View Full Isaca AAISM Exam Dumps and Practice Test Dumps
Question 261. What is the primary purpose of defining AI governance decision rights?
- To ensure every decision is made by the same individual
- To eliminate the need for escalation procedures
- To clarify who has authority to make, approve, challenge, and escalate AI-related decisions
- To transfer all AI decisions to external vendors
Correct Answer: 3. To clarify who has authority to make, approve, challenge, and escalate AI-related decisions
Explanation:
Clearly defined decision rights prevent ambiguity when AI-related decisions require approval, challenge, escalation, or risk acceptance. Governance should identify which roles can approve use cases, accept residual risk, authorize exceptions, suspend systems, approve material changes, and escalate significant issues. Decision rights should be aligned with the organization’s risk appetite and the level of potential impact associated with the AI activity. Without clear authority, employees may make decisions beyond their responsibilities or delay important actions while searching for approval. Documented decision rights also improve accountability because governance reviewers can determine whether a decision was made by an appropriately authorized person.
Question 262. Which governance practice best prevents unauthorized AI use cases from entering production?
- A formal intake and approval process before deployment
- Allowing developers to deploy prototypes directly
- Relying only on employee awareness
- Reviewing AI systems only after an incident
Correct Answer: 1. A formal intake and approval process before deployment
Explanation:
A formal AI intake and approval process provides a controlled mechanism for identifying proposed use cases before they become operational. The process can capture the intended purpose, data involved, stakeholders, risk classification, regulatory considerations, ownership, security requirements, and required testing. Appropriate approval authorities can then determine whether the proposed use is acceptable and what conditions must be satisfied before deployment. Relying solely on awareness may not prevent unauthorized applications, particularly when employees can easily access external AI services. Post-incident review is reactive and may expose the organization to avoidable risk. A controlled intake process establishes governance at the beginning of the AI lifecycle.
Question 263. Why should AI governance require documented approval conditions for higher-risk systems?
- To prevent any future changes to the system
- To define the requirements and limitations under which the system is authorized to operate
- To replace all monitoring activities
- To ensure the system can be used for any business purpose
Correct Answer: 2. To define the requirements and limitations under which the system is authorized to operate
Explanation:
Higher-risk AI systems may be approved only under specific conditions, such as restricted data sources, mandatory human review, defined user groups, performance thresholds, geographic limitations, monitoring requirements, or periodic reassessment. Documenting these conditions creates a clear connection between the approval decision and the system’s permitted operating boundaries. It also helps operational teams understand what is and is not authorized. Conditions should be monitored because a system can become noncompliant if it is later used outside the approved scope. Documented conditions therefore support accountability, change management, auditability, and ongoing governance rather than simply serving as administrative paperwork.
Question 264. What should occur when an AI system begins operating outside its approved business purpose?
- The issue should be ignored if outputs remain accurate
- The system should automatically receive permanent approval
- The organization should assess the change and determine whether reassessment or additional authorization is required
- The original approval should automatically cover every future use
Correct Answer: 3. The organization should assess the change and determine whether reassessment or additional authorization is required
Explanation:
An AI system’s approved purpose is an important part of its risk assessment because the purpose determines how data, outputs, users, and decisions are governed. Using the system for a materially different purpose can introduce new privacy, security, fairness, regulatory, operational, or business risks. The organization should therefore determine whether the change is within the existing approval or requires a new assessment and authorization. Accuracy alone does not demonstrate that the new use is acceptable. Governance should evaluate the changed context, affected stakeholders, applicable requirements, controls, and decision impact. This prevents approval for one use case from being incorrectly interpreted as unlimited authorization.
Question 265. Which control most directly supports segregation of duties in AI model deployment?
- Allowing the developer to approve and deploy their own model
- Separating model development, approval, and production deployment responsibilities
- Removing deployment records
- Giving all project members administrator privileges
Correct Answer: 2. Separating model development, approval, and production deployment responsibilities
Explanation:
Segregation of duties reduces the risk that one individual can independently develop, approve, and deploy an AI model without effective oversight. Separating these responsibilities creates independent checkpoints where changes can be reviewed and authorization can be verified. The exact structure depends on organizational size and risk, but higher-risk systems generally benefit from stronger separation. This control also supports accountability because the organization can determine who created the model, who validated it, who approved it, and who deployed it. Removing records or granting broad administrative privileges weakens these protections. Where complete separation is impractical, compensating controls should be considered and documented.
Question 266. What is a compensating control in an AI governance environment?
- A control that provides an alternative risk-reduction mechanism when the preferred control cannot be implemented as designed
- A control that eliminates the need for risk assessment
- A control used only for financial accounting
- A control that automatically accepts residual risk
Correct Answer: 1. A control that provides an alternative risk-reduction mechanism when the preferred control cannot be implemented as designed
Explanation:
A compensating control is an alternative measure used when a primary control cannot reasonably be implemented or cannot operate as intended. For example, if a technical segregation mechanism is unavailable, additional independent review, enhanced logging, restricted access, or more frequent monitoring may reduce the associated risk. A compensating control should not simply be a weaker version of the original control without justification. Governance should document why the primary control is unavailable, how the alternative reduces risk, who approved it, and how its effectiveness will be monitored. Compensating controls should be reviewed periodically to determine whether the original control can eventually be implemented or whether the alternative remains appropriate.
Question 267. Why should AI governance monitor policy exceptions after they are approved?
- To determine whether exceptions remain justified and do not become permanent uncontrolled practices
- To ensure every exception is automatically renewed
- To prevent management from reviewing exceptions
- To eliminate the need for policy requirements
Correct Answer: 1. To determine whether exceptions remain justified and do not become permanent uncontrolled practices
Explanation:
Policy exceptions may be necessary when legitimate business circumstances make full compliance with a standard requirement impractical. However, an exception can create additional risk and should therefore have defined scope, ownership, duration, compensating controls, and approval authority. Monitoring helps determine whether the exception remains necessary, whether its conditions are being followed, and whether the underlying reason has been resolved. Without periodic review, temporary exceptions can become permanent practices that effectively bypass governance requirements. Exception reporting can also reveal recurring situations that indicate a policy needs clarification or redesign. Governance should therefore track exceptions as active risk decisions rather than treating approval as the end of the process.
Question 268. What should an organization consider when defining the scope of an AI governance policy?
- Only systems developed internally
- Only models purchased from vendors
- AI systems, services, use cases, data, and organizational activities relevant to the policy’s objectives
- Only AI systems classified as low risk
Correct Answer: 3. AI systems, services, use cases, data, and organizational activities relevant to the policy’s objectives
Explanation:
An AI governance policy should clearly define what activities and systems it covers so that employees and stakeholders understand their responsibilities. Depending on organizational needs, scope may include internally developed models, externally provided AI services, embedded AI capabilities, experimental systems, business-process integrations, relevant data activities, and third-party dependencies. Restricting the policy only to internally developed models can create significant gaps because externally hosted services may introduce substantial privacy, security, contractual, or compliance risks. Scope should be aligned with the policy’s objectives and risk environment. Clear definitions also support consistent application and make it easier to determine whether a proposed AI activity falls within governance requirements.
Question 269. Which factor should influence the level of governance oversight applied to an AI use case?
- The number of pages in its documentation
- The popularity of the AI vendor
- The age of the development team
- The potential impact, risk, sensitivity, and criticality of the use case
Correct Answer: 4. The potential impact, risk, sensitivity, and criticality of the use case
Explanation:
Risk-based governance applies oversight proportionate to the potential consequences and characteristics of an AI use case. Factors may include the sensitivity of data, impact on individuals, criticality of the business process, regulatory requirements, degree of automation, security exposure, potential financial consequences, and uncertainty in system behavior. A low-impact internal productivity tool may require fewer controls than an AI system supporting high-impact decisions. Applying identical governance requirements to every system can consume resources inefficiently while failing to address important risks appropriately. Governance teams should therefore define risk criteria that determine approval, validation, monitoring, human oversight, documentation, and assurance requirements.
Question 270. What is the purpose of defining AI risk appetite at the enterprise level?
- To establish the types and levels of AI risk the organization is willing to accept while pursuing its objectives
- To guarantee that no AI risk will ever occur
- To eliminate business-unit responsibility
- To require every AI system to use identical controls
Correct Answer: 1. To establish the types and levels of AI risk the organization is willing to accept while pursuing its objectives
Explanation:
AI risk appetite provides strategic guidance about the amount and nature of risk the organization is willing to accept in pursuit of business objectives. It helps management determine boundaries for AI deployment and supports consistent decisions across business units. Risk appetite can address areas such as privacy, security, reliability, regulatory exposure, human impact, financial loss, or operational disruption. It does not mean that the organization expects zero risk. Instead, it establishes acceptable boundaries and informs risk treatment, escalation, and acceptance decisions. Governance teams can use risk appetite to define thresholds and criteria that translate enterprise expectations into practical requirements for individual AI systems.
Question 271. What should happen when an AI system approaches or exceeds a defined risk appetite threshold?
- The threshold should be deleted
- The issue should trigger appropriate monitoring, escalation, or risk treatment according to governance procedures
- The system should automatically receive approval
- The risk should be hidden from management
Correct Answer: 2. The issue should trigger appropriate monitoring, escalation, or risk treatment according to governance procedures
Explanation:
Risk appetite thresholds provide a basis for determining when AI exposure requires management attention. When a system approaches or exceeds a threshold, the organization should follow predefined procedures that may include increased monitoring, additional controls, reassessment, escalation, temporary restriction, or formal risk acceptance by an authorized authority. The appropriate response depends on the nature and severity of the threshold breach. Deleting the threshold or hiding the issue would undermine governance. Thresholds should also be periodically reviewed to ensure they remain meaningful as the organization’s objectives, AI portfolio, regulatory environment, and risk tolerance evolve. Effective threshold management connects risk measurement with actionable governance decisions.
Question 272. Why should AI governance include clear ownership for data used by AI systems?
- To ensure accountability for data quality, access, use, and lifecycle requirements
- To make every employee responsible for the same dataset
- To eliminate data classification
- To allow unrestricted data sharing
Correct Answer: 1. To ensure accountability for data quality, access, use, and lifecycle requirements
Explanation:
Data ownership establishes accountability for how important datasets are managed throughout their lifecycle. For AI systems, ownership may include responsibility for data quality, classification, access permissions, retention, appropriate use, provenance, privacy requirements, and issue resolution. Without clear ownership, problems such as outdated information, excessive access, unauthorized reuse, or unclear retention responsibilities may remain unresolved. Ownership does not necessarily mean that one person performs every data-management task; operational responsibilities can be delegated while accountability remains clear. Governance should also define how data owners interact with AI system owners, security teams, privacy functions, and other stakeholders when data-related risks affect model performance or compliance.
Question 273. Which practice best supports responsible reuse of data across multiple AI systems?
- Allowing unrestricted reuse because the data was already collected
- Evaluating whether the secondary use is authorized, appropriate, and consistent with applicable requirements
- Removing all data documentation
- Automatically approving every new AI application
Correct Answer: 2. Evaluating whether the secondary use is authorized, appropriate, and consistent with applicable requirements
Explanation:
Data collected for one purpose may not automatically be appropriate for every subsequent AI use. Secondary use should be evaluated against applicable permissions, privacy expectations, contractual conditions, security requirements, data quality considerations, and organizational policies. The organization should determine whether the new purpose is compatible with the original collection context and whether additional safeguards or authorization are necessary. Simply assuming that previously collected data can be reused can create privacy, legal, ethical, or governance risks. Responsible reuse may also require data minimization, de-identification, access restrictions, documentation, or additional impact assessment. The evaluation should be proportionate to the sensitivity of the data and the potential impact of the new AI use.
Question 274. What is the main governance purpose of maintaining an AI system inventory?
- To create a complete and current view of AI systems that require oversight
- To increase the number of AI systems deployed
- To replace all risk assessments
- To track only retired applications
Correct Answer: 1. To create a complete and current view of AI systems that require oversight
Explanation:
An AI system inventory provides visibility into the organization’s AI landscape. Useful inventory information may include system owner, business purpose, risk classification, data categories, deployment status, model or provider, critical dependencies, approval status, and lifecycle stage. This information allows governance teams to identify systems that require assessment, monitoring, reassessment, or retirement. Without an accurate inventory, organizations may overlook unauthorized or unmanaged AI applications, particularly when employees can acquire external AI services independently. The inventory should be maintained as systems are introduced, modified, transferred, or retired. It should also connect with risk management and governance workflows so that inventory information remains operationally useful rather than becoming a static list.
Question 275. What should an organization do when an AI system is identified outside the official governance inventory?
- Ignore it until it causes an incident
- Automatically delete it without assessment
- Identify ownership, assess its use and risk, and bring it into the appropriate governance process
- Grant it unrestricted production access
Correct Answer: 3. Identify ownership, assess its use and risk, and bring it into the appropriate governance process
Explanation:
An AI system outside the official inventory may represent an unauthorized application, an overlooked business system, an experimental tool, or a third-party service acquired without appropriate review. Governance should first establish what the system does, who owns it, what data it uses, how it is being used, and what risks it introduces. The organization can then determine whether it should be approved, restricted, remediated, or retired. Automatically deleting an unknown system without understanding its business dependencies could create operational disruption. Ignoring it can leave significant risks unmanaged. Bringing the system into the formal inventory and governance process restores visibility and accountability.
Question 276. Which governance measure helps reduce the risk of employees entering confidential information into unauthorized generative AI services?
- Increasing the number of public AI tools
- Combining acceptable-use policies with technical data-loss controls and employee training
- Removing all monitoring
- Allowing unrestricted external AI access
Correct Answer: 2. Combining acceptable-use policies with technical data-loss controls and employee training
Explanation:
Preventing inappropriate disclosure to external generative AI services usually requires multiple complementary controls. An acceptable-use policy establishes clear expectations about what information employees may or may not submit. Technical controls such as data-loss prevention, access restrictions, browser controls, or approved-service lists can reduce opportunities for accidental disclosure. Training helps employees recognize sensitive information and understand approved alternatives. No single control is likely to address every scenario because users may interact with different services and data types. Governance should also monitor policy violations and update controls as AI services evolve. The objective is to reduce exposure while allowing legitimate and appropriately governed AI use.
Question 277. What is an important governance requirement for AI systems that process personal information?
- Ignoring data-subject rights
- Using all available personal data to maximize model performance
- Applying appropriate privacy, purpose, access, retention, and security controls
- Retaining personal information indefinitely
Correct Answer: 3. Applying appropriate privacy, purpose, access, retention, and security controls
Explanation:
AI systems that process personal information require governance that addresses the complete data lifecycle. Relevant controls may include defined purposes, data minimization, appropriate access, retention limits, security safeguards, transparency requirements, and mechanisms for addressing applicable individual rights. The exact obligations depend on the organization, jurisdiction, data type, and use case. Maximizing the quantity of personal data is not automatically appropriate because unnecessary data can increase privacy and security exposure. Indefinite retention can create additional risks as well. Governance should ensure that personal information is collected, processed, stored, shared, and disposed of according to applicable requirements and documented organizational practices.
Question 278. Why should AI governance consider explainability requirements when defining controls?
- Because every AI model must expose all source code
- Because relevant stakeholders may need understandable information about how AI outputs are produced or used
- Because explainability eliminates all model errors
- Because technical documentation is never necessary
Correct Answer: 2. Because relevant stakeholders may need understandable information about how AI outputs are produced or used
Explanation:
Explainability requirements should be proportionate to the AI system’s purpose, risk, and affected stakeholders. In higher-impact contexts, users, decision-makers, auditors, regulators, or affected individuals may need understandable information about the factors influencing an AI output or how the output is incorporated into a decision. Explainability does not necessarily require disclosure of proprietary source code or complete technical details. The organization should determine what information is necessary to support transparency, accountability, review, and appropriate challenge. Explainability also has limitations, particularly for complex models, so governance should consider complementary controls such as human oversight, testing, documentation, and outcome monitoring.
Question 279. What should governance teams consider when an AI system produces inconsistent results for similar inputs?
- Whether the inconsistency could indicate reliability, data, configuration, or model-behavior issues
- Whether all monitoring should be disabled
- Whether inconsistent results should automatically be accepted
- Whether the system should be exempted from validation
Correct Answer: 1. Whether the inconsistency could indicate reliability, data, configuration, or model-behavior issues
Explanation:
Unexpected inconsistency can be an indicator of a problem with model behavior, input data, configuration, dependencies, randomness, system integration, or other operating conditions. Governance should establish appropriate criteria for identifying material inconsistencies and investigating their causes. The significance depends on the use case because some AI systems may naturally produce variable outputs while others require highly consistent behavior. Testing should therefore reflect the system’s intended purpose and risk. If inconsistency creates unacceptable exposure, the organization may need additional controls, model changes, human review, restricted use, or escalation. Monitoring should continue after remediation to confirm that the issue has been adequately addressed.
Question 280. Which action best supports governance when an AI system reaches the end of its approved lifecycle?
- Keep all access active indefinitely
- Continue using the system without review
- Remove all records immediately
- Follow a controlled retirement process covering access, data, dependencies, records, and residual risks
Correct Answer: 4. Follow a controlled retirement process covering access, data, dependencies, records, and residual risks
Explanation:
AI retirement should be governed as carefully as deployment because systems may remain connected to data, users, applications, vendors, or business processes after their active use ends. A controlled retirement process should address access removal, credential revocation, data retention and disposal, infrastructure decommissioning, dependency changes, contractual obligations, documentation retention, and any remaining risks. Relevant records should be retained according to applicable requirements rather than deleted automatically. Business stakeholders should also confirm that replacement processes are functioning before critical services are discontinued. Controlled retirement reduces the likelihood that obsolete AI systems remain accessible or create unmanaged security, privacy, operational, or compliance exposure after their approved lifecycle has ended.