View Full Isaca AAISM Exam Dumps and Practice Test Dumps
Question 81. Which activity is most important when establishing an AI governance committee?
- Defining clear responsibilities, authority, membership, and escalation procedures
- Allowing the committee to operate without documented objectives
- Limiting participation to software developers
- Reviewing AI systems only after incidents occur
Correct Answer: 1. Defining clear responsibilities, authority, membership, and escalation procedures
Explanation:
An AI governance committee needs clearly defined responsibilities and authority to operate effectively. Its structure should identify appropriate stakeholders, such as business leadership, risk, security, privacy, legal, compliance, data, and technical representatives, depending on organizational needs. The committee should have documented objectives, decision rights, escalation paths, meeting requirements, and reporting responsibilities. Without clear authority, governance decisions may be inconsistent or delayed. The committee should also coordinate with existing governance structures instead of duplicating them unnecessarily. Effective governance requires more than creating a committee name; the organization must ensure that members have the information, authority, and accountability needed to oversee AI risks and make informed decisions.
Question 82. What is the primary purpose of an AI policy framework?
- To provide mandatory technical specifications for every model
- To define organizational principles, requirements, responsibilities, and expectations for AI use
- To eliminate the need for risk assessments
- To allow unrestricted AI adoption
Correct Answer: 2. To define organizational principles, requirements, responsibilities, and expectations for AI use
Explanation:
An AI policy framework establishes the organization’s overall expectations for developing, acquiring, deploying, and using AI. It can define principles for responsible use, accountability, security, privacy, data management, risk assessment, human oversight, acceptable use, third-party services, and monitoring. Policies provide direction that can then be translated into procedures, standards, and technical controls. A policy should be sufficiently clear to guide decision-making while allowing detailed implementation requirements to evolve as AI capabilities and organizational needs change. Effective policies also identify roles and responsibilities so employees understand what is expected of them. Regular review ensures that the framework remains aligned with business objectives and applicable obligations.
Question 83. Which document should describe detailed steps for implementing an AI governance requirement?
- A procedure
- A marketing brochure
- An employee directory
- A financial statement
Correct Answer: 1. A procedure
Explanation:
A procedure translates higher-level governance requirements into specific operational steps. For example, an AI policy may require risk assessment before deployment, while a supporting procedure can define who submits the assessment, what information must be provided, which teams review it, how findings are documented, and what approval is required. Procedures make governance requirements actionable and consistent across teams. They should be sufficiently detailed for personnel to follow without requiring them to interpret broad policy language on their own. Procedures may be supported by templates, checklists, workflows, and technical controls. Keeping these materials current is important because changes in AI systems, organizational processes, or external requirements may affect how governance activities should be performed.
Question 84. Why should AI governance requirements be mapped to applicable regulations and organizational obligations?
- To identify relevant obligations and demonstrate how governance controls address them
- To guarantee that regulations will never change
- To eliminate the need for legal review
- To make all AI systems subject to identical controls
Correct Answer: 1. To identify relevant obligations and demonstrate how governance controls address them
Explanation:
Mapping AI governance requirements to applicable regulations, contractual obligations, and internal requirements helps an organization understand what obligations apply to particular AI systems. A mapping can connect requirements to policies, controls, evidence, responsible owners, and monitoring activities. This supports compliance assessments and helps identify gaps where an obligation does not have an appropriate control. It can also reduce duplicated work when multiple requirements address similar risks. However, a compliance mapping is not a substitute for professional legal interpretation when legal requirements are complex or ambiguous. Governance teams should periodically review mappings because regulations, contracts, business activities, and AI capabilities may change, potentially creating new obligations.
Question 85. What is the main purpose of an AI control framework?
- To provide a structured set of controls addressing identified AI risks and governance objectives
- To guarantee that every model produces correct results
- To replace all organizational policies
- To prevent any employee from using AI
Correct Answer: 1. To provide a structured set of controls addressing identified AI risks and governance objectives
Explanation:
An AI control framework organizes safeguards that support governance objectives and address identified risks. Depending on the organization’s environment, controls may address data protection, access management, model validation, monitoring, human oversight, documentation, third-party risk, incident response, change management, and accountability. A framework helps organizations determine which controls apply to different risk categories and provides a consistent basis for assessing control effectiveness. It does not guarantee perfect model performance or eliminate every AI risk. Controls should be selected according to the organization’s risk profile and business requirements. A mature framework also defines evidence requirements, control ownership, testing approaches, and mechanisms for addressing control deficiencies.
Question 86. Which activity provides evidence that an AI control is operating as intended?
- Control testing
- Informal discussion without records
- Removing the control documentation
- Assuming the control works because it was implemented
Correct Answer: 1. Control testing
Explanation:
Control testing provides evidence about whether a control is appropriately designed and operating as expected. For AI governance, testing might examine whether required approvals were obtained, access reviews occurred, model changes were authorized, monitoring alerts were investigated, or data-handling requirements were followed. The specific testing approach should reflect the nature and risk of the control. Simply implementing a control does not demonstrate that it is functioning effectively. Test results should be documented, including the scope, criteria, evidence examined, findings, and remediation requirements. Repeated testing can also help identify control degradation over time. This provides management and assurance functions with greater confidence in the operational effectiveness of AI governance controls.
Question 87. What is a control deficiency?
- A condition in which a control is missing, inadequately designed, or not operating effectively
- A successful completion of every governance requirement
- A documented AI business objective
- A completed employee training session
Correct Answer: 1. A condition in which a control is missing, inadequately designed, or not operating effectively
Explanation:
A control deficiency occurs when an expected safeguard does not adequately address the relevant risk or does not operate as intended. In an AI environment, examples may include missing approval records, excessive access permissions, incomplete monitoring, outdated model documentation, or failure to perform required validation. Identifying a deficiency does not automatically mean that an incident has occurred, but it indicates that the organization may have increased exposure. Deficiencies should be documented, assessed according to their potential impact, assigned to responsible owners, and addressed within appropriate timeframes. Governance teams should also consider whether similar weaknesses exist elsewhere. This helps organizations improve control effectiveness rather than simply correcting isolated documentation issues.
Question 88. Which factor should influence the frequency of AI control assessments?
- The color of the application’s interface
- The number of employees in unrelated departments
- The risk level, criticality, change rate, and control environment of the AI system
- The age of the organization’s office furniture
Correct Answer: 3. The risk level, criticality, change rate, and control environment of the AI system
Explanation:
The frequency of AI control assessments should be proportionate to the system’s risk and operating characteristics. High-impact systems may require more frequent assessments because failures could have significant consequences. Rapidly changing models, data pipelines, integrations, or external providers can also justify more frequent review. Lower-risk systems with stable configurations may be assessed less frequently, provided that monitoring does not indicate emerging concerns. Organizations should define assessment criteria in advance and document why a particular frequency was selected. Trigger-based reassessment can complement scheduled reviews, especially after significant changes, incidents, new threats, regulatory developments, or changes in intended use. This risk-based approach helps focus assurance resources where they are most needed.
Question 89. Why should AI governance exceptions be formally documented?
- To create visibility into deviations from approved requirements and support accountability
- To make exceptions permanent
- To avoid management involvement
- To eliminate the need for risk analysis
Correct Answer: 1. To create visibility into deviations from approved requirements and support accountability
Explanation:
Exceptions occur when an AI system or process cannot fully comply with an established requirement. Formal documentation should identify the affected requirement, business justification, associated risks, compensating controls, approval authority, duration, and review date. This prevents exceptions from becoming informal or permanent deviations that are forgotten over time. Risk owners and appropriate management should determine whether the residual exposure is acceptable. Temporary exceptions should normally have expiration or reassessment dates so that they do not remain indefinitely without review. Tracking exceptions also allows governance teams to identify recurring issues that may indicate unclear policies, inadequate resources, or the need to redesign a process or control.
Question 90. What is the purpose of compensating controls in AI governance?
- To provide an alternative safeguard when a primary control cannot fully be implemented
- To eliminate all governance requirements
- To allow risks to remain undocumented
- To replace risk ownership
Correct Answer: 1. To provide an alternative safeguard when a primary control cannot fully be implemented
Explanation:
A compensating control is an alternative measure designed to reduce risk when the preferred or primary control cannot be implemented as intended. For example, if a technical restriction is temporarily unavailable, additional monitoring, manual review, or stricter access procedures might provide partial risk reduction. A compensating control should be formally evaluated to determine whether it adequately addresses the relevant risk and should not simply be assumed to provide equivalent protection. Its use should be documented, approved by appropriate authority, and reviewed periodically. In AI governance, compensating controls can support practical risk management during transitional periods while the organization works toward implementing the intended control.
Question 91. Which activity best supports accountability for AI decisions?
- Clearly assigning decision responsibilities and maintaining appropriate records of significant decisions
- Allowing anonymous approvals
- Removing decision records after deployment
- Assigning every decision to the AI model
Correct Answer: 1. Clearly assigning decision responsibilities and maintaining appropriate records of significant decisions
Explanation:
Accountability requires the organization to know who is responsible for important AI-related decisions and to maintain sufficient evidence of how those decisions were made. Responsibilities may include approving use cases, accepting risks, validating models, authorizing deployment, reviewing exceptions, and responding to incidents. Records should be proportionate to the significance of the decision and may include approvals, assessment results, supporting evidence, and relevant dates. An AI model itself cannot replace organizational accountability. Clear responsibility structures help ensure that decisions can be reviewed and challenged when necessary. They also support audits and investigations by establishing a reliable record of authorization and oversight throughout the AI lifecycle.
Question 92. Why is segregation of duties important in high-risk AI processes?
- It reduces the possibility that one individual can control incompatible activities without independent oversight
- It allows one person to perform every governance function
- It removes the need for access controls
- It guarantees that no employee will make an error
Correct Answer: 1. It reduces the possibility that one individual can control incompatible activities without independent oversight
Explanation:
Segregation of duties reduces the risk associated with concentrating incompatible responsibilities in a single individual. In an AI environment, for example, the person developing a high-impact model might not also be the person responsible for independently approving its production deployment. Similarly, personnel who administer access may be subject to independent review. The exact separation should reflect organizational size and risk. Smaller organizations may use compensating controls when complete separation is impractical. Segregation of duties is not intended to imply distrust of employees; it creates structural checks that reduce opportunities for unauthorized changes, concealment of errors, or conflicts of interest. Properly designed separation strengthens accountability and independent oversight.
Question 93. What is the purpose of an AI risk appetite statement?
- To define the types and levels of AI risk the organization is willing to accept
- To guarantee that all AI risks are eliminated
- To define the programming language used for models
- To replace incident response procedures
Correct Answer: 1. To define the types and levels of AI risk the organization is willing to accept
Explanation:
An AI risk appetite statement provides management direction regarding the amount and types of AI-related risk the organization is prepared to accept while pursuing its objectives. It can help guide decisions about high-impact use cases, acceptable residual risk, data sensitivity, automation levels, third-party dependencies, and human oversight. Risk appetite should be translated into practical thresholds and escalation criteria so that teams can apply it consistently. It should also align with the organization’s broader enterprise risk framework rather than operating as an isolated document. Management should review the statement periodically because business objectives, AI capabilities, regulatory expectations, and threat conditions can change over time.
Question 94. Which practice helps ensure AI governance decisions remain traceable over time?
- Maintaining documented approvals, assessments, changes, exceptions, and review outcomes
- Relying only on verbal agreements
- Deleting historical governance records
- Allowing undocumented changes
Correct Answer: 1. Maintaining documented approvals, assessments, changes, exceptions, and review outcomes
Explanation:
Traceability allows an organization to reconstruct important governance decisions and understand how an AI system evolved. Relevant records may include risk assessments, approval decisions, model versions, validation results, policy exceptions, significant changes, monitoring findings, and review outcomes. These records support audits, incident investigations, regulatory inquiries, and internal accountability. Documentation should be sufficiently detailed to demonstrate what happened, when it occurred, who was responsible, and what evidence supported the decision. Records should also be protected from unauthorized alteration or deletion. Effective traceability does not mean retaining every piece of information indefinitely; retention should follow defined legal, business, security, and privacy requirements.
Question 95. What should happen when an AI monitoring process detects a significant risk threshold breach?
- The event should trigger predefined investigation, escalation, and response procedures
- The alert should automatically be ignored
- The system should continue operating without assessment
- All monitoring should be permanently disabled
Correct Answer: 1. The event should trigger predefined investigation, escalation, and response procedures
Explanation:
A meaningful monitoring threshold should be connected to an established response process. When an AI system exceeds a defined threshold for performance degradation, security anomalies, fairness concerns, unusual usage, or another important risk indicator, responsible personnel should know what actions are required. Depending on the severity, the response may include investigation, additional validation, temporary restrictions, escalation to management, human review, or suspension of the affected functionality. Thresholds and response procedures should be documented and tested so that teams do not need to develop a response during a crisis. Effective monitoring therefore requires more than collecting metrics; organizations need clear decision rules and escalation mechanisms for responding to significant findings.
Question 96. Why should AI governance metrics be reviewed as trends rather than isolated numbers?
- Trends can reveal whether risk conditions and control performance are improving, worsening, or remaining stable
- Single measurements are always useless
- Trends eliminate the need for management judgment
- Trend analysis guarantees accurate predictions
Correct Answer: 1. Trends can reveal whether risk conditions and control performance are improving, worsening, or remaining stable
Explanation:
A single governance metric provides only a snapshot, while trends can reveal changes over time. For example, an organization may have a small number of overdue remediation actions today, but a steadily increasing trend could indicate deteriorating governance performance. Similarly, repeated decreases in monitoring exceptions may indicate improvement, although the reason for the change should still be examined. Trend analysis should consider context, such as changes in the number of AI systems, business activity, or reporting methods. Management should avoid interpreting metrics mechanically and should investigate significant movements. Combining trend data with qualitative findings, incidents, assessments, and risk information provides a more complete basis for governance decisions.
Question 97. Which stakeholder is typically responsible for ensuring AI governance aligns with business objectives?
- Only the model’s end users
- Business leadership working with appropriate governance and risk stakeholders
- Only the external AI provider
- Only the database administrator
Correct Answer: 2. Business leadership working with appropriate governance and risk stakeholders
Explanation:
AI governance should remain connected to organizational objectives rather than becoming solely a technical exercise. Business leadership is responsible for ensuring that AI initiatives support legitimate business purposes and that associated risks are understood and appropriately managed. Governance, risk, legal, privacy, security, data, and technical stakeholders contribute specialized expertise. The precise allocation of responsibilities varies by organization, but accountability should be formally defined. External providers can supply services and contractual commitments but generally do not replace the organization’s responsibility for governing how those services are used. Strong alignment helps ensure that AI investments, risk controls, and oversight mechanisms support business goals while remaining consistent with organizational requirements.
Question 98. What is the purpose of an AI governance maturity assessment?
- To evaluate the current capability of AI governance processes and identify areas for improvement
- To guarantee that the organization has no AI risks
- To determine employee salaries
- To replace all governance policies
Correct Answer: 1. To evaluate the current capability of AI governance processes and identify areas for improvement
Explanation:
A governance maturity assessment evaluates how effectively an organization has established and operates its AI governance capabilities. Areas may include leadership oversight, policies, accountability, risk management, data governance, model lifecycle controls, monitoring, third-party management, incident response, training, and assurance. The assessment can identify strengths, gaps, inconsistencies, and opportunities for improvement. Maturity results should be interpreted as a way to guide improvement rather than as proof that all AI risks have been eliminated. Organizations can use findings to establish priorities, assign owners, define target capabilities, and track progress over time. Periodic reassessment can show whether governance improvements are becoming embedded in day-to-day operations.
Question 99. Which approach best supports continuous improvement of an AI governance program?
- Use assessment findings, incidents, monitoring results, lessons learned, and changing requirements to update governance practices
- Freeze governance policies permanently
- Ignore control deficiencies after remediation
- Review governance only when an external auditor requests it
Correct Answer: 1. Use assessment findings, incidents, monitoring results, lessons learned, and changing requirements to update governance practices
Explanation:
Continuous improvement requires organizations to use evidence from multiple sources to refine governance. Audit findings, risk assessments, incidents, near misses, monitoring results, user feedback, regulatory developments, and changes in AI capabilities can all reveal opportunities to improve policies and controls. Organizations should analyze root causes rather than addressing only individual symptoms. Improvements should be assigned to responsible owners, tracked to completion, and evaluated to determine whether they actually reduced the underlying problem. Governance should therefore be treated as an evolving capability rather than a static set of documents. Regular improvement cycles help organizations adapt their AI oversight as risks, technologies, business uses, and external expectations change.
Question 100. What is the most important characteristic of effective AI governance reporting?
- It provides decision-relevant, accurate, timely, and appropriately contextualized information to responsible stakeholders
- It contains the largest possible number of metrics
- It reports only successful AI deployments
- It avoids discussing unresolved risks
Correct Answer: 1. It provides decision-relevant, accurate, timely, and appropriately contextualized information to responsible stakeholders
Explanation:
Effective AI governance reporting should help responsible stakeholders understand the organization’s current risk and control environment and determine whether action is needed. Reports should focus on information relevant to decisions, such as significant risks, unresolved findings, incidents, exceptions, control performance, system changes, and emerging concerns. Metrics should be accurate and presented with sufficient context to prevent misleading interpretations. Reporting frequency should reflect the importance and volatility of the information. A report that contains many measurements but does not identify meaningful issues may provide little value. Good reporting supports transparency and accountability while enabling management and governance bodies to prioritize resources and respond appropriately to significant AI-related risks.