{"id":16872,"date":"2026-09-19T11:45:17","date_gmt":"2026-09-19T11:45:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=16872"},"modified":"2026-09-19T11:45:17","modified_gmt":"2026-09-19T11:45:17","slug":"isaca-aaism-practice-test-questions-and-exam-dumps-part20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aaism-practice-test-questions-and-exam-dumps-part20-q381-400\/","title":{"rendered":"Isaca AAISM Practice Test Questions and Exam Dumps Part20 Q381-400"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aaism-exam-dumps\"><b>Isaca AAISM Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 381. Which activity BEST helps an organization identify AI systems that may be operating without proper authorization?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing the enterprise AI inventory against approved procurement and deployment records<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increasing the number of AI models in development<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing inactive users from unrelated applications<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing only systems that have experienced incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Reviewing the enterprise AI inventory against approved procurement and deployment records<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Unauthorized AI systems can create significant governance, privacy, security, and compliance exposure because they may operate without appropriate risk assessment, ownership, monitoring, or approval. Comparing the enterprise AI inventory with procurement records, application inventories, deployment records, and other authoritative sources can help identify systems that are missing from governance processes. The objective is to establish organizational visibility and determine whether each system has an accountable owner and appropriate authorization. Reviewing only systems involved in incidents is reactive and may miss significant risks. Increasing development activity or modifying unrelated user accounts does not provide effective discovery. Regular reconciliation of inventories therefore helps identify shadow AI and ensures systems are brought into the appropriate governance lifecycle.<\/span><\/p>\n<h3><b>Question 382. What is the PRIMARY purpose of defining escalation criteria for AI-related risks?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure every issue is handled by the same employee<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To establish when a risk requires additional authority, expertise, or intervention<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for risk assessments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent management from accepting any risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To establish when a risk requires additional authority, expertise, or intervention<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI risks can vary significantly in severity, business impact, regulatory significance, and urgency. Clearly defined escalation criteria establish when an issue should move from operational management to specialized risk personnel, senior management, a governance committee, or another authorized decision-maker. Criteria may consider factors such as potential harm, regulatory exposure, affected individuals, security impact, model performance deterioration, or risk appetite thresholds. Escalation does not mean that management must reject every risk. Some risks may be accepted by authorized personnel when they fall within established tolerance. Effective escalation processes therefore improve accountability and ensure that significant AI risks receive the appropriate level of attention and decision-making authority.<\/span><\/p>\n<h3><b>Question 383. An AI system is producing increasingly inconsistent results after a major change in its operating environment. What should be evaluated FIRST?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the environmental change may have affected model assumptions or performance<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether all historical governance documents should be deleted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization should immediately purchase a new model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether monitoring should be permanently disabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether the environmental change may have affected model assumptions or performance<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A major operating-environment change can affect assumptions that supported the original AI validation and risk assessment. Changes may involve data sources, infrastructure, user behavior, integrations, business processes, external dependencies, or other environmental conditions. When model outputs become inconsistent after such a change, management should first determine whether there is a relationship between the environmental change and the observed behavior. This may require reviewing monitoring data, model inputs, dependencies, validation evidence, and recent changes. Immediate replacement may be premature because the underlying cause has not yet been established. Governance records should be preserved, and monitoring should remain active because it provides evidence needed for investigation, remediation, and future reassessment.<\/span><\/p>\n<h3><b>Question 384. Which control MOST effectively supports separation of duties during AI model deployment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing developers to approve their own production releases<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Giving one administrator responsibility for development, validation, and deployment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Requiring independent approval before production deployment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removing deployment records after successful implementation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Requiring independent approval before production deployment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Segregation of duties reduces the risk that one individual can develop, validate, approve, and deploy an AI model without independent oversight. Requiring an appropriately independent approval before production deployment creates an additional control point where evidence can be reviewed and potential weaknesses identified. Depending on the organization&#8217;s risk profile, development, validation, approval, and deployment responsibilities may be distributed across different individuals or teams. Allowing developers to approve their own releases creates a conflict of interest and reduces control effectiveness. Removing deployment records also eliminates important evidence. Independent approval should be supported by documented criteria, traceable evidence, and clearly assigned responsibilities.<\/span><\/p>\n<h3><b>Question 385. Which information is MOST important to include in documentation for an AI system&#8217;s intended use?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the model&#8217;s programming language<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the vendor&#8217;s marketing description<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the system&#8217;s storage location<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The business purpose, expected users, decision context, and significant limitations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. The business purpose, expected users, decision context, and significant limitations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documentation of intended use should provide enough context to determine how an AI system is authorized to operate and what boundaries apply. Important information includes the business purpose, expected users, types of decisions or recommendations supported, relevant data, operating context, significant limitations, and potentially prohibited or restricted uses. This information helps governance personnel determine whether actual usage remains within the approved scope. Technical details such as programming language and storage location can be useful but do not by themselves establish intended use. Vendor marketing material may also be incomplete or promotional. Clear intended-use documentation supports risk assessment, user training, monitoring, change management, and future reassessment when the system&#8217;s purpose or environment changes.<\/span><\/p>\n<h3><b>Question 386. What is the PRIMARY reason to maintain evidence linking an AI model version to its validation results?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prove that every model will produce identical outputs<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To establish which validated model was approved for a particular deployment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent all future model changes<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To establish which validated model was approved for a particular deployment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Model validation evidence is meaningful only when the organization can determine which specific model version was evaluated. Linking model versions to validation results creates traceability between testing and the artifact actually approved for use. Without this connection, a later or modified model could be deployed while the organization continues relying on validation results associated with an earlier version. Effective traceability can include model identifiers, version numbers, validation dates, datasets, test results, approval records, and deployment information. This control does not guarantee identical outputs or eliminate monitoring. Instead, it provides evidence that the model operating in production corresponds to the model that was evaluated and authorized under the organization&#8217;s governance process.<\/span><\/p>\n<h3><b>Question 387. Which approach BEST addresses privacy risk when AI training data contains more personal information than is necessary for the approved purpose?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Collecting additional personal information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Making the dataset available to all developers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Applying data minimization and removing or reducing unnecessary personal information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling all data-quality checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Applying data minimization and removing or reducing unnecessary personal information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data minimization reduces privacy exposure by limiting personal information to what is necessary for the legitimate and approved AI purpose. If training data contains unnecessary personal information, the organization should evaluate whether those fields can be removed, masked, aggregated, anonymized, or otherwise reduced while preserving required functionality. Broad access by developers increases exposure and does not address the underlying issue. Collecting additional information can increase privacy risk rather than reduce it. Data-quality checks should remain active because quality and privacy controls serve different objectives. Data minimization should be incorporated into AI data governance from collection and preparation through training, testing, deployment, retention, and disposal, with documented justification for sensitive data elements that remain necessary.<\/span><\/p>\n<h3><b>Question 388. An AI vendor uses subcontractors to process organizational data. What should governance personnel verify?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether subcontractor activities are covered by appropriate contractual and oversight requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether subcontractors can change the organization&#8217;s risk appetite<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether subcontractors can approve organizational AI deployments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether all subcontractor employees have unrestricted access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether subcontractor activities are covered by appropriate contractual and oversight requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party AI risk can extend beyond the primary vendor when subcontractors process data, provide infrastructure, operate model components, or perform other material services. Governance personnel should therefore determine which subcontractors are involved, what responsibilities they perform, what information they can access, and whether appropriate contractual protections and oversight mechanisms apply. Relevant requirements may include security controls, privacy obligations, confidentiality, incident notification, audit rights, data handling, geographic restrictions, and change notification. Subcontractors should not be given unrestricted access simply because they support the vendor. Nor should they determine the organization&#8217;s risk appetite or approve its deployments. Effective third-party governance requires visibility into material dependencies throughout the provider&#8217;s supply chain.<\/span><\/p>\n<h3><b>Question 389. What should management do when an AI control repeatedly fails despite previous corrective actions?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Close the finding without further analysis<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase the reporting frequency without changing the control<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ignore the issue if no incident has occurred<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Perform root-cause analysis and reassess whether the control design is appropriate<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Perform root-cause analysis and reassess whether the control design is appropriate<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated control failure suggests that previous remediation may have addressed symptoms rather than the underlying cause. Management should investigate why the control continues to fail and determine whether the problem involves control design, ownership, implementation, resources, system dependencies, training, monitoring, or unrealistic requirements. Root-cause analysis helps distinguish between isolated execution errors and structural weaknesses. If the control itself is poorly designed, simply repeating the same corrective action is unlikely to produce sustainable improvement. Governance personnel should document the analysis, assign accountable owners, establish corrective actions, and monitor effectiveness after implementation. Repeated findings should also be considered when evaluating residual risk and determining whether escalation to senior management is necessary.<\/span><\/p>\n<h3><b>Question 390. Which activity BEST demonstrates that AI governance is integrated into the organization&#8217;s risk management process?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AI risks are identified, assessed, treated, monitored, and reported through established enterprise risk processes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AI risks are maintained only by developers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AI risks are reviewed only after security incidents<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AI risks are excluded from enterprise reporting<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AI risks are identified, assessed, treated, monitored, and reported through established enterprise risk processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Integration with enterprise risk management helps ensure that AI risks receive consistent treatment alongside other significant organizational risks. This means AI risks should be identified, assessed according to defined criteria, assigned owners, treated through appropriate controls, monitored over time, and escalated or reported according to established governance requirements. Maintaining AI risks exclusively within development teams can create fragmented oversight and may prevent senior management from understanding enterprise-level exposure. Reactive review after incidents is also insufficient because risk management should be preventive as well as responsive. Effective integration allows management to consider AI risks in strategic planning, risk appetite decisions, resource allocation, assurance activities, and enterprise reporting.<\/span><\/p>\n<h3><b>Question 391. Which factor should MOST influence the level of human oversight required for an AI system?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of developers who built the system<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The potential impact and risk associated with AI-supported decisions<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The programming language used by the model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The physical size of the model&#8217;s infrastructure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The potential impact and risk associated with AI-supported decisions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Human oversight should be proportionate to the potential consequences of AI-supported decisions. Systems that influence high-impact decisions, sensitive activities, safety-related processes, or significant rights and interests generally require stronger review and intervention mechanisms than low-impact applications. The required level of oversight may include pre-decision review, approval, exception handling, ongoing monitoring, or the ability to override AI recommendations. Technical characteristics such as programming language or infrastructure size do not by themselves determine the appropriate governance level. The number of developers is similarly unrelated to the potential consequences of an AI decision. Risk-based human oversight helps ensure that AI systems remain subject to appropriate accountability while allowing lower-risk applications to operate with proportionate controls.<\/span><\/p>\n<h3><b>Question 392. What is the PRIMARY purpose of an AI risk register?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To document and track identified AI risks, owners, treatments, and status<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To store source code for every model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace all technical monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that no AI risk will occur<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To document and track identified AI risks, owners, treatments, and status<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An AI risk register provides a structured record of identified risks and supports ongoing risk management. Typical information can include the risk description, affected system, risk owner, inherent risk, existing controls, treatment plan, residual risk, target dates, status, and escalation information. Maintaining this information allows management to monitor whether identified risks are being treated effectively and whether important actions remain overdue. A risk register does not replace technical monitoring, testing, or other control activities, and it cannot guarantee that risks will not occur. Its value comes from creating accountability and visibility across the AI portfolio. It also provides evidence for governance committees, management reporting, audits, and periodic risk reassessments.<\/span><\/p>\n<h3><b>Question 393. Which condition should generally trigger reassessment of an AI system&#8217;s governance requirements?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A routine user login<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A minor formatting change in an unrelated report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A material change in the system&#8217;s purpose, data, model, or operating environment<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A scheduled employee vacation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. A material change in the system&#8217;s purpose, data, model, or operating environment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Governance requirements should be reassessed when changes could materially affect the assumptions, risks, controls, or approved purpose of an AI system. Examples include significant changes to the model, training or operational data, intended business use, user population, geographic scope, external provider, integrations, or operating environment. Such changes can introduce new privacy, security, fairness, performance, compliance, or operational risks. Routine events unrelated to the system&#8217;s risk profile generally do not require a governance reassessment. Organizations should define material-change triggers in their governance procedures so that responsible personnel know when to initiate additional risk assessment, validation, approval, documentation, or control changes before continuing or expanding use.<\/span><\/p>\n<h3><b>Question 394. Which practice BEST supports accountability for decisions made using AI recommendations?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing users to remain anonymous<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assigning responsibility only to the AI model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Avoiding documentation of decision outcomes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maintaining identifiable decision ownership and appropriate supporting records<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Maintaining identifiable decision ownership and appropriate supporting records<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AI systems may provide recommendations, classifications, predictions, or other outputs, but organizations still need clear accountability for consequential decisions. Identifiable decision ownership establishes who is responsible for reviewing the AI output, applying relevant policies, exercising judgment, and making or approving the final decision. Supporting records can include the AI system and version used, relevant inputs, output, human review, decision rationale, approvals, and applicable exceptions. Assigning responsibility to the model is not an effective accountability mechanism because the model cannot exercise organizational authority. Avoiding documentation also makes investigations and audits difficult. Strong governance therefore connects AI-assisted decisions to authorized individuals or functions and maintains sufficient evidence to support accountability.<\/span><\/p>\n<h3><b>Question 395. Why should organizations evaluate the portability of critical AI workloads when relying on an external provider?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To ensure every provider uses identical infrastructure<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To reduce dependence on a single provider and improve resilience<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate all vendor management requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To prevent any model from being updated<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To reduce dependence on a single provider and improve resilience<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Portability can reduce operational and strategic dependence on a single AI provider. If a critical provider experiences prolonged service disruption, changes pricing or functionality, introduces unacceptable model changes, or becomes unavailable, the organization&#8217;s ability to move workloads can affect business continuity. Portability considerations may include data formats, model artifacts, interfaces, contractual rights, documentation, alternative providers, migration procedures, and technical dependencies. Portability does not require providers to use identical infrastructure and does not eliminate vendor management. It also does not mean that model updates should be prohibited. Instead, understanding portability and exit requirements helps management evaluate concentration and lock-in risk and develop practical continuity options for critical AI services.<\/span><\/p>\n<h3><b>Question 396. What is the PRIMARY purpose of maintaining AI governance training records?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To demonstrate that relevant personnel received required governance education<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To guarantee that employees will never make mistakes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To replace competency assessments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To eliminate the need for policy communication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. To demonstrate that relevant personnel received required governance education<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Training records provide evidence that personnel who have AI-related responsibilities received the education required by organizational policy or governance standards. Depending on their roles, employees may need training covering acceptable AI use, data handling, privacy, security, risk escalation, human oversight, documentation, or other governance requirements. Records can help management identify gaps, support compliance reviews, and determine whether refresher training is necessary. Training records do not guarantee that employees will never make mistakes, so organizations may also need competency checks, monitoring, and supervision. Maintaining records should complement rather than replace policy communication. Effective training governance links role requirements to appropriate learning activities and retains evidence that those activities were completed.<\/span><\/p>\n<h3><b>Question 397. Which approach BEST supports transparency when communicating the limitations of an AI system to users?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hiding known limitations to encourage adoption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Providing clear information about relevant limitations, uncertainty, and appropriate use<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Claiming that the system is always accurate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing users to discover limitations only through incidents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Providing clear information about relevant limitations, uncertainty, and appropriate use<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Transparency requires users to have sufficient information to understand how an AI system should and should not be used. Communicating relevant limitations, uncertainty, known failure conditions, data constraints, and appropriate-use boundaries helps users make informed judgments about AI outputs. This is particularly important where inaccurate or misleading outputs could cause significant consequences. Hiding limitations can encourage inappropriate reliance, while claims of perfect accuracy create unrealistic expectations. Users should not have to discover important limitations through incidents. Transparency should be proportionate to the system&#8217;s risk and may include documentation, user guidance, interface notices, training, and escalation procedures. Clear communication supports responsible use and helps maintain appropriate human oversight.<\/span><\/p>\n<h3><b>Question 398. What should an organization consider when determining whether an AI governance exception is acceptable?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether granting the exception is convenient for the development team<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the exception can remain undocumented<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The risk created, compensating controls, authorization authority, duration, and review requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether similar exceptions were previously ignored<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The risk created, compensating controls, authorization authority, duration, and review requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Governance exceptions should be managed through a controlled process rather than informal agreements. Management should understand why the exception is needed, what risk it creates, whether compensating controls can reduce that risk, who has authority to approve it, how long it remains valid, and when it must be reviewed or closed. Documentation provides evidence of the decision and allows future reviewers to determine whether the exception remains justified. Convenience alone is not sufficient justification, and undocumented exceptions weaken accountability. Previous informal exceptions do not establish that a new exception is acceptable. A risk-based exception process helps organizations balance legitimate operational needs with governance requirements while ensuring that deviations remain visible, authorized, time-bound, and appropriately monitored.<\/span><\/p>\n<h3><b>Question 399. Which activity BEST helps an organization identify emerging AI governance risks before they become significant issues?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Conducting horizon scanning and periodically evaluating new developments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Waiting for incidents to reveal new risks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Reviewing only last year&#8217;s audit findings<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Discontinuing monitoring of external developments<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Conducting horizon scanning and periodically evaluating new developments<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Horizon scanning helps organizations identify emerging AI risks arising from changes in technology, regulations, threat patterns, business practices, vendor capabilities, and societal expectations. Early identification gives management more time to assess potential impacts and determine whether policies, controls, training, contracts, or risk assessments need to change. Waiting for incidents is reactive and may expose the organization to avoidable harm. Historical audit findings remain useful but cannot fully identify future developments. Effective horizon scanning should be structured and connected to governance decision-making, with relevant developments evaluated for materiality and translated into appropriate actions when necessary. This supports proactive governance and helps ensure that the AI risk management program remains responsive to a changing environment.<\/span><\/p>\n<h3><b>Question 400. Which outcome MOST clearly indicates that an AI governance framework is operating effectively?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Governance activities are performed only when auditors request evidence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AI risks are managed consistently, accountability is clear, controls are monitored, and identified weaknesses are addressed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All AI systems are managed exclusively by technical staff<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Governance documentation exists but is not used operationally<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. AI risks are managed consistently, accountability is clear, controls are monitored, and identified weaknesses are addressed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An effective AI governance framework should operate as an active management process rather than as documentation created primarily for audits. Evidence of effectiveness includes consistent risk identification and treatment, clear ownership, appropriate decision rights, functioning controls, monitoring, escalation of significant issues, and timely remediation of identified weaknesses. Governance should influence how AI systems are approved, deployed, monitored, changed, and retired. Technical personnel have important responsibilities, but enterprise governance should also involve business, risk, legal, privacy, security, compliance, and other appropriate functions. Simply having policies or records does not demonstrate effectiveness. The strongest evidence comes from governance processes being consistently applied and producing measurable improvements in accountability, risk management, control performance, and organizational resilience.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAISM Exam Dumps and Practice Test Dumps &nbsp; Question 381. Which activity BEST helps an organization identify AI systems that may be operating without proper authorization? Reviewing the enterprise AI inventory against approved procurement and deployment records Increasing the number of AI models in development Removing inactive users from unrelated applications Reviewing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16872"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=16872"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16872\/revisions"}],"predecessor-version":[{"id":16917,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/16872\/revisions\/16917"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=16872"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=16872"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=16872"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}