the use of an AI system and maintain sufficient evidence to understand how important decisions were made. Depending on the use case, evidence may include the AI system version, relevant inputs, outputs, human review, approval records, decision rationale, and timestamps. Documentation should be proportionate to the risk and legal requirements of the process. Removing human review or deleting records can make it difficult to investigate errors, complaints, or incidents. Anonymous use can also weaken accountability. Clearly assigned decision ownership combined with reliable evidence enables organizations to investigate outcomes and demonstrate that appropriate governance procedures were followed.

Question 226. What is an important governance consideration when AI systems are reused for a new business purpose?

  1. Whether the original approval remains valid for the new purpose
  2. Whether the system has enough storage capacity
  3. Whether the original development team is still employed
  4. Whether the system has been deployed for exactly one year

Correct Answer: 1. Whether the original approval remains valid for the new purpose

Explanation:

An AI system approved for one business purpose may introduce different risks when reused for another purpose. The new use may involve different data, affected individuals, decision consequences, regulatory requirements, accuracy expectations, or human oversight needs. Governance should therefore determine whether the original risk assessment and approval remain applicable or whether a new assessment is required. Reuse should not automatically be treated as low risk simply because the underlying model already exists. The organization should evaluate material changes in purpose, data, context, users, and outcomes. This helps ensure that controls and accountability remain appropriate for the actual way the AI system is being used.

Question 227. Which factor should trigger governance reassessment of an existing AI system?

  1. A routine employee vacation
  2. A change in office furniture
  3. A material change to the model, data, purpose, or risk profile
  4. A reduction in meeting frequency

Correct Answer: 3. A material change to the model, data, purpose, or risk profile

Explanation:

Governance reassessment should occur when changes could materially alter an AI system’s risk or expected behavior. Examples include significant model modifications, new training data, changes in intended purpose, expansion into a higher-impact decision process, new jurisdictions, major vendor changes, or significant changes in the affected population. Routine administrative events that do not affect the system’s risk profile generally would not justify a full reassessment. Establishing clear reassessment triggers helps organizations maintain governance throughout the AI lifecycle rather than treating approval as permanent. The reassessment should determine whether existing controls, documentation, testing, monitoring, human oversight, and authorization remain appropriate after the material change.

Question 228. What is the main governance risk of allowing an AI system to expand into additional jurisdictions without review?

  1. Increased server storage consumption
  2. Faster model training
  3. Lower employee productivity
  4. New legal, regulatory, privacy, and operational obligations may apply

Correct Answer: 4. New legal, regulatory, privacy, and operational obligations may apply

Explanation:

AI governance requirements can vary across jurisdictions because laws, regulatory expectations, privacy requirements, sector rules, data transfer restrictions, and consumer protections may differ. Expanding an AI system into a new jurisdiction without review could therefore create compliance or operational risks that were not present in the original deployment. Governance should assess the destination jurisdiction, affected data, intended use, applicable obligations, contractual arrangements, and any required safeguards before expansion. This does not mean every jurisdiction must use a completely separate governance framework. Instead, the organization should identify local requirements and integrate them into the enterprise governance process. Geographic expansion should therefore be treated as a potential reassessment trigger.

Question 229. What should an organization consider when an AI model provider changes its model without direct action by the customer?

  1. Whether the change could affect the system’s risk, performance, controls, or approved use
  2. Whether the provider has increased its advertising budget
  3. Whether employees prefer the provider’s new logo
  4. Whether the organization should automatically terminate every AI service

Correct Answer: 1. Whether the change could affect the system’s risk, performance, controls, or approved use

Explanation:

Provider-managed model changes can introduce governance risks because the organization may not control the exact timing or technical details of the update. A change in model behavior could affect accuracy, bias, security, privacy, explainability, output consistency, or compatibility with existing controls. Governance should therefore require appropriate notification, change documentation, testing, monitoring, and reassessment mechanisms where feasible. The organization should understand its contractual rights and available rollback or contingency options as well. Automatic termination may be unnecessary, while ignoring provider changes can leave an approved system operating under materially different conditions. Effective third-party governance ensures that provider changes remain visible and appropriately assessed.

Question 230. Which contractual provision is particularly valuable when an organization depends on a third-party AI provider for a critical service?

  1. A requirement that the provider never change its branding
  2. Appropriate service continuity, incident notification, and material-change obligations
  3. A prohibition on all provider employees taking leave
  4. A requirement that the provider use only one internal employee

Correct Answer: 2. Appropriate service continuity, incident notification, and material-change obligations

Explanation:

Contracts for critical AI services should address the risks created by the organization’s dependency on the provider. Relevant provisions may include service availability expectations, incident notification requirements, security obligations, data handling responsibilities, material-change notifications, audit or assurance rights, subcontractor controls, termination assistance, and continuity arrangements. The exact requirements should reflect the service’s criticality and risk profile. Contractual protections do not eliminate all third-party risk, but they provide clearer responsibilities and enforceable expectations. Governance teams should also verify that contract provisions are supported by operational processes. A well-designed agreement therefore forms one part of a broader third-party risk management program rather than serving as the only control.

Question 231. What is the purpose of establishing an AI control owner for each significant governance control?

  1. To make one person responsible for every organizational risk
  2. To remove the need for control testing
  3. To identify who is accountable for implementing, maintaining, and monitoring the control
  4. To ensure controls can never be changed

Correct Answer: 3. To identify who is accountable for implementing, maintaining, and monitoring the control

Explanation:

Every significant AI governance control should have clear ownership so that responsibility for its operation does not become ambiguous. A control owner typically coordinates implementation, confirms that the control operates as intended, monitors relevant performance, maintains evidence, and supports remediation when deficiencies are identified. Control ownership does not mean that one individual becomes responsible for every organizational risk. Different controls can have different owners, while governance leaders maintain oversight of the overall framework. Clear ownership also supports accountability during audits and reviews. When ownership is undefined, controls may exist on paper but fail operationally because no one is clearly responsible for maintaining them.

Question 232. Why is independence important when performing assurance over high-risk AI systems?

  1. It prevents the assurance function from reviewing evidence
  2. It reduces the need for technical expertise
  3. It guarantees that all findings will be negative
  4. It helps reduce conflicts of interest and supports objective evaluation

Correct Answer: 4. It helps reduce conflicts of interest and supports objective evaluation

Explanation:

Independent assurance helps provide an objective assessment of whether governance controls are appropriately designed and operating effectively. If the same personnel who develop or operate a high-risk AI system are solely responsible for evaluating their own controls, there may be a conflict of interest or an unconscious tendency to overlook weaknesses. Independence does not mean the assurance team must lack technical knowledge; rather, it means the evaluation should be sufficiently separate from operational responsibility to support objectivity. The level of independence should be proportionate to risk. Findings should be supported by evidence and communicated to appropriate stakeholders so that identified weaknesses can be addressed.

Question 233. Which evidence would best demonstrate that a high-risk AI system received the required governance approval before production deployment?

  1. A documented approval record linked to the relevant risk assessment and system version
  2. An employee’s verbal statement that approval was obtained
  3. A marketing presentation describing the AI project
  4. A general company policy with no system-specific evidence

Correct Answer: 1. A documented approval record linked to the relevant risk assessment and system version

Explanation:

Effective governance requires evidence that approval actually occurred and applied to the specific system being deployed. A documented approval record should identify the relevant use case, risk assessment, decision authority, approval date, conditions, and, where appropriate, the model or system version reviewed. This creates traceability between the governance decision and the production implementation. Verbal statements and general policies may provide context but are weaker evidence because they do not demonstrate that the specific system received the required authorization. Maintaining reliable approval evidence also supports audits, incident investigations, regulatory inquiries, and later reassessments when the AI system changes materially.

Question 234. What should governance teams do when an AI system cannot provide reliable evidence of its data provenance?

  1. Assume the data is trustworthy
  2. Identify the provenance gap and assess whether additional controls or remediation are required
  3. Delete all available documentation immediately
  4. Automatically classify the system as low risk

Correct Answer: 2. Identify the provenance gap and assess whether additional controls or remediation are required

Explanation:

Data provenance helps organizations understand where data originated, how it was collected, transformed, combined, and used. When provenance evidence is incomplete, governance teams should identify the gap and determine how it affects data quality, privacy, security, compliance, reproducibility, and model risk. Appropriate responses may include additional documentation, source verification, data-quality testing, restrictions on use, remediation, or escalation depending on the significance of the gap. Assuming the data is trustworthy without evidence can hide material risks, while automatically classifying the system as low risk is inappropriate. Provenance requirements should be proportionate to the AI system’s purpose and the sensitivity and importance of the underlying data.

Question 235. Which governance practice best supports traceability when multiple versions of an AI model are used?

  1. Allowing teams to overwrite old model files
  2. Keeping only the newest version
  3. Maintaining controlled version records linking models to relevant data, testing, approvals, and deployments
  4. Naming every model with the same identifier

Correct Answer: 3. Maintaining controlled version records linking models to relevant data, testing, approvals, and deployments

Explanation:

Model version management is essential for understanding which model was used at a particular point in time. Controlled version records should allow the organization to connect a model version with relevant training or configuration information, validation results, approvals, deployment dates, changes, and monitoring evidence. This traceability supports investigations, audits, rollback decisions, incident analysis, and reproducibility. Overwriting previous versions or retaining only the newest version can make it difficult to determine what produced a historical output. Consistent identifiers and controlled repositories improve accountability. Version management should also include appropriate access controls and integrity protections so that historical records cannot be changed without authorization.

Question 236. What is a key governance consideration when AI systems use open-source models or components?

  1. Assuming open-source components have no governance requirements
  2. Reviewing licensing, security, provenance, maintenance, and dependency risks
  3. Prohibiting all testing because the software is publicly available
  4. Treating open-source components as automatically approved

Correct Answer: 2. Reviewing licensing, security, provenance, maintenance, and dependency risks

Explanation:

Open-source AI components can provide significant value, but they still require appropriate governance. Organizations should evaluate licensing obligations, component provenance, known vulnerabilities, maintenance status, dependencies, model documentation, update practices, and suitability for the intended use. Public availability does not guarantee security, quality, legal suitability, or ongoing support. Governance should determine whether the component meets organizational requirements and whether its risks can be managed through testing, monitoring, approved repositories, dependency controls, or contractual arrangements where applicable. The depth of review should reflect the component’s criticality and the risks associated with the AI system. Proper oversight allows organizations to benefit from open-source resources while maintaining accountability.

Question 237. Which activity best supports identification of AI-related skill gaps across an organization?

  1. Comparing required role competencies with current employee capabilities
  2. Counting the number of AI systems deployed
  3. Measuring only employee attendance at meetings
  4. Assigning identical training to every employee

Correct Answer: 1. Comparing required role competencies with current employee capabilities

Explanation:

A competency gap analysis compares what employees need to know for their assigned AI responsibilities with the skills they currently possess. The process can identify gaps in areas such as AI risk management, privacy, security, data governance, model validation, regulatory awareness, incident response, and responsible use. Results can then inform targeted training, recruitment, mentoring, certification, or reassignment decisions. Simply counting AI systems or meeting attendance does not reveal whether personnel are capable of performing governance responsibilities. Identical training may also be inefficient because different roles require different levels of expertise. A structured competency assessment provides a more reliable basis for workforce planning and governance capability development.

Question 238. What should happen when an AI governance control repeatedly fails despite previous remediation?

  1. The control should automatically be considered effective
  2. The issue should be ignored if no incident has occurred
  3. The control should be reassessed to identify underlying causes and determine whether redesign is necessary
  4. All AI systems should automatically be shut down

Correct Answer: 3. The control should be reassessed to identify underlying causes and determine whether redesign is necessary

Explanation:

Repeated control failures indicate that previous remediation may not have addressed the underlying cause. Governance teams should perform root-cause analysis to determine whether the problem involves unclear ownership, insufficient resources, ineffective procedures, inadequate automation, poor training, unrealistic control requirements, or changes in the operating environment. Depending on the findings, the control may need to be redesigned, strengthened, automated, or replaced. Simply repeating the same remediation may not resolve the issue, while shutting down every AI system may be disproportionate. Persistent control deficiencies should be tracked and escalated according to risk. Management should also verify that corrective actions actually improve control performance.

Question 239. Which approach best supports continuous improvement of an AI governance framework?

  1. Reviewing governance only after a major failure
  2. Combining performance metrics, incidents, assurance findings, emerging risks, and stakeholder feedback
  3. Changing policies every month regardless of need
  4. Avoiding changes to preserve consistency

Correct Answer: 2. Combining performance metrics, incidents, assurance findings, emerging risks, and stakeholder feedback

Explanation:

Continuous improvement requires governance decisions to be informed by multiple sources of evidence. Performance metrics can reveal trends, incidents can expose control weaknesses, assurance findings can identify deficiencies, emerging-risk analysis can highlight new threats, and stakeholder feedback can reveal practical difficulties or unintended consequences. Reviewing these inputs together provides a more complete view of governance effectiveness. Improvement should be risk-based rather than driven by arbitrary policy changes. Excessive changes without evidence can create confusion, while refusing to update governance can leave the organization poorly prepared for changing AI capabilities and obligations. A mature program uses documented findings to prioritize improvements, assign ownership, establish target dates, and verify results.

Question 240. What is the strongest indication that an AI governance program is operating effectively?

  1. The organization has the largest possible number of AI policies
  2. Every AI system uses identical controls regardless of risk
  3. Governance committees meet frequently
  4. AI risks are identified, owned, managed, monitored, and reported in a way that supports organizational objectives

Correct Answer: 4. AI risks are identified, owned, managed, monitored, and reported in a way that supports organizational objectives

Explanation:

Effective AI governance is demonstrated through outcomes and consistent management practices rather than the volume of policies or number of governance meetings. A mature program identifies relevant AI risks, assigns clear ownership, applies controls proportionate to risk, monitors performance, maintains evidence, addresses deficiencies, and provides useful information to decision-makers. Governance should also remain aligned with business objectives, regulatory obligations, and the organization’s risk appetite. Identical controls for every system may be inefficient or inadequate because AI use cases have different risk profiles. The strongest evidence of effectiveness is therefore an operating governance framework that enables accountable decisions, timely risk treatment, reliable oversight, and continuous improvement across the AI lifecycle.