Isaca AAIR Practice Test Questions and Exam Dumps Part7 Q121-140

View Full Isaca AAIR Exam Dumps and Practice Test Dumps.


Q121. An enterprise wants to compare AI risk exposure across business units that use different scoring methods. What should the organization do FIRST?

  1. Eliminate all business-unit risk assessments
    2. Establish a common AI risk scoring methodology and definitions
    3. Allow each unit to report only its highest risk
    4. Compare raw scores without normalization

Correct Answer: 2. Establish a common AI risk scoring methodology and definitions

Explanation: Enterprise-level comparison requires a consistent basis for evaluating and communicating risk. A common methodology should define concepts such as likelihood, impact, inherent risk, residual risk, control effectiveness, and escalation thresholds. Without common definitions, a “high” risk in one business unit may not be comparable with a “high” risk elsewhere. Standardization does not prevent local context from being considered; rather, it creates a shared framework for aggregation and reporting. This supports consistent prioritization, governance, and board-level oversight across the organization.

Q122. A new AI use case has significant potential value but falls outside the organization’s current risk appetite. What is the MOST appropriate governance response?

  1. Deploy immediately because expected value is high
    2. Lower the risk score without changing controls
    3. Escalate for an authorized risk appetite or strategy decision before proceeding
    4. Remove the use case from documentation

Correct Answer: 3. Escalate for an authorized risk appetite or strategy decision before proceeding

Explanation: When a proposed use case exceeds established risk appetite, project teams should not proceed unilaterally. The issue should be escalated to the appropriate governance body or executive authority that can decide whether to revise strategy, change appetite, require stronger controls, or reject the use case. High expected value does not automatically override approved risk boundaries. Proper escalation preserves accountability and ensures that strategic tradeoffs are made by those authorized to accept enterprise-level consequences.

Q123. An organization is implementing a new AI governance framework. Which activity BEST helps avoid duplicate controls and conflicting requirements?

  1. Map framework requirements to existing enterprise policies and controls
    2. Create an entirely separate governance organization
    3. Ignore existing risk frameworks
    4. Remove all legacy controls before mapping

Correct Answer: 1. Map framework requirements to existing enterprise policies and controls

Explanation: Framework mapping identifies where existing controls already satisfy new requirements and where gaps remain. This prevents unnecessary duplication, reduces conflicting terminology, and helps the organization integrate AI governance with established enterprise risk, privacy, security, compliance, and internal-control programs. Mapping also helps demonstrate coverage during audits and regulatory reviews. Replacing all existing controls without analysis can create disruption and may eliminate controls that already address important AI risks.

Q124. A high-risk AI system requires human oversight. Which factor is MOST important in determining whether that oversight is effective?

  1. The number of reviewers assigned
    2. Whether reviewers always agree with the model
    3. Whether review is performed after every decision regardless of risk
    4. Whether reviewers can understand, challenge, and override the AI output**

Correct Answer: 4. Whether reviewers can understand, challenge, and override the AI output

Explanation: Human oversight is meaningful only when the reviewer has sufficient authority, information, competence, and practical ability to disagree with the system. A nominal review step in which people simply approve AI recommendations does not provide effective risk reduction. Reviewers should understand the context and limitations of the model and have clear escalation and override procedures. The required level of oversight should be proportionate to the impact and reversibility of the AI-supported decision.

Q125. During AI model development, a dataset contains significantly fewer examples from one population than others. What risk should be assessed MOST directly?

  1. Potential representativeness and fairness issues
    2. Certificate revocation risk
    3. Vendor lock-in only
    4. Disaster recovery risk

Correct Answer: 1. Potential representativeness and fairness issues

Explanation: Underrepresentation of a relevant population can reduce model performance for that group and create unfair or discriminatory outcomes. The organization should assess whether the dataset adequately represents the population affected by the AI system and whether performance differs materially across groups. Data collection, rebalancing, alternative modeling approaches, or use-case restrictions may be needed. The appropriate response depends on the business context and applicable legal or ethical requirements.

Q126. An AI model has high overall accuracy but performs poorly for a small, high-risk subgroup. What should management conclude?

  1. Overall accuracy proves the model is acceptable
    2. Subgroup performance must be evaluated separately because aggregate metrics can hide material risk
    3. The subgroup should be removed from reporting
    4. Accuracy metrics should no longer be used

Correct Answer: 2. Subgroup performance must be evaluated separately because aggregate metrics can hide material risk

Explanation: Aggregate performance can conceal poor outcomes for smaller populations or specialized scenarios. When an affected subgroup faces meaningful consequences, separate performance analysis may be necessary to understand fairness, safety, and reliability. Management should determine whether the disparity is within acceptable tolerance and whether additional controls, model changes, or use restrictions are needed. A model can appear successful overall while still creating unacceptable risk for particular groups.

Q127. A model is retrained using new data but its architecture remains unchanged. Why should the new version still undergo validation?

  1. Retraining can materially change model behavior even without code changes
    2. Validation is needed only when source code changes
    3. New data never affects fairness or accuracy
    4. Previous validation automatically covers all future versions

Correct Answer: 1. Retraining can materially change model behavior even without code changes

Explanation: New training data can alter accuracy, calibration, fairness, robustness, and decision boundaries even when model architecture and code remain identical. The organization should therefore treat retraining as a potentially material lifecycle change. Validation should be proportionate to the change and risk level and may include comparison with the prior version, regression testing, fairness testing, and updated documentation. This ensures that deployment decisions are based on current evidence rather than outdated assumptions.

Q128. An AI system requires multiple external data sources to function. One source suddenly becomes unavailable. What risk management concept is MOST relevant?

  1. Model explainability
    2. Data minimization
    3. Dependency and resilience risk
    4. Intellectual-property ownership only

Correct Answer: 3. Dependency and resilience risk

Explanation: AI systems often rely on upstream data, APIs, cloud services, and other components. Failure of one dependency can degrade or disable the AI system even if the model itself remains healthy. Risk assessment should therefore identify critical dependencies, single points of failure, fallback options, service-level expectations, and recovery arrangements. Understanding dependencies is also important for business continuity, third-party risk, and concentration analysis.

Q129. A generative AI system produces fabricated but plausible information. What risk is MOST directly illustrated?

  1. Data poisoning
    2. Model hallucination
    3. Membership inference
    4. Supply-chain concentration

Correct Answer: 2. Model hallucination

Explanation: Hallucination occurs when a generative AI system produces information that appears coherent and confident but is unsupported or incorrect. This can create significant risk when users rely on AI outputs for legal, financial, medical, or operational decisions. Controls may include grounding responses in trusted sources, human review, confidence or uncertainty handling, restricted use cases, and factual verification. The required controls should reflect the consequence of an incorrect answer.

Q130. An organization wants to know whether an AI control actually reduced the targeted risk after implementation. What is the BEST approach?

  1. Assume implementation means the control is effective
    2. Review only the control documentation
    3. Compare relevant risk indicators and evidence before and after implementation
    4. Remove the risk from the register immediately

Correct Answer: 3. Compare relevant risk indicators and evidence before and after implementation

Explanation: Control effectiveness should be demonstrated through evidence that the control is operating as intended and reducing the target risk. This may involve monitoring KRIs, incident rates, exception volumes, test results, or other relevant measures before and after implementation. Documentation alone proves design intent, not actual effectiveness. Residual risk should be reassessed after treatment based on evidence rather than assumed to have improved automatically.

Q131. A risk owner accepts a material AI risk but provides no rationale or review date. What is the PRIMARY governance weakness?

  1. The model is necessarily inaccurate
    2. Risk acceptance lacks documented accountability and lifecycle management
    3. Risk treatment must always be avoidance
    4. The AI system should be decommissioned immediately

Correct Answer: 2. Risk acceptance lacks documented accountability and lifecycle management

Explanation: Formal risk acceptance should document who accepted the risk, why it was accepted, the residual exposure, any conditions or compensating controls, and when the decision should be reviewed. Without this information, temporary acceptance can become indefinite and management may lose visibility into changing conditions. Good governance ensures that acceptance is an explicit business decision made by an authorized risk owner rather than an undocumented default.

Q132. An AI risk dashboard contains 50 metrics but senior management struggles to identify what requires action. What should be improved?

  1. Add more metrics
    2. Remove thresholds
    3. Focus reporting on material indicators, trends, thresholds, and required decisions
    4. Report only technical logs

Correct Answer: 3. Focus reporting on material indicators, trends, thresholds, and required decisions

Explanation: Effective executive reporting emphasizes information that supports decisions. A large collection of metrics without context can obscure important issues. Dashboards should highlight material exposures, trends, tolerance breaches, major control weaknesses, treatment progress, and items requiring escalation. Supporting detail can remain available for specialists. The goal is not to maximize the number of metrics but to communicate the organization’s AI risk profile clearly and consistently.

Q133. An AI service provider operates from several regions and may process data outside the customer’s home jurisdiction. What risk should be evaluated MOST directly?

  1. Cross-border data transfer and data residency obligations
    2. Model parameter count
    3. Office equipment availability
    4. Training-course completion rates

Correct Answer: 1. Cross-border data transfer and data residency obligations

Explanation: AI services may process, store, or replicate data across multiple jurisdictions. Organizations should identify where data is handled and whether cross-border transfers comply with legal, regulatory, contractual, and customer requirements. Data residency commitments may also affect cloud architecture and vendor selection. The organization should assess subprocessors, transfer mechanisms, contractual safeguards, and deletion requirements where relevant. Geographic processing can create compliance risk even when the AI system itself performs well technically.

Q134. A third-party AI provider experiences a major outage that affects a critical business process. What is the BEST evidence that the organization was prepared?

  1. The vendor had a well-designed website
    2. A tested continuity plan with defined fallback and escalation procedures
    3. The contract was signed by senior management
    4. The organization had many AI projects

Correct Answer: 2. A tested continuity plan with defined fallback and escalation procedures

Explanation: Preparedness is demonstrated through tested procedures rather than documentation alone. A continuity plan should identify fallback processes, communication responsibilities, decision authority, recovery objectives, vendor coordination, and alternative arrangements where appropriate. Exercises or tests can reveal hidden dependencies and unrealistic assumptions before a real outage occurs. Contractual commitments remain important but do not guarantee that the organization itself can continue operating during a provider disruption.

Q135. Which factor should MOST influence the frequency of control testing for an AI system?

  1. The system’s risk level, rate of change, and control criticality
    2. The number of pages in the policy
    3. The developer’s preferred schedule
    4. The vendor’s marketing calendar

Correct Answer: 1. The system’s risk level, rate of change, and control criticality

Explanation: Control testing frequency should be risk based. High-impact systems, rapidly changing models, and critical controls may require more frequent testing than stable, low-risk use cases. Significant incidents, material changes, new regulations, or emerging threats can also trigger out-of-cycle testing. Fixed schedules can provide a baseline, but governance should allow testing intensity to increase when risk changes. This helps assurance resources focus where control failure could have the greatest consequence.

Q136. An AI program wants to identify whether risk treatment actions are being completed on time. Which metric is MOST useful?

  1. Percentage of overdue AI risk remediation actions
    2. Number of model parameters
    3. Number of governance meetings
    4. Average employee tenure

Correct Answer: 1. Percentage of overdue AI risk remediation actions

Explanation: Overdue remediation directly indicates whether agreed risk-treatment actions are being implemented within expected timelines. A rising percentage can signal weak accountability, resource constraints, or ineffective governance. The metric should be paired with risk severity because overdue remediation for a critical risk may require stronger escalation than a low-risk item. Defined owners, due dates, and escalation rules are essential for making treatment plans actionable.

Q137. An AI incident occurs because an approved model was used for a different purpose than originally assessed. What is the PRIMARY lesson?

  1. Intended-use boundaries must be governed and changes in use should trigger reassessment
    2. Model validation is unnecessary
    3. Risk ownership should be removed
    4. AI systems should never be reused

Correct Answer: 1. Intended-use boundaries must be governed and changes in use should trigger reassessment

Explanation: An AI model can be suitable for one purpose and inappropriate for another. Changes in users, decisions, data, scale, autonomy, or business context may materially alter risk. Governance should define approved use and require reassessment when the model is repurposed beyond that boundary. This prevents organizations from assuming that prior validation and risk acceptance automatically apply to new use cases.

Q138. A model’s monitoring system identifies a significant fairness deterioration in production. What should happen NEXT?

  1. Suppress the alert to avoid reputational risk
    2. Follow the predefined escalation and remediation process, including possible restriction or suspension
    3. Increase model autonomy
    4. Remove fairness metrics from monitoring

Correct Answer: 2. Follow the predefined escalation and remediation process, including possible restriction or suspension

Explanation: A material fairness deterioration should trigger an established response. The organization may need to investigate data changes, retraining, model behavior, or operational conditions and determine whether the system should be restricted, rolled back, or suspended while remediation occurs. Thresholds should be linked to clear ownership and decision authority. Ignoring or hiding the issue would undermine governance and could increase legal, ethical, and reputational exposure.

Q139. An AI governance team receives multiple recurring exceptions for the same control requirement. What should the team consider FIRST?

  1. Whether the underlying policy or control design is impractical or misaligned with operations
    2. Automatically approve all future exceptions
    3. Stop documenting exceptions
    4. Increase exception duration indefinitely

Correct Answer: 1. Whether the underlying policy or control design is impractical or misaligned with operations

Explanation: Repeated exceptions can indicate more than poor compliance; they may reveal that the policy, control, or implementation model is poorly designed for actual business conditions. Governance should analyze root causes before continuing to approve the same deviation. The organization may need to redesign the control, provide better tooling, revise requirements, or strengthen enforcement. Exception trends are valuable governance signals and should inform continuous improvement.

Q140. An organization is using AI to summarize audit findings for executives. What is the MOST important control before distribution?

  1. Allow the AI to publish directly
    2. Remove access to source findings
    3. Increase response creativity
    4. Require qualified human verification of material facts and conclusions**

Correct Answer: 4. Require qualified human verification of material facts and conclusions

Explanation: AI-generated summaries can omit nuance, misstate severity, or invent conclusions even when the source material is correct. A qualified reviewer should verify that material findings, ratings, business implications, and recommendations accurately reflect the underlying evidence before distribution. The reviewer should also ensure confidential information is handled appropriately. AI can improve efficiency, but accountability for formal audit and risk communication remains with authorized professionals.