{"id":16858,"date":"2026-09-19T11:49:27","date_gmt":"2026-09-19T11:49:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16858"},"modified":"2026-09-19T11:49:27","modified_gmt":"2026-09-19T11:49:27","slug":"isaca-aaism-practice-test-questions-and-exam-dumps-part6-q101-120","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aaism-practice-test-questions-and-exam-dumps-part6-q101-120\/","title":{"rendered":"Isaca AAISM Practice Test Questions and Exam Dumps Part6 Q101-120"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aaism-exam-dumps\"><b>Isaca AAISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 101. What is the primary purpose of an AI governance charter?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define the governance body&#8217;s purpose, authority, responsibilities, and scope<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all technical AI documentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee model accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide unrestricted authority to individual developers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To define the governance body&#8217;s purpose, authority, responsibilities, and scope<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI governance charter formally establishes how governance responsibilities will operate within an organization. It can define the purpose of the governance body, its scope, membership, decision-making authority, responsibilities, reporting relationships, and escalation mechanisms. A clear charter reduces ambiguity between business, technical, risk, legal, privacy, and security functions. It also helps ensure that governance activities are supported by appropriate organizational authority rather than relying on informal cooperation. The charter should align with the organization&#8217;s broader governance structure and should be reviewed when responsibilities or organizational objectives change. A well-defined charter provides the foundation for consistent oversight without replacing the detailed policies, procedures, and technical controls required to manage AI systems.<\/span><\/p>\n<h3><b>Question 102. Which responsibility should normally remain with senior management for significant AI initiatives?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Writing every model&#8217;s source code<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Approving risk appetite and overseeing significant AI-related risks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Performing every data transformation manually<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Configuring individual user accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Approving risk appetite and overseeing significant AI-related risks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Senior management provides strategic direction and accountability for significant organizational risks, including risks created by AI initiatives. Management should establish or approve the organization&#8217;s risk appetite and ensure that appropriate governance structures exist to identify, assess, treat, and monitor AI-related risks. Senior leaders do not need to perform technical development tasks or configure individual systems themselves. Instead, they should receive meaningful reporting and challenge significant risk decisions when appropriate. Management oversight is especially important for high-impact AI applications because these systems may create financial, operational, legal, privacy, security, or reputational consequences. Clear executive accountability helps ensure that AI governance remains connected to organizational objectives and enterprise risk management.<\/span><\/p>\n<h3><b>Question 103. Why should AI governance roles be documented in a responsibility matrix?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify who is responsible, accountable, consulted, and informed for important governance activities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for management oversight<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure one person performs every activity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all AI policies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To identify who is responsible, accountable, consulted, and informed for important governance activities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A responsibility matrix helps clarify ownership across complex AI governance activities. Different stakeholders may participate in risk assessments, model validation, privacy reviews, security testing, deployment approval, monitoring, incident response, and policy management. Without clearly defined responsibilities, important tasks can be overlooked or duplicated. A matrix such as RACI can distinguish who performs an activity, who is ultimately accountable, who must provide expertise or consultation, and who needs to be informed. This structure improves coordination and reduces ambiguity. The matrix should reflect the organization&#8217;s actual operating model and should be updated when roles, systems, or processes change. Clear accountability is particularly important for high-risk AI use cases.<\/span><\/p>\n<h3><b>Question 104. What is an AI impact assessment intended to identify?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the computational resources required by a model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The potential effects of an AI system on individuals, groups, the organization, and other stakeholders<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the cost of purchasing an AI service<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The preferred programming language for development<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The potential effects of an AI system on individuals, groups, the organization, and other stakeholders<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI impact assessment examines the potential consequences of deploying or using an AI system. Depending on the context, it can consider effects on individuals, groups, customers, employees, business operations, privacy, security, fairness, legal obligations, and other stakeholders. The assessment helps organizations identify concerns before or during deployment and determine whether additional safeguards are necessary. It can also support transparent decision-making by documenting assumptions, affected parties, potential harms, and mitigation measures. The depth of an impact assessment should be proportionate to the system&#8217;s risk and intended use. For higher-impact applications, organizations may need more extensive analysis, stakeholder involvement, testing, documentation, and approval before operational use.<\/span><\/p>\n<h3><b>Question 105. Which activity should occur when an AI use case changes materially after approval?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the change if the original system remains online<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reassess the use case and determine whether additional approval or controls are required<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the original risk assessment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically classify the system as low risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Reassess the use case and determine whether additional approval or controls are required<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An approved AI use case may become materially different when its purpose, users, data, model, decision authority, or operating environment changes. For example, an internal recommendation tool could become significantly higher risk if it is later used to support consequential decisions. Governance processes should therefore define what types of changes trigger reassessment. A material change may require a new impact assessment, updated risk classification, additional testing, revised documentation, or renewed approval. The original approval should not automatically be assumed to cover substantially different use. Change-triggered reassessment helps organizations maintain appropriate oversight throughout the lifecycle and ensures that controls remain aligned with the system&#8217;s actual purpose and risk profile.<\/span><\/p>\n<h3><b>Question 106. Which practice can help prevent sensitive information from being unintentionally submitted to an external generative AI service?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data loss prevention controls and clearly defined approved-use requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling all employee training<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing unrestricted external AI access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing data classification labels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Data loss prevention controls and clearly defined approved-use requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">External generative AI services can create information leakage risks when users submit confidential, proprietary, personal, or otherwise sensitive information. Organizations can address this through a combination of policy and technical controls. Acceptable-use requirements should explain what information may or may not be entered into external AI services. Technical measures such as data loss prevention, browser controls, approved enterprise AI platforms, access restrictions, and monitoring can reinforce those requirements. User training is also important because employees need to understand why certain information is restricted. Controls should reflect the organization&#8217;s data classification scheme and contractual obligations. The objective is to reduce inappropriate disclosure while still enabling authorized and useful AI adoption.<\/span><\/p>\n<h3><b>Question 107. What is the purpose of data classification in AI governance?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine appropriate handling and protection requirements based on data sensitivity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee data accuracy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure all data receives identical controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for access management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To determine appropriate handling and protection requirements based on data sensitivity<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data classification categorizes information according to characteristics such as sensitivity, confidentiality, criticality, or regulatory requirements. In AI environments, classification can help determine whether information may be used for training, testing, prompts, retrieval, or model outputs and what safeguards are required. Highly sensitive information may require stronger access restrictions, encryption, monitoring, retention controls, or prohibitions on use in certain external services. Classification does not itself guarantee data quality or security. It provides a basis for applying proportionate controls. Effective AI governance should connect data classifications with practical handling rules so that employees, applications, and AI systems can consistently determine how different categories of information should be protected.<\/span><\/p>\n<h3><b>Question 108. Which principle is most relevant when collecting only the information necessary for a defined AI purpose?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Unlimited data retention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Universal access<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maximum data collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Data minimization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization means collecting, processing, or retaining only the information that is necessary for a legitimate and defined purpose. In AI systems, minimizing data can reduce privacy exposure, security risk, storage requirements, and the potential consequences of a breach or misuse. It can also make governance easier because teams have fewer categories of information to manage. Organizations should first identify the intended AI purpose and then determine what information is genuinely required. Collecting additional data simply because it might become useful later can increase risk without providing corresponding value. Data minimization should be considered during system design, dataset creation, prompt handling, retention planning, and changes to the AI use case.<\/span><\/p>\n<h3><b>Question 109. What is the purpose of conducting bias and fairness testing on an AI system?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify whether model behavior may produce materially different or inappropriate outcomes across relevant groups<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that no model can ever make an error<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate all human decision-making<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To increase model size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To identify whether model behavior may produce materially different or inappropriate outcomes across relevant groups<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Fairness testing helps organizations investigate whether an AI system produces problematic differences in outcomes across relevant groups or populations. The appropriate evaluation depends on the use case, affected population, data characteristics, and organizational or legal requirements. Testing may examine differences in error rates, selection rates, false positives, false negatives, or other outcome measures. Results should be interpreted carefully because fairness metrics can sometimes produce different conclusions and may not capture every relevant concern. Testing should therefore be combined with contextual analysis, documentation, and appropriate stakeholder review. Identified disparities should be investigated to determine whether they arise from data, model behavior, business rules, or other aspects of the overall decision process.<\/span><\/p>\n<h3><b>Question 110. Why should fairness assessment methods be selected according to the AI use case?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because fairness concerns and appropriate metrics depend on the context, population, decisions, and consequences involved<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because one fairness metric is universally correct<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because technical performance is unrelated to fairness<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because fairness testing is only necessary for image models<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Because fairness concerns and appropriate metrics depend on the context, population, decisions, and consequences involved<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">There is no single fairness measurement that is appropriate for every AI application. The relevant assessment depends on what the system does, who is affected, what decisions are being supported, and what types of errors create harm. For example, an organization may need to examine different outcome and error measures depending on whether an AI system recommends content, detects fraud, supports resource allocation, or assists with another consequential process. Governance teams should define relevant populations and metrics before evaluating results and should document why the selected methods are appropriate. Fairness assessment should also consider limitations in the available data and should not treat a favorable metric as proof that every fairness concern has been resolved.<\/span><\/p>\n<h3><b>Question 111. Which practice best supports explainability of a high-impact AI decision?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Providing relevant information about the factors, process, and limitations underlying the decision<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hiding all information about the model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Providing only the model&#8217;s version number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing users to assume the output is always correct<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Providing relevant information about the factors, process, and limitations underlying the decision<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Explainability helps relevant stakeholders understand how an AI system arrived at an output or recommendation, to the extent appropriate for the model and use case. For high-impact decisions, stakeholders may need information about important input factors, decision logic, model limitations, confidence or uncertainty indicators, and the role of human review. The appropriate level of explanation varies by system and audience. Explainability does not necessarily mean exposing proprietary source code or every internal model parameter. Instead, governance should ensure that explanations provide meaningful information for oversight, challenge, and decision-making. Documentation should also clearly identify situations where the AI output may be unreliable or where additional human investigation is required.<\/span><\/p>\n<h3><b>Question 112. What is the role of human oversight when an AI system supports a high-impact decision?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide meaningful review, challenge, and intervention when appropriate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To approve every output without examination<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To transfer accountability entirely to the model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To remove all escalation procedures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To provide meaningful review, challenge, and intervention when appropriate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Human oversight is intended to ensure that consequential AI-supported decisions are not accepted automatically without appropriate review. Effective oversight requires people with suitable knowledge, authority, and access to relevant information. Reviewers should understand the AI system&#8217;s limitations and know when to question, reject, or escalate an output. Human oversight is ineffective if the reviewer simply approves every recommendation without examination or lacks the authority to intervene. Governance should therefore define when human review is mandatory, what evidence should be considered, and how decisions are documented. The level of oversight should be proportionate to risk, with higher-impact decisions generally requiring stronger review and intervention mechanisms.<\/span><\/p>\n<h3><b>Question 113. What is a key objective of AI model validation before production deployment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To obtain evidence that the model meets defined performance, risk, and governance requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that the model will never fail<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate all monitoring after deployment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To avoid documenting test results<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To obtain evidence that the model meets defined performance, risk, and governance requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Model validation provides evidence that an AI model is suitable for its intended purpose before it is placed into production. Validation can address performance, robustness, security, fairness, privacy, reliability, and other requirements relevant to the use case. The testing approach should use appropriate datasets and clearly defined criteria. Results and limitations should be documented so decision-makers understand what was tested and what was not. Validation does not guarantee future performance because models and operating environments can change. Consequently, predeployment validation should be complemented by postdeployment monitoring and periodic reassessment. Strong validation provides an evidence-based basis for deciding whether a model is ready for controlled operational use.<\/span><\/p>\n<h3><b>Question 114. Which situation should normally trigger additional AI risk assessment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A significant change to the model, data, purpose, users, or operating environment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A routine employee lunch break<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A change in office furniture<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A cosmetic change to an unrelated website<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A significant change to the model, data, purpose, users, or operating environment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI risk is dynamic, so material changes should trigger consideration of whether the existing assessment remains valid. Significant changes may include replacing a model, introducing a new dataset, expanding the system to a new population, changing the intended purpose, increasing automation, connecting new external services, or moving the system into a more critical business process. These changes can introduce risks that were not present during the original assessment. Organizations should establish defined change thresholds and reassessment triggers so teams know when additional review is required. Risk reassessment does not necessarily mean repeating every activity from the beginning; the scope should be proportionate to the nature and significance of the change.<\/span><\/p>\n<h3><b>Question 115. Why should AI-related incidents be analyzed for root causes?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify underlying weaknesses and reduce the likelihood of similar incidents recurring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To assign blame without examining controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To avoid documenting incidents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that future incidents are impossible<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To identify underlying weaknesses and reduce the likelihood of similar incidents recurring<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Root-cause analysis looks beyond the immediate symptom of an AI incident to determine why the event occurred and what weaknesses allowed it to happen. For example, an inaccurate output might result from poor data quality, inadequate validation, an unexpected model change, insufficient monitoring, or unclear user procedures. Identifying the underlying cause allows the organization to implement corrective actions that address the source of the problem rather than repeatedly fixing the same symptom. Findings can also reveal weaknesses that affect other AI systems. Incident analysis should be documented and incorporated into governance improvement activities. The goal is organizational learning, stronger controls, and reduced recurrence rather than simply assigning responsibility to an individual.<\/span><\/p>\n<h3><b>Question 116. Which element is important in an AI incident response plan?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Defined roles, escalation paths, containment actions, communication procedures, and recovery steps<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A requirement to ignore low-confidence alerts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An assumption that every incident is identical<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A prohibition on documenting incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Defined roles, escalation paths, containment actions, communication procedures, and recovery steps<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI incident response plan should provide clear guidance for handling events that may affect the security, reliability, privacy, fairness, or safety of an AI system. Important elements include incident classification, responsible roles, escalation thresholds, containment options, evidence preservation, communication requirements, investigation procedures, recovery actions, and post-incident review. Plans should account for AI-specific scenarios such as compromised models, data poisoning, inappropriate outputs, prompt-based attacks, privacy exposure, and unexpected model behavior. Testing the plan through exercises can identify gaps before a real incident occurs. Clear procedures reduce confusion during high-pressure situations and help ensure that technical, business, legal, privacy, and security stakeholders coordinate effectively.<\/span><\/p>\n<h3><b>Question 117. What is the purpose of maintaining an audit trail for significant AI governance activities?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To provide evidence of actions, decisions, approvals, changes, and events for accountability and review<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that all decisions are correct<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for access controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To store only successful AI outputs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To provide evidence of actions, decisions, approvals, changes, and events for accountability and review<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An audit trail provides a historical record of significant actions and decisions associated with an AI system. Depending on the environment, this can include model deployments, configuration changes, approvals, access events, risk decisions, exceptions, monitoring alerts, and incident actions. Reliable audit trails support investigations, compliance reviews, internal assurance, and accountability. Logs should be protected against unauthorized alteration and should have appropriate retention requirements. Organizations should also avoid collecting excessive information without a defined purpose, particularly where logs may contain sensitive data. Auditability is strongest when records are consistent, time-stamped, attributable to authenticated identities, and sufficiently detailed to reconstruct important events without creating unnecessary privacy or security exposure.<\/span><\/p>\n<h3><b>Question 118. Which practice helps protect the integrity of AI governance records?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Restricting modification access and maintaining controlled, traceable records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing every employee to edit approval records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deleting records whenever a model is updated<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Using shared anonymous accounts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Restricting modification access and maintaining controlled, traceable records<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Governance records such as risk assessments, approvals, model validation results, exceptions, and incident reports can be important evidence for accountability and assurance. Protecting their integrity requires controls that prevent unauthorized modification or deletion. Appropriate measures can include role-based access, separation of duties, authenticated identities, version history, audit logging, retention controls, and protected storage. Organizations should define who may create, approve, modify, or archive governance records. These controls help ensure that historical decisions remain trustworthy and that investigators can determine what changed and who performed the change. Strong record integrity is particularly important when governance evidence may later be required for audits, investigations, regulatory inquiries, or management review.<\/span><\/p>\n<h3><b>Question 119. What should an organization consider when evaluating an AI system&#8217;s transparency requirements?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The intended audience, use-case risk, relevant information needs, confidentiality constraints, and applicable obligations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the model&#8217;s computational speed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the vendor&#8217;s marketing materials<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the interface uses a modern design<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The intended audience, use-case risk, relevant information needs, confidentiality constraints, and applicable obligations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transparency requirements should be determined according to the context in which an AI system is used. Different stakeholders may require different information. Users may need to know that they are interacting with AI and understand important limitations, while auditors or governance teams may require deeper information about model versions, data sources, controls, and validation. Organizations must also consider confidentiality, intellectual property, privacy, security, and other obligations when deciding what information can be disclosed. Transparency does not mean revealing every technical detail to every audience. Instead, governance should provide appropriate and useful information to relevant stakeholders while protecting legitimate confidential or security-sensitive information.<\/span><\/p>\n<h3><b>Question 120. Which approach best demonstrates effective AI governance at the enterprise level?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Integrating AI oversight with enterprise risk management, accountability, policies, controls, monitoring, and continuous improvement<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Treating AI governance as the responsibility of developers alone<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing AI only after major failures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing each AI system to operate without common requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Integrating AI oversight with enterprise risk management, accountability, policies, controls, monitoring, and continuous improvement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Enterprise AI governance is most effective when it is integrated with existing organizational governance and risk-management structures. AI oversight should connect strategy, accountability, policies, risk assessment, data governance, security, privacy, model lifecycle management, third-party oversight, monitoring, incident response, assurance, and continuous improvement. Treating AI governance as a separate technical activity can create gaps because significant AI risks often involve business, legal, operational, and human factors. Enterprise integration also helps management establish consistent expectations while allowing controls to be tailored to individual risk levels. Effective governance is an ongoing process rather than a one-time approval exercise, requiring organizations to review performance, emerging risks, incidents, and changing requirements over time.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAISM Exam Dumps and Practice Test Dumps &nbsp; Question 101. What is the primary purpose of an AI governance charter? To define the governance body&#8217;s purpose, authority, responsibilities, and scope To replace all technical AI documentation To guarantee model accuracy To provide unrestricted authority to individual developers Correct Answer: 1. To define [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16858"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16858"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16858\/revisions"}],"predecessor-version":[{"id":16931,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16858\/revisions\/16931"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}