Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free ISACA Advanced in AI Risk AAIR Exam Questions

Page: 1 / 9 Total 90 questions

Want more questions? Get Premium Access.

Question 1

Which of the following is a risk practitioner's BEST recommendation to establish accountability for AI system outputs and decisions?

Correct Answer: D. Formal documented role assignments with named owners
Explanation:

Accountability in AI governance requires that specific individuals or roles be clearly designated as responsible for AI system outputs, decisions, and associated risks. Without formal documentation of ownership, accountability gaps emerge.

Why D is Correct: The ISACA AAIR framework emphasizes that accountability must be explicit and documented, with named individuals assigned to own AI outcomes. Formal role assignments create a traceable chain of responsibility that supports auditability, regulatory compliance, and effective escalation when issues arise. Named ownership prevents diffusion of responsibility.

Why A is Wrong: A centralized task force creates collective responsibility, which can dilute individual accountability. Governance bodies support oversight but do not replace individual role ownership for specific outputs.

Why B is Wrong: Continuous monitoring and KPIs are valuable operational controls but represent monitoring mechanisms, not accountability structures. Monitoring detects issues but does not assign responsibility for them.

Why C is Wrong: Resource allocation reviews address investment efficiency rather than accountability for AI decisions and outputs. This is a management activity, not an accountability framework.


Question 2

Which risk treatment is MOST appropriate when an organization's AI system presents residual risk within tolerance and impacts non-critical functions?

Correct Answer: A. Document a formal risk acceptance.
Explanation:

Risk treatment decisions are driven by two factors: whether the residual risk falls within or outside tolerance, and the criticality of the affected function. When both conditions---risk within tolerance AND non-critical function impact---are met, formal risk acceptance is the appropriate and proportionate treatment.

Why A is Correct: According to ISACA AAIR risk treatment guidance, documented formal risk acceptance is the appropriate response when residual risk is within defined tolerance for non-critical functions. Risk acceptance acknowledges the identified exposure, documents the organization's conscious decision to accept it, and establishes accountability for that decision. This proportionate response avoids over-investing in controls for risk that the organization has determined is acceptable.

Why B is Wrong: Recommending increases to tolerance thresholds is a governance manipulation rather than a risk treatment. Adjusting thresholds upward to accommodate risk does not address the risk; it merely reclassifies it as acceptable. This approach undermines risk governance integrity.

Why C is Wrong: Enhancing monitoring to detect deviations represents additional control investment that may be disproportionate for risk that is already within tolerance affecting non-critical functions. Enhanced monitoring is more appropriate when risk is near the tolerance boundary or when trends indicate potential future breach.

Why D is Wrong: Periodic vulnerability scanning is a security assurance activity that identifies technical weaknesses. It represents an ongoing control measure rather than the appropriate risk treatment decision for a residual risk that is already within tolerance.


Question 3

Which of the following BEST helps to ensure AI model outputs can be reproduced in other environments?

Correct Answer: B. Capturing and archiving complete snapshots of training datasets
Explanation:

AI model reproducibility---the ability to recreate identical or near-identical outputs in different environments---depends on having access to the exact training data, model weights, and configurations used to produce a given model version. Training dataset snapshots are foundational to this capability.

Why B is Correct: The ISACA AAIR model documentation and auditability guidance identifies capturing and archiving complete training dataset snapshots as essential for reproducibility. To reproduce a model's outputs in another environment, the development team must be able to reconstruct the exact training conditions---including the precise dataset used. Without archived snapshots, datasets evolve and the original training conditions become impossible to recreate.

Why A is Wrong: Manual review of outputs validates accuracy for a specific deployment but does not address reproducibility across environments. Manual review cannot substitute for the technical artifacts needed to recreate a model.

Why C is Wrong: Continuous performance monitoring detects behavioral changes in production but does not enable reproduction of the model in alternative environments. Monitoring is forward-looking, while reproducibility is about reconstructing past conditions.

Why D is Wrong: AI-specific change management processes control how models are modified and deployed but do not capture the training artifacts needed for environmental reproduction. Change management governs transitions; reproducibility requires data preservation.


Question 4

Which of the following is the PRIMARY benefit of using AI-based data analytic tools to monitor AI system risk?

Correct Answer: B. Early detection of latent vulnerabilities by identifying anomalous patterns within large datasets
Explanation:

AI systems generate large volumes of operational data---model outputs, query logs, performance metrics, system telemetry. AI-powered analytics tools can process this data at scale and speed to identify subtle patterns that indicate developing vulnerabilities before they manifest as incidents.

Why B is Correct: According to ISACA AAIR monitoring and analytics guidance, the primary benefit of AI-based risk monitoring tools is their ability to identify latent vulnerabilities through anomaly detection in large datasets. Human analysts cannot process the volume and velocity of data produced by AI systems at sufficient scale to detect subtle, early-stage indicators of emerging risks. AI-powered analytics provide this capability---identifying patterns that precede security incidents, model failures, or compliance violations.

Why A is Wrong: Industry trend forecasting is a strategic risk intelligence activity. While valuable for planning, it represents a secondary, external-facing use of AI analytics rather than the primary benefit of monitoring organizational AI system risks.

Why C is Wrong: Access attempt logging and documentation are security event recording functions. While comprehensive logging is important for audit trails, the primary benefit of AI analytics is pattern detection across that logged data---not the logging activity itself.

Why D is Wrong: Automation of risk analysis and treatment decisions is a contested application of AI in risk management. Human judgment in risk treatment decisions is typically retained as a governance requirement. Removing human involvement from treatment decisions is not the primary benefit of AI monitoring tools.


Question 5

A risk practitioner is developing risk scenarios related to successful data poisoning attacks on an AI model used across the organization. Which of the following is the BEST approach to help ensure the scenarios are relevant?

Correct Answer: D. Engage key stakeholders in risk scenario development.
Explanation:

Risk scenario development in AI requires that scenarios be grounded in organizational context, business processes, and actual threat landscapes. Risk scenarios must reflect the specific systems, data flows, and stakeholder concerns relevant to the organization.

Why D is Correct: According to the ISACA AAIR Study Guide, engaging key stakeholders is the cornerstone of effective risk scenario development. Stakeholders bring domain knowledge, business context, and awareness of operational dependencies that technical practitioners may lack. This collaborative approach ensures scenarios address real-world consequences, organizational risk appetite, and business-critical functions---making them actionable and relevant.

Why A is Wrong: Adversarial testing in a sandbox validates controls but does not by itself produce contextually relevant risk scenarios. It is a technical activity, not a scenario development process.

Why B is Wrong: Peer benchmarking provides useful threat intelligence but cannot replace stakeholder engagement. Industry peer data may not reflect the organization's specific AI architecture or risk tolerance.

Why C is Wrong: Data flow diagrams are useful supporting artifacts but describe technical pathways rather than capturing the organizational and business context required for relevant risk scenarios.


Question 6

An organization plans to deploy an AI system that ingests multiple sources with varying completeness and accuracy. Which of the following is the risk practitioner's BEST recommendation?

Correct Answer: C. Implement continuous real-time quality assurance (QA) processes.
Explanation:

Data quality directly determines AI model accuracy and reliability. When input sources vary in completeness and accuracy, the AI system is exposed to continuous data quality risks that can produce unreliable outputs. This requires ongoing, real-time quality management rather than periodic or reactive responses.

Why C is Correct: According to ISACA AAIR data quality guidance, implementing continuous real-time QA processes is the most effective approach for managing variable-quality multi-source inputs. Real-time QA identifies and addresses quality issues as data enters the system---before they contaminate model inputs and outputs. This prevents quality problems from accumulating and ensures the model consistently receives the highest-quality available data.

Why A is Wrong: Synthetic data augmentation is useful for addressing data scarcity but does not resolve accuracy and completeness issues in existing real-world sources. Generating synthetic data alongside poor-quality real data does not improve the real data.

Why B is Wrong: Post-implementation assessments are reactive---they identify problems after they have already affected model behavior and potentially produced harmful outputs. Prevention through real-time QA is superior to post-hoc remediation.

Why D is Wrong: Fine-tuning model parameters can improve robustness to input variation but does not address underlying data quality problems. Models trained to tolerate poor data may produce less reliable outputs than models receiving consistently high-quality data.


Question 7

Which of the following AI capabilities would BEST enable a forecasting system to accurately predict the point at which specific equipment components are likely to fail?

Correct Answer: D. Real-time analysis of sensor monitoring data
Explanation:

Predictive maintenance for equipment components requires continuous analysis of operational data---vibration, temperature, pressure, electrical signatures---that indicate component health over time. AI systems performing this function must process high-frequency sensor data to detect patterns that precede failure.

Why D is Correct: According to ISACA AAIR AI application guidance, real-time sensor monitoring data analysis is the core capability enabling accurate failure point prediction. By continuously analyzing sensor readings against learned patterns of pre-failure behavior, AI systems can detect early-stage degradation signals and forecast time-to-failure with precision unavailable through periodic inspection or rule-based thresholds.

Why A is Wrong: Root cause identification occurs after a defect has already manifested. For predictive maintenance---predicting failure before it occurs---post-defect analysis provides no forward-looking capability.

Why B is Wrong: Replacement product recommendation is a procurement and inventory support function. It assists in planning responses to predicted failures but is not the capability that enables the prediction itself.

Why C is Wrong: Dynamic inventory management of spare parts supports maintenance operations but is a supply chain function dependent on failure predictions, not a capability that generates those predictions.


Question 8

A credit-scoring AI solution exhibits steadily declining accuracy despite unchanged input distributions. Which of the following should a risk practitioner consider to be the GREATEST risk?

Correct Answer: C. Concept drift leading to faulty decisions
Explanation:

When an AI model's accuracy declines despite stable input distributions, the most likely cause is concept drift---where the underlying relationship between inputs and the target variable changes over time. In credit scoring, this may occur when economic conditions, consumer behavior, or risk patterns shift in ways not captured in the original training data.

Why C is Correct: The ISACA AAIR model drift guidance identifies concept drift as the greatest risk in this scenario because it means the model is making credit decisions based on relationships that no longer hold in the current environment. Faulty credit decisions can lead to incorrect denials of creditworthy applicants, incorrect approvals of high-risk applicants, regulatory violations, financial losses, and harm to individuals---all high-severity consequences for a credit-scoring application.

Why A is Wrong: Technical delays in credit score updates are an operational performance concern. Delays create business friction but do not cause the fundamental accuracy problem described in the scenario.

Why B is Wrong: Underfitting from shortened training cycles is a model development quality issue. The scenario specifies stable input distributions and declining accuracy---characteristic of drift, not underfitting, which would manifest differently.

Why D is Wrong: Increased retraining costs represent a financial efficiency concern. While budgetary impacts are real, they are secondary to the risk of faulty credit decisions affecting individuals and regulatory compliance.


Question 9

Which of the following is the PRIMARY reason to include contractual requirements for model updates and disclosures from third-party AI suppliers?

Correct Answer: B. To ensure timely detection and mitigation of new system risks that could harm individuals
Explanation:

Third-party AI suppliers introduce significant risk through model updates, changes in training data, and modifications to system behavior. Contractual disclosure requirements ensure the acquiring organization can maintain active risk oversight despite not controlling the vendor's development processes.

Why B is Correct: The ISACA AAIR framework emphasizes that third-party AI contracts must protect against harms arising from undisclosed changes. When vendors make silent updates to models, the acquiring organization cannot assess new risks before they affect users, decisions, or regulated outcomes. Timely disclosure requirements enable proactive risk detection and mitigation before individuals are harmed.

Why A is Wrong: Availability guarantees are service-level concerns addressed by SLA provisions. While important operationally, they do not address the risk management imperative of understanding what changes have been made to AI models.

Why C is Wrong: Internal trust-building is a change management consideration, not the primary purpose of contractual disclosure requirements. Contracts address risk obligations, not organizational confidence.

Why D is Wrong: Vendor staff access to sensitive datasets is a data access and privacy concern addressed through data processing agreements and access controls, not model update disclosure requirements.


Question 10

Which of the following is the GREATEST concern when AI risk management operates separately from enterprise risk management (ERM)?

Correct Answer: A. Lack of strategic control alignment
Explanation:

Enterprise Risk Management (ERM) provides the strategic framework within which all organizational risks---including AI risks---should be managed. When AI risk management operates in isolation, it loses connection to enterprise strategy, risk appetite, and cross-functional control objectives.

Why A is Correct: The ISACA AAIR curriculum identifies strategic control alignment as a foundational ERM integration requirement. When AI risk operates independently, controls may conflict with or duplicate enterprise controls, risk appetite thresholds may differ, and AI risks cannot be aggregated or prioritized alongside other organizational risks. This misalignment creates blind spots at the enterprise level and undermines coherent strategic risk management.

Why B is Wrong: Inconsistent regulatory reporting is a compliance concern but is a downstream consequence of poor governance rather than the greatest organizational risk from separation. Regulatory gaps can often be patched operationally without full integration.

Why C is Wrong: Training cost increases represent a financial efficiency concern unrelated to the governance challenge of separate risk management functions. ROI impacts are not driven by organizational structure of risk management.

Why D is Wrong: Redundant documentation is an operational inefficiency, not a strategic risk. Duplicated records are wasteful but do not threaten organizational strategy or expose the enterprise to unmanaged risk.