View Full Isaca AAISM Exam Dumps and Practice Test Dumps
Question 321. What is the main purpose of defining AI system risk criteria before deployment?
- To determine the appropriate level of governance and control based on risk
- To guarantee that the system will never fail
- To eliminate the need for system documentation
- To allow unrestricted use of every AI application
Correct Answer: 1. To determine the appropriate level of governance and control based on risk
Explanation:
Risk criteria provide a consistent basis for determining how an AI system should be governed. They can consider factors such as potential impact, data sensitivity, degree of automation, affected individuals, business criticality, regulatory requirements, and security exposure. Establishing criteria before deployment helps organizations avoid making inconsistent decisions based solely on individual opinions or project urgency. The classification can then determine requirements for approval, testing, human oversight, monitoring, documentation, and assurance. Risk criteria should be documented and periodically reviewed because organizational priorities, AI capabilities, and external requirements can change. A consistent risk-based approach helps focus stronger governance measures on systems where potential consequences are greater.
Question 322. Which activity is most useful for identifying AI systems that may have been deployed without formal approval?
- Increasing the number of approved applications
- Comparing the AI inventory with discovery and usage information
- Removing application ownership records
- Disabling monitoring of employee activity
Correct Answer: 2. Comparing the AI inventory with discovery and usage information
Explanation:
An approved AI inventory provides a governance baseline, but organizations also need ways to identify systems that may not have been formally registered. Comparing inventory records with available application discovery, procurement, network, identity, or usage information can reveal previously unknown AI services or applications. These systems can then be assessed to determine their business purpose, ownership, data usage, risk level, and compliance requirements. This process is particularly important for externally hosted generative AI services because employees may independently adopt tools outside established procurement or governance channels. Discovery should be performed in a manner consistent with organizational privacy and security requirements and should result in appropriate registration, remediation, or escalation.
Question 323. What should be included in an AI system’s governance documentation to support accountability?
- Only the system’s marketing description
- Only the model’s programming language
- Responsible owners, intended purpose, risk information, controls, and approval evidence
- Only the number of users
Correct Answer: 3. Responsible owners, intended purpose, risk information, controls, and approval evidence
Explanation:
Governance documentation should provide sufficient information to understand how an AI system is managed and who is accountable for it. Important information can include the system’s purpose, owners, risk classification, data sources, applicable requirements, implemented controls, validation evidence, human oversight arrangements, approvals, monitoring expectations, and lifecycle status. The exact documentation should be proportional to the system’s risk and complexity. Well-maintained records help governance teams evaluate whether a system remains within its approved scope and whether changes require reassessment. They also support audits, incident investigations, regulatory inquiries, and management reporting. Documentation should be kept current because outdated ownership or risk information can weaken accountability.
Question 324. Why should organizations establish formal criteria for AI policy exceptions?
- To allow every policy requirement to be ignored
- To ensure exceptions are evaluated, authorized, documented, and monitored consistently
- To remove accountability from business owners
- To prevent all changes to governance policies
Correct Answer: 2. To ensure exceptions are evaluated, authorized, documented, and monitored consistently
Explanation:
Policy exceptions can sometimes be necessary because operational circumstances may make a standard control temporarily impractical. However, uncontrolled exceptions can weaken governance and create inconsistent risk treatment. Formal criteria help determine when an exception may be considered, who can approve it, what risk assessment is required, and whether compensating controls are necessary. Exceptions should normally have a defined scope and duration, with appropriate monitoring and review. Documentation provides evidence of the decision and makes it possible to determine whether the exception remains justified. A structured exception process preserves governance discipline while allowing legitimate business needs to be addressed without silently bypassing established requirements.
Question 325. Which approach best supports consistency when multiple business units classify similar AI systems differently?
- Allowing each unit to create unrelated definitions
- Removing risk classifications completely
- Using standardized enterprise risk criteria and classification guidance
- Allowing the newest business unit to determine the classification
Correct Answer: 3. Using standardized enterprise risk criteria and classification guidance
Explanation:
Standardized classification criteria help ensure that comparable AI systems receive comparable governance treatment across the organization. Without common criteria, one business unit may classify a system as low risk while another considers a similar system high risk, resulting in inconsistent controls and oversight. Enterprise guidance should define relevant risk factors, classification thresholds, approval requirements, and escalation rules. Business units can still provide contextual information because the same technology may have different risks depending on its purpose and data. Centralized guidance therefore promotes consistency while allowing appropriate contextual assessment. Periodic review of classification criteria is also important as AI capabilities, regulations, and organizational risk appetite evolve.
Question 326. What is an important objective of AI model validation before production use?
- To determine whether the model meets defined performance and risk requirements
- To increase the number of model parameters regardless of need
- To eliminate all human oversight
- To ensure that every model produces identical outputs
Correct Answer: 1. To determine whether the model meets defined performance and risk requirements
Explanation:
Model validation provides an independent or appropriately structured assessment of whether an AI model is suitable for its intended purpose. Validation can examine performance, robustness, data suitability, limitations, assumptions, fairness where relevant, security considerations, and other requirements established by the organization. The criteria should be defined in advance so that acceptance decisions are based on objective evidence rather than subjective impressions. Validation results should be documented and linked to the specific model version and relevant datasets or configurations. If the model fails required criteria, deployment should be delayed, restricted, or subjected to additional treatment according to the organization’s governance process.
Question 327. What should happen when a validated AI model is materially changed before production deployment?
- The change should automatically be ignored
- The original validation should always be considered sufficient
- The change should be assessed to determine whether additional validation is required
- All previous validation evidence should be deleted
Correct Answer: 3. The change should be assessed to determine whether additional validation is required
Explanation:
Material changes can affect model behavior, performance, security, fairness, explainability, or other risk characteristics. Therefore, an organization should determine whether the modification remains within the scope of previous validation or requires additional testing and approval. The assessment should consider the nature and significance of the change, affected components, intended use, and applicable governance requirements. Maintaining version history allows the organization to identify exactly which model was validated and which version was ultimately deployed. Automatically treating previous validation as sufficient can create a gap between the evidence reviewed by governance teams and the system actually placed into production. Change-based reassessment helps preserve validation integrity.
Question 328. Which practice best supports reproducibility of an AI model development process?
- Recording relevant datasets, configurations, code, dependencies, and model versions
- Allowing developers to overwrite all historical artifacts
- Removing configuration records after deployment
- Using undocumented manual changes
Correct Answer: 1. Recording relevant datasets, configurations, code, dependencies, and model versions
Explanation:
Reproducibility requires sufficient information to recreate or understand how a particular model version was developed and validated. Depending on the system, this may include dataset versions, preprocessing steps, source code, configuration parameters, dependencies, model artifacts, training procedures, and validation results. These records should be version-controlled and protected from unauthorized modification. Reproducibility is valuable for investigating unexpected outcomes, validating changes, supporting audits, and demonstrating that a model was developed according to approved processes. Complete reproducibility may not always mean obtaining identical outputs in every environment, but the organization should maintain enough controlled information to understand and reproduce the relevant development process to an appropriate degree.
Question 329. What is the primary governance concern associated with AI-generated content being used without verification?
- It may introduce inaccurate, misleading, biased, or otherwise inappropriate information into business processes
- It always consumes too little computing power
- It guarantees that decisions are unbiased
- It eliminates the need for human review
Correct Answer: 1. It may introduce inaccurate, misleading, biased, or otherwise inappropriate information into business processes
Explanation:
AI-generated content can appear plausible while containing inaccurate, incomplete, outdated, or misleading information. If such outputs are incorporated into business processes without appropriate verification, errors can propagate into reports, customer communications, operational decisions, or other downstream activities. Governance should therefore define where AI-generated outputs require human review, validation, source checking, or other controls. The appropriate level of verification depends on the potential consequences of incorrect information. Users should also understand system limitations and know when outputs should not be relied upon without additional evidence. Effective governance does not require treating every AI output as unusable; instead, it establishes controls proportionate to the risks associated with the intended use.
Question 330. Which control helps prevent unauthorized employees from using an AI service for restricted business purposes?
- Removing identity controls
- Applying access restrictions based on approved roles and business purposes
- Allowing unrestricted external AI access
- Deleting user activity records
Correct Answer: 2. Applying access restrictions based on approved roles and business purposes
Explanation:
Access controls can help ensure that AI services are available only to users and use cases that have been approved by the organization. Role-based access, identity management, authorization rules, and business-purpose restrictions can reduce the likelihood that employees use AI services to process sensitive information or perform activities outside approved requirements. Monitoring can provide additional visibility into usage patterns and potential violations. Access controls should be reviewed periodically because employee responsibilities and approved use cases can change. For higher-risk AI applications, stronger controls may include multi-factor authentication, privileged access management, approval workflows, or restrictions on specific data types. Governance should combine technical controls with policy and user awareness.
Question 331. What is the purpose of maintaining an AI model version history?
- To identify which model version was deployed and understand changes over time
- To prevent all future model updates
- To remove accountability for model changes
- To eliminate the need for testing
Correct Answer: 1. To identify which model version was deployed and understand changes over time
Explanation:
Model version history provides traceability across the AI lifecycle. It allows organizations to identify the specific model version used at a particular time and understand what changed between versions. This information is important for incident investigation, performance analysis, validation, audit activities, and rollback decisions. Version history should ideally be linked with relevant training data, configuration, dependencies, approval records, validation evidence, and deployment dates. Historical versions should be protected from unauthorized modification or deletion according to retention requirements. Without reliable version history, an organization may struggle to determine which model produced a particular output or whether a reported problem began after a specific change.
Question 332. Why should AI systems be monitored after deployment even when pre-deployment validation was successful?
- Because deployment conditions can differ from testing conditions and model risks may change over time
- Because validation has no value
- Because every model must be manually operated forever
- Because monitoring guarantees perfect performance
Correct Answer: 1. Because deployment conditions can differ from testing conditions and model risks may change over time
Explanation:
Pre-deployment validation provides evidence about a model under defined testing conditions, but production environments can change. Real-world data may differ from validation datasets, user behavior can evolve, external conditions may shift, and dependencies can change. Models can also experience performance deterioration or other forms of drift. Post-deployment monitoring helps identify these changes and determine whether corrective action, reassessment, retraining, rollback, or additional controls are required. Monitoring should focus on relevant performance, risk, security, compliance, and operational indicators. The frequency and depth of monitoring should be proportional to the system’s risk. Continuous oversight therefore complements, rather than replaces, pre-deployment validation.
Question 333. Which factor should be considered when setting AI monitoring thresholds?
- Only the model’s marketing name
- The potential impact of deviations and the organization’s defined risk tolerance
- The number of employees in unrelated departments
- The physical location of the development team
Correct Answer: 2. The potential impact of deviations and the organization’s defined risk tolerance
Explanation:
Monitoring thresholds should be meaningful in relation to the AI system’s purpose, expected behavior, risk level, and potential consequences of deterioration. A threshold that is too sensitive may create excessive alerts, while one that is too broad may allow significant problems to continue without timely intervention. Organizations should consider baseline performance, acceptable variation, risk appetite, regulatory requirements, business impact, and available response capabilities. Thresholds should be documented and periodically reviewed using actual monitoring results and lessons learned. For high-impact systems, thresholds may require more conservative settings and stronger escalation requirements. Proper threshold design helps monitoring produce actionable information rather than unnecessary or ineffective alerts.
Question 334. What is an appropriate response when an AI system’s operating environment changes significantly?
- Continue operating without review
- Delete previous governance records
- Assess the change and determine whether risk, controls, or approvals need to be updated
- Automatically classify the system as low risk
Correct Answer: 3. Assess the change and determine whether risk, controls, or approvals need to be updated
Explanation:
Changes in the operating environment can affect an AI system even when the underlying model has not changed. Examples include new users, different data sources, new jurisdictions, changed business processes, new integrations, or changes in external dependencies. These changes may alter the system’s risk profile or invalidate assumptions made during its original assessment. Governance should therefore establish triggers for reassessment and define who evaluates whether additional controls or approvals are necessary. The assessment should be proportionate to the significance of the change. Maintaining change records also supports traceability and helps demonstrate that governance remained active throughout the system’s operational lifecycle.
Question 335. What should an organization consider when AI outputs are incorporated into another automated system?
- Only the visual design of the receiving system
- The combined risks and dependencies created by the integration
- Removing all output validation
- Assuming the receiving system eliminates AI risks
Correct Answer: 2. The combined risks and dependencies created by the integration
Explanation:
When AI outputs feed another automated process, errors or unexpected behavior can propagate beyond the original system. Governance should consider the complete chain, including input quality, output reliability, interface controls, validation, decision logic, failure handling, monitoring, and human intervention. An AI system that appears low risk in isolation may become more consequential when its outputs automatically trigger financial, operational, customer, or security actions. Dependencies should therefore be documented and assessed as part of the broader process. Appropriate controls may include output validation, confidence thresholds, exception handling, human review, logging, and rollback capabilities. Understanding the integrated workflow helps organizations manage risks that arise from interactions between systems.
Question 336. Which practice best supports secure management of AI model artifacts?
- Storing artifacts in publicly accessible locations
- Allowing unrestricted modification
- Removing version identifiers
- Applying access controls, integrity protection, and version management
Correct Answer: 4. Applying access controls, integrity protection, and version management
Explanation:
AI model artifacts can include trained models, configuration files, weights, prompts, pipelines, and other components that directly influence system behavior. Unauthorized modification of these artifacts could alter outputs, introduce vulnerabilities, or undermine validation evidence. Organizations should therefore protect artifacts through appropriate access controls, integrity mechanisms, version management, and secure storage. Changes should be traceable and linked to authorized development or change-management activities. Retaining relevant historical versions can support rollback and investigation. Controls should also address the transfer of artifacts between development, testing, and production environments. Protecting model artifacts helps maintain confidence that the deployed system corresponds to the version that was approved and validated.
Question 337. Why should organizations maintain documented assumptions used during AI risk assessments?
- Assumptions help explain the basis for risk conclusions and can be reassessed when conditions change
- Assumptions guarantee that risk assessments never need updating
- Assumptions replace all evidence requirements
- Assumptions prevent AI systems from being modified
Correct Answer: 1. Assumptions help explain the basis for risk conclusions and can be reassessed when conditions change
Explanation:
Risk assessments often depend on assumptions about data, users, system behavior, business processes, controls, external dependencies, or operating conditions. Documenting these assumptions makes the reasoning behind risk conclusions more transparent and easier to review. If an assumption changes, governance teams can determine whether the associated risk assessment remains valid or needs to be updated. This is particularly important for AI because system behavior and external conditions can evolve. Documented assumptions also support auditability and reduce reliance on undocumented knowledge held by individual team members. The purpose is not to guarantee that assumptions remain correct but to provide a clear basis for identifying when reassessment may be necessary.
Question 338. What is a key governance consideration when an AI provider uses subcontractors?
- The organization should understand relevant subcontractor roles and associated risks
- Subcontractors automatically become responsible for all customer obligations
- Subcontractors eliminate the need for provider due diligence
- Subcontractor activity should never be documented
Correct Answer: 1. The organization should understand relevant subcontractor roles and associated risks
Explanation:
External AI providers may rely on subcontractors for infrastructure, data processing, model services, support, or other critical functions. These relationships can introduce additional security, privacy, availability, jurisdictional, and operational risks. Organizations should understand which subcontractors are relevant to the service and how responsibilities are distributed. Depending on the risk and contractual arrangement, requirements may address notification of material subcontractor changes, security expectations, data handling, audit rights, and incident responsibilities. Subcontractor oversight does not necessarily require the customer to manage every subcontractor directly, but the organization should have sufficient visibility to evaluate whether the overall service chain satisfies its governance requirements. This supports effective third-party risk management.
Question 339. Which activity helps determine whether AI governance responsibilities are being performed as intended?
- Reviewing only the system’s user interface
- Removing responsibility matrices
- Assessing governance roles, assigned responsibilities, evidence, and performance
- Allowing responsibilities to remain undocumented
Correct Answer: 3. Assessing governance roles, assigned responsibilities, evidence, and performance
Explanation:
Governance responsibilities should be evaluated to determine whether assigned roles are clear, understood, and actually being performed. An assessment can examine responsibility matrices, approval records, risk ownership, monitoring activities, escalation records, training, and evidence of required decisions. It may also identify gaps where responsibilities overlap or where no individual has clear ownership. Reviewing actual performance is important because a documented responsibility does not guarantee that the activity is being completed effectively. Findings should be assigned to appropriate owners and tracked through remediation. Periodic responsibility reviews are especially useful after organizational restructuring, changes in AI portfolios, or introduction of new governance requirements.
Question 340. What is the most appropriate approach when an AI risk cannot be fully eliminated?
- Ignore the risk because elimination is impossible
- Apply appropriate treatment, document residual risk, and obtain authorized acceptance when necessary
- Remove the risk from the register
- Transfer every responsibility to the AI vendor
Correct Answer: 2. Apply appropriate treatment, document residual risk, and obtain authorized acceptance when necessary
Explanation:
Not every AI risk can be completely eliminated, particularly when the organization must continue using a system for an important business purpose. In such situations, management should evaluate available treatment options, including reducing likelihood or impact, avoiding certain uses, transferring appropriate aspects of risk, or accepting residual exposure. Controls should be implemented based on the organization’s risk requirements, and remaining risk should be documented. Acceptance should be performed by an individual or body with appropriate authority and should consider risk appetite, legal obligations, business impact, and available alternatives. This structured approach ensures that unavoidable risk is consciously managed rather than ignored or left without accountable ownership.