Isaca AAIR Practice Test Questions and Exam Dumps Part2 Q21-40

View Full Isaca AAIR Exam Dumps and Practice Test Dumps.


Q21. An organization already uses an established enterprise risk management framework and plans to adopt AI extensively. What is the BEST approach to establishing AI risk governance?

  1. Replace the enterprise framework entirely with an AI-specific framework
    2. Allow each development team to create its own independent AI risk methodology
    3. Integrate AI-specific risk considerations into the existing enterprise framework and governance structure
    4. Manage AI risks only through cybersecurity procedures

Correct Answer: 3. Integrate AI-specific risk considerations into the existing enterprise framework and governance structure

Explanation: AI risk governance should normally extend and integrate with existing enterprise governance and risk management rather than creating an isolated structure. The organization can add AI-specific risks, controls, terminology, ownership requirements, and lifecycle activities while preserving established mechanisms for escalation, reporting, appetite, and accountability. This improves consistency and helps management compare AI risk with other enterprise exposures. AI risk is broader than cybersecurity because it may also involve privacy, bias, safety, legal, reputational, operational, and societal concerns. Separate team-specific methodologies can create inconsistent treatment and prevent leadership from obtaining an enterprise-wide view.

Q22. A risk manager is defining responsibilities for an enterprise AI governance program. Which tool is MOST useful for clarifying who is responsible, accountable, consulted, and informed for key AI risk activities?

  1. A RACI matrix
    2. A vulnerability scanner
    3. A model accuracy chart
    4. A data retention schedule only

Correct Answer: 1. A RACI matrix

Explanation: A RACI matrix identifies who is Responsible, Accountable, Consulted, and Informed for specific activities. In AI governance, it can clarify roles for model approval, risk acceptance, data ownership, validation, monitoring, incident response, regulatory compliance, and decommissioning. This is particularly useful because AI systems often involve business owners, data scientists, legal teams, privacy officers, information security, compliance, and risk professionals. Clear responsibility prevents important tasks from being overlooked or duplicated. Technical tools such as vulnerability scanners and accuracy dashboards provide evidence about specific risk areas but do not establish organizational accountability.

Q23. An organization operates AI systems in several countries with different legal requirements. What should the AI risk function do FIRST when assessing regulatory compliance?

  1. Apply the strictest known law globally without analysis
    2. Assume regulations apply only where the AI model was developed
    3. Wait until a regulator requests documentation
    4. Identify applicable jurisdictions, AI use cases, data processing activities, and relevant legal obligations**

Correct Answer: 4. Identify applicable jurisdictions, AI use cases, data processing activities, and relevant legal obligations

Explanation: Regulatory assessment begins by understanding where the organization operates, which individuals and data are affected, what the AI system does, and which legal or regulatory regimes apply. Different obligations may depend on jurisdiction, industry, data type, decision impact, or AI system classification. Once applicability is determined, the organization can map requirements to controls, documentation, monitoring, and reporting obligations. Automatically applying one law globally may be unnecessarily restrictive or still miss unrelated requirements. Waiting for regulatory scrutiny is reactive and exposes the organization to avoidable compliance risk.

Q24. A company is assessing whether an AI-enabled employee monitoring solution should be deployed. Which consideration is MOST important from an ethical and societal risk perspective?

  1. Whether the system uses the newest algorithm
    2. Potential impacts on privacy, fairness, autonomy, and affected stakeholders
    3. Whether the vendor has the largest market share
    4. Whether the model has more parameters than competitors

Correct Answer: 2. Potential impacts on privacy, fairness, autonomy, and affected stakeholders

Explanation: Ethical AI risk assessment should evaluate how a system affects people and stakeholders, not merely its technical sophistication. Employee monitoring can create significant concerns around privacy, discrimination, autonomy, transparency, power imbalance, and proportionality. The organization should consider whether the business purpose justifies these impacts and whether less intrusive alternatives exist. Stakeholder concerns, legal obligations, organizational values, and risk appetite should all inform the decision. A technically advanced model can still create unacceptable ethical or societal harm. ISACA’s AAIR scope explicitly includes trustworthiness, ethics, bias, privacy, safety, and broader societal implications.

Q25. During development of a high-impact AI model, the team cannot demonstrate where a portion of the training data originated. What is the PRIMARY risk management concern?

  1. Insufficient data provenance and uncertainty about legality, quality, or suitability
    2. The model will necessarily have low computational performance
    3. The AI system cannot use encryption
    4. The development environment will become unavailable

Correct Answer: 1. Insufficient data provenance and uncertainty about legality, quality, or suitability

Explanation: Data provenance establishes where data came from, how it was obtained, how it was transformed, and whether its use is authorized and appropriate. Unknown provenance can create legal, intellectual-property, privacy, bias, quality, and integrity risks. It can also make investigation difficult if the model later produces harmful or unexpected outcomes. The organization should document data sources, ownership, licensing, consent where applicable, lineage, transformations, and quality controls. Model performance alone cannot compensate for uncertainty about whether training data was lawfully acquired or suitable for the intended use.

Q26. A development team proposes using synthetic data because real customer data is highly sensitive. What should the risk professional emphasize?

  1. Synthetic data automatically eliminates all privacy and bias risks
    2. Synthetic data never requires validation
    3. Evaluate whether the synthetic data accurately represents required characteristics without recreating sensitive patterns or introducing bias
    4. Synthetic data should always replace real-world validation data

Correct Answer: 3. Evaluate whether the synthetic data accurately represents required characteristics without recreating sensitive patterns or introducing bias

Explanation: Synthetic data can reduce exposure to real sensitive records, but it is not automatically risk free. Poorly generated synthetic data may fail to represent important populations, amplify bias, distort statistical relationships, or unintentionally reproduce information from the source data. The organization should evaluate privacy leakage, representativeness, quality, and suitability for the intended AI use. Real-world validation may still be necessary depending on the system. Risk professionals should therefore treat synthetic data as one possible control or design choice rather than assuming it eliminates privacy, fairness, and data-quality concerns.

Q27. Senior management requires explanations for how a high-impact AI model reaches decisions. What is the PRIMARY risk management benefit of explainability?

  1. It guarantees that every model decision is correct
    2. It helps stakeholders understand, challenge, investigate, and govern model decisions
    3. It eliminates the need for monitoring
    4. It prevents all malicious attacks against the model

Correct Answer: 2. It helps stakeholders understand, challenge, investigate, and govern model decisions

Explanation: Explainability can help decision-makers, users, validators, regulators, and affected stakeholders understand the factors influencing an AI output. This supports oversight, investigation of unexpected behavior, identification of bias or errors, and meaningful challenge of high-impact decisions. The appropriate level of explainability depends on the model, use case, legal obligations, and risk. Explainability does not guarantee accuracy and does not replace testing, monitoring, security, or human accountability. It is one component of trustworthy AI and can be particularly important when AI outputs affect significant decisions involving individuals or critical business processes.

Q28. An AI model has passed technical validation, but the business process it supports has changed significantly before deployment. What should happen?

  1. Deploy because technical validation has already been completed
    2. Ignore business-process changes if the model code did not change
    3. Reduce monitoring after deployment
    4. Reassess model suitability and risk against the changed business context before deployment**

Correct Answer: 4. Reassess model suitability and risk against the changed business context before deployment

Explanation: AI validation must address suitability for the intended use, not only technical performance. A significant business-process change can alter input data, decision impact, users, dependencies, control requirements, or expected outcomes even when the model itself is unchanged. Therefore, risk and validation evidence should be reviewed again before deployment. Continuing based on outdated assumptions can introduce unacceptable risk. Change management should consider AI-specific impacts, including whether changes to business processes, data sources, models, regulations, or system integrations require renewed testing, approval, documentation, or risk assessment.

Q29. An organization discovers employees using unapproved AI tools for business tasks. What is this situation commonly called from an AI governance perspective?

  1. Model convergence
    2. Data normalization
    3. Shadow AI
    4. Federated learning

Correct Answer: 3. Shadow AI

Explanation: Shadow AI refers to AI tools, models, or services being used without appropriate organizational approval, governance, or visibility. It is similar to shadow IT but introduces AI-specific concerns such as confidential data exposure, unreviewed vendor terms, intellectual-property leakage, uncontrolled model outputs, regulatory risk, and inconsistent decision-making. Organizations should identify why employees are using unapproved tools and provide practical approved alternatives when possible. Discovery mechanisms, awareness, policies, access controls, procurement processes, and monitoring can all help address the issue. Merely banning AI without understanding business demand may drive usage further outside governance.

Q30. During threat modeling, an organization identifies that malicious instructions embedded in an external document could manipulate a generative AI agent that reads the document. Which threat is this?

  1. Indirect prompt injection
    2. Model drift
    3. Data minimization
    4. Algorithmic transparency

Correct Answer: 1. Indirect prompt injection

Explanation: Indirect prompt injection occurs when malicious instructions are embedded in content that an AI system later retrieves or processes, such as documents, emails, webpages, or tickets. The attacker may attempt to manipulate the model into ignoring its intended instructions, revealing information, or invoking tools improperly. Controls can include treating retrieved content as untrusted, isolating instructions from data, restricting tool permissions, validating outputs, applying least privilege, and requiring approval for high-impact actions. This differs from model drift, which concerns performance changes over time rather than deliberate manipulation through contextual input.

Q31. A malicious actor repeatedly queries a proprietary AI model and uses the outputs to build a similar substitute model. Which threat does this BEST describe?

  1. Model hallucination
    2. Data retention
    3. Concept drift
    4. Model extraction**

Correct Answer: 4. Model extraction

Explanation: Model extraction involves querying an AI system and using its outputs to infer or reproduce aspects of the original model’s behavior. This can threaten intellectual property, business advantage, and potentially security controls built around the proprietary model. Defenses may include authentication, rate limiting, monitoring unusual query patterns, limiting output detail, contractual protections, and detecting automated extraction behavior. Model extraction differs from model inversion, which seeks to infer sensitive information about underlying training data. Risk assessments for externally accessible AI models should consider both abuse of the model and unauthorized replication of its capabilities.

Q32. An AI risk treatment plan includes a control requiring human review before a model can approve transactions above a defined financial threshold. What type of control is this primarily?

  1. Physical control
    2. Preventive control
    3. Recovery control only
    4. Environmental control

Correct Answer: 2. Preventive control

Explanation: Requiring human approval before a high-value transaction is finalized is primarily preventive because it aims to stop an inappropriate or erroneous AI-generated decision before the business action occurs. The control creates an intervention point where an authorized reviewer can challenge the model’s recommendation. Depending on implementation, related monitoring may also provide detective benefits, but the central purpose is prevention. Control design should align with the severity, reversibility, and likelihood of the underlying risk. High-impact AI decisions often benefit from defined human-in-the-loop thresholds rather than unrestricted automation.

Q33. A control is well designed on paper but is consistently bypassed in day-to-day operation. What should the AI risk manager conclude?

  1. Control operating effectiveness is inadequate
    2. The control is effective because its documentation is complete
    3. Residual risk must be zero
    4. No additional monitoring is required

Correct Answer: 1. Control operating effectiveness is inadequate

Explanation: Control effectiveness includes both design and operation. A control may be theoretically capable of reducing risk but still fail if users bypass it, systems do not enforce it, or responsible teams do not perform required activities consistently. Testing should therefore assess whether controls operate as intended over an appropriate period, not simply whether policies and procedures exist. If operating effectiveness is inadequate, residual risk may be higher than originally assessed and additional remediation may be required. Documentation is evidence of control design, but it does not prove that the control actually works in practice.

Q34. A risk team tracks the percentage of high-risk AI models that have completed independent validation before production deployment. What type of metric is this MOST directly?

  1. Revenue metric
    2. Environmental metric
    3. Model latency metric
    4. Control-performance or risk-management metric**

Correct Answer: 4. Control-performance or risk-management metric

Explanation: The percentage of high-risk AI models completing required validation indicates whether a defined governance or control process is being performed consistently. It can help management identify gaps in the AI risk program and determine whether models are bypassing required review. The metric may be used as a KPI, control-performance indicator, or related risk-management measure depending on the organization’s terminology. It does not directly measure model latency or business revenue. Useful risk metrics should connect to defined expectations, thresholds, owners, and escalation processes so management can take action when performance falls outside acceptable limits.

Q35. An organization relies on one cloud provider for nearly every critical AI capability, including models, vector storage, and inference infrastructure. Which risk deserves particular attention?

  1. Keyboard compatibility risk
    2. Data-formatting risk only
    3. Third-party concentration risk
    4. Office-location risk

Correct Answer: 3. Third-party concentration risk

Explanation: Concentration risk arises when critical business capabilities depend heavily on one provider, technology, region, or service. A major outage, contractual dispute, security incident, regulatory restriction, price change, or strategic decision by the provider could affect many organizational AI services simultaneously. Supply-chain risk management should therefore evaluate dependencies, substitutability, exit strategies, resilience, data portability, contractual protections, and alternative providers where appropriate. Individual vendor controls may be strong while concentration risk remains high because the organization has limited options if that provider becomes unavailable or unsuitable.

Q36. A critical AI vendor changes its model significantly without notifying the customer. What is the BEST contractual control to reduce this risk?

  1. Require the customer to accept all vendor changes automatically
    2. Define notification, impact assessment, and approval requirements for material service or model changes
    3. Remove all service-level commitments
    4. Permit the vendor to change data-use terms silently

Correct Answer: 2. Define notification, impact assessment, and approval requirements for material service or model changes

Explanation: Material changes to a third-party AI model can affect performance, bias, privacy, security, explainability, or regulatory compliance even when the customer’s own application remains unchanged. Contracts should therefore define when the vendor must notify the customer of significant changes and what assessment, testing, or approval rights apply. The organization may need time to validate new behavior before accepting it into critical processes. This is especially important for externally managed models where the customer has limited visibility into vendor development. Uncontrolled changes undermine lifecycle governance and can invalidate previous risk assessments.

Q37. An AI system supports a business process with a maximum acceptable outage of four hours. Which business continuity metric should reflect this requirement?

  1. Maximum model size
    2. False-positive rate
    3. Mean training time
    4. Recovery Time Objective (RTO)**

Correct Answer: 4. Recovery Time Objective (RTO)

Explanation: Recovery Time Objective defines the targeted maximum time within which a disrupted service or business process should be restored following an outage. If the organization determines that the AI-supported process cannot remain unavailable for more than four hours, the RTO should reflect that business requirement. The AI solution’s architecture, redundancy, fallback procedures, vendor commitments, and recovery plans can then be designed and tested against the target. RTO differs from Recovery Point Objective, which concerns acceptable data-loss periods. AI services should be incorporated into existing business continuity and disaster recovery planning according to their business criticality.

Q38. An AI incident playbook addresses model failure but does not identify who can disable the model in an emergency. What is the MOST important improvement?

  1. Define clear incident authority, escalation paths, and emergency shutdown responsibilities
    2. Remove human involvement from incident response
    3. Require developers to wait for the next scheduled governance meeting
    4. Allow any employee to disable production AI without authorization

Correct Answer: 2. Define clear incident authority, escalation paths, and emergency shutdown responsibilities

Explanation: AI incident response requires clear decision rights so critical actions can be taken quickly and safely. The organization should identify who has authority to disable a model, invoke a fallback process, notify stakeholders, declare an incident, or accept temporary business impacts. Ambiguous authority can delay containment and increase harm. At the same time, emergency powers should be restricted to appropriate roles to avoid unauthorized disruption. AI-specific scenarios should be integrated into the organization’s existing incident management structure, including communications, evidence preservation, escalation, recovery, and lessons learned.

Q39. An organization is deciding whether to accept a moderate residual AI risk. Who should make the acceptance decision?

  1. The designated risk owner with the authority appropriate to the exposure
    2. Any developer who worked on the model
    3. The AI vendor exclusively
    4. An automated model without human accountability

Correct Answer: 1. The designated risk owner with the authority appropriate to the exposure

Explanation: Risk acceptance should be made by an accountable risk owner with sufficient authority to understand and accept the potential business consequences. The required approval level may depend on risk magnitude, regulatory requirements, financial exposure, or organizational policy. Risk professionals provide analysis and recommendations, while technical teams provide evidence about controls and model behavior. However, they should not independently accept business risk unless governance explicitly assigns that authority to them. Documented acceptance should identify the residual risk, rationale, conditions, monitoring requirements, and any expiration or reassessment date.

Q40. An organization uses AI to prioritize enterprise risks for management review. Which control is MOST important to prevent overreliance on the AI output?

  1. Remove access to the underlying risk data
    2. Permit the AI to automatically accept risks
    3. Require validation and human judgment before material risk decisions are finalized
    4. Hide the model’s limitations from decision-makers

Correct Answer: 3. Require validation and human judgment before material risk decisions are finalized

Explanation: AI can improve risk analysis by identifying trends, summarizing large datasets, and highlighting potential priorities, but material risk decisions should remain subject to appropriate validation and human accountability. The model may omit context, reflect biased data, or produce incorrect prioritization. Decision-makers should understand the tool’s limitations and use AI output as evidence rather than unquestioned authority. Independent data checks, explainability, monitoring, and human review help ensure that enterprise risk decisions remain aligned with strategy and risk appetite. ISACA includes leveraging AI within the risk management program while maintaining sound governance and oversight.