View Full Isaca AAIR Exam Dumps and Practice Test Dumps.
Q141. An organization has operated its AI governance framework for one year. What is the BEST way to determine whether the framework remains effective?
- Review only whether all governance documents are still available
2. Measure only the number of AI projects approved
3. Evaluate outcomes, exceptions, incidents, control performance, stakeholder feedback, and changes in the risk environment
4. Assume the framework remains effective until a regulator identifies a problem
Correct Answer: 3. Evaluate outcomes, exceptions, incidents, control performance, stakeholder feedback, and changes in the risk environment
Explanation: Governance effectiveness should be evaluated using evidence from actual operation. Useful indicators include recurring exceptions, incidents, risk tolerance breaches, control failures, stakeholder feedback, regulatory changes, and whether AI systems continue to align with business objectives and risk appetite. Documentation and approval counts provide limited evidence because a well-documented framework can still operate poorly. Periodic effectiveness reviews allow the organization to update policies, responsibilities, escalation thresholds, and controls as AI technologies and risks evolve. Continuous improvement is particularly important for AI because new use cases, threats, legal obligations, and model capabilities can change the risk landscape quickly.
Q142. A business unit proposes a highly complex AI algorithm even though a simpler model provides similar business performance. Which consideration should the risk professional emphasize?
- Whether added complexity creates risk without proportional business value
2. Whether the complex model has more parameters
3. Whether the complex model is newer
4. Whether competitors use a similar algorithm
Correct Answer: 1. Whether added complexity creates risk without proportional business value
Explanation: Model selection should balance business value, technical performance, risk, explainability, maintainability, cost, and operational complexity. A more complex model may create additional challenges in validation, explainability, monitoring, security, infrastructure, and skills without delivering significant business improvement. The newest or largest model is not automatically the most appropriate. Risk professionals should encourage selection of an AI solution that is fit for purpose and proportionate to the organization’s objectives and risk appetite. This reflects ISACA’s focus on evaluating AI models and solutions for suitability throughout their lifecycle rather than equating greater technical sophistication with better governance.
Q143. An AI system is approved for internal document summarization. Management later wants it to make binding customer decisions. What should happen BEFORE the new use begins?
- Reuse the original approval because the same model is involved
2. Increase monitoring only after deployment
3. Ask the vendor whether other customers use it this way
4. Perform a new risk assessment and approval based on the materially changed use case**
Correct Answer: 4. Perform a new risk assessment and approval based on the materially changed use case
Explanation: Risk is determined not only by the model but also by how it is used. Moving from internal summarization to binding customer decisions changes the impact, affected stakeholders, legal requirements, fairness concerns, oversight needs, and consequences of error. The original assessment may therefore no longer be valid. Change management should trigger reassessment when a system’s purpose, autonomy, data, users, scale, or decision impact changes materially. The organization should evaluate additional controls, validation, explainability, appeal mechanisms, and risk acceptance before authorizing the new use.
Q144. A customer asks why an AI-supported decision was made. Which documentation would provide the MOST useful governance evidence?
- The office location of the development team
2. Records describing the decision process, model version, relevant inputs, limitations, and available explanation
3. The vendor’s advertising materials
4. The number of processors used during training
Correct Answer: 2. Records describing the decision process, model version, relevant inputs, limitations, and available explanation
Explanation: Meaningful governance evidence should help reconstruct how a decision was produced and what limitations apply. Depending on the system and legal requirements, relevant documentation may include the model version, input data categories, important decision factors, confidence or explanation information, human review, and approved use. This supports customer inquiries, complaints, audit, regulatory review, and incident investigation. Technical infrastructure statistics alone do not explain a decision. Documentation should be proportionate to the decision’s impact and designed so stakeholders can challenge or review consequential AI-supported outcomes when required.
Q145. An organization purchases a dataset from a commercial provider for AI training. Which due diligence step is MOST important before using it?
- Confirm only that the dataset is large
2. Check whether the dataset uses a common file format
3. Confirm that competitors use the same provider
4. Verify provenance, licensing, collection rights, permitted uses, quality, and relevant privacy obligations**
Correct Answer: 4. Verify provenance, licensing, collection rights, permitted uses, quality, and relevant privacy obligations
Explanation: Purchased data can create legal, privacy, intellectual-property, quality, and bias risks. The organization should understand where the data originated, whether the provider had appropriate rights to collect and license it, whether the intended AI use is permitted, and whether relevant privacy requirements are satisfied. Quality and representativeness should also be evaluated because lawful data can still be unsuitable for a model. A large dataset or common file format provides no assurance regarding rights or fitness for purpose. Data due diligence should be completed before the information becomes embedded in model training and difficult to remove.
Q146. A lending model does not use a protected characteristic directly, but one input variable is highly correlated with it and drives different outcomes. What risk should be evaluated?
- Proxy discrimination
2. Certificate expiration
3. Business continuity only
4. Model extraction
Correct Answer: 1. Proxy discrimination
Explanation: Proxy discrimination can occur when a model uses variables that indirectly represent or strongly correlate with protected characteristics, producing discriminatory outcomes even though the protected attribute itself is omitted. Risk assessment should therefore examine model features, relationships among variables, subgroup outcomes, and legal context rather than assuming fairness because explicit protected fields are absent. Appropriate controls may include feature review, fairness testing, alternative variables, model changes, or enhanced human oversight. This demonstrates why AI fairness assessment must focus on actual outcomes and decision mechanisms instead of relying only on whether certain data fields are directly present.
Q147. An AI model produces confidence scores, but decision-makers consistently treat a 60% confidence prediction as certain. What risk is MOST directly present?
- Data residency risk
2. Vendor concentration risk
3. Misinterpretation and automation bias in human decision-making
4. Training data poisoning
Correct Answer: 3. Misinterpretation and automation bias in human decision-making
Explanation: Human users can over-trust AI outputs, particularly when scores or recommendations are presented with apparent precision. A 60% confidence level still represents substantial uncertainty, and treating it as certainty can create poor decisions. Controls may include better interface design, user training, calibrated confidence measures, documented limitations, and escalation rules for uncertain cases. Human oversight is effective only if reviewers can challenge AI outputs rather than automatically defer to them. Risk management should therefore consider how humans interact with AI, not merely whether the underlying model performs adequately in technical testing.
Q148. A production AI application generates free-form text that is inserted directly into a downstream automated workflow. What control is MOST important before the text drives business actions?
- Increase the model’s response length
2. Validate and constrain AI output before downstream execution
3. Assume generated output follows business rules
4. Remove all logging from the workflow
Correct Answer: 2. Validate and constrain AI output before downstream execution
Explanation: Generative AI output is probabilistic and can contain incorrect, malformed, unsafe, or unexpected content. When outputs drive automated actions, a deterministic validation layer should check required format, allowed values, business rules, authorization, and scope before execution. Structured output schemas, policy checks, approval thresholds, and least-privilege downstream permissions can reduce risk. Relying solely on prompt instructions is insufficient because models can hallucinate or be manipulated. The level of validation should increase with the potential impact and irreversibility of the downstream action.
Q149. An AI risk assessment identifies a scenario with moderate likelihood and catastrophic impact. Which action is MOST appropriate?
- Evaluate the scenario against risk appetite and consider treatment proportionate to the catastrophic impact
2. Ignore it because likelihood is not high
3. Automatically classify it as acceptable
4. Remove it from the risk register to avoid overstating exposure
Correct Answer: 1. Evaluate the scenario against risk appetite and consider treatment proportionate to the catastrophic impact
Explanation: Risk assessment must consider both likelihood and consequence. A scenario with catastrophic impact may require significant controls, contingency planning, or avoidance even if likelihood is only moderate. The organization should compare the exposure with defined risk appetite and tolerance and assess available treatment options. High-consequence scenarios may also warrant stress testing, stronger monitoring, or executive escalation. Focusing only on probability can underestimate tail risks. Effective AI risk management considers the full scenario, including affected stakeholders, reversibility, velocity, regulatory impact, and potential cascading effects.
Q150. An organization wants to compare the effect of several proposed controls before selecting a treatment plan for an AI risk. Which approach is MOST useful?
- Choose the least expensive control automatically
2. Select every available control regardless of cost or effectiveness
3. Ignore residual risk until implementation is complete
4. Compare expected risk reduction, feasibility, cost, and resulting residual risk for each option**
Correct Answer: 4. Compare expected risk reduction, feasibility, cost, and resulting residual risk for each option
Explanation: Risk treatment decisions should consider how much each control reduces exposure, whether it is feasible, its implementation and operating costs, and the residual risk remaining afterward. The cheapest control may provide inadequate protection, while implementing every possible control can be inefficient or disproportionate. Management needs sufficient information to choose a treatment aligned with risk appetite and business objectives. The analysis should also consider side effects such as reduced usability, slower processes, or concentration risk. Treatment selection is therefore an optimization problem involving risk reduction, value, feasibility, and organizational constraints.
Q151. A control prevents unauthorized users from changing an AI model’s production configuration. Which control category is MOST directly represented?
- Recovery control
2. Preventive access control
3. Detective monitoring control
4. Corrective backup control
Correct Answer: 2. Preventive access control
Explanation: Restricting configuration changes to authorized users aims to prevent unauthorized activity before it occurs, making it a preventive control. Examples include role-based access control, privileged access management, strong authentication, and separation of duties. Detective controls could alert when a change occurs, while corrective controls might restore an approved configuration after unauthorized modification. Strong AI control environments often combine preventive, detective, and corrective measures so one control’s failure does not leave the system unprotected. Control classification helps management understand coverage and identify gaps.
Q152. A monitoring control detects changes to production model files but generates so many false alerts that operators routinely ignore them. What should the risk manager conclude?
- The control is effective because alerts exist
2. The control should be classified as preventive
3. Control operating effectiveness is impaired because excessive false positives undermine response
4. Monitoring should be discontinued permanently
Correct Answer: 3. Control operating effectiveness is impaired because excessive false positives undermine response
Explanation: A detective control provides value only when meaningful events can be identified and acted upon. Excessive false positives create alert fatigue and can cause genuine unauthorized changes to be overlooked. The control may need better baselines, tuning, prioritization, or contextual information. Management should measure not just whether alerts are generated but whether the control reliably identifies material events and supports timely response. Eliminating monitoring entirely would create another gap. Control optimization should improve signal quality while preserving sufficient detection coverage.
Q153. A key risk indicator for AI privacy events has exceeded its escalation threshold. What is the BEST immediate governance response?
- Change the threshold to match current performance
2. Stop collecting the indicator
3. Wait until the annual risk review
4. Escalate according to the predefined process and investigate the underlying exposure**
Correct Answer: 4. Escalate according to the predefined process and investigate the underlying exposure
Explanation: Thresholds provide value only when breaches lead to action. If a privacy-related KRI exceeds its escalation level, responsible stakeholders should investigate the cause, determine whether the risk profile has changed, and decide whether controls or restrictions are required. The issue may reflect a temporary anomaly or a material deterioration, but that determination requires analysis. Automatically changing the threshold to avoid escalation undermines governance. Risk indicators should have defined owners, thresholds, reporting frequency, and response procedures established before breaches occur.
Q154. An AI risk dashboard shows that risk exposure is stable but control failures are increasing. What should management do FIRST?
- Investigate whether the apparent stable risk rating still reflects the deteriorating control environment
2. Ignore control failures because the risk score is unchanged
3. Remove control metrics from the dashboard
4. Automatically lower the risk rating
Correct Answer: 1. Investigate whether the apparent stable risk rating still reflects the deteriorating control environment
Explanation: Residual risk assessments depend partly on control effectiveness. If controls are failing more frequently, the existing risk rating may no longer be accurate even if the dashboard has not yet changed. Management should reassess control performance and determine whether residual exposure has increased. Lagging risk measures can remain stable temporarily while leading indicators deteriorate. Effective risk programs use both risk and control information to identify emerging weaknesses before incidents or losses occur. A stable historical rating should never override current evidence showing that safeguards are degrading.
Q155. An organization is evaluating a critical AI vendor. Which evidence BEST supports understanding the vendor’s financial resilience?
- Its social media follower count
2. Appropriate financial information and indicators relevant to continued service capability
3. Number of AI models in its catalog
4. Size of its office building
Correct Answer: 2. Appropriate financial information and indicators relevant to continued service capability
Explanation: Third-party risk extends beyond cybersecurity. A vendor experiencing severe financial stress may reduce services, fail to invest in controls, be acquired, or cease operations. For critical providers, the organization should evaluate appropriate financial evidence and monitor material changes over time. The level of review should reflect criticality and concentration risk. Financial resilience should be considered together with security, compliance, operational performance, contractual obligations, data handling, and exit readiness. Popularity or product breadth does not establish that a provider can sustain critical service commitments.
Q156. A cloud provider hosts several critical AI vendors used by the organization. What risk may be underestimated if each vendor is assessed separately?
- Model documentation risk
2. Employee training risk
3. Shared cloud concentration and correlated outage risk
4. Individual model calibration risk
Correct Answer: 3. Shared cloud concentration and correlated outage risk
Explanation: Several independent AI vendors can appear diversified while depending on the same underlying cloud provider, region, identity service, or infrastructure. A single upstream outage could therefore disrupt all of them simultaneously. Supply-chain risk assessment should look beyond direct providers to identify shared dependencies and concentration. This enterprise-level view can influence continuity planning, architecture, vendor selection, contractual requirements, and fallback strategies. Evaluating each direct vendor in isolation may miss common-cause risks that become visible only when dependencies are aggregated.
Q157. During an AI incident, management must decide whether affected customers require notification. What should drive the decision MOST directly?
- Applicable legal, regulatory, contractual, and documented incident criteria
2. Whether the incident occurred outside business hours
3. The model’s parameter count
4. Whether the incident received media coverage first
Correct Answer: 1. Applicable legal, regulatory, contractual, and documented incident criteria
Explanation: Notification requirements should be determined through established legal, regulatory, contractual, privacy, and incident-response criteria. Different incidents may trigger different deadlines and obligations depending on data involved, affected individuals, jurisdictions, severity, or customer agreements. Decisions should involve appropriate legal, privacy, risk, and business stakeholders rather than being based on publicity or convenience. Predefined notification procedures reduce delay and inconsistent judgment during high-pressure incidents. AI-specific scenarios should therefore be incorporated into existing incident communication and regulatory response processes.
Q158. A business impact analysis identifies an AI service as critical because several revenue-generating processes depend on it. What should happen NEXT?
- Increase the model size
2. Define recovery priorities, dependencies, RTO/RPO requirements, and continuity strategies
3. Remove the service from the BIA
4. Assume the vendor’s recovery plan is sufficient
Correct Answer: 3. Define recovery priorities, dependencies, RTO/RPO requirements, and continuity strategies
Explanation: Once an AI service is identified as business critical, the organization should translate that criticality into practical continuity and recovery requirements. This includes understanding dependencies, establishing recovery time and recovery point objectives where relevant, defining fallback procedures, and ensuring vendor capabilities align with enterprise needs. Plans should be tested rather than assumed to work. The vendor’s resilience is only one part of the solution because internal processes, integrations, data, credentials, and downstream systems may also determine whether the business service can recover.
Q159. An AI incident was caused by a configuration error introduced during an emergency change. What activity BEST addresses the underlying cause after recovery?
- Root-cause analysis and improvement of the relevant change controls
2. Delete the incident record
3. Increase the model’s creativity
4. Stop tracking emergency changes
Correct Answer: 1. Root-cause analysis and improvement of the relevant change controls
Explanation: Recovery restores service, but root-cause analysis identifies why the incident occurred and what should change to reduce recurrence. If an emergency configuration change caused the failure, the organization should review approval, testing, segregation of duties, rollback, documentation, and emergency-change procedures. Lessons learned should feed into governance, training, and technical controls. Deleting evidence or ceasing change tracking would weaken future response. Incident management is most valuable when it drives measurable improvements to risk treatment and operating practices.
Q160. An organization uses a generative AI system to propose updates to its enterprise risk register. What is the BEST control before proposed updates become official records?
- Permit automatic changes whenever the model is confident
2. Remove human risk owners from the workflow
3. Require an authorized risk professional to validate and approve material changes
4. Allow the model to redefine the risk taxonomy independently
Correct Answer: 4. Require an authorized risk professional to validate and approve material changes
Explanation: AI can help identify risks, suggest wording, classify scenarios, and summarize evidence, but the enterprise risk register is a formal governance record. Material additions, ratings, ownership changes, and treatment decisions should be validated and approved by authorized professionals. The AI may use incomplete evidence or misunderstand organizational context. Human review also ensures consistency with approved taxonomy, risk appetite, and scoring methodologies. AI should improve the efficiency of risk management without replacing accountable ownership of official enterprise risk decisions.