{"id":16866,"date":"2026-09-19T11:47:04","date_gmt":"2026-09-19T11:47:04","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16866"},"modified":"2026-09-19T11:47:04","modified_gmt":"2026-09-19T11:47:04","slug":"isaca-aaism-practice-test-questions-and-exam-dumps-part14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aaism-practice-test-questions-and-exam-dumps-part14-q261-280\/","title":{"rendered":"Isaca AAISM Practice Test Questions and Exam Dumps Part14 Q261-280"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aaism-exam-dumps\"><b>Isaca AAISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<h3><b>Question 261. What is the primary purpose of defining AI governance decision rights?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure every decision is made by the same individual<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for escalation procedures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To clarify who has authority to make, approve, challenge, and escalate AI-related decisions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To transfer all AI decisions to external vendors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. To clarify who has authority to make, approve, challenge, and escalate AI-related decisions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Clearly defined decision rights prevent ambiguity when AI-related decisions require approval, challenge, escalation, or risk acceptance. Governance should identify which roles can approve use cases, accept residual risk, authorize exceptions, suspend systems, approve material changes, and escalate significant issues. Decision rights should be aligned with the organization\u2019s risk appetite and the level of potential impact associated with the AI activity. Without clear authority, employees may make decisions beyond their responsibilities or delay important actions while searching for approval. Documented decision rights also improve accountability because governance reviewers can determine whether a decision was made by an appropriately authorized person.<\/span><\/p>\n<h3><b>Question 262. Which governance practice best prevents unauthorized AI use cases from entering production?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A formal intake and approval process before deployment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing developers to deploy prototypes directly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Relying only on employee awareness<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing AI systems only after an incident<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A formal intake and approval process before deployment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A formal AI intake and approval process provides a controlled mechanism for identifying proposed use cases before they become operational. The process can capture the intended purpose, data involved, stakeholders, risk classification, regulatory considerations, ownership, security requirements, and required testing. Appropriate approval authorities can then determine whether the proposed use is acceptable and what conditions must be satisfied before deployment. Relying solely on awareness may not prevent unauthorized applications, particularly when employees can easily access external AI services. Post-incident review is reactive and may expose the organization to avoidable risk. A controlled intake process establishes governance at the beginning of the AI lifecycle.<\/span><\/p>\n<h3><b>Question 263. Why should AI governance require documented approval conditions for higher-risk systems?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent any future changes to the system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To define the requirements and limitations under which the system is authorized to operate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all monitoring activities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure the system can be used for any business purpose<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To define the requirements and limitations under which the system is authorized to operate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Higher-risk AI systems may be approved only under specific conditions, such as restricted data sources, mandatory human review, defined user groups, performance thresholds, geographic limitations, monitoring requirements, or periodic reassessment. Documenting these conditions creates a clear connection between the approval decision and the system\u2019s permitted operating boundaries. It also helps operational teams understand what is and is not authorized. Conditions should be monitored because a system can become noncompliant if it is later used outside the approved scope. Documented conditions therefore support accountability, change management, auditability, and ongoing governance rather than simply serving as administrative paperwork.<\/span><\/p>\n<h3><b>Question 264. What should occur when an AI system begins operating outside its approved business purpose?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The issue should be ignored if outputs remain accurate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system should automatically receive permanent approval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The organization should assess the change and determine whether reassessment or additional authorization is required<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The original approval should automatically cover every future use<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The organization should assess the change and determine whether reassessment or additional authorization is required<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI system\u2019s approved purpose is an important part of its risk assessment because the purpose determines how data, outputs, users, and decisions are governed. Using the system for a materially different purpose can introduce new privacy, security, fairness, regulatory, operational, or business risks. The organization should therefore determine whether the change is within the existing approval or requires a new assessment and authorization. Accuracy alone does not demonstrate that the new use is acceptable. Governance should evaluate the changed context, affected stakeholders, applicable requirements, controls, and decision impact. This prevents approval for one use case from being incorrectly interpreted as unlimited authorization.<\/span><\/p>\n<h3><b>Question 265. Which control most directly supports segregation of duties in AI model deployment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing the developer to approve and deploy their own model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Separating model development, approval, and production deployment responsibilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing deployment records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Giving all project members administrator privileges<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Separating model development, approval, and production deployment responsibilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segregation of duties reduces the risk that one individual can independently develop, approve, and deploy an AI model without effective oversight. Separating these responsibilities creates independent checkpoints where changes can be reviewed and authorization can be verified. The exact structure depends on organizational size and risk, but higher-risk systems generally benefit from stronger separation. This control also supports accountability because the organization can determine who created the model, who validated it, who approved it, and who deployed it. Removing records or granting broad administrative privileges weakens these protections. Where complete separation is impractical, compensating controls should be considered and documented.<\/span><\/p>\n<h3><b>Question 266. What is a compensating control in an AI governance environment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A control that provides an alternative risk-reduction mechanism when the preferred control cannot be implemented as designed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A control that eliminates the need for risk assessment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A control used only for financial accounting<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A control that automatically accepts residual risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A control that provides an alternative risk-reduction mechanism when the preferred control cannot be implemented as designed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A compensating control is an alternative measure used when a primary control cannot reasonably be implemented or cannot operate as intended. For example, if a technical segregation mechanism is unavailable, additional independent review, enhanced logging, restricted access, or more frequent monitoring may reduce the associated risk. A compensating control should not simply be a weaker version of the original control without justification. Governance should document why the primary control is unavailable, how the alternative reduces risk, who approved it, and how its effectiveness will be monitored. Compensating controls should be reviewed periodically to determine whether the original control can eventually be implemented or whether the alternative remains appropriate.<\/span><\/p>\n<h3><b>Question 267. Why should AI governance monitor policy exceptions after they are approved?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To determine whether exceptions remain justified and do not become permanent uncontrolled practices<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure every exception is automatically renewed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent management from reviewing exceptions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for policy requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To determine whether exceptions remain justified and do not become permanent uncontrolled practices<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Policy exceptions may be necessary when legitimate business circumstances make full compliance with a standard requirement impractical. However, an exception can create additional risk and should therefore have defined scope, ownership, duration, compensating controls, and approval authority. Monitoring helps determine whether the exception remains necessary, whether its conditions are being followed, and whether the underlying reason has been resolved. Without periodic review, temporary exceptions can become permanent practices that effectively bypass governance requirements. Exception reporting can also reveal recurring situations that indicate a policy needs clarification or redesign. Governance should therefore track exceptions as active risk decisions rather than treating approval as the end of the process.<\/span><\/p>\n<h3><b>Question 268. What should an organization consider when defining the scope of an AI governance policy?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only systems developed internally<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only models purchased from vendors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AI systems, services, use cases, data, and organizational activities relevant to the policy\u2019s objectives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only AI systems classified as low risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. AI systems, services, use cases, data, and organizational activities relevant to the policy\u2019s objectives<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI governance policy should clearly define what activities and systems it covers so that employees and stakeholders understand their responsibilities. Depending on organizational needs, scope may include internally developed models, externally provided AI services, embedded AI capabilities, experimental systems, business-process integrations, relevant data activities, and third-party dependencies. Restricting the policy only to internally developed models can create significant gaps because externally hosted services may introduce substantial privacy, security, contractual, or compliance risks. Scope should be aligned with the policy\u2019s objectives and risk environment. Clear definitions also support consistent application and make it easier to determine whether a proposed AI activity falls within governance requirements.<\/span><\/p>\n<h3><b>Question 269. Which factor should influence the level of governance oversight applied to an AI use case?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of pages in its documentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The popularity of the AI vendor<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The age of the development team<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The potential impact, risk, sensitivity, and criticality of the use case<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The potential impact, risk, sensitivity, and criticality of the use case<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk-based governance applies oversight proportionate to the potential consequences and characteristics of an AI use case. Factors may include the sensitivity of data, impact on individuals, criticality of the business process, regulatory requirements, degree of automation, security exposure, potential financial consequences, and uncertainty in system behavior. A low-impact internal productivity tool may require fewer controls than an AI system supporting high-impact decisions. Applying identical governance requirements to every system can consume resources inefficiently while failing to address important risks appropriately. Governance teams should therefore define risk criteria that determine approval, validation, monitoring, human oversight, documentation, and assurance requirements.<\/span><\/p>\n<h3><b>Question 270. What is the purpose of defining AI risk appetite at the enterprise level?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To establish the types and levels of AI risk the organization is willing to accept while pursuing its objectives<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that no AI risk will ever occur<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate business-unit responsibility<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To require every AI system to use identical controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To establish the types and levels of AI risk the organization is willing to accept while pursuing its objectives<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI risk appetite provides strategic guidance about the amount and nature of risk the organization is willing to accept in pursuit of business objectives. It helps management determine boundaries for AI deployment and supports consistent decisions across business units. Risk appetite can address areas such as privacy, security, reliability, regulatory exposure, human impact, financial loss, or operational disruption. It does not mean that the organization expects zero risk. Instead, it establishes acceptable boundaries and informs risk treatment, escalation, and acceptance decisions. Governance teams can use risk appetite to define thresholds and criteria that translate enterprise expectations into practical requirements for individual AI systems.<\/span><\/p>\n<h3><b>Question 271. What should happen when an AI system approaches or exceeds a defined risk appetite threshold?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The threshold should be deleted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The issue should trigger appropriate monitoring, escalation, or risk treatment according to governance procedures<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system should automatically receive approval<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The risk should be hidden from management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The issue should trigger appropriate monitoring, escalation, or risk treatment according to governance procedures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk appetite thresholds provide a basis for determining when AI exposure requires management attention. When a system approaches or exceeds a threshold, the organization should follow predefined procedures that may include increased monitoring, additional controls, reassessment, escalation, temporary restriction, or formal risk acceptance by an authorized authority. The appropriate response depends on the nature and severity of the threshold breach. Deleting the threshold or hiding the issue would undermine governance. Thresholds should also be periodically reviewed to ensure they remain meaningful as the organization\u2019s objectives, AI portfolio, regulatory environment, and risk tolerance evolve. Effective threshold management connects risk measurement with actionable governance decisions.<\/span><\/p>\n<h3><b>Question 272. Why should AI governance include clear ownership for data used by AI systems?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure accountability for data quality, access, use, and lifecycle requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To make every employee responsible for the same dataset<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate data classification<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To allow unrestricted data sharing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To ensure accountability for data quality, access, use, and lifecycle requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data ownership establishes accountability for how important datasets are managed throughout their lifecycle. For AI systems, ownership may include responsibility for data quality, classification, access permissions, retention, appropriate use, provenance, privacy requirements, and issue resolution. Without clear ownership, problems such as outdated information, excessive access, unauthorized reuse, or unclear retention responsibilities may remain unresolved. Ownership does not necessarily mean that one person performs every data-management task; operational responsibilities can be delegated while accountability remains clear. Governance should also define how data owners interact with AI system owners, security teams, privacy functions, and other stakeholders when data-related risks affect model performance or compliance.<\/span><\/p>\n<h3><b>Question 273. Which practice best supports responsible reuse of data across multiple AI systems?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing unrestricted reuse because the data was already collected<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluating whether the secondary use is authorized, appropriate, and consistent with applicable requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing all data documentation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically approving every new AI application<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Evaluating whether the secondary use is authorized, appropriate, and consistent with applicable requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data collected for one purpose may not automatically be appropriate for every subsequent AI use. Secondary use should be evaluated against applicable permissions, privacy expectations, contractual conditions, security requirements, data quality considerations, and organizational policies. The organization should determine whether the new purpose is compatible with the original collection context and whether additional safeguards or authorization are necessary. Simply assuming that previously collected data can be reused can create privacy, legal, ethical, or governance risks. Responsible reuse may also require data minimization, de-identification, access restrictions, documentation, or additional impact assessment. The evaluation should be proportionate to the sensitivity of the data and the potential impact of the new AI use.<\/span><\/p>\n<h3><b>Question 274. What is the main governance purpose of maintaining an AI system inventory?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To create a complete and current view of AI systems that require oversight<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To increase the number of AI systems deployed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all risk assessments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To track only retired applications<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To create a complete and current view of AI systems that require oversight<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI system inventory provides visibility into the organization\u2019s AI landscape. Useful inventory information may include system owner, business purpose, risk classification, data categories, deployment status, model or provider, critical dependencies, approval status, and lifecycle stage. This information allows governance teams to identify systems that require assessment, monitoring, reassessment, or retirement. Without an accurate inventory, organizations may overlook unauthorized or unmanaged AI applications, particularly when employees can acquire external AI services independently. The inventory should be maintained as systems are introduced, modified, transferred, or retired. It should also connect with risk management and governance workflows so that inventory information remains operationally useful rather than becoming a static list.<\/span><\/p>\n<h3><b>Question 275. What should an organization do when an AI system is identified outside the official governance inventory?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore it until it causes an incident<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automatically delete it without assessment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Identify ownership, assess its use and risk, and bring it into the appropriate governance process<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Grant it unrestricted production access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Identify ownership, assess its use and risk, and bring it into the appropriate governance process<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI system outside the official inventory may represent an unauthorized application, an overlooked business system, an experimental tool, or a third-party service acquired without appropriate review. Governance should first establish what the system does, who owns it, what data it uses, how it is being used, and what risks it introduces. The organization can then determine whether it should be approved, restricted, remediated, or retired. Automatically deleting an unknown system without understanding its business dependencies could create operational disruption. Ignoring it can leave significant risks unmanaged. Bringing the system into the formal inventory and governance process restores visibility and accountability.<\/span><\/p>\n<h3><b>Question 276. Which governance measure helps reduce the risk of employees entering confidential information into unauthorized generative AI services?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing the number of public AI tools<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Combining acceptable-use policies with technical data-loss controls and employee training<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing all monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing unrestricted external AI access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Combining acceptable-use policies with technical data-loss controls and employee training<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Preventing inappropriate disclosure to external generative AI services usually requires multiple complementary controls. An acceptable-use policy establishes clear expectations about what information employees may or may not submit. Technical controls such as data-loss prevention, access restrictions, browser controls, or approved-service lists can reduce opportunities for accidental disclosure. Training helps employees recognize sensitive information and understand approved alternatives. No single control is likely to address every scenario because users may interact with different services and data types. Governance should also monitor policy violations and update controls as AI services evolve. The objective is to reduce exposure while allowing legitimate and appropriately governed AI use.<\/span><\/p>\n<h3><b>Question 277. What is an important governance requirement for AI systems that process personal information?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignoring data-subject rights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Using all available personal data to maximize model performance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Applying appropriate privacy, purpose, access, retention, and security controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retaining personal information indefinitely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Applying appropriate privacy, purpose, access, retention, and security controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI systems that process personal information require governance that addresses the complete data lifecycle. Relevant controls may include defined purposes, data minimization, appropriate access, retention limits, security safeguards, transparency requirements, and mechanisms for addressing applicable individual rights. The exact obligations depend on the organization, jurisdiction, data type, and use case. Maximizing the quantity of personal data is not automatically appropriate because unnecessary data can increase privacy and security exposure. Indefinite retention can create additional risks as well. Governance should ensure that personal information is collected, processed, stored, shared, and disposed of according to applicable requirements and documented organizational practices.<\/span><\/p>\n<h3><b>Question 278. Why should AI governance consider explainability requirements when defining controls?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because every AI model must expose all source code<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because relevant stakeholders may need understandable information about how AI outputs are produced or used<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because explainability eliminates all model errors<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because technical documentation is never necessary<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Because relevant stakeholders may need understandable information about how AI outputs are produced or used<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Explainability requirements should be proportionate to the AI system\u2019s purpose, risk, and affected stakeholders. In higher-impact contexts, users, decision-makers, auditors, regulators, or affected individuals may need understandable information about the factors influencing an AI output or how the output is incorporated into a decision. Explainability does not necessarily require disclosure of proprietary source code or complete technical details. The organization should determine what information is necessary to support transparency, accountability, review, and appropriate challenge. Explainability also has limitations, particularly for complex models, so governance should consider complementary controls such as human oversight, testing, documentation, and outcome monitoring.<\/span><\/p>\n<h3><b>Question 279. What should governance teams consider when an AI system produces inconsistent results for similar inputs?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the inconsistency could indicate reliability, data, configuration, or model-behavior issues<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether all monitoring should be disabled<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether inconsistent results should automatically be accepted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the system should be exempted from validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether the inconsistency could indicate reliability, data, configuration, or model-behavior issues<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unexpected inconsistency can be an indicator of a problem with model behavior, input data, configuration, dependencies, randomness, system integration, or other operating conditions. Governance should establish appropriate criteria for identifying material inconsistencies and investigating their causes. The significance depends on the use case because some AI systems may naturally produce variable outputs while others require highly consistent behavior. Testing should therefore reflect the system\u2019s intended purpose and risk. If inconsistency creates unacceptable exposure, the organization may need additional controls, model changes, human review, restricted use, or escalation. Monitoring should continue after remediation to confirm that the issue has been adequately addressed.<\/span><\/p>\n<h3><b>Question 280. Which action best supports governance when an AI system reaches the end of its approved lifecycle?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keep all access active indefinitely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continue using the system without review<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove all records immediately<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Follow a controlled retirement process covering access, data, dependencies, records, and residual risks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Follow a controlled retirement process covering access, data, dependencies, records, and residual risks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI retirement should be governed as carefully as deployment because systems may remain connected to data, users, applications, vendors, or business processes after their active use ends. A controlled retirement process should address access removal, credential revocation, data retention and disposal, infrastructure decommissioning, dependency changes, contractual obligations, documentation retention, and any remaining risks. Relevant records should be retained according to applicable requirements rather than deleted automatically. Business stakeholders should also confirm that replacement processes are functioning before critical services are discontinued. Controlled retirement reduces the likelihood that obsolete AI systems remain accessible or create unmanaged security, privacy, operational, or compliance exposure after their approved lifecycle has ended.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAISM Exam Dumps and Practice Test Dumps Question 261. What is the primary purpose of defining AI governance decision rights? To ensure every decision is made by the same individual To eliminate the need for escalation procedures To clarify who has authority to make, approve, challenge, and escalate AI-related decisions To transfer [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16866"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16866"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16866\/revisions"}],"predecessor-version":[{"id":16923,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16866\/revisions\/16923"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16866"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16866"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16866"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}