Isaca AAIR Practice Test Questions and Exam Dumps Part1 Q1-20

View Full Isaca AAIR Exam Dumps and Practice Test Dumps.


Q1. An organization is considering an AI solution that could improve customer service but introduces privacy and reputational risk. What should the risk professional do FIRST?

  1. Reject the AI initiative because it introduces new risk
    2. Evaluate the use case against business objectives and the organization’s risk appetite
    3. Purchase additional cybersecurity insurance
    4. Require the AI development team to eliminate all residual risk

Correct Answer: 2. Evaluate the use case against business objectives and the organization’s risk appetite

Explanation: AI initiatives should first be assessed in the context of organizational objectives, expected value, and established risk appetite. The purpose of AI risk management is not to eliminate every risk or automatically reject innovative technologies, but to determine whether expected benefits justify the exposure and whether risk can be managed within acceptable limits. Privacy, reputation, legal obligations, and business value should all be considered. Insurance may later be part of risk treatment, but it is premature before the risk is understood. Eliminating all residual risk is generally unrealistic because most business activities retain some level of risk.

Q2. Who should have ultimate accountability for ensuring that significant AI-related risks are managed within approved organizational tolerance?

  1. The AI model itself
    2. External auditors only
    3. Individual end users
    4. Appropriate business and risk owners assigned through governance**

Correct Answer: 4. Appropriate business and risk owners assigned through governance

Explanation: Effective AI governance requires clear ownership and accountability. Business and risk owners should be formally identified for significant AI systems and associated risks so decisions about acceptance, treatment, escalation, and monitoring have accountable human authorities. Technical developers and end users may have important responsibilities, but accountability should not be left solely to them. External auditors provide independent assurance rather than owning operational risks. AI systems themselves cannot be accountable organizational actors. Defined ownership also enables escalation, reporting, control monitoring, and alignment with enterprise risk management practices.

Q3. An organization already maintains an enterprise risk register. What is the BEST way to manage newly identified AI risks?

  1. Integrate material AI risks into the existing enterprise risk register and taxonomy
    2. Maintain AI risks only in developers’ project notes
    3. Exclude AI risks because they are technology-specific
    4. Create an undocumented AI risk list outside governance processes

Correct Answer: 1. Integrate material AI risks into the existing enterprise risk register and taxonomy

Explanation: AI risk management should be integrated into existing enterprise risk processes rather than operating as an isolated discipline. Adding AI risks to the established risk register promotes consistent ownership, scoring, treatment, escalation, and reporting. Existing taxonomies may need to be expanded for AI-specific concerns such as model drift, bias, hallucination, data poisoning, or excessive agency, but the governance structure should remain connected to enterprise risk management. Separate undocumented lists can create fragmented accountability and prevent senior management from seeing aggregate exposure. Integration also helps compare AI risks with other strategic, operational, compliance, and technology risks.

Q4. A bank uses an AI model to help determine credit eligibility. Which control is MOST important for addressing the risk of unfair outcomes across demographic groups?

  1. Increase the model’s computational capacity
    2. Retrain the model every day regardless of performance
    3. Perform bias and fairness testing using appropriate representative data and metrics
    4. Remove all human oversight from credit decisions

Correct Answer: 3. Perform bias and fairness testing using appropriate representative data and metrics

Explanation: An AI system used in a high-impact decision such as credit eligibility should be evaluated for discriminatory or systematically unfair outcomes. Bias and fairness testing should use representative data and appropriate metrics to detect differences across relevant populations. Findings should be reviewed in the context of legal obligations, organizational ethics, and approved risk tolerances. More computing power does not address fairness, and frequent retraining without controls can introduce new risk. Human oversight may also be appropriate depending on the use case. Fairness management should continue throughout the model lifecycle because data and behavior can change over time.

Q5. An enterprise is procuring a third-party generative AI service that will process confidential business information. Which contractual consideration is MOST important?

  1. The vendor’s office location only
    2. The number of AI features in the product
    3. The vendor’s marketing budget
    4. Terms governing data use, retention, confidentiality, intellectual property, and incident notification**

Correct Answer: 4. Terms governing data use, retention, confidentiality, intellectual property, and incident notification

Explanation: Contracts for AI services should clearly address how organizational data is used, retained, shared, protected, and deleted. They should also clarify intellectual-property rights, confidentiality obligations, subcontractor involvement, breach or incident notification, audit rights, and service termination requirements where appropriate. These terms directly affect supply-chain and data risk. Product features and vendor size may influence procurement decisions, but they do not substitute for explicit contractual protections. Risk professionals should work with legal, privacy, security, procurement, and business stakeholders to ensure third-party AI agreements reflect the organization’s risk appetite and regulatory obligations.

Q6. A machine-learning model performs well during initial testing but becomes progressively less accurate as customer behavior changes. What risk is MOST directly illustrated?

  1. Data encryption failure
    2. Model drift
    3. Physical asset theft
    4. Certificate expiration

Correct Answer: 2. Model drift

Explanation: Model drift occurs when the statistical relationships, data patterns, or operating environment change so that a model’s performance degrades over time. A model that was accurate during development may become less reliable as customers, markets, systems, or external conditions evolve. Risk management should therefore include ongoing monitoring of accuracy, inputs, outcomes, and other relevant performance indicators. Thresholds can trigger review, recalibration, retraining, rollback, or retirement. Drift demonstrates why AI risk does not end at deployment. Continuous monitoring is necessary throughout the operational lifecycle to determine whether the model remains suitable for its intended use.

Q7. Before an AI model is placed into production, what is the BEST evidence that it is suitable for its intended business purpose?

  1. Independent validation against defined performance, risk, and business requirements
    2. The development team’s confidence in the model
    3. The fact that a similar model is popular in the industry
    4. The model has the largest number of parameters available

Correct Answer: 1. Independent validation against defined performance, risk, and business requirements

Explanation: Suitability should be demonstrated through objective validation against documented requirements rather than confidence or popularity. Validation should examine whether the model performs adequately for its intended use, behaves within acceptable risk limits, and satisfies relevant requirements for robustness, fairness, security, explainability, or reliability. The degree of independence should be proportionate to the model’s impact and risk. Large parameter counts do not necessarily mean better business performance. Validation should also be repeated when significant model, data, or environmental changes occur because an acceptable model at one point may later become inappropriate.

Q8. An organization’s AI policy has been approved, but employees frequently upload confidential information into unapproved public AI tools. What is the BEST next step?

  1. Assume employees will eventually learn the policy
    2. Remove all AI policies
    3. Implement targeted awareness, training, monitoring, and enforceable usage controls
    4. Allow unrestricted public AI use to encourage innovation

Correct Answer: 3. Implement targeted awareness, training, monitoring, and enforceable usage controls

Explanation: A policy is effective only when users understand it and the organization can reinforce appropriate behavior. If employees continue placing sensitive information into unapproved AI tools, the organization should address the gap through targeted awareness, role-appropriate training, approved alternatives, technical monitoring, and enforceable controls where appropriate. Risk professionals should also investigate why users bypass approved processes; the approved tools may be inconvenient or poorly communicated. Removing policy or permitting unrestricted use increases data leakage and compliance risk. Governance should combine clear expectations with practical processes and controls that support responsible AI adoption.

Q9. A risk assessment identifies a high-impact AI failure scenario with low likelihood but potentially severe regulatory and financial consequences. How should it be treated?

  1. Ignore it because likelihood is low
    2. Evaluate the combined likelihood and impact against risk appetite and determine appropriate treatment
    3. Automatically shut down every AI system
    4. Classify it as acceptable without further analysis

Correct Answer: 2. Evaluate the combined likelihood and impact against risk appetite and determine appropriate treatment

Explanation: Risk decisions should consider both likelihood and impact, as well as organizational risk appetite and tolerance. A low-likelihood event may still require significant attention when potential consequences are severe, such as regulatory sanctions, safety impacts, major financial loss, or significant reputational damage. Risk treatment may include mitigation, avoidance, transfer, acceptance, or combinations of these approaches. Automatically ignoring low-likelihood events or shutting down all AI systems is inappropriate. Scenario analysis helps decision-makers understand plausible consequences and determine whether controls or contingency planning are proportionate to the exposure.

Q10. Which activity is MOST important when establishing an inventory of enterprise AI assets?

  1. Record AI systems, models, datasets, owners, dependencies, purposes, and relevant risk classifications
    2. List only systems purchased from external vendors
    3. Document only AI systems that have already caused incidents
    4. Exclude embedded AI capabilities from the inventory

Correct Answer: 1. Record AI systems, models, datasets, owners, dependencies, purposes, and relevant risk classifications

Explanation: Effective AI risk management depends on understanding which AI assets exist, why they are used, who owns them, which data and models they depend on, and what risk they create. An inventory should therefore cover internally developed, externally acquired, embedded, and significant third-party AI capabilities where relevant. Risk classification can help determine which systems require enhanced controls, monitoring, validation, or oversight. Limiting the inventory to vendor products or known incidents leaves major blind spots. An accurate inventory is foundational for lifecycle management, regulatory compliance, incident response, supply-chain governance, and enterprise reporting.

Q11. A threat actor deliberately modifies training records to cause a machine-learning model to behave incorrectly after deployment. Which AI-specific threat does this describe?

  1. Model drift
    2. Data retention
    3. Explainability failure
    4. Data poisoning

Correct Answer: 4. Data poisoning

Explanation: Data poisoning is an attack in which adversaries manipulate training or related data to influence model behavior. The attack may attempt to degrade overall accuracy, create targeted weaknesses, or introduce hidden behaviors that activate under specific conditions. Controls can include trusted data sources, access restrictions, provenance tracking, integrity verification, anomaly detection, segregation of duties, and careful validation before training data is accepted. Model drift is an operational change over time rather than deliberate manipulation. Because AI systems depend heavily on data quality, attacks against datasets can undermine models even when the model code itself remains unchanged.

Q12. A company has reduced an AI risk using several controls, but some exposure remains. What is the remaining exposure called?

  1. Inherent risk
    2. Transfer risk
    3. Residual risk
    4. Audit risk only

Correct Answer: 3. Residual risk

Explanation: Residual risk is the risk remaining after management has implemented controls or other treatment measures. Inherent risk represents exposure before considering controls. Management should compare residual risk with approved risk appetite and tolerance to determine whether additional treatment is required or whether the remaining exposure can be formally accepted. Controls rarely remove all risk completely, particularly in complex and evolving AI systems. Residual risk should therefore be documented, assigned to an accountable owner, monitored for changes, and communicated to decision-makers at the appropriate level.

Q13. An AI system is used to support medical triage. Which factor should MOST influence the level of governance and oversight applied?

  1. The potential impact on individuals and the criticality of the decisions supported
    2. The color scheme of the user interface
    3. The development team’s preferred programming language
    4. The physical size of the servers

Correct Answer: 1. The potential impact on individuals and the criticality of the decisions supported

Explanation: AI governance should be risk based. Systems influencing health, safety, employment, credit, legal rights, or other consequential outcomes generally require stronger controls and oversight than low-impact productivity tools. The organization should consider potential harm, scale, affected populations, reversibility, legal obligations, model autonomy, and dependence on AI outputs. High-impact systems may require stronger validation, documentation, monitoring, transparency, human oversight, and escalation mechanisms. Technology choices such as programming language or server size do not determine governance intensity. Oversight should correspond to the nature and consequence of the decisions the AI supports.

Q14. A vendor provides an AI model but refuses to disclose important information about training data provenance and model limitations. What is the BEST risk response before adoption?

  1. Accept the model because the vendor is well known
    2. Remove vendor due diligence requirements
    3. Assume undisclosed information is not relevant
    4. Evaluate whether the lack of transparency creates unacceptable residual third-party risk**

Correct Answer: 4. Evaluate whether the lack of transparency creates unacceptable residual third-party risk

Explanation: Lack of transparency can make it difficult to assess bias, privacy, intellectual property, security, data quality, regulatory compliance, and model suitability. The organization should determine whether available contractual assurances, independent testing, compensating controls, or vendor evidence can reduce the uncertainty to an acceptable level. If significant unknowns remain outside risk tolerance, the model may need to be rejected or restricted. A well-known vendor name is not a substitute for due diligence. Third-party AI risk management requires sufficient evidence to make informed decisions about both the product and the vendor’s ongoing practices.

Q15. Which metric would BEST serve as a key risk indicator for an AI model whose approved error rate must remain below 3%?

  1. Number of developers assigned to the project
    2. Percentage of model outputs that are incorrect over a defined monitoring period
    3. Total lines of source code
    4. Number of meetings held by the AI governance committee

Correct Answer: 2. Percentage of model outputs that are incorrect over a defined monitoring period

Explanation: A useful key risk indicator should directly measure an exposure relevant to a defined risk threshold. If the approved error rate must remain below 3%, the observed error rate over an appropriate monitoring period directly indicates whether the model is approaching or exceeding tolerance. The metric should be defined consistently, use representative data, and trigger escalation when thresholds are breached. Staffing levels, source-code size, and meeting counts may provide operational information but do not directly measure the risk in question. Effective KRIs connect measurable conditions to risk appetite, thresholds, escalation, and management action.

Q16. An organization plans to retire an AI model and replace it with a newer version. Which activity is MOST important during decommissioning?

  1. Delete all records immediately regardless of retention obligations
    2. Leave the old model accessible indefinitely
    3. Securely address model, data, access, retention, dependency, and archival requirements
    4. Stop documenting the system because it is no longer active

Correct Answer: 3. Securely address model, data, access, retention, dependency, and archival requirements

Explanation: AI lifecycle management continues through decommissioning. The organization should determine how models, datasets, logs, credentials, interfaces, and documentation will be archived, retained, transferred, or securely destroyed according to legal and business requirements. Dependencies must be identified so removing the model does not break other systems. Access should be revoked when no longer needed, and historical evidence may need preservation for audit, investigations, or regulatory purposes. Simply deleting everything can violate retention obligations, while leaving retired systems indefinitely accessible creates unnecessary security and governance exposure. Decommissioning should follow a documented controlled process.

Q17. A generative AI application allows a model to invoke external tools autonomously. Which risk becomes particularly important?

  1. Storage fragmentation
    2. Keyboard failure
    3. Printer availability
    4. Excessive agency causing unintended or unauthorized actions**

Correct Answer: 4. Excessive agency causing unintended or unauthorized actions

Explanation: Excessive agency arises when an AI system has too much freedom to perform actions or invoke tools without sufficient constraints, oversight, or authorization. A model that can send messages, modify records, transfer funds, execute code, or change infrastructure can transform an incorrect or manipulated output into a real-world impact. Controls should include least-privilege tool permissions, scope limits, validation, human approval for high-impact actions, audit logs, and deterministic policy enforcement. The level of autonomy should reflect the potential harm and reversibility of the action. Tool-enabled AI therefore requires stronger governance than a purely informational chatbot.

Q18. An AI-related incident causes a critical customer service to become unavailable. Which existing enterprise process should the AI incident response capability MOST closely integrate with?

  1. Incident response, business continuity, and disaster recovery processes
    2. Office furniture procurement
    3. Employee vacation scheduling
    4. Marketing campaign approval only

Correct Answer: 1. Incident response, business continuity, and disaster recovery processes

Explanation: AI incidents can create the same operational consequences as other technology or business incidents, including service outages, data exposure, harmful decisions, or regulatory impacts. AI-specific scenarios should therefore be integrated into established incident response, business impact analysis, business continuity, and disaster recovery processes. Existing escalation paths, communications procedures, recovery priorities, and resilience plans can be extended to include AI-specific failure modes. Creating an isolated incident process can fragment response coordination. ISACA’s AAIR scope specifically includes incorporating AI risk considerations into incident response, BIA, BCP, and DRP activities.

Q19. A board asks for an AI risk report. Which information is MOST useful at the board level?

  1. Every individual model parameter
    2. Complete source code for all AI systems
    3. Material AI risk trends, exposures, tolerance breaches, business impacts, and management actions
    4. Raw application logs from every AI service

Correct Answer: 3. Material AI risk trends, exposures, tolerance breaches, business impacts, and management actions

Explanation: Board reporting should focus on information necessary for strategic oversight and decision-making. This includes material AI exposures, significant changes in risk profile, risk appetite or tolerance breaches, regulatory developments, major incidents, business impacts, treatment progress, and areas requiring management attention. Detailed model parameters and raw logs are generally more appropriate for technical teams unless they are directly relevant to a material governance issue. Effective risk reporting should be concise, reliable, contextual, and connected to organizational objectives so directors can understand whether AI adoption remains within acceptable risk boundaries.

Q20. An organization wants to use AI to help its own enterprise risk management team. Which use case is MOST appropriate if suitable controls are in place?

  1. Allow AI to make all final risk acceptance decisions without human accountability
    2. Use AI to assist with risk analysis, scenario identification, trend detection, and reporting while maintaining human oversight
    3. Replace the enterprise risk framework with a chatbot
    4. Eliminate risk owners because AI can monitor risk automatically

Correct Answer: 2. Use AI to assist with risk analysis, scenario identification, trend detection, and reporting while maintaining human oversight

Explanation: AI can support risk management by analyzing large datasets, identifying patterns, helping generate risk scenarios, summarizing information, and improving reporting efficiency. However, final accountability for material risk decisions should remain with authorized human stakeholders operating within the organization’s governance framework. AI outputs can be incomplete, biased, or incorrect and therefore require validation appropriate to their use. Risk owners remain necessary because accountability cannot simply be delegated to a model. ISACA explicitly recognizes leveraging AI to support risk profiles, reporting, evaluation, risk models, and analysis as part of AAIR practice.