Isaca AAISM Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Isaca AAISM Exam Dumps and Practice Test Dumps

 

Question 361. Which activity is MOST important when establishing accountability for an AI system used in a critical business process?

  1. Assigning responsibility to the IT help desk
    2. Defining a documented owner with decision-making authority
    3. Allowing the AI vendor to retain all accountability
    4. Reviewing the system only after an incident occurs

Correct Answer: 2. Defining a documented owner with decision-making authority

Explanation:

A clearly documented owner is essential for accountability because AI systems can affect business decisions, customers, employees, and regulatory obligations. The owner should have sufficient authority to approve use, accept or escalate risks, ensure controls are implemented, and coordinate remediation when problems occur. Assigning responsibility without decision-making authority can create gaps because individuals may be expected to manage risks they cannot actually control. Vendor responsibility can supplement, but should not replace, organizational accountability. Periodic reviews and incident management are also important, but they do not establish ownership by themselves. Effective AI governance therefore connects each important AI system to an identifiable business or functional owner with defined responsibilities and escalation paths.

Question 362. What is the PRIMARY purpose of documenting the approved purpose of an AI system?

  1. To establish boundaries for acceptable use and governance oversight
    2. To eliminate the need for monitoring
    3. To guarantee that model outputs are always accurate
    4. To prevent all future modifications to the model

Correct Answer: 1. To establish boundaries for acceptable use and governance oversight

Explanation:

Documenting an AI system’s approved purpose establishes the boundaries within which the system has been assessed and authorized. This is important because a model that is acceptable for one business activity may create substantially different risks when reused for another purpose. The approved purpose provides a reference point for determining whether proposed changes require reassessment, additional controls, or new approval. It also helps auditors and governance personnel determine whether actual use matches authorized use. Documentation does not guarantee accuracy, prevent modifications, or eliminate monitoring requirements. Instead, it creates a clear governance baseline against which changes, exceptions, and operational behavior can be evaluated throughout the AI lifecycle.

Question 363. An organization discovers that an AI system is being used for a purpose outside its approved scope. What should management do FIRST?

  1. Delete the system immediately
    2. Ignore the deviation if performance remains acceptable
    3. Assess the unauthorized use and determine whether governance reassessment is required
    4. Transfer ownership to the system vendor

Correct Answer: 3. Assess the unauthorized use and determine whether governance reassessment is required

Explanation:

Use outside an approved purpose can introduce new risks because the original risk assessment, controls, testing, privacy analysis, and approval may not cover the new activity. The appropriate first response is to assess the deviation and determine its materiality. Depending on the circumstances, the organization may need to pause the expanded use, perform a new risk assessment, update documentation, introduce additional controls, and obtain appropriate approval. Immediate deletion may be unnecessary, while ignoring the issue creates governance exposure. Transferring ownership to a vendor does not resolve the organization’s accountability. A structured assessment allows management to determine the appropriate corrective action based on the actual risk and impact of the changed use.

Question 364. Which control BEST supports traceability of AI model changes over time?

  1. Periodic employee surveys
    2. Unrestricted administrator access
    3. Manual verbal approvals
    4. Version-controlled model artifacts with documented change records

Correct Answer: 4. Version-controlled model artifacts with documented change records

Explanation:

Version control provides a reliable method for identifying which model artifact was deployed, when it changed, who authorized the change, and what modifications were introduced. This traceability is particularly important when investigating unexpected model behavior, validating production results, or demonstrating compliance with governance requirements. Documented change records can connect model versions with associated datasets, validation evidence, approvals, and deployment activities. Verbal approvals and unrestricted access provide weak accountability and are difficult to audit. Employee surveys are unrelated to technical model traceability. A controlled version-management process therefore provides stronger evidence that AI model changes were authorized, tested, and appropriately documented before or during deployment.

Question 365. Why should AI governance include monitoring for material changes in model performance after deployment?

  1. Because a model can behave differently as data, environments, or usage patterns change
    2. Because monitoring eliminates the need for model validation
    3. Because every performance change automatically means the model is defective
    4. Because models cannot be modified after deployment

Correct Answer: 1. Because a model can behave differently as data, environments, or usage patterns change

Explanation:

AI performance can change after deployment because real-world conditions may differ from the conditions present during development and validation. Changes in input distributions, business processes, user behavior, external data, or system dependencies can cause performance deterioration or unexpected behavior. Continuous monitoring helps organizations identify these changes and determine whether corrective action or reassessment is necessary. Monitoring does not replace formal validation and does not mean that every change indicates a defect. Some variation may be expected, while other changes may exceed established thresholds and require investigation. Governance should therefore define meaningful performance indicators, thresholds, escalation procedures, and responsibilities so that material deterioration can be detected and addressed promptly.

Question 366. Which evidence would BEST demonstrate that a high-risk AI system received appropriate approval before production deployment?

  1. A general statement from the development team
    2. A documented approval record linked to the risk assessment and validation evidence
    3. A screenshot of the system interface
    4. A vendor marketing document

Correct Answer: 2. A documented approval record linked to the risk assessment and validation evidence

Explanation:

For a high-risk AI system, approval should be supported by evidence demonstrating that appropriate governance activities were completed before production deployment. A strong approval record can identify the system, responsible owner, assessed risks, required controls, validation results, approval authority, date, and applicable conditions. Linking the approval to the risk assessment and validation evidence establishes traceability between the identified risks, the controls designed to address them, and the decision to authorize production use. A developer statement, interface screenshot, or vendor marketing material does not provide sufficient governance evidence. Maintaining complete approval records also supports future audits, reassessments, incident investigations, and accountability when the system or its operating environment changes.

Question 367. What is the PRIMARY governance concern when an AI provider automatically changes a production model without prior organizational notification?

  1. Increased employee training costs
    2. Reduced storage capacity
    3. Loss of traceability and inability to confirm continued validation status
    4. Slower user interface performance

Correct Answer: 3. Loss of traceability and inability to confirm continued validation status

Explanation:

Automatic provider changes can create governance risk because the organization may no longer know exactly which model version is operating in production or whether the changed model remains within the scope of its original validation and approval. This can affect performance, security, fairness, privacy, and regulatory compliance. The organization should establish contractual and technical mechanisms to obtain change notifications, version information, testing opportunities, and appropriate rollback or reassessment capabilities. Storage capacity and user-interface performance may be operational concerns, but they are not the primary governance issue. Maintaining traceability is critical because organizations need evidence that the production system continues to meet approved requirements after material changes by an external provider.

Question 368. Which practice BEST reduces the risk of unauthorized access to sensitive AI training data?

  1. Applying least-privilege access with periodic access reviews
    2. Giving all developers administrator privileges
    3. Storing training data in shared public repositories
    4. Removing access logs to reduce storage requirements

Correct Answer: 1. Applying least-privilege access with periodic access reviews

Explanation:

Least-privilege access limits users and systems to the permissions necessary for their assigned responsibilities. For sensitive AI training data, this reduces the likelihood that unauthorized individuals can view, modify, copy, or extract information. Periodic access reviews help ensure that permissions remain appropriate as employees change roles, projects end, or responsibilities evolve. Administrative access for all developers creates unnecessary exposure, while public repositories may cause direct disclosure of sensitive information. Removing access logs also weakens accountability and makes investigations more difficult. Effective governance combines access restrictions with authentication, authorization, monitoring, logging, and periodic review so that access to training data remains controlled throughout the AI development and operational lifecycle.

Question 369. An AI governance committee notices that several high-risk remediation items are repeatedly overdue. What should it do FIRST?

  1. Close the overdue items to improve reporting statistics
    2. Increase the number of committee meetings without analyzing the cause
    3. Remove the remediation deadlines
    4. Analyze the recurring delays and identify their root causes**

Correct Answer: 4. Analyze the recurring delays and identify their root causes

Explanation:

Repeatedly overdue remediation indicates that the organization may have a systemic weakness rather than isolated missed deadlines. The governance committee should first analyze why remediation is not being completed. Possible causes include unclear ownership, insufficient resources, unrealistic deadlines, ineffective escalation, inadequate prioritization, or dependencies on other teams. Closing items without remediation would weaken governance reporting, while removing deadlines would reduce accountability. Additional meetings may help later but do not address the underlying problem by themselves. Root-cause analysis allows management to determine whether changes are needed to ownership, resources, risk prioritization, escalation mechanisms, or control processes. Governance metrics should therefore drive corrective action rather than simply improving the appearance of compliance.

Question 370. Which activity BEST supports responsible use of AI-generated information in a high-impact decision process?

  1. Allowing the AI output to determine the decision automatically
    2. Requiring appropriate human review and verification before the decision
    3. Disabling all logging of AI outputs
    4. Allowing users to bypass established approval procedures

Correct Answer: 2. Requiring appropriate human review and verification before the decision

Explanation:

High-impact decisions can have significant consequences for individuals or the organization, so AI-generated information should not automatically be treated as authoritative. Appropriate human review allows qualified personnel to evaluate whether the output is relevant, accurate, complete, and consistent with applicable policies and decision criteria. The level of review should be proportionate to the potential impact and risk of the AI application. Automatic acceptance of AI outputs can amplify errors, bias, or unsupported conclusions. Disabling logs removes important evidence, while bypassing approval procedures weakens governance. Human oversight should be supported by defined responsibilities, escalation procedures, documented decision criteria, and sufficient information for reviewers to challenge or override AI-generated recommendations when necessary.

Question 371. What is the PRIMARY purpose of maintaining an enterprise-wide AI system inventory?

  1. To identify, classify, and govern AI systems throughout the organization
    2. To replace all individual system documentation
    3. To guarantee that every AI system uses the same model
    4. To eliminate the need for risk assessments

Correct Answer: 1. To identify, classify, and govern AI systems throughout the organization

Explanation:

An enterprise-wide AI inventory provides visibility into the organization’s AI landscape. It can identify systems in development, testing, production, retirement, or external service environments and associate them with owners, purposes, risk classifications, providers, data types, and governance requirements. This visibility supports risk prioritization and helps management identify systems that may otherwise operate without appropriate oversight. An inventory does not replace detailed system documentation or eliminate the need for risk assessments. It also does not require every system to use the same technology. Instead, it provides a centralized governance foundation that enables organizations to determine which systems require enhanced controls, monitoring, validation, approval, or periodic reassessment based on their characteristics and risks.

Question 372. What should an organization do when an AI system’s risk classification changes from moderate to high?

  1. Continue operating without modification
    2. Remove the system from the inventory
    3. Apply the governance requirements associated with the higher risk classification
    4. Transfer all responsibility to the end users

Correct Answer: 3. Apply the governance requirements associated with the higher risk classification

Explanation:

A change from moderate to high risk indicates that the system’s potential impact or exposure has materially changed. The organization should reassess the system against the requirements applicable to high-risk AI and implement any additional controls, approvals, validation, human oversight, monitoring, documentation, or escalation procedures that are required. Continuing under the previous control level could leave significant risks insufficiently addressed. Removing the system from the inventory would reduce visibility, while transferring responsibility to users would not satisfy organizational governance obligations. Risk classification should therefore drive proportional governance. When the classification changes, management should document the reason for the change, reassess relevant risks, confirm control effectiveness, and obtain any required approval before continuing or expanding use.

Question 373. Which metric would provide the MOST useful indication that AI governance remediation is becoming less effective?

  1. Number of employees attending unrelated training sessions
    2. Number of AI systems purchased during the year
    3. Number of AI models stored in development repositories
    4. Increasing age and recurrence of unresolved high-risk findings

Correct Answer: 4. Increasing age and recurrence of unresolved high-risk findings

Explanation:

The age and recurrence of unresolved high-risk findings provide direct insight into whether governance weaknesses are being addressed effectively. If high-risk findings remain open for extended periods or repeatedly reappear after remediation, the organization may have problems with ownership, root-cause analysis, resource allocation, control design, or management escalation. A useful governance metric should help decision-makers identify deteriorating control effectiveness rather than merely measure activity. Employee training attendance, procurement volume, and the number of development models do not directly demonstrate whether governance deficiencies are being resolved. Combining remediation aging with recurrence trends can provide stronger insight into whether corrective actions are sustainable and whether management needs to intervene.

Question 374. Which control is MOST appropriate for protecting the integrity of AI governance records?

  1. Allowing all users to edit records
    2. Using controlled access, audit logging, and change tracking
    3. Deleting historical approval records periodically
    4. Storing governance records without ownership information

Correct Answer: 2. Using controlled access, audit logging, and change tracking

Explanation:

Governance records can include risk assessments, approvals, validation results, exceptions, remediation evidence, and other information needed to demonstrate accountability. Protecting their integrity requires controls that restrict who can modify records and provide evidence of changes. Controlled access limits unauthorized modifications, while audit logging and change tracking help identify who made a change, when it occurred, and what was changed. Deleting historical approval records weakens traceability and may remove evidence required for audits or investigations. Records without ownership information also create accountability gaps. Effective governance therefore treats critical records as controlled evidence, with appropriate retention, access, versioning, monitoring, and protection against unauthorized alteration or deletion.

Question 375. Why is third-party AI concentration risk important to enterprise governance?

  1. Multiple critical systems may depend on the same provider or underlying model
    2. It guarantees lower procurement costs
    3. It eliminates the need for contingency planning
    4. It prevents providers from changing their services

Correct Answer: 1. Multiple critical systems may depend on the same provider or underlying model

Explanation:

Concentration risk occurs when an organization becomes heavily dependent on one external AI provider, model family, platform, or supporting service. If that provider experiences an outage, security incident, significant model change, contractual dispute, service degradation, or business failure, multiple organizational processes could be affected simultaneously. Governance should therefore identify critical dependencies and evaluate the potential impact of common points of failure. Appropriate responses may include contingency planning, alternative providers, portability requirements, contractual protections, resilience testing, and dependency monitoring. Concentration risk does not guarantee lower costs and does not eliminate the need for contingency planning. Understanding shared dependencies allows management to determine whether the organization’s reliance on an external provider is consistent with its risk appetite and business continuity requirements.

Question 376. What is the PRIMARY benefit of documenting assumptions used during an AI risk assessment?

  1. It prevents all future changes to the system
    2. It guarantees that the assessment will never become outdated
    3. It provides context for evaluating whether the assessment remains valid
    4. It removes the need for management approval

Correct Answer: 3. It provides context for evaluating whether the assessment remains valid

Explanation:

Risk assessments depend on assumptions about the AI system, data, users, operating environment, dependencies, business purpose, controls, and potential threats. Documenting those assumptions allows reviewers to understand the basis of the original assessment and determine whether the conclusions remain appropriate when circumstances change. For example, a change in data sources, user population, model provider, geographic scope, or business purpose may invalidate an important assumption and trigger reassessment. Documentation does not prevent future changes or guarantee that an assessment remains current. Instead, it creates a reference point for governance reviews and helps auditors and risk owners identify which changes could materially affect the original conclusions.

Question 377. Which action BEST supports effective AI incident response governance?

  1. Waiting until an incident occurs to identify responsibilities
    2. Establishing predefined roles, escalation criteria, and communication procedures
    3. Allowing each user to respond independently
    4. Disabling monitoring during an incident

Correct Answer: 2. Establishing predefined roles, escalation criteria, and communication procedures

Explanation:

AI incidents can involve technical failures, inaccurate outputs, privacy events, security compromises, model behavior changes, or other risks that require coordinated action. Predefined responsibilities and escalation criteria help the organization respond consistently rather than attempting to determine roles during a crisis. Communication procedures are also important because incidents may require notification of management, affected stakeholders, regulators, customers, vendors, or other parties depending on the circumstances. Individual users should not be expected to manage enterprise-level incidents independently. Disabling monitoring can also remove valuable evidence. Effective incident governance should integrate AI-specific considerations into the broader incident-management framework, including detection, containment, investigation, decision-making, communication, recovery, and lessons learned.

Question 378. What is the PRIMARY reason for periodically reviewing AI governance policies?

  1. To ensure policies remain aligned with organizational objectives, risks, and applicable requirements
    2. To make all policies longer
    3. To eliminate the need for procedures
    4. To prevent any employee from suggesting changes

Correct Answer: 1. To ensure policies remain aligned with organizational objectives, risks, and applicable requirements

Explanation:

AI governance policies should evolve as organizational objectives, AI capabilities, risks, regulations, contractual obligations, and operating environments change. Periodic review helps determine whether existing requirements remain appropriate and whether gaps or outdated provisions need to be addressed. The review should consider changes in the organization’s AI portfolio, incidents, audit findings, risk assessments, regulatory developments, and lessons learned from operational experience. Simply increasing policy length does not improve governance, and policies do not eliminate the need for detailed procedures and controls. Preventing employee feedback can also reduce opportunities to identify practical weaknesses. A structured review process helps maintain policies that are understandable, enforceable, risk-based, and relevant to current AI use.

Question 379. An organization wants to determine whether its AI governance program is improving over time. Which approach is MOST useful?

  1. Counting only the number of AI systems deployed
    2. Measuring governance outcomes and trends against defined objectives
    3. Tracking only the amount spent on AI
    4. Measuring the number of governance documents created

Correct Answer: 2. Measuring governance outcomes and trends against defined objectives

Explanation:

Governance maturity and effectiveness should be evaluated using meaningful outcomes rather than simple activity counts. Useful measures can include timely remediation of high-risk findings, completion of required assessments, control effectiveness, incident trends, policy exceptions, approval compliance, monitoring coverage, and recurring deficiencies. These indicators should be compared over time against defined governance objectives and risk expectations. Counting systems, spending, or documents may provide contextual information but does not demonstrate whether governance is actually improving. Trend analysis can help management determine whether controls are becoming more effective, whether weaknesses are recurring, and where additional investment or corrective action may be necessary. Effective measurement connects governance activities to risk reduction, accountability, compliance, and sustainable operational outcomes.

Question 380. Which characteristic BEST demonstrates effective enterprise AI governance?

  1. All AI decisions are centralized within one technical team
    2. Governance focuses exclusively on technical model accuracy
    3. AI systems operate without documented exceptions
    4. AI use is governed through clear accountability, risk-based controls, monitoring, and continuous improvement

Correct Answer: 4. AI use is governed through clear accountability, risk-based controls, monitoring, and continuous improvement

Explanation:

Effective enterprise AI governance requires more than technical model performance. It establishes clear accountability, defined decision rights, risk-based controls, appropriate approval processes, monitoring, documentation, human oversight where needed, and mechanisms for responding to incidents and changing conditions. Governance should operate throughout the AI lifecycle rather than only during development or after deployment. Continuous improvement allows organizations to learn from incidents, audits, performance trends, regulatory developments, and operational experience. Centralizing every decision within one technical team can create accountability and independence problems, while focusing only on accuracy overlooks privacy, security, compliance, fairness, and business risks. A mature governance program integrates these elements into a structured and sustainable enterprise framework.