Isaca AAISM Practice Test Questions and Exam Dumps Part9 Q161-180

View Full Isaca AAISM Exam Dumps and Practice Test Dumps

 

Question 161. Which governance activity helps ensure that AI objectives remain aligned with changing business priorities?

  1. Periodically review AI initiatives against approved business strategies and objectives
  2. Freeze all AI projects after initial approval
  3. Allow technical teams to redefine business objectives independently
  4. Evaluate AI initiatives only after retirement

Correct Answer: 1. Periodically review AI initiatives against approved business strategies and objectives

Explanation:

AI governance should ensure that investments and operational activities continue to support organizational objectives as those objectives evolve. Periodic strategic reviews allow management to determine whether AI initiatives remain relevant, whether expected benefits are being realized, and whether changing business priorities require modifications. These reviews can also identify projects that have become unnecessary, duplicated, or inconsistent with current strategy. Freezing projects after approval can prevent appropriate adaptation, while allowing technical teams to redefine business objectives may weaken accountability. Governance should establish appropriate review points and decision criteria so that AI initiatives can be continued, modified, paused, or retired based on documented business and risk considerations.

Question 162. What is the purpose of defining decision rights within an AI governance framework?

  1. To eliminate collaboration between departments
  2. To identify who has authority to make, approve, challenge, and escalate AI-related decisions
  3. To transfer every AI decision to external vendors
  4. To prevent management from reviewing AI risks

Correct Answer: 2. To identify who has authority to make, approve, challenge, and escalate AI-related decisions

Explanation:

Clearly defined decision rights help prevent ambiguity over who is responsible for important AI governance decisions. An organization may have business owners, technical teams, security professionals, privacy specialists, legal personnel, compliance functions, risk managers, and executives participating in different decisions. A governance framework should specify who can propose, approve, reject, challenge, or escalate decisions based on their authority and expertise. This improves accountability and reduces the possibility that critical decisions are delayed or made without appropriate oversight. Decision rights should also address conflicts of interest and escalation when a decision exceeds the authority of the responsible role. Clearly documented authority structures make AI governance more predictable, transparent, and effective.

Question 163. Which practice best supports accountability when several departments jointly operate an AI system?

  1. Assign all responsibilities to the department that purchased the system
  2. Allow responsibilities to remain informal
  3. Document roles and responsibilities across business, technical, security, privacy, and governance functions
  4. Require only the vendor to accept accountability

Correct Answer: 3. Document roles and responsibilities across business, technical, security, privacy, and governance functions

Explanation:

Shared AI operations can create accountability gaps if responsibilities are not explicitly defined. A system may have one department as the business owner, another responsible for technical operations, a security team responsible for controls, privacy specialists overseeing personal information, and governance functions providing oversight. Documenting these responsibilities clarifies who performs each activity and who is ultimately accountable for decisions. A responsibility matrix can identify ownership for risk assessment, data management, validation, monitoring, incident response, approvals, and periodic review. Assigning everything to one department may ignore important expertise, while relying entirely on the vendor can leave the organization without sufficient internal accountability. Clear cross-functional responsibility supports effective lifecycle governance.

Question 164. Why should AI governance define minimum requirements before a system enters production?

  1. To ensure required risk, security, privacy, validation, documentation, and approval controls are addressed before operational use
  2. To prevent all AI experimentation
  3. To guarantee that every model will be error-free
  4. To remove the need for post-deployment monitoring

Correct Answer: 1. To ensure required risk, security, privacy, validation, documentation, and approval controls are addressed before operational use

Explanation:

Production deployment can create material business and risk consequences, so governance should establish minimum requirements that must be satisfied before an AI system becomes operational. Depending on the system’s risk classification, these requirements may include security testing, privacy assessment, data-quality evaluation, model validation, documentation, human oversight, monitoring arrangements, business approval, and incident-response preparation. Minimum requirements create a consistent baseline and reduce the likelihood that important controls are overlooked under schedule pressure. They do not prevent experimentation when separate development or testing environments are appropriately governed. Nor do they guarantee error-free systems. Instead, they provide evidence that known risks have been considered and that the organization has established appropriate controls before relying on the AI capability in production.

Question 165. What is the governance value of establishing an AI approval workflow?

  1. It ensures every AI system is approved by the same technical employee
  2. It eliminates the need to identify AI risks
  3. It creates a repeatable process for assessing, reviewing, approving, rejecting, or escalating AI use cases
  4. It allows business users to bypass organizational policies

Correct Answer: 3. It creates a repeatable process for assessing, reviewing, approving, rejecting, or escalating AI use cases

Explanation:

An AI approval workflow creates a consistent path from initial proposal through governance review and operational authorization. It can define required information, risk classification, stakeholder reviews, approval authorities, documentation requirements, exception handling, and escalation procedures. A repeatable workflow helps prevent individual projects from receiving inconsistent treatment and makes it easier to demonstrate that governance requirements were followed. The workflow should remain risk-based, meaning higher-impact or more sensitive use cases may require additional scrutiny. Approval does not mean that governance ends once deployment occurs; ongoing monitoring and reassessment remain important. A structured approval process therefore provides a foundation for accountability while allowing organizations to scale AI adoption in a controlled manner.

Question 166. Which condition should cause an AI use case to receive enhanced governance review?

  1. The application has a new logo
  2. The system has low-risk internal documentation
  3. The development team changes its meeting schedule
  4. The AI begins influencing high-impact decisions or processing significantly more sensitive information

Correct Answer: 4. The AI begins influencing high-impact decisions or processing significantly more sensitive information

Explanation:

Governance intensity should generally correspond to the potential impact and risk of an AI use case. If a system begins influencing decisions that can materially affect individuals or the organization, its risk profile may change substantially. Similarly, expanding the system to process more sensitive information can introduce additional privacy, security, and compliance concerns. Such changes may warrant enhanced assessment, additional controls, independent review, or updated approval. Minor administrative changes do not normally justify the same level of scrutiny. Organizations should establish clear triggers for enhanced governance so that material changes are identified consistently. This risk-based approach allows low-impact systems to remain manageable while directing stronger oversight toward use cases with greater potential consequences.

Question 167. What should an AI governance framework require when a system has a significant dependency on a critical external service?

  1. Ignore the dependency because the AI model remains internally controlled
  2. Identify the dependency, assess associated risks, establish resilience measures, and assign ownership
  3. Transfer all responsibility to the external provider
  4. Remove the dependency without assessing business impact

Correct Answer: 2. Identify the dependency, assess associated risks, establish resilience measures, and assign ownership

Explanation:

Critical external dependencies can affect the availability, security, performance, and continuity of AI services. Governance should identify these dependencies and assess the consequences of provider outages, service degradation, contractual changes, security incidents, or termination. Appropriate resilience measures may include alternative providers, backup processes, service-level requirements, contingency procedures, or manual fallback mechanisms. Ownership should be clearly assigned so that someone is responsible for monitoring the dependency and coordinating responses to significant issues. Simply transferring responsibility to the provider does not eliminate the organization’s exposure, particularly when the AI capability supports important business operations. Dependency governance should therefore be integrated with third-party risk management, business continuity, and AI lifecycle oversight.

Question 168. Which control is most appropriate for managing sensitive AI development environments?

  1. Apply least-privilege access, environment separation, monitoring, and controlled handling of sensitive data
  2. Give every developer administrator access
  3. Copy production data into development environments without restrictions
  4. Disable access logging to improve performance

Correct Answer: 1. Apply least-privilege access, environment separation, monitoring, and controlled handling of sensitive data

Explanation:

AI development environments can contain source data, training datasets, model artifacts, credentials, prompts, configurations, and other sensitive information. Strong controls should restrict access according to job responsibilities and separate development, testing, and production environments where appropriate. Sensitive production information should not automatically be copied into development environments without assessing necessity and applying suitable safeguards. Access logging and monitoring help identify inappropriate activity and support investigations. Administrator access should be limited to authorized personnel because excessive privileges increase the potential impact of compromised accounts or mistakes. These controls support confidentiality, integrity, and accountability throughout the AI development lifecycle while allowing authorized teams to perform their work.

Question 169. Why should AI governance address model and data artifact retention?

  1. To ensure every artifact is retained forever
  2. To increase storage costs
  3. To support reproducibility, investigation, auditability, and regulatory or business requirements while respecting retention limits
  4. To eliminate the need for version control

Correct Answer: 3. To support reproducibility, investigation, auditability, and regulatory or business requirements while respecting retention limits

Explanation:

Model and data artifacts can provide important evidence about how an AI system operated at a particular point in time. Appropriate retention may support reproducibility, incident investigation, audit activities, regulatory obligations, and analysis of changes in system behavior. Relevant artifacts can include model versions, configuration information, dataset references, validation results, approval records, and selected logs. However, retention should not mean keeping every artifact indefinitely. Organizations should define retention periods based on legal, regulatory, operational, security, and business requirements, while considering privacy and data-minimization principles. Controlled retention helps preserve necessary evidence without creating unnecessary storage, privacy, or security exposure. Retention requirements should be documented and consistently applied.

Question 170. What is the purpose of defining AI data-handling standards?

  1. To ensure that data used or processed by AI systems is handled consistently according to classification, purpose, security, privacy, and retention requirements
  2. To permit unrestricted use of all available organizational data
  3. To remove data classification from governance processes
  4. To allow AI systems to determine their own data retention policies

Correct Answer: 1. To ensure that data used or processed by AI systems is handled consistently according to classification, purpose, security, privacy, and retention requirements

Explanation:

AI systems may process large quantities of information from multiple sources, making consistent data-handling standards important. Such standards can define requirements for classification, approved purposes, access control, storage, transmission, retention, deletion, privacy, and secure disposal. They can also specify restrictions on using confidential or regulated information with external AI services. Consistent standards reduce the likelihood that teams will apply different protections to similar information. They also provide a foundation for monitoring and assessing whether AI systems comply with organizational expectations. Data-handling requirements should reflect the purpose for which information is processed and should be proportionate to its sensitivity. This supports responsible data use while reducing unnecessary security and privacy exposure.

Question 171. Which practice best supports secure handling of AI prompts and user inputs?

  1. Allow users to submit any information to public AI services
  2. Establish acceptable-use rules, sensitive-data restrictions, access controls, logging, and monitoring for prompt activity where appropriate
  3. Disable all user authentication
  4. Store every prompt indefinitely without considering sensitivity

Correct Answer: 2. Establish acceptable-use rules, sensitive-data restrictions, access controls, logging, and monitoring for prompt activity where appropriate

Explanation:

Prompts and user inputs can contain confidential business information, personal information, credentials, proprietary material, or other sensitive content. Governance should therefore establish clear rules describing what users may submit to different AI services and what information is prohibited or restricted. Access controls help limit use of AI tools to authorized users, while monitoring and logging can support detection of misuse when implemented with appropriate privacy safeguards. Organizations should also define retention practices rather than automatically keeping every prompt indefinitely. These controls are especially important when external AI services are involved because information submitted by users may be processed outside the organization’s direct environment. Effective prompt governance combines user awareness, technical controls, and clear accountability.

Question 172. What governance measure can help reduce unauthorized use of unapproved AI applications?

  1. Permit employees to select any AI service without oversight
  2. Eliminate acceptable-use policies
  3. Maintain an approved AI service list supported by access controls, awareness, monitoring, and exception procedures
  4. Rely solely on employees to remember vendor names

Correct Answer: 3. Maintain an approved AI service list supported by access controls, awareness, monitoring, and exception procedures

Explanation:

Unauthorized use of AI applications can create data leakage, privacy, security, contractual, and compliance risks. An approved-service process helps employees understand which AI tools have been assessed and may be used for organizational work. Technical controls can restrict access to prohibited services where practical, while awareness training explains the reasons behind the restrictions and provides guidance for safe alternatives. Monitoring may identify unexpected usage patterns, and a defined exception process allows legitimate business needs to be evaluated rather than forcing employees toward uncontrolled workarounds. The approved list should be maintained because vendor capabilities and organizational requirements can change. Combining policy, technology, education, and governance provides stronger control than relying solely on employee awareness.

Question 173. Which governance principle is most relevant when an organization permits employees to use generative AI for business activities?

  1. Employees should be accountable for following approved use requirements and protecting organizational information
  2. Generative AI use should never be documented
  3. All AI-generated information should be accepted without review
  4. Employees should be allowed to bypass security controls for convenience

Correct Answer: 1. Employees should be accountable for following approved use requirements and protecting organizational information

Explanation:

Generative AI can improve productivity but may also introduce risks involving confidential information, inaccurate outputs, intellectual property, privacy, and inappropriate use. Governance should establish clear acceptable-use requirements and assign accountability to employees who use these services. Users should understand what information may be entered, how outputs should be reviewed, which uses require approval, and when human judgment is required. AI-generated information should not automatically be treated as accurate or suitable for every purpose. Security and privacy requirements should remain applicable even when AI tools are easy to access. Clear accountability combined with practical guidance helps organizations gain value from generative AI while reducing the likelihood of uncontrolled or inappropriate use.

Question 174. Why should AI governance distinguish between experimental and production AI systems?

  1. Experimental systems never require any controls
  2. Production systems are always risk-free
  3. The distinction prevents all innovation
  4. Production systems generally require stronger operational, security, validation, monitoring, and accountability controls because they directly support business activities

Correct Answer: 4. Production systems generally require stronger operational, security, validation, monitoring, and accountability controls because they directly support business activities

Explanation:

Experimental AI systems may be used for research, prototyping, or evaluation and may not yet affect production business processes. Production systems, however, can directly influence customers, employees, financial outcomes, operational processes, or other significant activities. They therefore generally require stronger controls for security, privacy, validation, monitoring, availability, incident response, change management, and accountability. Experimental environments still need appropriate safeguards, especially when sensitive information is involved, but governance can be proportionate to their risk and purpose. Distinguishing lifecycle stages helps organizations avoid imposing identical requirements on every experiment while ensuring that systems entering operational use meet appropriate governance standards.

Question 175. Which practice supports controlled transition of an AI system from development to production?

  1. Deploy directly from an individual developer’s workstation
  2. Use documented release criteria, testing evidence, approvals, controlled deployment, and rollback procedures
  3. Skip validation if development testing was successful
  4. Remove the previous version before deployment

Correct Answer: 2. Use documented release criteria, testing evidence, approvals, controlled deployment, and rollback procedures

Explanation:

A controlled transition from development to production reduces the likelihood that untested or improperly configured AI components will affect business operations. Release criteria should specify what testing, validation, documentation, security review, and approvals are required before deployment. Controlled deployment mechanisms help ensure that the approved version is actually introduced into production. Rollback procedures provide a way to restore a previous known state if unexpected behavior or failures occur. Direct deployment from an individual workstation creates traceability and integrity concerns, while deleting the previous version can make recovery and investigation more difficult. A formal release process connects development activities with operational governance and provides evidence that production deployment was authorized and appropriately tested.

Question 176. What is the governance benefit of maintaining a rollback capability for critical AI systems?

  1. It guarantees that no incident will ever occur
  2. It eliminates the need for model validation
  3. It provides a controlled recovery option when a new model or configuration causes unacceptable behavior or operational impact
  4. It permits unlimited production experimentation

Correct Answer: 3. It provides a controlled recovery option when a new model or configuration causes unacceptable behavior or operational impact

Explanation:

Rollback capability is an important resilience and change-management control for critical AI systems. A new model version, configuration, data pipeline, or integration can behave unexpectedly despite prior testing. If the change creates unacceptable performance, security, reliability, or business impact, a documented rollback procedure can help restore a previously validated state. Rollback does not replace testing, monitoring, or approval because preventing problems remains preferable to recovering from them. The organization should know which prior version is available, how it can be restored, who can authorize the rollback, and how associated data or configurations will be handled. This supports operational resilience and reduces the potential duration and impact of AI-related incidents.

Question 177. Which governance activity best supports accountability after an AI-related incident?

  1. Preserve relevant evidence, document decisions and actions, identify responsible roles, and perform a structured post-incident review
  2. Delete system logs immediately
  3. Assign blame before investigating the incident
  4. Prevent affected stakeholders from receiving any information

Correct Answer: 1. Preserve relevant evidence, document decisions and actions, identify responsible roles, and perform a structured post-incident review

Explanation:

Post-incident governance should focus on understanding what occurred, how the organization responded, and what improvements are needed. Relevant evidence should be preserved so investigators can reconstruct events and evaluate contributing factors. Decisions, actions, approvals, and communications should be documented, while responsibilities should be identified based on established roles rather than assumptions made before investigation. A structured post-incident review can identify root causes, control weaknesses, process gaps, and lessons learned. Deleting logs can destroy important evidence, while assigning blame prematurely may interfere with objective analysis. Effective incident governance converts operational experience into improvements for controls, training, monitoring, documentation, and risk management.

Question 178. What should an AI governance program do with lessons identified from significant incidents?

  1. Keep them confidential from all governance personnel
  2. Use them to update risk assessments, controls, policies, training, monitoring, and other relevant governance practices
  3. Ignore them after the incident is closed
  4. Apply every lesson identically to every AI system regardless of risk

Correct Answer: 2. Use them to update risk assessments, controls, policies, training, monitoring, and other relevant governance practices

Explanation:

Incident lessons provide valuable evidence about how AI controls and governance processes perform under real conditions. Organizations should evaluate whether an incident reveals weaknesses in risk assessments, security controls, monitoring thresholds, policies, training, vendor management, or incident-response procedures. Relevant lessons can then be incorporated into governance improvements and shared with appropriate stakeholders. Not every lesson needs to be applied identically to every system; changes should be proportionate to the risks and circumstances involved. Ignoring lessons wastes an important source of information and can allow similar failures to recur. A mature governance program uses incidents as inputs for continuous improvement while maintaining appropriate documentation and accountability.

Question 179. Which practice helps ensure that AI governance remains effective as regulations and organizational requirements evolve?

  1. Freeze governance policies indefinitely
  2. Review relevant regulatory developments and organizational changes and update policies, controls, and procedures when necessary
  3. Allow individual developers to interpret regulations independently
  4. Update governance only after a regulatory penalty occurs

Correct Answer: 2. Review relevant regulatory developments and organizational changes and update policies, controls, and procedures when necessary

Explanation:

AI governance operates within an environment that can change over time. New laws, regulations, contractual requirements, business strategies, technologies, threats, and organizational structures can affect the controls that are appropriate for AI systems. Governance should therefore include a process for monitoring relevant changes and assessing their impact. When requirements change, policies, procedures, control frameworks, training, documentation, and system assessments may need to be updated. Waiting for a penalty before responding is reactive and may leave the organization exposed. Individual developers should not independently determine enterprise regulatory interpretations without appropriate oversight. A structured review process helps maintain alignment between AI practices and current organizational and external requirements.

Question 180. Which outcome best demonstrates that AI governance is providing effective oversight?

  1. The organization has many AI policies but no evidence of implementation
  2. Every AI system is governed identically regardless of risk
  3. Governance meetings occur frequently without documented decisions
  4. AI risks are identified, responsibilities are clear, controls are monitored, issues are escalated, and management receives useful information for decisions

**Correct Answer: 4. AI risks are identified, responsibilities are clear, controls are monitored, issues are escalated, and management receives useful information for decisions

Explanation:

Effective AI governance should be demonstrated through practical outcomes rather than simply the existence of policies or meetings. Important indicators include consistent identification and assessment of AI risks, clear ownership, appropriate controls, ongoing monitoring, timely remediation, effective escalation, reliable records, and meaningful reporting to management. Governance should be proportionate to risk rather than applying identical controls to every system. Meetings and policies can support governance, but they do not demonstrate effectiveness unless they lead to informed decisions and appropriate action. A mature program creates visibility into AI activities and risks while enabling accountable stakeholders to respond when conditions change. This combination of accountability, control, monitoring, and management oversight is central to effective AI governance.