View Full Isaca AAIR Exam Dumps and Practice Test Dumps.
Q381. An organization plans to introduce AI into a process that directly supports a strategic corporate objective. What should the AI risk professional establish FIRST?
- Which AI vendor offers the most features
2. How the proposed AI use case supports the objective and what risks could affect value realization
3. Whether the model can operate without documentation
4. How quickly the project can bypass normal governance
Correct Answer: 2. How the proposed AI use case supports the objective and what risks could affect value realization
Explanation: AI risk management should support value creation rather than operate independently from business strategy. Before selecting technology or designing controls, the organization should understand the business problem, expected benefits, affected stakeholders, and risks that could prevent the AI initiative from creating the intended value. This creates the context needed to determine appropriate risk appetite, governance, and lifecycle requirements. A sophisticated AI implementation that does not address a meaningful business objective may create cost and exposure without sufficient benefit. ISACA emphasizes alignment of AI use cases with organizational goals and risk appetite.
Q382. An AI governance committee wants to delegate some low-risk approvals to business units while retaining oversight of high-risk systems. What governance design is MOST appropriate?
- Require the board to approve every AI change
2. Eliminate central governance entirely
3. Permit unrestricted self-approval by all teams
4. Establish risk-based delegated authority with defined thresholds and escalation requirements**
Correct Answer: 4. Establish risk-based delegated authority with defined thresholds and escalation requirements
Explanation: Risk-based delegation allows governance to remain efficient while preserving appropriate oversight. Low-risk AI use cases may be approved within business units if predefined criteria are met, while high-impact, autonomous, regulated, or sensitive-data use cases can be escalated to central governance. Thresholds should be documented and applied consistently. This avoids unnecessary bottlenecks while maintaining enterprise accountability. Requiring central approval for every minor AI activity can slow innovation, while unrestricted self-approval can create inconsistent risk treatment. Delegated authority works best when roles, limits, evidence requirements, and exception processes are clearly defined.
Q383. A company discovers that AI policy requirements differ from an existing enterprise privacy policy. What should happen FIRST?
- Reconcile the conflicting requirements through the appropriate governance and policy-management process
2. Apply only the AI policy
3. Apply whichever policy was written most recently
4. Allow project teams to choose independently
Correct Answer: 1. Reconcile the conflicting requirements through the appropriate governance and policy-management process
Explanation: Conflicting policies can create inconsistent implementation and unclear accountability. The organization should determine the intended requirements, applicable legal obligations, policy hierarchy, and whether one policy must be revised. Relevant stakeholders such as privacy, legal, risk, security, and AI governance should participate in the reconciliation. Simply choosing the newer document does not guarantee the correct outcome. Once resolved, the organization should communicate the interpretation and update related procedures and controls. AI governance should integrate with existing enterprise policies rather than creating parallel requirements that contradict established programs.
Q384. A high-impact AI system affects individuals who may not understand how to challenge its decisions. Which governance capability is MOST important?
- Larger model capacity
2. More automated decisions
3. Accessible transparency, challenge, and redress mechanisms
4. Fewer records of AI-supported decisions
Correct Answer: 3. Accessible transparency, challenge, and redress mechanisms
Explanation: Individuals affected by consequential AI decisions may need a meaningful way to understand the AI’s role, challenge an outcome, provide additional information, and seek human review or remediation. Such mechanisms support accountability, fairness, and trustworthiness and may also be required under applicable laws or policies. A challenge process should be accessible and understandable rather than purely technical. Increasing automation does not solve concerns about rights or unfair outcomes. Appropriate records should also be retained so the organization can reconstruct and review disputed decisions.
Q385. An organization trains an AI model on data collected from several business processes. Before reusing those records, what should the data governance team verify?
- Only that storage capacity is sufficient
2. Only that the dataset is large
3. Whether every record has the same file type
4. Whether the proposed reuse is permitted, appropriate, and consistent with data-governance obligations**
Correct Answer: 4. Whether the proposed reuse is permitted, appropriate, and consistent with data-governance obligations
Explanation: Data gathered for one business purpose cannot automatically be reused for AI training. The organization should evaluate legal basis, purpose limitation, consent where applicable, contractual restrictions, classification, retention, confidentiality, and any commitments made to data subjects or customers. Data lineage should identify where the records originated and how they have been transformed. A large or technically clean dataset can still be unsuitable for AI use if the organization lacks appropriate rights or if reuse conflicts with privacy expectations. Responsible AI development therefore begins with lawful and governed data use.
Q386. A machine-learning model uses hundreds of features, but many are unnecessary for achieving acceptable performance. Which risk-management principle should the team consider?
- Minimize unnecessary data and features to reduce exposure and complexity
2. Add more features regardless of need
3. Retain all available data indefinitely
4. Avoid documenting feature selection
Correct Answer: 2. Minimize unnecessary data and features to reduce exposure and complexity
Explanation: Using unnecessary features can increase privacy exposure, security risk, model complexity, bias pathways, and maintenance burden without meaningful performance benefit. Feature minimization extends the broader principle of data minimization into model design. The development team should evaluate whether each feature contributes sufficient value and whether sensitive attributes or proxy variables are necessary. Reducing unnecessary inputs can also improve explainability and reduce attack surface. This does not mean automatically selecting the smallest possible feature set; the objective is to retain what is reasonably needed for the approved purpose and performance requirements.
Q387. A model performs well on average but fails badly on unusual combinations of valid input values. Which testing approach is MOST appropriate?
- Test only the most common inputs
2. Remove unusual cases from monitoring
3. Perform edge-case and boundary-condition testing
4. Increase model autonomy
Correct Answer: 3. Perform edge-case and boundary-condition testing
Explanation: Average performance can hide serious weaknesses in rare but valid situations. Edge-case and boundary testing examines conditions near decision thresholds, unusual feature combinations, extreme values, incomplete inputs, and other scenarios that may occur less frequently but still matter. This is particularly important when the consequences of an incorrect output are significant. Findings may lead to model improvements, human escalation, input restrictions, or safer failure behavior. High-impact AI validation should therefore include more than routine samples and should reflect plausible adverse or unusual operating conditions.
Q388. A high-risk AI system uses a newly updated model, but the previous approved version is still available. What capability does retaining the earlier version primarily support?
- Permanent avoidance of future validation
2. Controlled rollback if the new model behaves unexpectedly
3. Elimination of all change-management requirements
4. Automatic risk acceptance
Correct Answer: 1. Controlled rollback if the new model behaves unexpectedly
Explanation: Retaining a previous known-good model supports recovery if the new deployment produces unacceptable errors, fairness issues, security problems, or operational degradation. Effective rollback requires more than keeping the model file; dependencies, configuration, data compatibility, and deployment procedures should also support restoration. Rollback is a corrective capability and complements predeployment validation and postdeployment monitoring. It does not eliminate the need for change management or approval. Organizations should define objective rollback triggers and test the procedure so restoration can occur quickly when production behavior falls outside approved tolerances.
Q389. A risk team wants to prioritize an AI scenario that could persist undetected for months and accumulate harm gradually. Which additional risk characteristic is MOST relevant?
- Persistence or duration of exposure
2. Model name length
3. Development-team size
4. Vendor headquarters location only
Correct Answer: 2. Persistence or duration of exposure
Explanation: Some AI failures create immediate harm, while others can remain undetected and accumulate consequences over long periods. Persistence helps management understand whether exposure can compound before discovery. For example, a subtle discriminatory model may affect many decisions over months without triggering an obvious operational incident. This characteristic can influence monitoring intensity, detection controls, review frequency, and remediation urgency. Risk methodologies commonly focus on likelihood and impact, but additional dimensions such as velocity, detectability, reversibility, and persistence can improve prioritization for complex AI scenarios.
Q390. An organization identifies a significant AI risk for which no feasible mitigation currently exists, but the business activity is optional. What treatment is MOST appropriate if exposure exceeds tolerance?
- Accept the risk automatically
2. Hide the risk from reporting
3. Transfer it to the development team
4. Avoid the risk by not proceeding with the activity**
Correct Answer: 4. Avoid the risk by not proceeding with the activity
Explanation: Risk avoidance removes the activity creating the exposure when residual risk cannot be reduced within acceptable tolerance and the activity is not mandatory. This may mean not deploying the AI system, disabling an autonomous capability, or selecting a different process. Acceptance would be inappropriate if exposure remains outside authorized appetite. Transfer may shift certain financial consequences but does not necessarily remove operational, legal, or reputational risk. Treatment decisions should reflect business value, feasibility, legal obligations, risk appetite, and whether alternative approaches can accomplish the underlying objective more safely.
Q391. A control is designed to detect unauthorized changes to AI system prompts. What evidence BEST shows the control is functioning?
- Logs and test results showing prompt changes are detected and appropriately escalated
2. The prompt document exists
3. The model owner states that prompts rarely change
4. The system has a high accuracy score
Correct Answer: 2. Logs and test results showing prompt changes are detected and appropriately escalated
Explanation: Detective control effectiveness requires evidence that relevant events are actually identified and lead to appropriate response. Testing can introduce controlled prompt changes and confirm that the monitoring system detects them, records sufficient context, and alerts the responsible team. Production logs can provide additional evidence that the process continues operating over time. A written prompt or verbal assurance does not demonstrate control effectiveness. Model accuracy is unrelated to whether unauthorized configuration changes are detected. Material AI prompt changes can alter behavior significantly and therefore may require strong change-monitoring controls.
Q392. An organization uses the same individual to develop, approve, and validate a high-risk AI control. What is the PRIMARY concern?
- The control will automatically fail
2. The control will become too expensive
3. Independence of control validation may be insufficient
4. AI models cannot use the control
Correct Answer: 3. Independence of control validation may be insufficient
Explanation: High-risk controls benefit from sufficient independent challenge. When one person designs, approves, and validates the same control, confirmation bias or unrecognized weaknesses may reduce assurance quality. Organizational size and practicality influence the degree of separation possible, so complete independence is not always required. Compensating measures can include peer review, second-line risk validation, independent testing, or periodic assurance. The objective is to ensure that control effectiveness is not based solely on self-assessment by the person responsible for creating and operating it.
Q393. A model’s KRI remains within tolerance, but a related KCI shows that a critical safeguard is failing frequently. What should management do?
- Ignore the KCI until the KRI breaches tolerance
2. Investigate whether residual risk is increasing despite the current KRI level
3. Remove the KCI from reporting
4. Automatically classify the risk as low
Correct Answer: 1. Investigate whether residual risk is increasing despite the current KRI level
Explanation: KRIs and KCIs provide different but complementary information. A KRI may not immediately reflect deterioration in the control environment, particularly if it is a lagging measure. A failing critical control can signal that exposure is increasing before incidents or other risk outcomes become visible. Management should evaluate the control failure, reassess residual risk, and determine whether compensating controls or remediation are needed. Waiting for the risk indicator itself to breach tolerance may allow preventable exposure to persist. Leading control information is valuable precisely because it can provide earlier warning.
Q394. Senior management receives monthly AI risk reports, but each month uses a different scoring scale. What is the MOST important improvement?
- Add additional scoring scales
2. Standardize the rating methodology so trends are comparable over time
3. Remove historical comparisons
4. Report only qualitative narratives
Correct Answer: 4. Standardize the rating methodology so trends are comparable over time
Explanation: Trend analysis requires consistency. If risk-rating scales change frequently, movement may reflect methodology differences rather than actual changes in exposure. The organization should establish a stable methodology with documented definitions, thresholds, and data sources and use formal change control when modifications are necessary. If the methodology must change, management should explain the effect and recalculate prior periods where practical. Reliable reporting allows decision-makers to identify genuine deterioration or improvement and prevents misleading comparisons caused by measurement changes.
Q395. A critical AI supplier begins outsourcing more of its service to subcontractors. What should the customer reassess?
- Only the supplier’s marketing position
2. Whether outsourcing automatically improves risk
3. Supply-chain exposure, control reliance, data handling, and concentration across new subcontractors
4. Only the supplier’s pricing
Correct Answer: 3. Supply-chain exposure, control reliance, data handling, and concentration across new subcontractors
Explanation: Increased subcontracting can materially alter the supplier’s risk profile. New parties may process customer data, host critical components, provide foundation models, or introduce geographic and concentration dependencies. The customer should determine whether contractual notification requirements apply and whether new assurance is needed. The assessment should focus on material upstream dependencies rather than every minor supplier. A provider can remain contractually responsible while still creating increased operational or compliance exposure through its subcontractors. Ongoing supplier monitoring should capture such changes rather than relying only on initial due diligence.
Q396. A vendor’s AI service is critical, but the contract contains no requirement to return customer data in a usable format at termination. What risk is MOST directly increased?
- Exit and portability risk
2. Model calibration risk
3. Employee awareness risk
4. Physical-security risk
Correct Answer: 1. Exit and portability risk
Explanation: If data cannot be returned in a usable format, migration to another provider can become difficult, expensive, or impossible. Exit planning should define data export formats, metadata, timing, deletion, assistance, and other transition obligations. Portability is particularly important when AI services rely on prompts, configuration, embeddings, logs, model outputs, or specialized datasets that another platform may need. A technically strong provider can still create high lock-in risk when contracts do not support transition. Exit requirements should therefore be negotiated before the organization becomes operationally dependent.
Q397. An AI incident involves corrupted outputs, but it is unclear whether the cause was an attack or an ordinary model failure. What should incident responders do?
- Assume malicious activity immediately
2. Preserve evidence and investigate both security and nonsecurity failure hypotheses
3. Close the incident because cause is uncertain
4. Delete the affected model before collecting evidence
Correct Answer: 2. Preserve evidence and investigate both security and nonsecurity failure hypotheses
Explanation: Similar AI symptoms can result from attacks, software defects, bad data, configuration errors, drift, or infrastructure problems. Responders should avoid prematurely deciding on one cause. Evidence such as logs, model versions, data changes, access records, configuration, and external dependencies should be preserved and analyzed systematically. Containment should proceed when ongoing harm is possible, but investigation should remain broad enough to identify the true cause. This improves remediation because security controls will not fix an ordinary data pipeline defect, and model retraining will not resolve a compromised system.
Q398. An AI service is considered critical, but the organization’s business continuity plan assumes its third-party provider will recover within four hours without supporting evidence. What is the BEST action?
- Treat the assumption as sufficient
2. Remove the provider from the BIA
3. Validate the provider’s recovery capability against the organization’s continuity requirements
4. Increase the RTO automatically
Correct Answer: 1. Validate the provider’s recovery capability against the organization’s continuity requirements
Explanation: Continuity assumptions about third parties should be supported by evidence. The organization can review contractual commitments, independent assurance, provider testing, architectural information, or joint exercises to determine whether supplier recovery capability aligns with business requirements. If the provider cannot meet the required recovery time, management may need fallback processes, alternate providers, additional redundancy, or formal risk acceptance. Adjusting the organization’s RTO merely to match the supplier would undermine the purpose of business impact analysis unless decision-makers explicitly determine that the business can tolerate the longer disruption.
Q399. A recovery test restores an AI application correctly, but the restored environment lacks historical logs required for audit and investigation. What should be improved?
- Only model training procedures
2. The AI risk appetite statement
3. Employee prompt-writing skills
4. Backup and recovery requirements for required operational and audit evidence**
Correct Answer: 4. Backup and recovery requirements for required operational and audit evidence
Explanation: Recovery requirements may include more than the application, model, and production data. Logs and decision records can be necessary for audit, compliance, security investigation, customer disputes, and model-performance analysis. The organization should determine which evidence must remain available after a disaster and ensure backup, retention, and recovery procedures support those requirements. Not every log needs identical recovery objectives, so prioritization should reflect legal, business, and investigative needs. Recovery testing is valuable because it reveals whether required evidence actually survives a disruption.
Q400. An organization wants to use AI to estimate emerging risk scenarios from internal and external data. What is the BEST way to govern the model’s output?
- Treat all AI-generated estimates as official enterprise risk ratings
2. Remove expert review to avoid subjective judgment
3. Validate assumptions, evidence, and methodology before incorporating estimates into formal risk decisions
4. Allow the AI model to accept the risks it identifies
Correct Answer: 3. Validate assumptions, evidence, and methodology before incorporating estimates into formal risk decisions
Explanation: AI can help identify patterns and emerging scenarios that risk teams might otherwise miss, but generated estimates may rely on incomplete data, hidden assumptions, or unreliable relationships. Qualified risk professionals should validate the underlying evidence, methodology, relevance, and uncertainty before using the output in formal risk ratings or treatment decisions. The AI system itself should also be monitored for performance and limitations. This approach captures the analytical benefits of AI while preserving human accountability for official enterprise risk management decisions.