View Full Isaca AAISM Exam Dumps and Practice Test Dumps
Question 281. Which practice best supports accountability when an AI system produces decisions that affect customers?
- Allowing the model to make decisions without human review
- Assigning clear ownership for the AI system and its decisions
- Removing decision records after deployment
- Allowing every employee to modify the model
Correct Answer: 2. Assigning clear ownership for the AI system and its decisions
Explanation:
Clear accountability is a fundamental component of effective AI governance. An organization should identify responsible owners for the AI system, including ownership of its business purpose, risk management, performance, compliance, and ongoing monitoring. Assigning ownership ensures that decisions can be traced to an accountable role when problems or unexpected outcomes occur. Accountability should not depend solely on the technical development team because business and governance responsibilities may also be involved. Defined ownership also supports escalation when performance, compliance, privacy, or security concerns arise. A documented responsibility model helps ensure that AI systems remain governed throughout their lifecycle rather than becoming unmanaged after deployment.
Question 282. What should an organization do when an AI system begins operating outside its formally approved business purpose?
- Ignore the change if the model still performs well
- Allow users to decide whether the new purpose is acceptable
- Remove all monitoring requirements
- Reassess the system and obtain appropriate governance approval
Correct Answer: 4. Reassess the system and obtain appropriate governance approval
Explanation:
Using an AI system for a materially different purpose can change its risks, affected stakeholders, data requirements, legal obligations, and required controls. Therefore, an organization should not assume that an existing approval automatically covers a new use. The changed purpose should trigger an appropriate reassessment, including consideration of privacy, security, fairness, performance, regulatory, and operational risks. Depending on the organization’s governance framework, additional approval may be required before the new use becomes operational. This approach maintains traceability between the approved business purpose and actual usage. It also helps prevent informal expansion of AI capabilities that could create unmanaged risks or violate organizational policies.
Question 283. Which control is most appropriate for ensuring that changes to an AI model are properly authorized before production deployment?
- Formal model change management
- Unrestricted developer access
- Informal verbal approval
- Deleting previous model versions
Correct Answer: 1. Formal model change management
Explanation:
Formal model change management provides a controlled process for modifying, testing, approving, and deploying AI models. Changes may involve model architecture, parameters, training data, prompts, dependencies, or configuration and can affect model behavior and risk. A formal process should identify the proposed change, document its rationale, assess its impact, perform appropriate testing and validation, and obtain authorization before production deployment. Maintaining records of approved versions also supports traceability and auditability. Unrestricted changes or informal approvals can make it difficult to determine which version was operating when an incident occurred. Effective change management therefore connects technical changes with governance, risk assessment, testing, and accountability.
Question 284. Why should an organization maintain evidence of AI model approvals?
- To increase model processing speed
- To eliminate the need for testing
- To demonstrate that required governance decisions occurred
- To prevent all future model changes
Correct Answer: 3. To demonstrate that required governance decisions occurred
Explanation:
Approval evidence provides an auditable record showing that the organization followed its established governance process before deploying or materially changing an AI system. Such evidence can include documented approvals, risk assessments, validation results, business-owner authorization, security reviews, and applicable compliance sign-offs. Maintaining these records helps demonstrate that decision rights were exercised by appropriate individuals and that required conditions were considered. Approval evidence is also useful during internal audits, regulatory reviews, incident investigations, and post-deployment assessments. It does not mean that a system is permanently approved without further oversight. Instead, it establishes traceability between governance requirements, decisions, responsible parties, and the specific AI system version or use case.
Question 285. What is the primary governance concern when an AI system relies on a critical external model provider?
- The provider may introduce changes or disruptions outside the organization’s direct control
- The organization will automatically own the provider’s infrastructure
- External providers eliminate the need for risk management
- The AI system cannot require monitoring
Correct Answer: 1. The provider may introduce changes or disruptions outside the organization’s direct control
Explanation:
Dependence on an external AI provider can create risks related to service availability, model changes, security, privacy, data handling, contractual obligations, and business continuity. A provider may modify a model, change service behavior, introduce new limitations, experience an outage, or alter supporting infrastructure. Because the organization may not directly control these activities, governance should address the dependency explicitly. Appropriate measures can include contractual requirements, provider due diligence, change notifications, service-level expectations, contingency planning, alternative providers, and monitoring of provider-related risks. Understanding external dependency is especially important when the AI capability supports critical business processes or handles sensitive information.
Question 286. Which activity provides the strongest evidence that AI controls are operating effectively?
- Publishing an AI policy
- Conducting documented control testing
- Assigning a system name
- Increasing the model’s processing capacity
Correct Answer: 2. Conducting documented control testing
Explanation:
A policy establishes expectations, but it does not by itself demonstrate that controls operate effectively. Documented control testing provides evidence that specific governance, security, privacy, risk, or operational controls are actually functioning as intended. Testing should be based on defined criteria and may include inspection of records, observation, technical testing, sampling, interviews, or automated monitoring. Results should identify exceptions, weaknesses, and required remediation. Evidence from control testing can then support assurance activities and management reporting. Repeating tests at appropriate intervals also helps determine whether controls continue to operate effectively as AI systems, risks, regulations, and business processes change over time.
Question 287. What should management consider before accepting residual risk associated with an AI system?
- Whether the model has the largest possible parameter count
- Whether the system has the newest interface
- Whether the risk remains within approved risk appetite and acceptance authority
- Whether users prefer the model’s responses
Correct Answer: 3. Whether the risk remains within approved risk appetite and acceptance authority
Explanation:
Residual risk is the risk remaining after controls and risk treatments have been implemented. Management should determine whether that remaining exposure is consistent with the organization’s approved risk appetite and whether the person or body accepting the risk has the appropriate authority. Risk acceptance should be informed by the potential impact, likelihood, affected stakeholders, regulatory requirements, control effectiveness, and available treatment options. Acceptance should be documented rather than handled informally. If residual risk exceeds established thresholds, escalation or additional treatment may be necessary. This ensures that AI-related risks are consciously accepted by authorized decision-makers instead of becoming unmanaged simply because controls have already been implemented.
Question 288. Which approach best protects sensitive information used with an externally hosted generative AI service?
- Sending all available internal information to the service
- Disabling access logging
- Allowing unrestricted employee use
- Applying approved data-handling and access controls before information is submitted
Correct Answer: 4. Applying approved data-handling and access controls before information is submitted
Explanation:
Externally hosted generative AI services can create significant information-security and privacy concerns when users submit confidential, personal, proprietary, or regulated information. Organizations should establish approved-use requirements that define what information may be submitted and under which circumstances. Technical controls such as data loss prevention, access restrictions, monitoring, classification enforcement, and approved enterprise AI services can help reduce unauthorized disclosure. Employees should also understand the organization’s rules for handling sensitive information with AI tools. These measures help align AI usage with existing information-security policies and regulatory obligations. Simply trusting users to recognize sensitive information is less reliable than combining policy, training, technical controls, and monitoring.
Question 289. What is the main purpose of maintaining an inventory of AI systems?
- To identify and track AI systems that require governance and oversight
- To increase the number of AI applications deployed
- To eliminate the need for risk assessments
- To prevent business units from using approved AI systems
Correct Answer: 1. To identify and track AI systems that require governance and oversight
Explanation:
An AI inventory provides visibility into the organization’s AI environment and supports consistent governance. It can record information such as system ownership, business purpose, provider, model version, data sources, risk classification, deployment location, affected stakeholders, and lifecycle status. Without an inventory, organizations may have difficulty identifying unauthorized, obsolete, duplicated, or high-risk AI systems. Inventory information can also support risk assessments, compliance reviews, incident response, vendor management, and retirement activities. Maintaining the inventory as systems change is important because AI portfolios are dynamic. A reliable inventory therefore serves as a foundation for governance by helping management understand what AI systems exist and where oversight is required.
Question 290. Which condition should generally trigger reassessment of an AI system’s governance requirements?
- A minor formatting change in an internal report
- A material change in the system’s purpose, data, or operating environment
- A routine user login
- A scheduled backup completing successfully
Correct Answer: 2. A material change in the system’s purpose, data, or operating environment
Explanation:
Governance requirements should be reassessed when significant changes could alter an AI system’s risk profile. Examples include a new business purpose, substantially different training or operational data, deployment in a new jurisdiction, integration into a critical process, major model changes, or changes in affected populations. These events can introduce new privacy, security, fairness, compliance, operational, or performance risks that were not considered during the original approval. Reassessment does not necessarily mean restarting the entire governance process. Instead, the organization should evaluate the scope and significance of the change and apply the appropriate review. This risk-based approach keeps governance proportional while preventing material changes from bypassing oversight.
Question 291. Why is data provenance important in AI governance?
- It guarantees that every model produces identical outputs
- It eliminates all privacy obligations
- It helps establish where data originated, how it was handled, and whether its use is appropriate
- It removes the need for data-quality controls
Correct Answer: 3. It helps establish where data originated, how it was handled, and whether its use is appropriate
Explanation:
Data provenance provides information about the origin, movement, transformation, and use of data throughout an AI lifecycle. Strong provenance helps organizations determine whether data came from an authorized source, whether it was modified appropriately, and whether its intended use is consistent with applicable requirements. It can also support data-quality investigations, reproducibility, privacy reviews, intellectual-property assessments, and audit activities. If an AI system produces unexpected results, provenance records can help investigators identify whether a particular source or transformation contributed to the issue. Provenance therefore strengthens accountability and traceability by connecting AI outputs and model development activities to the underlying data used in the process.
Question 292. What is an important governance requirement for AI systems handling personal information?
- Collecting the maximum possible amount of personal information
- Applying appropriate privacy controls throughout the AI lifecycle
- Removing all access restrictions
- Retaining personal information indefinitely
Correct Answer: 2. Applying appropriate privacy controls throughout the AI lifecycle
Explanation:
AI systems that process personal information should incorporate privacy controls throughout their lifecycle rather than addressing privacy only after deployment. Relevant practices can include data minimization, purpose limitation, access control, retention management, appropriate transparency, secure processing, and mechanisms for addressing applicable individual rights. Organizations should also assess whether personal information is appropriate for model training, testing, prompting, or inference. Privacy requirements may vary depending on the jurisdiction, type of information, and intended processing activity. Governance should therefore connect privacy obligations with AI risk assessment and operational controls. Maintaining privacy oversight throughout design, development, deployment, monitoring, and retirement helps reduce unnecessary exposure and supports responsible handling of personal information.
Question 293. What should an organization do when repeated AI control failures indicate the same underlying weakness?
- Ignore the failures because individual incidents were already resolved
- Increase the number of AI systems
- Remove the control from the governance framework
- Perform root-cause analysis and implement corrective action
Correct Answer: 4. Perform root-cause analysis and implement corrective action
Explanation:
Repeated control failures can indicate that the organization is treating symptoms rather than addressing an underlying governance or process weakness. Root-cause analysis helps determine why the control continues to fail and whether the problem relates to inadequate design, unclear ownership, insufficient training, technology limitations, ineffective procedures, or unrealistic control requirements. Corrective action should address the identified cause and include appropriate ownership and completion criteria. Follow-up testing can then determine whether the remediation was effective. This approach supports continuous improvement and prevents organizations from repeatedly closing individual findings without reducing the systemic risk that caused those findings in the first place.
Question 294. Which governance practice best supports responsible reuse of an existing AI system for a new business process?
- Conducting an appropriate impact and risk reassessment before reuse
- Assuming the previous approval applies automatically
- Removing the original system owner
- Disabling monitoring after reuse
Correct Answer: 1. Conducting an appropriate impact and risk reassessment before reuse
Explanation:
An AI system approved for one business purpose may not be suitable for another purpose because the new process can involve different data, users, decisions, affected individuals, legal requirements, and operational consequences. Before reuse, the organization should assess whether the existing controls remain appropriate and whether additional safeguards are required. The assessment should consider changes to the system’s purpose, inputs, outputs, risk classification, human oversight, security, privacy, and compliance obligations. Appropriate governance approval should be obtained when required. Responsible reuse allows organizations to benefit from existing AI capabilities while ensuring that previous assumptions are not incorrectly treated as sufficient for a materially different operating context.
Question 295. Which activity most directly supports traceability between an AI model and the data used to develop it?
- Increasing user permissions
- Maintaining documented model and dataset version relationships
- Removing dataset metadata
- Allowing unrestricted model modifications
Correct Answer: 2. Maintaining documented model and dataset version relationships
Explanation:
Traceability requires the organization to understand which model version was developed or validated using which datasets, configurations, and supporting artifacts. Documenting relationships among model versions, dataset versions, preprocessing steps, parameters, and validation results supports reproducibility and investigation. If a problem emerges in production, teams can determine what data and model artifacts contributed to the affected version. This information also helps distinguish legitimate changes from unauthorized modifications. Version relationships should be maintained throughout the AI lifecycle and protected from unauthorized alteration. Strong traceability therefore improves governance, auditability, incident investigation, and the ability to reproduce or validate decisions made during AI development.
Question 296. What is the primary purpose of human oversight for a high-impact AI decision process?
- To eliminate the need for technical testing
- To make every AI decision manually
- To provide appropriate review, intervention, and accountability when automated decisions may have significant consequences
- To prevent the use of AI in all business processes
Correct Answer: 3. To provide appropriate review, intervention, and accountability when automated decisions may have significant consequences
Explanation:
Human oversight is intended to provide meaningful review and intervention where AI decisions can materially affect individuals, organizations, or critical operations. The appropriate level of oversight depends on the risk and context of the AI system. Effective oversight should include defined review criteria, authority to challenge or override outputs, escalation procedures, and accountability for decisions. Simply placing a person somewhere in the workflow does not necessarily provide meaningful oversight if that person lacks sufficient information, authority, time, or competence to evaluate the AI output. Governance should therefore ensure that human reviewers are appropriately trained and that their responsibilities are clearly documented and auditable.
Question 297. What should an organization establish for an AI system approaching retirement?
- A controlled decommissioning process
- Permanent unrestricted access
- Automatic retention of all data forever
- Removal of all documentation
Correct Answer: 1. A controlled decommissioning process
Explanation:
AI retirement should be managed as a formal lifecycle stage rather than simply turning off a system. A controlled decommissioning process can address data retention or deletion requirements, access removal, dependent applications, model and artifact preservation, contractual obligations, audit records, user communications, and replacement arrangements. Organizations should also verify that the retired system is no longer being used through unauthorized channels. Appropriate documentation provides evidence of when and why the system was retired and what happened to associated data and assets. Controlled retirement reduces the risk that obsolete models, credentials, integrations, or sensitive information remain active after the business has stopped relying on the AI capability.
Question 298. Why should AI governance policies be reviewed periodically?
- To make policies longer regardless of relevance
- To remove accountability requirements
- To ensure policies remain aligned with changing risks, business activities, and applicable obligations
- To guarantee that AI systems never change
Correct Answer: 3. To ensure policies remain aligned with changing risks, business activities, and applicable obligations
Explanation:
AI governance policies operate within an environment that can change over time. New AI capabilities, business uses, security threats, regulatory obligations, vendor arrangements, and organizational structures may make existing requirements incomplete or outdated. Periodic policy review helps determine whether governance principles, responsibilities, approval requirements, risk criteria, and control expectations remain appropriate. Reviews should consider lessons from incidents, audits, control testing, emerging risks, and changes in the organization’s AI portfolio. Policy updates should be formally approved, communicated, and incorporated into relevant procedures and training. This helps ensure that governance remains practical and aligned with the organization’s current risk environment rather than relying on outdated assumptions.
Question 299. Which metric would provide useful insight into the effectiveness of AI governance remediation?
- Number of employees with email accounts
- Average screen brightness of AI users
- Number of AI model parameters
- Percentage of high-risk AI findings remediated within the required timeframe
Correct Answer: 4. Percentage of high-risk AI findings remediated within the required timeframe
Explanation:
Governance metrics should provide meaningful information about whether identified risks and control weaknesses are being addressed. The percentage of high-risk findings remediated within the required timeframe measures both remediation progress and management responsiveness to significant issues. It can help governance bodies identify overdue actions, recurring weaknesses, or areas where resources may be insufficient. Effective metrics should be tied to defined thresholds and reviewed by appropriate stakeholders. Other useful measures may include unresolved high-risk findings, repeat control failures, overdue risk assessments, or remediation aging. Selecting metrics that reflect actual governance outcomes is more useful than relying on activity counts that do not demonstrate whether AI-related risks are being reduced.
Question 300. What is a key characteristic of an effective AI governance program?
- Governance is performed only before initial deployment
- Governance is integrated throughout the AI lifecycle with clear accountability, risk management, monitoring, and continuous improvement
- Governance is limited to the technical development team
- Governance requirements are optional for high-risk systems
Correct Answer: 2. Governance is integrated throughout the AI lifecycle with clear accountability, risk management, monitoring, and continuous improvement
Explanation:
Effective AI governance is a continuous organizational process rather than a one-time approval activity. It should establish clear accountability, define acceptable uses, identify and assess risks, implement appropriate controls, validate systems, monitor performance and compliance, manage changes, address incidents, and support controlled retirement. Governance should involve relevant business, technical, security, privacy, legal, compliance, and assurance stakeholders according to the organization’s structure and risk profile. Continuous improvement is also important because AI capabilities and associated risks evolve over time. By integrating governance throughout the lifecycle, an organization can maintain oversight from initial planning through development, deployment, operation, change management, monitoring, and eventual retirement.