{"id":16871,"date":"2026-09-19T11:45:36","date_gmt":"2026-09-19T11:45:36","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16871"},"modified":"2026-09-19T11:45:36","modified_gmt":"2026-09-19T11:45:36","slug":"isaca-aaism-practice-test-questions-and-exam-dumps-part19-q361-380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aaism-practice-test-questions-and-exam-dumps-part19-q361-380\/","title":{"rendered":"Isaca AAISM Practice Test Questions and Exam Dumps Part19 Q361-380"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aaism-exam-dumps\"><b>Isaca AAISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 361. Which activity is MOST important when establishing accountability for an AI system used in a critical business process?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assigning responsibility to the IT help desk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Defining a documented owner with decision-making authority<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allowing the AI vendor to retain all accountability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reviewing the system only after an incident occurs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Defining a documented owner with decision-making authority<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A clearly documented owner is essential for accountability because AI systems can affect business decisions, customers, employees, and regulatory obligations. The owner should have sufficient authority to approve use, accept or escalate risks, ensure controls are implemented, and coordinate remediation when problems occur. Assigning responsibility without decision-making authority can create gaps because individuals may be expected to manage risks they cannot actually control. Vendor responsibility can supplement, but should not replace, organizational accountability. Periodic reviews and incident management are also important, but they do not establish ownership by themselves. Effective AI governance therefore connects each important AI system to an identifiable business or functional owner with defined responsibilities and escalation paths.<\/span><\/p>\n<h3><b>Question 362. What is the PRIMARY purpose of documenting the approved purpose of an AI system?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To establish boundaries for acceptable use and governance oversight<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To guarantee that model outputs are always accurate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To prevent all future modifications to the model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To establish boundaries for acceptable use and governance oversight<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documenting an AI system&#8217;s approved purpose establishes the boundaries within which the system has been assessed and authorized. This is important because a model that is acceptable for one business activity may create substantially different risks when reused for another purpose. The approved purpose provides a reference point for determining whether proposed changes require reassessment, additional controls, or new approval. It also helps auditors and governance personnel determine whether actual use matches authorized use. Documentation does not guarantee accuracy, prevent modifications, or eliminate monitoring requirements. Instead, it creates a clear governance baseline against which changes, exceptions, and operational behavior can be evaluated throughout the AI lifecycle.<\/span><\/p>\n<h3><b>Question 363. An organization discovers that an AI system is being used for a purpose outside its approved scope. What should management do FIRST?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Delete the system immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore the deviation if performance remains acceptable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Assess the unauthorized use and determine whether governance reassessment is required<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer ownership to the system vendor<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Assess the unauthorized use and determine whether governance reassessment is required<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Use outside an approved purpose can introduce new risks because the original risk assessment, controls, testing, privacy analysis, and approval may not cover the new activity. The appropriate first response is to assess the deviation and determine its materiality. Depending on the circumstances, the organization may need to pause the expanded use, perform a new risk assessment, update documentation, introduce additional controls, and obtain appropriate approval. Immediate deletion may be unnecessary, while ignoring the issue creates governance exposure. Transferring ownership to a vendor does not resolve the organization&#8217;s accountability. A structured assessment allows management to determine the appropriate corrective action based on the actual risk and impact of the changed use.<\/span><\/p>\n<h3><b>Question 364. Which control BEST supports traceability of AI model changes over time?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Periodic employee surveys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Unrestricted administrator access<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Manual verbal approvals<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Version-controlled model artifacts with documented change records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Version-controlled model artifacts with documented change records<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Version control provides a reliable method for identifying which model artifact was deployed, when it changed, who authorized the change, and what modifications were introduced. This traceability is particularly important when investigating unexpected model behavior, validating production results, or demonstrating compliance with governance requirements. Documented change records can connect model versions with associated datasets, validation evidence, approvals, and deployment activities. Verbal approvals and unrestricted access provide weak accountability and are difficult to audit. Employee surveys are unrelated to technical model traceability. A controlled version-management process therefore provides stronger evidence that AI model changes were authorized, tested, and appropriately documented before or during deployment.<\/span><\/p>\n<h3><b>Question 365. Why should AI governance include monitoring for material changes in model performance after deployment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Because a model can behave differently as data, environments, or usage patterns change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Because monitoring eliminates the need for model validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Because every performance change automatically means the model is defective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Because models cannot be modified after deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Because a model can behave differently as data, environments, or usage patterns change<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI performance can change after deployment because real-world conditions may differ from the conditions present during development and validation. Changes in input distributions, business processes, user behavior, external data, or system dependencies can cause performance deterioration or unexpected behavior. Continuous monitoring helps organizations identify these changes and determine whether corrective action or reassessment is necessary. Monitoring does not replace formal validation and does not mean that every change indicates a defect. Some variation may be expected, while other changes may exceed established thresholds and require investigation. Governance should therefore define meaningful performance indicators, thresholds, escalation procedures, and responsibilities so that material deterioration can be detected and addressed promptly.<\/span><\/p>\n<h3><b>Question 366. Which evidence would BEST demonstrate that a high-risk AI system received appropriate approval before production deployment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A general statement from the development team<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A documented approval record linked to the risk assessment and validation evidence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A screenshot of the system interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A vendor marketing document<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A documented approval record linked to the risk assessment and validation evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For a high-risk AI system, approval should be supported by evidence demonstrating that appropriate governance activities were completed before production deployment. A strong approval record can identify the system, responsible owner, assessed risks, required controls, validation results, approval authority, date, and applicable conditions. Linking the approval to the risk assessment and validation evidence establishes traceability between the identified risks, the controls designed to address them, and the decision to authorize production use. A developer statement, interface screenshot, or vendor marketing material does not provide sufficient governance evidence. Maintaining complete approval records also supports future audits, reassessments, incident investigations, and accountability when the system or its operating environment changes.<\/span><\/p>\n<h3><b>Question 367. What is the PRIMARY governance concern when an AI provider automatically changes a production model without prior organizational notification?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increased employee training costs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Reduced storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Loss of traceability and inability to confirm continued validation status<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Slower user interface performance<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Loss of traceability and inability to confirm continued validation status<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automatic provider changes can create governance risk because the organization may no longer know exactly which model version is operating in production or whether the changed model remains within the scope of its original validation and approval. This can affect performance, security, fairness, privacy, and regulatory compliance. The organization should establish contractual and technical mechanisms to obtain change notifications, version information, testing opportunities, and appropriate rollback or reassessment capabilities. Storage capacity and user-interface performance may be operational concerns, but they are not the primary governance issue. Maintaining traceability is critical because organizations need evidence that the production system continues to meet approved requirements after material changes by an external provider.<\/span><\/p>\n<h3><b>Question 368. Which practice BEST reduces the risk of unauthorized access to sensitive AI training data?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Applying least-privilege access with periodic access reviews<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Giving all developers administrator privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Storing training data in shared public repositories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Removing access logs to reduce storage requirements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Applying least-privilege access with periodic access reviews<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least-privilege access limits users and systems to the permissions necessary for their assigned responsibilities. For sensitive AI training data, this reduces the likelihood that unauthorized individuals can view, modify, copy, or extract information. Periodic access reviews help ensure that permissions remain appropriate as employees change roles, projects end, or responsibilities evolve. Administrative access for all developers creates unnecessary exposure, while public repositories may cause direct disclosure of sensitive information. Removing access logs also weakens accountability and makes investigations more difficult. Effective governance combines access restrictions with authentication, authorization, monitoring, logging, and periodic review so that access to training data remains controlled throughout the AI development and operational lifecycle.<\/span><\/p>\n<h3><b>Question 369. An AI governance committee notices that several high-risk remediation items are repeatedly overdue. What should it do FIRST?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Close the overdue items to improve reporting statistics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Increase the number of committee meetings without analyzing the cause<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove the remediation deadlines<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Analyze the recurring delays and identify their root causes**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Analyze the recurring delays and identify their root causes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeatedly overdue remediation indicates that the organization may have a systemic weakness rather than isolated missed deadlines. The governance committee should first analyze why remediation is not being completed. Possible causes include unclear ownership, insufficient resources, unrealistic deadlines, ineffective escalation, inadequate prioritization, or dependencies on other teams. Closing items without remediation would weaken governance reporting, while removing deadlines would reduce accountability. Additional meetings may help later but do not address the underlying problem by themselves. Root-cause analysis allows management to determine whether changes are needed to ownership, resources, risk prioritization, escalation mechanisms, or control processes. Governance metrics should therefore drive corrective action rather than simply improving the appearance of compliance.<\/span><\/p>\n<h3><b>Question 370. Which activity BEST supports responsible use of AI-generated information in a high-impact decision process?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing the AI output to determine the decision automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Requiring appropriate human review and verification before the decision<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disabling all logging of AI outputs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allowing users to bypass established approval procedures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Requiring appropriate human review and verification before the decision<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">High-impact decisions can have significant consequences for individuals or the organization, so AI-generated information should not automatically be treated as authoritative. Appropriate human review allows qualified personnel to evaluate whether the output is relevant, accurate, complete, and consistent with applicable policies and decision criteria. The level of review should be proportionate to the potential impact and risk of the AI application. Automatic acceptance of AI outputs can amplify errors, bias, or unsupported conclusions. Disabling logs removes important evidence, while bypassing approval procedures weakens governance. Human oversight should be supported by defined responsibilities, escalation procedures, documented decision criteria, and sufficient information for reviewers to challenge or override AI-generated recommendations when necessary.<\/span><\/p>\n<h3><b>Question 371. What is the PRIMARY purpose of maintaining an enterprise-wide AI system inventory?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To identify, classify, and govern AI systems throughout the organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To replace all individual system documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To guarantee that every AI system uses the same model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for risk assessments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To identify, classify, and govern AI systems throughout the organization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An enterprise-wide AI inventory provides visibility into the organization&#8217;s AI landscape. It can identify systems in development, testing, production, retirement, or external service environments and associate them with owners, purposes, risk classifications, providers, data types, and governance requirements. This visibility supports risk prioritization and helps management identify systems that may otherwise operate without appropriate oversight. An inventory does not replace detailed system documentation or eliminate the need for risk assessments. It also does not require every system to use the same technology. Instead, it provides a centralized governance foundation that enables organizations to determine which systems require enhanced controls, monitoring, validation, approval, or periodic reassessment based on their characteristics and risks.<\/span><\/p>\n<h3><b>Question 372. What should an organization do when an AI system&#8217;s risk classification changes from moderate to high?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Continue operating without modification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the system from the inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Apply the governance requirements associated with the higher risk classification<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Transfer all responsibility to the end users<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Apply the governance requirements associated with the higher risk classification<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A change from moderate to high risk indicates that the system&#8217;s potential impact or exposure has materially changed. The organization should reassess the system against the requirements applicable to high-risk AI and implement any additional controls, approvals, validation, human oversight, monitoring, documentation, or escalation procedures that are required. Continuing under the previous control level could leave significant risks insufficiently addressed. Removing the system from the inventory would reduce visibility, while transferring responsibility to users would not satisfy organizational governance obligations. Risk classification should therefore drive proportional governance. When the classification changes, management should document the reason for the change, reassess relevant risks, confirm control effectiveness, and obtain any required approval before continuing or expanding use.<\/span><\/p>\n<h3><b>Question 373. Which metric would provide the MOST useful indication that AI governance remediation is becoming less effective?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Number of employees attending unrelated training sessions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Number of AI systems purchased during the year<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of AI models stored in development repositories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increasing age and recurrence of unresolved high-risk findings<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Increasing age and recurrence of unresolved high-risk findings<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The age and recurrence of unresolved high-risk findings provide direct insight into whether governance weaknesses are being addressed effectively. If high-risk findings remain open for extended periods or repeatedly reappear after remediation, the organization may have problems with ownership, root-cause analysis, resource allocation, control design, or management escalation. A useful governance metric should help decision-makers identify deteriorating control effectiveness rather than merely measure activity. Employee training attendance, procurement volume, and the number of development models do not directly demonstrate whether governance deficiencies are being resolved. Combining remediation aging with recurrence trends can provide stronger insight into whether corrective actions are sustainable and whether management needs to intervene.<\/span><\/p>\n<h3><b>Question 374. Which control is MOST appropriate for protecting the integrity of AI governance records?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing all users to edit records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Using controlled access, audit logging, and change tracking<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Deleting historical approval records periodically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Storing governance records without ownership information<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Using controlled access, audit logging, and change tracking<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Governance records can include risk assessments, approvals, validation results, exceptions, remediation evidence, and other information needed to demonstrate accountability. Protecting their integrity requires controls that restrict who can modify records and provide evidence of changes. Controlled access limits unauthorized modifications, while audit logging and change tracking help identify who made a change, when it occurred, and what was changed. Deleting historical approval records weakens traceability and may remove evidence required for audits or investigations. Records without ownership information also create accountability gaps. Effective governance therefore treats critical records as controlled evidence, with appropriate retention, access, versioning, monitoring, and protection against unauthorized alteration or deletion.<\/span><\/p>\n<h3><b>Question 375. Why is third-party AI concentration risk important to enterprise governance?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Multiple critical systems may depend on the same provider or underlying model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It guarantees lower procurement costs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for contingency planning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents providers from changing their services<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Multiple critical systems may depend on the same provider or underlying model<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Concentration risk occurs when an organization becomes heavily dependent on one external AI provider, model family, platform, or supporting service. If that provider experiences an outage, security incident, significant model change, contractual dispute, service degradation, or business failure, multiple organizational processes could be affected simultaneously. Governance should therefore identify critical dependencies and evaluate the potential impact of common points of failure. Appropriate responses may include contingency planning, alternative providers, portability requirements, contractual protections, resilience testing, and dependency monitoring. Concentration risk does not guarantee lower costs and does not eliminate the need for contingency planning. Understanding shared dependencies allows management to determine whether the organization&#8217;s reliance on an external provider is consistent with its risk appetite and business continuity requirements.<\/span><\/p>\n<h3><b>Question 376. What is the PRIMARY benefit of documenting assumptions used during an AI risk assessment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It prevents all future changes to the system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It guarantees that the assessment will never become outdated<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It provides context for evaluating whether the assessment remains valid<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It removes the need for management approval<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. It provides context for evaluating whether the assessment remains valid<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Risk assessments depend on assumptions about the AI system, data, users, operating environment, dependencies, business purpose, controls, and potential threats. Documenting those assumptions allows reviewers to understand the basis of the original assessment and determine whether the conclusions remain appropriate when circumstances change. For example, a change in data sources, user population, model provider, geographic scope, or business purpose may invalidate an important assumption and trigger reassessment. Documentation does not prevent future changes or guarantee that an assessment remains current. Instead, it creates a reference point for governance reviews and helps auditors and risk owners identify which changes could materially affect the original conclusions.<\/span><\/p>\n<h3><b>Question 377. Which action BEST supports effective AI incident response governance?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Waiting until an incident occurs to identify responsibilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Establishing predefined roles, escalation criteria, and communication procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allowing each user to respond independently<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disabling monitoring during an incident<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Establishing predefined roles, escalation criteria, and communication procedures<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI incidents can involve technical failures, inaccurate outputs, privacy events, security compromises, model behavior changes, or other risks that require coordinated action. Predefined responsibilities and escalation criteria help the organization respond consistently rather than attempting to determine roles during a crisis. Communication procedures are also important because incidents may require notification of management, affected stakeholders, regulators, customers, vendors, or other parties depending on the circumstances. Individual users should not be expected to manage enterprise-level incidents independently. Disabling monitoring can also remove valuable evidence. Effective incident governance should integrate AI-specific considerations into the broader incident-management framework, including detection, containment, investigation, decision-making, communication, recovery, and lessons learned.<\/span><\/p>\n<h3><b>Question 378. What is the PRIMARY reason for periodically reviewing AI governance policies?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure policies remain aligned with organizational objectives, risks, and applicable requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To make all policies longer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To eliminate the need for procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To prevent any employee from suggesting changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To ensure policies remain aligned with organizational objectives, risks, and applicable requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI governance policies should evolve as organizational objectives, AI capabilities, risks, regulations, contractual obligations, and operating environments change. Periodic review helps determine whether existing requirements remain appropriate and whether gaps or outdated provisions need to be addressed. The review should consider changes in the organization&#8217;s AI portfolio, incidents, audit findings, risk assessments, regulatory developments, and lessons learned from operational experience. Simply increasing policy length does not improve governance, and policies do not eliminate the need for detailed procedures and controls. Preventing employee feedback can also reduce opportunities to identify practical weaknesses. A structured review process helps maintain policies that are understandable, enforceable, risk-based, and relevant to current AI use.<\/span><\/p>\n<h3><b>Question 379. An organization wants to determine whether its AI governance program is improving over time. Which approach is MOST useful?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Counting only the number of AI systems deployed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Measuring governance outcomes and trends against defined objectives<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Tracking only the amount spent on AI<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Measuring the number of governance documents created<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Measuring governance outcomes and trends against defined objectives<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Governance maturity and effectiveness should be evaluated using meaningful outcomes rather than simple activity counts. Useful measures can include timely remediation of high-risk findings, completion of required assessments, control effectiveness, incident trends, policy exceptions, approval compliance, monitoring coverage, and recurring deficiencies. These indicators should be compared over time against defined governance objectives and risk expectations. Counting systems, spending, or documents may provide contextual information but does not demonstrate whether governance is actually improving. Trend analysis can help management determine whether controls are becoming more effective, whether weaknesses are recurring, and where additional investment or corrective action may be necessary. Effective measurement connects governance activities to risk reduction, accountability, compliance, and sustainable operational outcomes.<\/span><\/p>\n<h3><b>Question 380. Which characteristic BEST demonstrates effective enterprise AI governance?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> All AI decisions are centralized within one technical team<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Governance focuses exclusively on technical model accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> AI systems operate without documented exceptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> AI use is governed through clear accountability, risk-based controls, monitoring, and continuous improvement<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. AI use is governed through clear accountability, risk-based controls, monitoring, and continuous improvement<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective enterprise AI governance requires more than technical model performance. It establishes clear accountability, defined decision rights, risk-based controls, appropriate approval processes, monitoring, documentation, human oversight where needed, and mechanisms for responding to incidents and changing conditions. Governance should operate throughout the AI lifecycle rather than only during development or after deployment. Continuous improvement allows organizations to learn from incidents, audits, performance trends, regulatory developments, and operational experience. Centralizing every decision within one technical team can create accountability and independence problems, while focusing only on accuracy overlooks privacy, security, compliance, fairness, and business risks. A mature governance program integrates these elements into a structured and sustainable enterprise framework.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAISM Exam Dumps and Practice Test Dumps &nbsp; Question 361. Which activity is MOST important when establishing accountability for an AI system used in a critical business process? Assigning responsibility to the IT help desk 2. Defining a documented owner with decision-making authority 3. Allowing the AI vendor to retain all accountability [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16871"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16871"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16871\/revisions"}],"predecessor-version":[{"id":16918,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16871\/revisions\/16918"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16871"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16871"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16871"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}