View Full Isaca AAISM Exam Dumps and Practice Test Dumps
Question 341. What is the primary purpose of an AI governance charter?
- To define the governance structure, authority, responsibilities, and objectives for AI oversight
- To replace all technical documentation
- To prevent organizations from using AI systems
- To authorize every AI user automatically
Correct Answer: 1. To define the governance structure, authority, responsibilities, and objectives for AI oversight
Explanation:
An AI governance charter establishes the formal foundation for how an organization oversees its AI activities. It can define the purpose of governance, scope, decision-making authority, responsibilities, reporting relationships, escalation mechanisms, and expectations for oversight bodies. A well-defined charter helps prevent ambiguity about who is accountable for important AI decisions and how governance activities relate to business objectives and risk management. It should be aligned with the organization’s broader governance structure and periodically reviewed as responsibilities or AI activities change. The charter does not replace operational procedures or technical controls; instead, it provides the organizational framework within which those activities are governed and monitored.
Question 342. Which activity best supports alignment between AI governance and organizational objectives?
- Allowing AI initiatives to operate independently of business strategy
- Reviewing AI objectives against current business priorities and risk considerations
- Measuring only the number of AI models deployed
- Removing management participation from AI decisions
Correct Answer: 2. Reviewing AI objectives against current business priorities and risk considerations
Explanation:
AI governance should remain connected to the organization’s strategic objectives rather than operating as an isolated compliance function. Reviewing AI objectives against current business priorities helps determine whether AI investments, use cases, and risk treatments continue to support organizational goals. The review should also consider risk appetite, available resources, regulatory obligations, operational dependencies, and expected business outcomes. Business priorities can change over time, so an AI initiative that was previously appropriate may require modification, reprioritization, or additional controls. Governance bodies should therefore periodically evaluate whether AI activities remain aligned with organizational direction and whether associated risks are understood and managed appropriately.
Question 343. What should an organization establish for escalating significant AI risks?
- An informal process based on personal relationships
- A process that applies only after an incident
- Defined thresholds, responsible roles, and escalation procedures
- A process that allows employees to bypass management
Correct Answer: 3. Defined thresholds, responsible roles, and escalation procedures
Explanation:
Effective risk escalation requires clear criteria that indicate when an issue must be raised to a higher level of authority. Thresholds may relate to potential impact, risk appetite, regulatory significance, security exposure, repeated control failures, or deterioration in model performance. The governance framework should identify who receives escalations, what information must be provided, and what decisions the recipient is authorized to make. Defined procedures reduce the likelihood that significant AI risks remain unresolved because employees are uncertain about when or how to escalate them. Escalation should also be documented so that management can demonstrate how important risk decisions were handled and whether appropriate actions followed.
Question 344. Why should an organization define AI risk appetite?
- To establish the amount and type of AI-related risk the organization is willing to accept
- To guarantee that no AI risk will ever occur
- To remove all governance controls
- To allow unrestricted AI experimentation
Correct Answer: 1. To establish the amount and type of AI-related risk the organization is willing to accept
Explanation:
AI risk appetite provides a management-level boundary for deciding how much risk the organization is prepared to accept while pursuing its objectives. It can guide decisions about AI use cases, investment, controls, residual risk, and escalation. Risk appetite should be consistent with the organization’s broader strategy, legal obligations, operational capabilities, and stakeholder expectations. It should also be translated into practical criteria or thresholds that decision-makers can apply to specific systems. If an AI system creates exposure beyond approved appetite, management may need to introduce additional controls, modify the use case, or escalate the decision to an appropriate authority. Risk appetite therefore connects strategic direction with operational AI governance.
Question 345. What should happen when an AI system exceeds an established risk appetite threshold?
- The threshold should automatically be removed
- The issue should be assessed and escalated or treated according to governance requirements
- The system should continue without documentation
- The risk should be deleted from the risk register
Correct Answer: 2. The issue should be assessed and escalated or treated according to governance requirements
Explanation:
A risk appetite threshold establishes a boundary for acceptable exposure. When an AI system exceeds that boundary, the organization should not simply continue operation without review. The situation should be assessed to determine whether the exposure is temporary, caused by inaccurate information, or represents a genuine increase in risk. Appropriate actions may include additional controls, changes to the system, temporary restrictions, risk transfer, or escalation to authorized management. Any risk acceptance beyond established appetite should follow the organization’s defined authority and documentation requirements. This process ensures that exceeding risk appetite becomes a deliberate governance decision rather than an unnoticed operational condition.
Question 346. Which practice best supports accountability for AI decisions made across multiple departments?
- Assigning responsibility only to the technical team
- Allowing each department to use undocumented responsibilities
- Defining cross-functional roles and decision responsibilities
- Removing business ownership
Correct Answer: 3. Defining cross-functional roles and decision responsibilities
Explanation:
AI systems frequently involve multiple stakeholders, including business owners, developers, data teams, security personnel, privacy specialists, legal or compliance teams, and assurance functions. Assigning responsibility only to the technical team can leave important business or governance decisions unclear. A cross-functional responsibility structure identifies who owns the business purpose, data, technical implementation, security, privacy, risk, approval, monitoring, and incident response activities. Responsibility matrices can help make these relationships explicit. Clear role definitions also support escalation because stakeholders know where issues should be directed. Cross-functional accountability is particularly important for high-impact AI systems where decisions may have consequences beyond the technical environment.
Question 347. What is the purpose of an AI control framework?
- To provide structured control expectations for managing identified AI risks
- To eliminate the need for organizational policies
- To guarantee that all AI systems are risk-free
- To prevent control testing
Correct Answer: 1. To provide structured control expectations for managing identified AI risks
Explanation:
An AI control framework organizes control expectations that address relevant governance, security, privacy, data, model, operational, and compliance risks. It can help organizations establish consistent requirements across different AI systems while allowing additional controls for higher-risk use cases. A framework should connect controls to identified risks and organizational requirements rather than becoming a collection of unrelated technical measures. It can also support control ownership, testing, evidence collection, and assurance activities. As AI capabilities and risks evolve, the framework should be reviewed and updated. A structured control framework helps organizations apply governance requirements consistently while maintaining a clear relationship between risk, control objectives, implementation, and assurance.
Question 348. Why is control ownership important in AI governance?
- It identifies who is accountable for implementing and maintaining a specific control
- It allows controls to operate without monitoring
- It removes the need for documentation
- It makes every employee responsible for every control
Correct Answer: 1. It identifies who is accountable for implementing and maintaining a specific control
Explanation:
Every important AI control should have clearly defined ownership so that someone is accountable for its design, operation, maintenance, and evidence. Without control ownership, deficiencies may remain unresolved because stakeholders assume someone else is responsible. Ownership should be assigned according to the organization’s governance model and should consider the nature of the control. For example, technical controls may have technology owners, while privacy or policy controls may involve specialized functions. Control owners should understand their responsibilities and have sufficient authority and resources to perform them. Clear ownership also makes testing and remediation more effective because findings can be assigned directly to accountable parties.
Question 349. What should be considered when designing controls for a high-impact AI system?
- Only the system’s user interface
- The potential consequences, risk profile, affected stakeholders, and applicable requirements
- Only the cost of the AI model
- The number of developers assigned to the project
Correct Answer: 2. The potential consequences, risk profile, affected stakeholders, and applicable requirements
Explanation:
High-impact AI systems require controls that reflect the potential consequences of incorrect, biased, insecure, or unauthorized behavior. Control design should consider the system’s purpose, affected individuals, data sensitivity, decision-making role, regulatory obligations, security threats, human oversight requirements, and business criticality. Controls may include enhanced validation, stronger access restrictions, explainability measures, human review, detailed monitoring, incident escalation, and independent assurance. The control environment should be proportionate to risk rather than determined solely by the technology used. Designing controls around actual consequences helps ensure that governance resources are focused on areas where failures could have significant organizational or societal effects.
Question 350. Which evidence is most useful for demonstrating that a high-risk AI system received appropriate approval?
- A verbal statement from an employee
- A marketing presentation
- A documented approval record linked to the relevant risk assessment and system version
- An outdated system description
Correct Answer: 3. A documented approval record linked to the relevant risk assessment and system version
Explanation:
Approval evidence is strongest when it clearly connects the governance decision to the specific AI system, intended use, risk assessment, and version that was reviewed. Relevant evidence may include documented approvals, risk assessments, validation results, conditions of approval, responsible decision-makers, and dates. Linking approval records to model or system versions helps establish that the approved configuration corresponds to what was actually deployed. This is especially important for high-risk systems because changes after approval may alter the risk profile. Maintaining complete evidence supports audits, regulatory reviews, incident investigations, and management assurance. Informal verbal approval provides limited traceability and can be difficult to verify later.
Question 351. What is a key objective of AI governance reporting to senior management?
- To provide information needed for oversight, risk decisions, and accountability
- To list every technical configuration detail
- To replace operational monitoring
- To prevent management from reviewing AI risks
Correct Answer: 1. To provide information needed for oversight, risk decisions, and accountability
Explanation:
Senior management reporting should provide decision-relevant information about the organization’s AI portfolio, significant risks, control performance, incidents, exceptions, remediation status, and alignment with strategic objectives. Reports should be understandable to the intended audience and focus on material issues rather than overwhelming management with unnecessary technical details. Appropriate metrics and trends can help management determine whether risk remains within appetite and whether additional resources or actions are required. Reporting should also highlight significant changes and unresolved issues that require management attention. Effective reporting creates a communication link between operational AI governance and senior-level accountability, supporting informed oversight without replacing detailed operational controls.
Question 352. Which metric can help management identify weaknesses in AI governance remediation?
- Number of AI logos created
- Percentage of overdue high-risk remediation actions
- Number of employees using office software
- Amount of storage available on development servers
Correct Answer: 2. Percentage of overdue high-risk remediation actions
Explanation:
Overdue high-risk remediation actions can indicate that significant control or governance weaknesses are not being addressed within expected timeframes. Tracking the percentage of overdue actions helps management understand remediation performance and identify areas where ownership, resources, prioritization, or escalation may be insufficient. The metric becomes more useful when combined with trend analysis, risk severity, aging, responsible owners, and root-cause information. Management can then determine whether repeated delays reflect isolated circumstances or a broader governance problem. Metrics should support action rather than simply generate reports. Clear thresholds can also define when overdue remediation requires escalation to a higher governance authority.
Question 353. What should an organization do when an AI system produces outputs that consistently fail established quality criteria?
- Ignore the results if users are familiar with the system
- Remove the quality criteria
- Investigate the cause and apply appropriate corrective measures
- Continue deployment without monitoring
Correct Answer: 3. Investigate the cause and apply appropriate corrective measures
Explanation:
Consistent failure against defined quality criteria may indicate model degradation, unsuitable data, changes in the operating environment, incorrect configuration, inadequate validation, or other weaknesses. The organization should investigate the underlying cause rather than simply lowering the criteria to make the system appear compliant. Depending on the findings, corrective measures could include retraining, model changes, data-quality improvements, additional validation, stronger human oversight, restricted use, or temporary suspension. The investigation and response should be documented and linked to the affected model version. Quality criteria should themselves be reviewed periodically to ensure they remain appropriate, but changes should be based on evidence and governance decisions rather than a desire to conceal poor performance.
Question 354. Which practice helps organizations manage AI-related intellectual property risk?
- Allowing employees to submit any proprietary material to public AI services
- Defining rules for approved AI use of protected or proprietary information
- Removing data classification requirements
- Disabling employee training
Correct Answer: 2. Defining rules for approved AI use of protected or proprietary information
Explanation:
AI tools may process information that is protected by intellectual-property rights, confidentiality agreements, licensing terms, or organizational policies. Governance should define what proprietary or third-party information may be submitted to AI services and under what conditions. Controls may include approved-service requirements, data classification, access restrictions, contractual review, employee training, and technical safeguards. Organizations should also consider how AI-generated outputs will be used and whether applicable licensing or ownership concerns arise. Clear rules help employees understand the boundaries of acceptable AI use and reduce the likelihood of unauthorized disclosure or inappropriate reuse of protected information. The controls should reflect the organization’s legal and contractual environment.
Question 355. Why should AI incident response procedures identify AI-specific responsibilities?
- AI incidents may require specialized investigation, model analysis, data review, and governance decisions
- AI incidents never involve security teams
- AI systems cannot create operational incidents
- Incident response is unnecessary after deployment
Correct Answer: 1. AI incidents may require specialized investigation, model analysis, data review, and governance decisions
Explanation:
AI incidents can involve unusual characteristics such as model behavior, data poisoning, prompt manipulation, unexpected outputs, privacy exposure, bias concerns, model drift, or failures in human oversight. Incident response procedures should therefore identify responsibilities for technical investigation, business impact assessment, security response, privacy review, legal or compliance evaluation, communication, and governance escalation. The organization should also preserve relevant evidence such as model versions, prompts or inputs where appropriate, logs, data lineage, configuration, and decisions. Clear responsibilities reduce delays during high-pressure situations. AI incident procedures should integrate with the broader incident-management framework while addressing AI-specific evidence, risks, and decision requirements.
Question 356. What is the purpose of an AI business continuity strategy?
- To ensure that critical AI-supported processes can continue or recover appropriately after disruption
- To eliminate all third-party dependencies
- To prevent organizations from using cloud services
- To guarantee that every AI model remains permanently available
Correct Answer: 1. To ensure that critical AI-supported processes can continue or recover appropriately after disruption
Explanation:
AI systems may support important business processes, and their unavailability can create operational consequences. A business continuity strategy should identify critical AI dependencies, acceptable recovery objectives, alternative processes, fallback mechanisms, provider dependencies, data availability requirements, and responsibilities during disruption. The appropriate strategy depends on the importance of the AI capability and the consequences of interruption. Options may include manual procedures, alternative models, secondary providers, backups, or temporary suspension of affected processes. Continuity planning should be tested periodically so that assumptions about recovery capabilities are validated. This approach helps organizations maintain or restore essential operations without assuming that the AI service will always remain available.
Question 357. Which factor is important when assessing concentration risk from AI providers?
- Dependence on the same provider or model across multiple critical business processes
- The number of colors in provider documentation
- The provider’s office furniture
- The number of unrelated software licenses
Correct Answer: 1. Dependence on the same provider or model across multiple critical business processes
Explanation:
Concentration risk occurs when multiple important business processes depend on the same external provider, model, infrastructure, or underlying service. A single provider outage, security event, model change, contractual dispute, or service degradation could therefore affect several processes simultaneously. Organizations should identify critical dependencies and evaluate whether the level of concentration is consistent with risk appetite and business continuity requirements. Mitigation options may include alternative providers, fallback procedures, architectural diversification, contractual protections, or reduced dependence on a single service. Concentration analysis should consider both direct dependencies and hidden shared dependencies because different applications may rely on the same underlying model or infrastructure.
Question 358. What should an organization do when an AI governance control is found to be ineffective?
- Remove the finding from governance reports
- Determine the cause, assess the resulting risk, and implement appropriate remediation
- Continue relying on the ineffective control without review
- Automatically classify the control as effective
Correct Answer: 2. Determine the cause, assess the resulting risk, and implement appropriate remediation
Explanation:
An ineffective control indicates that the organization may not be managing the intended risk as expected. The response should begin with understanding why the control failed, whether the problem is related to control design or operation, and what risk exposure resulted. Management should then determine appropriate remediation, which may involve redesigning the control, improving implementation, assigning clearer ownership, adding compensating measures, or changing the underlying process. Remediation should have defined responsibilities and timelines, with follow-up testing to confirm effectiveness. Simply documenting the failure without addressing the cause does not improve the control environment. Effective remediation connects the finding to measurable corrective action and subsequent assurance.
Question 359. Which practice best supports transparency about limitations of an AI system?
- Documenting known limitations, assumptions, intended use, and situations where outputs require additional review
- Hiding known limitations from users
- Claiming that AI outputs are always accurate
- Removing system documentation
Correct Answer: 1. Documenting known limitations, assumptions, intended use, and situations where outputs require additional review
Explanation:
Transparency requires users and relevant stakeholders to understand the boundaries within which an AI system is expected to operate. Documentation can describe intended use, known limitations, important assumptions, data constraints, expected performance, uncertainty, and circumstances requiring human review or additional verification. This information helps users interpret outputs appropriately and reduces the risk of treating AI-generated results as universally reliable. Transparency should be proportionate to the system’s risk and audience. It should also be updated when significant changes occur. Documenting limitations does not eliminate model risk, but it supports informed use, meaningful oversight, accountability, and more appropriate decisions about when AI outputs should or should not be relied upon.
Question 360. What is an important characteristic of effective AI governance oversight?
- Oversight occurs only when an incident becomes public
- Oversight focuses exclusively on technical performance
- Oversight is based on regular evidence, defined responsibilities, risk information, and timely escalation
- Oversight is delegated permanently to individual users
Correct Answer: 3. Oversight is based on regular evidence, defined responsibilities, risk information, and timely escalation
Explanation:
Effective oversight requires an ongoing view of whether AI systems remain within approved purposes, risk appetite, control requirements, and performance expectations. Governance bodies need reliable evidence from monitoring, risk assessments, audits, incidents, control testing, exceptions, and remediation activities. Responsibilities should be clearly defined so that issues have accountable owners, while escalation criteria should identify when management intervention is necessary. Oversight should also consider changes in the business environment, AI capabilities, regulatory obligations, and external dependencies. This continuous approach allows governance leaders to identify emerging concerns before they become major failures. Strong oversight therefore combines evidence, accountability, risk awareness, and timely decision-making throughout the AI lifecycle.