{"id":18326,"date":"2026-09-22T06:44:52","date_gmt":"2026-09-22T06:44:52","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18326"},"modified":"2026-09-22T06:44:52","modified_gmt":"2026-09-22T06:44:52","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part2-q21-40","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part2-q21-40\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part2 Q21-40"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q21. An organization already uses an established enterprise risk management framework and plans to adopt AI extensively. What is the BEST approach to establishing AI risk governance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace the enterprise framework entirely with an AI-specific framework<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Allow each development team to create its own independent AI risk methodology<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Integrate AI-specific risk considerations into the existing enterprise framework and governance structure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Manage AI risks only through cybersecurity procedures<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Integrate AI-specific risk considerations into the existing enterprise framework and governance structure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI risk governance should normally extend and integrate with existing enterprise governance and risk management rather than creating an isolated structure. The organization can add AI-specific risks, controls, terminology, ownership requirements, and lifecycle activities while preserving established mechanisms for escalation, reporting, appetite, and accountability. This improves consistency and helps management compare AI risk with other enterprise exposures. AI risk is broader than cybersecurity because it may also involve privacy, bias, safety, legal, reputational, operational, and societal concerns. Separate team-specific methodologies can create inconsistent treatment and prevent leadership from obtaining an enterprise-wide view.<\/span><\/p>\n<p><b>Q22. A risk manager is defining responsibilities for an enterprise AI governance program. Which tool is MOST useful for clarifying who is responsible, accountable, consulted, and informed for key AI risk activities?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A RACI matrix<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A vulnerability scanner<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> A model accuracy chart<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> A data retention schedule only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. A RACI matrix<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A RACI matrix identifies who is Responsible, Accountable, Consulted, and Informed for specific activities. In AI governance, it can clarify roles for model approval, risk acceptance, data ownership, validation, monitoring, incident response, regulatory compliance, and decommissioning. This is particularly useful because AI systems often involve business owners, data scientists, legal teams, privacy officers, information security, compliance, and risk professionals. Clear responsibility prevents important tasks from being overlooked or duplicated. Technical tools such as vulnerability scanners and accuracy dashboards provide evidence about specific risk areas but do not establish organizational accountability.<\/span><\/p>\n<p><b>Q23. An organization operates AI systems in several countries with different legal requirements. What should the AI risk function do FIRST when assessing regulatory compliance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Apply the strictest known law globally without analysis<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Assume regulations apply only where the AI model was developed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Wait until a regulator requests documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Identify applicable jurisdictions, AI use cases, data processing activities, and relevant legal obligations**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Identify applicable jurisdictions, AI use cases, data processing activities, and relevant legal obligations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Regulatory assessment begins by understanding where the organization operates, which individuals and data are affected, what the AI system does, and which legal or regulatory regimes apply. Different obligations may depend on jurisdiction, industry, data type, decision impact, or AI system classification. Once applicability is determined, the organization can map requirements to controls, documentation, monitoring, and reporting obligations. Automatically applying one law globally may be unnecessarily restrictive or still miss unrelated requirements. Waiting for regulatory scrutiny is reactive and exposes the organization to avoidable compliance risk.<\/span><\/p>\n<p><b>Q24. A company is assessing whether an AI-enabled employee monitoring solution should be deployed. Which consideration is MOST important from an ethical and societal risk perspective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the system uses the newest algorithm<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Potential impacts on privacy, fairness, autonomy, and affected stakeholders<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether the vendor has the largest market share<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether the model has more parameters than competitors<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Potential impacts on privacy, fairness, autonomy, and affected stakeholders<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Ethical AI risk assessment should evaluate how a system affects people and stakeholders, not merely its technical sophistication. Employee monitoring can create significant concerns around privacy, discrimination, autonomy, transparency, power imbalance, and proportionality. The organization should consider whether the business purpose justifies these impacts and whether less intrusive alternatives exist. Stakeholder concerns, legal obligations, organizational values, and risk appetite should all inform the decision. A technically advanced model can still create unacceptable ethical or societal harm. ISACA\u2019s AAIR scope explicitly includes trustworthiness, ethics, bias, privacy, safety, and broader societal implications.<\/span><\/p>\n<p><b>Q25. During development of a high-impact AI model, the team cannot demonstrate where a portion of the training data originated. What is the PRIMARY risk management concern?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Insufficient data provenance and uncertainty about legality, quality, or suitability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The model will necessarily have low computational performance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The AI system cannot use encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The development environment will become unavailable<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Insufficient data provenance and uncertainty about legality, quality, or suitability<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Data provenance establishes where data came from, how it was obtained, how it was transformed, and whether its use is authorized and appropriate. Unknown provenance can create legal, intellectual-property, privacy, bias, quality, and integrity risks. It can also make investigation difficult if the model later produces harmful or unexpected outcomes. The organization should document data sources, ownership, licensing, consent where applicable, lineage, transformations, and quality controls. Model performance alone cannot compensate for uncertainty about whether training data was lawfully acquired or suitable for the intended use.<\/span><\/p>\n<p><b>Q26. A development team proposes using synthetic data because real customer data is highly sensitive. What should the risk professional emphasize?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Synthetic data automatically eliminates all privacy and bias risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Synthetic data never requires validation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Evaluate whether the synthetic data accurately represents required characteristics without recreating sensitive patterns or introducing bias<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Synthetic data should always replace real-world validation data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Evaluate whether the synthetic data accurately represents required characteristics without recreating sensitive patterns or introducing bias<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Synthetic data can reduce exposure to real sensitive records, but it is not automatically risk free. Poorly generated synthetic data may fail to represent important populations, amplify bias, distort statistical relationships, or unintentionally reproduce information from the source data. The organization should evaluate privacy leakage, representativeness, quality, and suitability for the intended AI use. Real-world validation may still be necessary depending on the system. Risk professionals should therefore treat synthetic data as one possible control or design choice rather than assuming it eliminates privacy, fairness, and data-quality concerns.<\/span><\/p>\n<p><b>Q27. Senior management requires explanations for how a high-impact AI model reaches decisions. What is the PRIMARY risk management benefit of explainability?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It guarantees that every model decision is correct<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It helps stakeholders understand, challenge, investigate, and govern model decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It eliminates the need for monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It prevents all malicious attacks against the model<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It helps stakeholders understand, challenge, investigate, and govern model decisions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Explainability can help decision-makers, users, validators, regulators, and affected stakeholders understand the factors influencing an AI output. This supports oversight, investigation of unexpected behavior, identification of bias or errors, and meaningful challenge of high-impact decisions. The appropriate level of explainability depends on the model, use case, legal obligations, and risk. Explainability does not guarantee accuracy and does not replace testing, monitoring, security, or human accountability. It is one component of trustworthy AI and can be particularly important when AI outputs affect significant decisions involving individuals or critical business processes.<\/span><\/p>\n<p><b>Q28. An AI model has passed technical validation, but the business process it supports has changed significantly before deployment. What should happen?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy because technical validation has already been completed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Ignore business-process changes if the model code did not change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Reduce monitoring after deployment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Reassess model suitability and risk against the changed business context before deployment**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Reassess model suitability and risk against the changed business context before deployment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI validation must address suitability for the intended use, not only technical performance. A significant business-process change can alter input data, decision impact, users, dependencies, control requirements, or expected outcomes even when the model itself is unchanged. Therefore, risk and validation evidence should be reviewed again before deployment. Continuing based on outdated assumptions can introduce unacceptable risk. Change management should consider AI-specific impacts, including whether changes to business processes, data sources, models, regulations, or system integrations require renewed testing, approval, documentation, or risk assessment.<\/span><\/p>\n<p><b>Q29. An organization discovers employees using unapproved AI tools for business tasks. What is this situation commonly called from an AI governance perspective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Model convergence<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data normalization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shadow AI<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Federated learning<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Shadow AI<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Shadow AI refers to AI tools, models, or services being used without appropriate organizational approval, governance, or visibility. It is similar to shadow IT but introduces AI-specific concerns such as confidential data exposure, unreviewed vendor terms, intellectual-property leakage, uncontrolled model outputs, regulatory risk, and inconsistent decision-making. Organizations should identify why employees are using unapproved tools and provide practical approved alternatives when possible. Discovery mechanisms, awareness, policies, access controls, procurement processes, and monitoring can all help address the issue. Merely banning AI without understanding business demand may drive usage further outside governance.<\/span><\/p>\n<p><b>Q30. During threat modeling, an organization identifies that malicious instructions embedded in an external document could manipulate a generative AI agent that reads the document. Which threat is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Indirect prompt injection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model drift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Algorithmic transparency<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Indirect prompt injection<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Indirect prompt injection occurs when malicious instructions are embedded in content that an AI system later retrieves or processes, such as documents, emails, webpages, or tickets. The attacker may attempt to manipulate the model into ignoring its intended instructions, revealing information, or invoking tools improperly. Controls can include treating retrieved content as untrusted, isolating instructions from data, restricting tool permissions, validating outputs, applying least privilege, and requiring approval for high-impact actions. This differs from model drift, which concerns performance changes over time rather than deliberate manipulation through contextual input.<\/span><\/p>\n<p><b>Q31. A malicious actor repeatedly queries a proprietary AI model and uses the outputs to build a similar substitute model. Which threat does this BEST describe?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Model hallucination<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data retention<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Concept drift<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Model extraction**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Model extraction<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Model extraction involves querying an AI system and using its outputs to infer or reproduce aspects of the original model&#8217;s behavior. This can threaten intellectual property, business advantage, and potentially security controls built around the proprietary model. Defenses may include authentication, rate limiting, monitoring unusual query patterns, limiting output detail, contractual protections, and detecting automated extraction behavior. Model extraction differs from model inversion, which seeks to infer sensitive information about underlying training data. Risk assessments for externally accessible AI models should consider both abuse of the model and unauthorized replication of its capabilities.<\/span><\/p>\n<p><b>Q32. An AI risk treatment plan includes a control requiring human review before a model can approve transactions above a defined financial threshold. What type of control is this primarily?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Physical control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Preventive control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Recovery control only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Environmental control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Preventive control<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Requiring human approval before a high-value transaction is finalized is primarily preventive because it aims to stop an inappropriate or erroneous AI-generated decision before the business action occurs. The control creates an intervention point where an authorized reviewer can challenge the model&#8217;s recommendation. Depending on implementation, related monitoring may also provide detective benefits, but the central purpose is prevention. Control design should align with the severity, reversibility, and likelihood of the underlying risk. High-impact AI decisions often benefit from defined human-in-the-loop thresholds rather than unrestricted automation.<\/span><\/p>\n<p><b>Q33. A control is well designed on paper but is consistently bypassed in day-to-day operation. What should the AI risk manager conclude?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Control operating effectiveness is inadequate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The control is effective because its documentation is complete<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Residual risk must be zero<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> No additional monitoring is required<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Control operating effectiveness is inadequate<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Control effectiveness includes both design and operation. A control may be theoretically capable of reducing risk but still fail if users bypass it, systems do not enforce it, or responsible teams do not perform required activities consistently. Testing should therefore assess whether controls operate as intended over an appropriate period, not simply whether policies and procedures exist. If operating effectiveness is inadequate, residual risk may be higher than originally assessed and additional remediation may be required. Documentation is evidence of control design, but it does not prove that the control actually works in practice.<\/span><\/p>\n<p><b>Q34. A risk team tracks the percentage of high-risk AI models that have completed independent validation before production deployment. What type of metric is this MOST directly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Revenue metric<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Environmental metric<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Model latency metric<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Control-performance or risk-management metric**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Control-performance or risk-management metric<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> The percentage of high-risk AI models completing required validation indicates whether a defined governance or control process is being performed consistently. It can help management identify gaps in the AI risk program and determine whether models are bypassing required review. The metric may be used as a KPI, control-performance indicator, or related risk-management measure depending on the organization&#8217;s terminology. It does not directly measure model latency or business revenue. Useful risk metrics should connect to defined expectations, thresholds, owners, and escalation processes so management can take action when performance falls outside acceptable limits.<\/span><\/p>\n<p><b>Q35. An organization relies on one cloud provider for nearly every critical AI capability, including models, vector storage, and inference infrastructure. Which risk deserves particular attention?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keyboard compatibility risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data-formatting risk only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Third-party concentration risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Office-location risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Third-party concentration risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Concentration risk arises when critical business capabilities depend heavily on one provider, technology, region, or service. A major outage, contractual dispute, security incident, regulatory restriction, price change, or strategic decision by the provider could affect many organizational AI services simultaneously. Supply-chain risk management should therefore evaluate dependencies, substitutability, exit strategies, resilience, data portability, contractual protections, and alternative providers where appropriate. Individual vendor controls may be strong while concentration risk remains high because the organization has limited options if that provider becomes unavailable or unsuitable.<\/span><\/p>\n<p><b>Q36. A critical AI vendor changes its model significantly without notifying the customer. What is the BEST contractual control to reduce this risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Require the customer to accept all vendor changes automatically<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Define notification, impact assessment, and approval requirements for material service or model changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Remove all service-level commitments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Permit the vendor to change data-use terms silently<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Define notification, impact assessment, and approval requirements for material service or model changes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Material changes to a third-party AI model can affect performance, bias, privacy, security, explainability, or regulatory compliance even when the customer&#8217;s own application remains unchanged. Contracts should therefore define when the vendor must notify the customer of significant changes and what assessment, testing, or approval rights apply. The organization may need time to validate new behavior before accepting it into critical processes. This is especially important for externally managed models where the customer has limited visibility into vendor development. Uncontrolled changes undermine lifecycle governance and can invalidate previous risk assessments.<\/span><\/p>\n<p><b>Q37. An AI system supports a business process with a maximum acceptable outage of four hours. Which business continuity metric should reflect this requirement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maximum model size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> False-positive rate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Mean training time<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Recovery Time Objective (RTO)**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Recovery Time Objective (RTO)<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Recovery Time Objective defines the targeted maximum time within which a disrupted service or business process should be restored following an outage. If the organization determines that the AI-supported process cannot remain unavailable for more than four hours, the RTO should reflect that business requirement. The AI solution&#8217;s architecture, redundancy, fallback procedures, vendor commitments, and recovery plans can then be designed and tested against the target. RTO differs from Recovery Point Objective, which concerns acceptable data-loss periods. AI services should be incorporated into existing business continuity and disaster recovery planning according to their business criticality.<\/span><\/p>\n<p><b>Q38. An AI incident playbook addresses model failure but does not identify who can disable the model in an emergency. What is the MOST important improvement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Define clear incident authority, escalation paths, and emergency shutdown responsibilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove human involvement from incident response<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require developers to wait for the next scheduled governance meeting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Allow any employee to disable production AI without authorization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Define clear incident authority, escalation paths, and emergency shutdown responsibilities<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI incident response requires clear decision rights so critical actions can be taken quickly and safely. The organization should identify who has authority to disable a model, invoke a fallback process, notify stakeholders, declare an incident, or accept temporary business impacts. Ambiguous authority can delay containment and increase harm. At the same time, emergency powers should be restricted to appropriate roles to avoid unauthorized disruption. AI-specific scenarios should be integrated into the organization&#8217;s existing incident management structure, including communications, evidence preservation, escalation, recovery, and lessons learned.<\/span><\/p>\n<p><b>Q39. An organization is deciding whether to accept a moderate residual AI risk. Who should make the acceptance decision?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The designated risk owner with the authority appropriate to the exposure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Any developer who worked on the model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The AI vendor exclusively<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> An automated model without human accountability<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The designated risk owner with the authority appropriate to the exposure<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Risk acceptance should be made by an accountable risk owner with sufficient authority to understand and accept the potential business consequences. The required approval level may depend on risk magnitude, regulatory requirements, financial exposure, or organizational policy. Risk professionals provide analysis and recommendations, while technical teams provide evidence about controls and model behavior. However, they should not independently accept business risk unless governance explicitly assigns that authority to them. Documented acceptance should identify the residual risk, rationale, conditions, monitoring requirements, and any expiration or reassessment date.<\/span><\/p>\n<p><b>Q40. An organization uses AI to prioritize enterprise risks for management review. Which control is MOST important to prevent overreliance on the AI output?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Remove access to the underlying risk data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permit the AI to automatically accept risks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Require validation and human judgment before material risk decisions are finalized<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Hide the model&#8217;s limitations from decision-makers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Require validation and human judgment before material risk decisions are finalized<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI can improve risk analysis by identifying trends, summarizing large datasets, and highlighting potential priorities, but material risk decisions should remain subject to appropriate validation and human accountability. The model may omit context, reflect biased data, or produce incorrect prioritization. Decision-makers should understand the tool&#8217;s limitations and use AI output as evidence rather than unquestioned authority. Independent data checks, explainability, monitoring, and human review help ensure that enterprise risk decisions remain aligned with strategy and risk appetite. ISACA includes leveraging AI within the risk management program while maintaining sound governance and oversight.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q21. An organization already uses an established enterprise risk management framework and plans to adopt AI extensively. What is the BEST approach to establishing AI risk governance? Replace the enterprise framework entirely with an AI-specific framework 2. Allow each development team to create its own [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18326"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18326"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18326\/revisions"}],"predecessor-version":[{"id":18327,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18326\/revisions\/18327"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}