{"id":18337,"date":"2026-09-22T06:47:17","date_gmt":"2026-09-22T06:47:17","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=18337"},"modified":"2026-09-22T06:47:17","modified_gmt":"2026-09-22T06:47:17","slug":"isaca-aair-practice-test-questions-and-exam-dumps-part7-q121-140","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-aair-practice-test-questions-and-exam-dumps-part7-q121-140\/","title":{"rendered":"Isaca AAIR Practice Test Questions and Exam Dumps Part7 Q121-140"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aair-exam-dumps\"><b>Isaca AAIR Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Q121. An enterprise wants to compare AI risk exposure across business units that use different scoring methods. What should the organization do FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate all business-unit risk assessments<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Establish a common AI risk scoring methodology and definitions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Allow each unit to report only its highest risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Compare raw scores without normalization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Establish a common AI risk scoring methodology and definitions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Enterprise-level comparison requires a consistent basis for evaluating and communicating risk. A common methodology should define concepts such as likelihood, impact, inherent risk, residual risk, control effectiveness, and escalation thresholds. Without common definitions, a \u201chigh\u201d risk in one business unit may not be comparable with a \u201chigh\u201d risk elsewhere. Standardization does not prevent local context from being considered; rather, it creates a shared framework for aggregation and reporting. This supports consistent prioritization, governance, and board-level oversight across the organization.<\/span><\/p>\n<p><b>Q122. A new AI use case has significant potential value but falls outside the organization&#8217;s current risk appetite. What is the MOST appropriate governance response?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deploy immediately because expected value is high<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Lower the risk score without changing controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Escalate for an authorized risk appetite or strategy decision before proceeding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the use case from documentation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Escalate for an authorized risk appetite or strategy decision before proceeding<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> When a proposed use case exceeds established risk appetite, project teams should not proceed unilaterally. The issue should be escalated to the appropriate governance body or executive authority that can decide whether to revise strategy, change appetite, require stronger controls, or reject the use case. High expected value does not automatically override approved risk boundaries. Proper escalation preserves accountability and ensures that strategic tradeoffs are made by those authorized to accept enterprise-level consequences.<\/span><\/p>\n<p><b>Q123. An organization is implementing a new AI governance framework. Which activity BEST helps avoid duplicate controls and conflicting requirements?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Map framework requirements to existing enterprise policies and controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Create an entirely separate governance organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Ignore existing risk frameworks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove all legacy controls before mapping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Map framework requirements to existing enterprise policies and controls<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Framework mapping identifies where existing controls already satisfy new requirements and where gaps remain. This prevents unnecessary duplication, reduces conflicting terminology, and helps the organization integrate AI governance with established enterprise risk, privacy, security, compliance, and internal-control programs. Mapping also helps demonstrate coverage during audits and regulatory reviews. Replacing all existing controls without analysis can create disruption and may eliminate controls that already address important AI risks.<\/span><\/p>\n<p><b>Q124. A high-risk AI system requires human oversight. Which factor is MOST important in determining whether that oversight is effective?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of reviewers assigned<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whether reviewers always agree with the model<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Whether review is performed after every decision regardless of risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Whether reviewers can understand, challenge, and override the AI output**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Whether reviewers can understand, challenge, and override the AI output<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Human oversight is meaningful only when the reviewer has sufficient authority, information, competence, and practical ability to disagree with the system. A nominal review step in which people simply approve AI recommendations does not provide effective risk reduction. Reviewers should understand the context and limitations of the model and have clear escalation and override procedures. The required level of oversight should be proportionate to the impact and reversibility of the AI-supported decision.<\/span><\/p>\n<p><b>Q125. During AI model development, a dataset contains significantly fewer examples from one population than others. What risk should be assessed MOST directly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Potential representativeness and fairness issues<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Certificate revocation risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Vendor lock-in only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disaster recovery risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Potential representativeness and fairness issues<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Underrepresentation of a relevant population can reduce model performance for that group and create unfair or discriminatory outcomes. The organization should assess whether the dataset adequately represents the population affected by the AI system and whether performance differs materially across groups. Data collection, rebalancing, alternative modeling approaches, or use-case restrictions may be needed. The appropriate response depends on the business context and applicable legal or ethical requirements.<\/span><\/p>\n<p><b>Q126. An AI model has high overall accuracy but performs poorly for a small, high-risk subgroup. What should management conclude?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Overall accuracy proves the model is acceptable<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Subgroup performance must be evaluated separately because aggregate metrics can hide material risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The subgroup should be removed from reporting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Accuracy metrics should no longer be used<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Subgroup performance must be evaluated separately because aggregate metrics can hide material risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Aggregate performance can conceal poor outcomes for smaller populations or specialized scenarios. When an affected subgroup faces meaningful consequences, separate performance analysis may be necessary to understand fairness, safety, and reliability. Management should determine whether the disparity is within acceptable tolerance and whether additional controls, model changes, or use restrictions are needed. A model can appear successful overall while still creating unacceptable risk for particular groups.<\/span><\/p>\n<p><b>Q127. A model is retrained using new data but its architecture remains unchanged. Why should the new version still undergo validation?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Retraining can materially change model behavior even without code changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Validation is needed only when source code changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> New data never affects fairness or accuracy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Previous validation automatically covers all future versions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Retraining can materially change model behavior even without code changes<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> New training data can alter accuracy, calibration, fairness, robustness, and decision boundaries even when model architecture and code remain identical. The organization should therefore treat retraining as a potentially material lifecycle change. Validation should be proportionate to the change and risk level and may include comparison with the prior version, regression testing, fairness testing, and updated documentation. This ensures that deployment decisions are based on current evidence rather than outdated assumptions.<\/span><\/p>\n<p><b>Q128. An AI system requires multiple external data sources to function. One source suddenly becomes unavailable. What risk management concept is MOST relevant?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Model explainability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Data minimization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Dependency and resilience risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Intellectual-property ownership only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Dependency and resilience risk<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI systems often rely on upstream data, APIs, cloud services, and other components. Failure of one dependency can degrade or disable the AI system even if the model itself remains healthy. Risk assessment should therefore identify critical dependencies, single points of failure, fallback options, service-level expectations, and recovery arrangements. Understanding dependencies is also important for business continuity, third-party risk, and concentration analysis.<\/span><\/p>\n<p><b>Q129. A generative AI system produces fabricated but plausible information. What risk is MOST directly illustrated?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Data poisoning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model hallucination<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Membership inference<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Supply-chain concentration<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Model hallucination<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Hallucination occurs when a generative AI system produces information that appears coherent and confident but is unsupported or incorrect. This can create significant risk when users rely on AI outputs for legal, financial, medical, or operational decisions. Controls may include grounding responses in trusted sources, human review, confidence or uncertainty handling, restricted use cases, and factual verification. The required controls should reflect the consequence of an incorrect answer.<\/span><\/p>\n<p><b>Q130. An organization wants to know whether an AI control actually reduced the targeted risk after implementation. What is the BEST approach?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume implementation means the control is effective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Review only the control documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Compare relevant risk indicators and evidence before and after implementation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove the risk from the register immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Compare relevant risk indicators and evidence before and after implementation<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Control effectiveness should be demonstrated through evidence that the control is operating as intended and reducing the target risk. This may involve monitoring KRIs, incident rates, exception volumes, test results, or other relevant measures before and after implementation. Documentation alone proves design intent, not actual effectiveness. Residual risk should be reassessed after treatment based on evidence rather than assumed to have improved automatically.<\/span><\/p>\n<p><b>Q131. A risk owner accepts a material AI risk but provides no rationale or review date. What is the PRIMARY governance weakness?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The model is necessarily inaccurate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Risk acceptance lacks documented accountability and lifecycle management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk treatment must always be avoidance<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The AI system should be decommissioned immediately<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Risk acceptance lacks documented accountability and lifecycle management<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Formal risk acceptance should document who accepted the risk, why it was accepted, the residual exposure, any conditions or compensating controls, and when the decision should be reviewed. Without this information, temporary acceptance can become indefinite and management may lose visibility into changing conditions. Good governance ensures that acceptance is an explicit business decision made by an authorized risk owner rather than an undocumented default.<\/span><\/p>\n<p><b>Q132. An AI risk dashboard contains 50 metrics but senior management struggles to identify what requires action. What should be improved?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Add more metrics<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove thresholds<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Focus reporting on material indicators, trends, thresholds, and required decisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Report only technical logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Focus reporting on material indicators, trends, thresholds, and required decisions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Effective executive reporting emphasizes information that supports decisions. A large collection of metrics without context can obscure important issues. Dashboards should highlight material exposures, trends, tolerance breaches, major control weaknesses, treatment progress, and items requiring escalation. Supporting detail can remain available for specialists. The goal is not to maximize the number of metrics but to communicate the organization\u2019s AI risk profile clearly and consistently.<\/span><\/p>\n<p><b>Q133. An AI service provider operates from several regions and may process data outside the customer&#8217;s home jurisdiction. What risk should be evaluated MOST directly?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Cross-border data transfer and data residency obligations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model parameter count<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Office equipment availability<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Training-course completion rates<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Cross-border data transfer and data residency obligations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI services may process, store, or replicate data across multiple jurisdictions. Organizations should identify where data is handled and whether cross-border transfers comply with legal, regulatory, contractual, and customer requirements. Data residency commitments may also affect cloud architecture and vendor selection. The organization should assess subprocessors, transfer mechanisms, contractual safeguards, and deletion requirements where relevant. Geographic processing can create compliance risk even when the AI system itself performs well technically.<\/span><\/p>\n<p><b>Q134. A third-party AI provider experiences a major outage that affects a critical business process. What is the BEST evidence that the organization was prepared?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The vendor had a well-designed website<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> A tested continuity plan with defined fallback and escalation procedures<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The contract was signed by senior management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The organization had many AI projects<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. A tested continuity plan with defined fallback and escalation procedures<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Preparedness is demonstrated through tested procedures rather than documentation alone. A continuity plan should identify fallback processes, communication responsibilities, decision authority, recovery objectives, vendor coordination, and alternative arrangements where appropriate. Exercises or tests can reveal hidden dependencies and unrealistic assumptions before a real outage occurs. Contractual commitments remain important but do not guarantee that the organization itself can continue operating during a provider disruption.<\/span><\/p>\n<p><b>Q135. Which factor should MOST influence the frequency of control testing for an AI system?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The system&#8217;s risk level, rate of change, and control criticality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> The number of pages in the policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> The developer&#8217;s preferred schedule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> The vendor&#8217;s marketing calendar<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. The system&#8217;s risk level, rate of change, and control criticality<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Control testing frequency should be risk based. High-impact systems, rapidly changing models, and critical controls may require more frequent testing than stable, low-risk use cases. Significant incidents, material changes, new regulations, or emerging threats can also trigger out-of-cycle testing. Fixed schedules can provide a baseline, but governance should allow testing intensity to increase when risk changes. This helps assurance resources focus where control failure could have the greatest consequence.<\/span><\/p>\n<p><b>Q136. An AI program wants to identify whether risk treatment actions are being completed on time. Which metric is MOST useful?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Percentage of overdue AI risk remediation actions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Number of model parameters<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Number of governance meetings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Average employee tenure<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Percentage of overdue AI risk remediation actions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Overdue remediation directly indicates whether agreed risk-treatment actions are being implemented within expected timelines. A rising percentage can signal weak accountability, resource constraints, or ineffective governance. The metric should be paired with risk severity because overdue remediation for a critical risk may require stronger escalation than a low-risk item. Defined owners, due dates, and escalation rules are essential for making treatment plans actionable.<\/span><\/p>\n<p><b>Q137. An AI incident occurs because an approved model was used for a different purpose than originally assessed. What is the PRIMARY lesson?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Intended-use boundaries must be governed and changes in use should trigger reassessment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Model validation is unnecessary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Risk ownership should be removed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> AI systems should never be reused<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Intended-use boundaries must be governed and changes in use should trigger reassessment<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> An AI model can be suitable for one purpose and inappropriate for another. Changes in users, decisions, data, scale, autonomy, or business context may materially alter risk. Governance should define approved use and require reassessment when the model is repurposed beyond that boundary. This prevents organizations from assuming that prior validation and risk acceptance automatically apply to new use cases.<\/span><\/p>\n<p><b>Q138. A model&#8217;s monitoring system identifies a significant fairness deterioration in production. What should happen NEXT?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Suppress the alert to avoid reputational risk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Follow the predefined escalation and remediation process, including possible restriction or suspension<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase model autonomy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Remove fairness metrics from monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Follow the predefined escalation and remediation process, including possible restriction or suspension<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> A material fairness deterioration should trigger an established response. The organization may need to investigate data changes, retraining, model behavior, or operational conditions and determine whether the system should be restricted, rolled back, or suspended while remediation occurs. Thresholds should be linked to clear ownership and decision authority. Ignoring or hiding the issue would undermine governance and could increase legal, ethical, and reputational exposure.<\/span><\/p>\n<p><b>Q139. An AI governance team receives multiple recurring exceptions for the same control requirement. What should the team consider FIRST?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the underlying policy or control design is impractical or misaligned with operations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Automatically approve all future exceptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Stop documenting exceptions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Increase exception duration indefinitely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Whether the underlying policy or control design is impractical or misaligned with operations<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> Repeated exceptions can indicate more than poor compliance; they may reveal that the policy, control, or implementation model is poorly designed for actual business conditions. Governance should analyze root causes before continuing to approve the same deviation. The organization may need to redesign the control, provide better tooling, revise requirements, or strengthen enforcement. Exception trends are valuable governance signals and should inform continuous improvement.<\/span><\/p>\n<p><b>Q140. An organization is using AI to summarize audit findings for executives. What is the MOST important control before distribution?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allow the AI to publish directly<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove access to source findings<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Increase response creativity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Require qualified human verification of material facts and conclusions**<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Require qualified human verification of material facts and conclusions<\/b><\/p>\n<p><b>Explanation:<\/b><span style=\"font-weight: 400;\"> AI-generated summaries can omit nuance, misstate severity, or invent conclusions even when the source material is correct. A qualified reviewer should verify that material findings, ratings, business implications, and recommendations accurately reflect the underlying evidence before distribution. The reviewer should also ensure confidential information is handled appropriately. AI can improve efficiency, but accountability for formal audit and risk communication remains with authorized professionals.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca AAIR Exam Dumps and Practice Test Dumps. Q121. An enterprise wants to compare AI risk exposure across business units that use different scoring methods. What should the organization do FIRST? Eliminate all business-unit risk assessments 2. Establish a common AI risk scoring methodology and definitions 3. Allow each unit to report only [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18337"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=18337"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18337\/revisions"}],"predecessor-version":[{"id":18338,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/18337\/revisions\/18338"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=18337"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=18337"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=18337"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}