View Full Isaca AAIR Exam Dumps and Practice Test Dumps.
Q181. An organization has formally approved AI governance policies, but business leaders routinely bypass them to accelerate projects. Which issue should the risk professional address FIRST?
- Increase the number of technical AI controls
2. Rewrite every AI policy from the beginning
3. Address governance culture, accountability, and management reinforcement
4. Remove business leaders from all AI decisions
Correct Answer: 3. Address governance culture, accountability, and management reinforcement
Explanation: Policies are unlikely to be effective when senior stakeholders routinely bypass them. The underlying issue is governance culture and accountability rather than simply inadequate documentation. Leadership should reinforce that AI risk requirements apply consistently, clarify consequences for unauthorized exceptions, and ensure incentives do not reward bypassing controls. Formal escalation and exception mechanisms should exist when business urgency is legitimate. Adding technical controls may help in specific cases, but weak management reinforcement can undermine even well-designed safeguards. Effective AI governance depends on tone from leadership, clear accountability, and alignment between business objectives and responsible risk-taking.
Q182. A business unit believes its AI system has been classified as too high risk and requests a lower governance tier. What should happen NEXT?
- Reassess the system using the approved risk-classification criteria and supporting evidence
2. Lower the classification because the business owner requested it
3. Remove the system from the AI inventory
4. Let the vendor decide the classification
Correct Answer: 1. Reassess the system using the approved risk-classification criteria and supporting evidence
Explanation: Risk classifications should be based on consistent, documented criteria rather than business preference. The organization should reassess the use case using factors such as impact, data sensitivity, autonomy, affected stakeholders, criticality, regulatory exposure, and reversibility. If evidence shows the original classification was incorrect, it can be adjusted through the normal governance process. If not, the existing tier should remain. Allowing business pressure to override classification criteria weakens governance and can result in insufficient validation, monitoring, or oversight for material AI risks.
Q183. A regulator issues new guidance affecting transparency obligations for certain AI systems. What is the BEST governance response?
- Wait until the next annual policy review
2. Apply the guidance only to new AI systems
3. Ask each project team to interpret the guidance independently
4. Assess applicability, update requirements, and determine which existing systems require remediation**
Correct Answer: 4. Assess applicability, update requirements, and determine which existing systems require remediation
Explanation: Regulatory change management should evaluate whether new guidance applies to current or planned AI systems and identify required changes to policies, controls, documentation, or user disclosures. Existing systems may need remediation even if they were compliant when first deployed. Central coordination is preferable to allowing each project team to interpret obligations independently because inconsistent interpretation can create compliance gaps. The organization should update its regulatory inventory, assign remediation owners, establish deadlines, and track progress. AI regulatory obligations can evolve quickly, so governance processes should support timely reassessment rather than relying only on annual reviews.
Q184. An organization wants to demonstrate that its AI sustainability commitments are supported by measurable evidence. Which metric is MOST relevant?
- Number of model-development meetings
2. Energy consumption or carbon-related impact associated with material AI workloads
3. Number of model parameters only
4. Number of AI vendors under contract
Correct Answer: 2. Energy consumption or carbon-related impact associated with material AI workloads
Explanation: Environmental commitments should be supported by metrics linked to actual environmental impact. Depending on the use case and infrastructure, relevant measures may include energy consumption, estimated carbon emissions, hardware utilization, or efficiency per inference or training cycle. These metrics can help management assess whether AI activities align with ESG commitments and whether optimization opportunities exist. Parameter count can influence compute demand but is not itself an environmental outcome. ISACA’s AAIR scope explicitly includes ethical, societal, and ESG implications, so environmental impacts should be assessed when they are material to the organization.
Q185. A model-development team has completed training but cannot produce evidence of key assumptions, limitations, and intended-use boundaries. What is the PRIMARY risk?
- The model will necessarily fail technically
2. The training infrastructure will become unavailable
3. The model cannot be encrypted
4. Governance and validation decisions may be made without sufficient documentation**
Correct Answer: 4. Governance and validation decisions may be made without sufficient documentation
Explanation: Model documentation supports informed approval, validation, monitoring, and later investigation. If assumptions, limitations, intended use, data characteristics, and known constraints are not documented, reviewers may be unable to determine whether the system is suitable for production or whether later changes remain within approved boundaries. Poor documentation also impairs incident response, auditability, regulatory review, and decommissioning. The model may still function technically, but governance confidence is weakened. Documentation should therefore be treated as a lifecycle control rather than an administrative afterthought.
Q186. An organization retains all historical training data indefinitely even after business and legal needs have ended. What risk principle should be applied?
- Maximum collection
2. Defined retention and secure disposal based on business and legal requirements
3. Permanent archival of all AI data
4. Elimination of data classification
Correct Answer: 2. Defined retention and secure disposal based on business and legal requirements
Explanation: AI data should not be retained indefinitely without a legitimate need. Retention schedules should consider legal obligations, business purpose, audit requirements, model reproducibility, privacy, security exposure, and contractual commitments. Once retention requirements expire, data should be securely deleted or otherwise disposed of according to policy. Unnecessary retention increases breach impact, privacy exposure, storage cost, and regulatory risk. At the same time, deleting data too early can undermine audit or reproducibility needs. A balanced lifecycle approach defines what must be kept, for how long, by whom, and how disposal is verified.
Q187. An AI team cannot explain which preprocessing transformations were applied to the dataset used to train a production model. Which control is MOST directly missing?
- Data lineage and transformation traceability
2. Disaster recovery testing
3. Vendor exit planning
4. Model availability monitoring
Correct Answer: 1. Data lineage and transformation traceability
Explanation: Data lineage documents how data moves from source systems through cleansing, labeling, feature engineering, normalization, aggregation, or other transformations before it reaches a model. Without lineage, the organization may be unable to reproduce results, investigate data-quality problems, assess privacy implications, or understand why model behavior changed. Traceability is particularly important for regulated or high-impact use cases. It should connect source data, transformations, dataset versions, model versions, and deployment records. A model can be technically available while still lacking the evidence needed for trustworthy governance.
Q188. A high-risk AI model has passed performance testing, but no evidence exists that required privacy and security reviews were completed. What should happen?
- Deploy because performance testing passed
2. Accept the missing reviews as low risk
3. Delay approval until required lifecycle reviews are completed or formally excepted
4. Remove privacy and security requirements from the checklist
Correct Answer: 3. Delay approval until required lifecycle reviews are completed or formally excepted
Explanation: Production approval should confirm that all required risk disciplines have completed their reviews, not only that the model performs well technically. High-risk AI can create privacy, security, legal, fairness, operational, and ethical exposure even when accuracy is excellent. Missing required reviews should block approval unless an authorized exception process assesses residual risk and formally approves the deviation. This prevents schedule pressure from bypassing established governance. A complete approval gate provides evidence that the organization considered the full AI risk profile before deployment.
Q189. A newly deployed AI model shows normal average performance, but error rates increase sharply during weekend operations. What should management do FIRST?
- Decommission the model permanently
2. Investigate whether operating conditions, data, or user behavior differ during weekends
3. Increase the risk tolerance automatically
4. Stop monitoring weekend performance
Correct Answer: 2. Investigate whether operating conditions, data, or user behavior differ during weekends
Explanation: Time-dependent performance degradation can indicate hidden changes in inputs, user populations, system dependencies, staffing, or data pipelines. The first step is to determine what differs during the affected period and whether the model is operating outside its tested assumptions. Monitoring should support segmentation by meaningful operating conditions rather than relying only on overall averages. Once the cause is understood, the organization can determine whether retraining, additional controls, process changes, or usage restrictions are appropriate. Automatically raising tolerance would mask rather than manage the underlying issue.
Q190. An AI system is being retired, but regulatory requirements require evidence of historical decisions for seven years. What should the decommissioning plan include?
- Immediate deletion of all model and decision records
2. Continued public access to the retired system
3. Removal of all documentation because the model is inactive
4. Controlled archival of required records with appropriate access and retention controls**
Correct Answer: 4. Controlled archival of required records with appropriate access and retention controls
Explanation: Decommissioning does not always permit immediate destruction of AI artifacts. Regulatory, contractual, legal, audit, or business requirements may require historical models, decisions, logs, explanations, or other records to be retained for a specified period. These records should be archived securely with appropriate access restrictions, integrity protection, and eventual disposal dates. Operational access to the retired model should be removed unless there is a justified need. A controlled archival process balances compliance and evidentiary requirements against unnecessary continued exposure of obsolete systems.
Q191. A risk team is unsure whether to rate an AI scenario as medium or high because likelihood estimates vary widely among experts. What is the BEST approach?
- Document uncertainty and use sensitivity or range-based analysis to support the decision
2. Select the lowest estimate to avoid overstating risk
3. Discard expert input and assign a random score
4. Remove the scenario from the risk register
Correct Answer: 1. Document uncertainty and use sensitivity or range-based analysis to support the decision
Explanation: Risk estimates often contain uncertainty, particularly for emerging AI threats with limited historical data. Rather than hiding this uncertainty behind a single number, the organization can document assumptions, use ranges, compare scenarios, and analyze how conclusions change under different likelihood estimates. This gives decision-makers a clearer view of confidence and potential exposure. Selecting only the lowest estimate creates optimism bias, while removing the risk avoids the problem rather than managing it. Transparent uncertainty analysis improves the quality of AI risk decisions.
Q192. An organization wants to understand how preventive controls, detection, and recovery measures collectively address a major AI failure scenario. Which analysis technique is MOST useful?
- Source-code formatting review
2. Bow-tie analysis linking causes, event, consequences, and controls
3. Employee headcount analysis
4. Model parameter benchmarking
Correct Answer: 3. Bow-tie analysis linking causes, event, consequences, and controls
Explanation: Bow-tie analysis visually connects potential causes of a risk event with preventive controls on one side and consequences with mitigating or recovery controls on the other. For an AI scenario, causes might include poisoned data, unauthorized changes, or model drift, while consequences might include harmful decisions or service disruption. The technique helps identify control gaps and whether too many safeguards depend on one layer. It can complement other risk assessment approaches by showing how threats, vulnerabilities, controls, and consequences relate within one scenario.
Q193. Several AI applications depend on the same weak monitoring control. What risk should management consider when assessing residual risk across the portfolio?
- Control dependency and aggregated residual risk
2. Only the individual application’s model size
3. Only vendor marketing risk
4. Employee scheduling risk
Correct Answer: 4. Control dependency and aggregated residual risk
Explanation: If multiple AI systems rely on the same control, weakness in that control can increase residual risk across the entire portfolio simultaneously. Assessing each application independently may underestimate enterprise exposure. Management should identify shared controls, dependencies, and potential common-mode failures and determine whether additional safeguards or independent layers are needed. This is particularly important when common identity, monitoring, data, or model infrastructure supports many AI systems. Portfolio-level aggregation helps reveal risk concentrations that are invisible in isolated project assessments.
Q194. Management wants a metric showing whether a required AI control is functioning within expected parameters. Which type of metric is MOST appropriate?
- Revenue forecast
2. Key Control Indicator (KCI)
3. Market share metric
4. Model parameter count
Correct Answer: 1. Key Control Indicator (KCI)
Explanation: A Key Control Indicator measures whether an important control is operating as intended. Examples might include the percentage of high-risk models receiving required independent validation, the rate of failed access reviews, or the percentage of privileged changes following approval procedures. KCIs complement KRIs, which focus more directly on risk exposure, and KPIs, which measure business or process performance. Clear control indicators can provide early warning when safeguards are deteriorating even before residual risk or incident rates visibly increase.
Q195. An AI risk report uses data drawn from several systems, but management questions whether the figures are reliable. What should the risk function strengthen?
- Report formatting only
2. The number of charts in the dashboard
3. Data validation, reconciliation, lineage, and quality controls for risk reporting
4. The font size of risk descriptions
Correct Answer: 3. Data validation, reconciliation, lineage, and quality controls for risk reporting
Explanation: Risk reporting is only as reliable as the underlying data. When metrics come from multiple systems, the organization should validate completeness, accuracy, timeliness, definitions, transformations, and reconciliation between sources. Data lineage helps explain where figures came from and how they were calculated. These controls support confidence that management decisions are based on trustworthy information. Attractive dashboards cannot compensate for inaccurate or inconsistent source data. AI risk reporting should therefore apply sound data-governance principles to metrics and reporting processes themselves.
Q196. An organization uses AI providers headquartered in different countries, but all providers depend on data centers in one geopolitical region. What risk remains?
- Geographic concentration risk
2. Model calibration risk
3. Training-data labeling risk
4. User-interface risk
Correct Answer: 2. Geographic concentration risk
Explanation: Vendor diversification does not eliminate concentration risk when supposedly independent providers share the same geographic or infrastructure dependency. Political instability, regional outages, natural disasters, connectivity failures, sanctions, or regulatory restrictions could affect multiple providers simultaneously. Supply-chain analysis should therefore examine upstream infrastructure, hosting regions, cloud platforms, and other common dependencies. Geographic concentration can influence continuity strategies, vendor selection, data-residency planning, and resilience investment. Portfolio risk needs to consider where services actually operate, not simply where vendors are headquartered.
Q197. An AI service agreement guarantees availability but provides no remedy when the vendor repeatedly misses the service level. What contractual improvement would BEST strengthen accountability?
- Remove the availability commitment
2. Allow the vendor to redefine the SLA after each outage
3. Define escalation, remediation, service credits, termination rights, or other consequences for sustained nonperformance
4. Measure only model accuracy instead
Correct Answer: 3. Define escalation, remediation, service credits, termination rights, or other consequences for sustained nonperformance
Explanation: A service-level commitment is stronger when persistent nonperformance leads to defined consequences or corrective action. Depending on service criticality, contracts may include escalation requirements, remediation plans, service credits, termination rights, or other remedies. These do not eliminate operational risk, but they create clearer accountability and incentives. The organization should also maintain continuity and exit plans because contractual compensation cannot restore a failed business service. AI contracts should address availability together with security, data use, incident notification, model changes, intellectual property, and other relevant risks.
Q198. An organization depends heavily on a critical AI vendor. What is the BEST way to validate that both parties can coordinate during a significant vendor incident?
- Rely solely on the vendor’s written incident plan
2. Conduct a joint incident-response or tabletop exercise
3. Wait for a real incident to test coordination
4. Remove vendor contacts from internal response plans
Correct Answer: 4. Conduct a joint incident-response or tabletop exercise
Explanation: A joint exercise tests whether communication channels, escalation paths, responsibilities, technical contacts, evidence sharing, notification expectations, and decision authority work in practice. Written plans can contain outdated contact details or unrealistic assumptions that become visible only during exercises. The scenario can include model compromise, data exposure, service outage, or upstream supplier failure. Findings should feed into contracts, incident procedures, continuity planning, and vendor oversight. Testing coordination before a real event reduces uncertainty when rapid response is required.
Q199. A disaster recovery architecture includes a secondary AI platform, but the organization has never attempted failover. What is the PRIMARY risk?
- The organization does not know whether the recovery design will actually meet required objectives
2. The secondary platform automatically eliminates all outage risk
3. The primary AI system no longer requires monitoring
4. RTO and RPO become irrelevant
Correct Answer: 1. The organization does not know whether the recovery design will actually meet required objectives
Explanation: Recovery capability should be demonstrated through testing. A secondary environment can fail because of configuration drift, missing data, incompatible models, credentials, network dependencies, or outdated procedures. Failover tests provide evidence that the organization can recover within defined RTO and RPO targets and reveal gaps before a real disruption. Tests should be proportionate to business criticality and can range from tabletop exercises to full technical failover. Merely purchasing redundant infrastructure does not establish resilience.
Q200. An AI service experiences a major outage, and the disaster recovery plan restores the application but not the data needed to resume accurate decision-making. What is the MOST important lesson?
- Application recovery alone is sufficient
2. Data should never be included in DR planning
3. Recovery objectives should address the complete AI service, including models, data, configuration, and dependencies
4. The organization should stop performing DR tests
Correct Answer: 3. Recovery objectives should address the complete AI service, including models, data, configuration, and dependencies
Explanation: AI recovery is an end-to-end capability. Restoring an application binary without the correct model version, feature data, configuration, prompts, credentials, or dependencies may leave the service unusable or produce incorrect outputs. Business impact analysis and disaster recovery planning should therefore identify all components necessary to restore the intended service and decision quality. Testing should verify not only that systems start but also that the recovered AI service functions accurately and safely. Comprehensive recovery design is essential when business processes depend materially on AI outputs.