ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 10 )

Updated On: 10-Sep-2026

Which of the following is the MOST significant risk associated with a deep learning system algorithm being updated as it learns?

  1. System algorithms can easily be modified by attackers because the algorithms reside in system memory.
  2. Project stakeholders may not endorse the system because its behavior may be contrary to their expectations.
  3. Operational risk may increase because the system is continuously running.
  4. The system may generate discriminatory output because of biases in training data.

Answer(s): D

Explanation:

The most significant risk is that the system may generate discriminatory output due to biases in training data. Since deep learning systems update as they learn, existing biases can be amplified, leading to unethical, non-compliant, and potentially harmful outcomes.



When assessing the potential risk of implementing an AI system, it is MOST important to validate the model's:

  1. processing speed and computational efficiency,
  2. decision-making explanations and interpretability of its outputs,
  3. number of parameters and its overall complexity,
  4. compatibility with existing legacy software used by the organization.

Answer(s): B

Explanation:

Validating the AI system’s decision-making explanations and interpretability of outputs is most important because it ensures transparency, accountability, and trustworthiness. This helps stakeholders understand how conclusions are reached and supports compliance with governance and regulatory requirements.



An organization uses an AI video generation platform to create videos for public audiences. An IS auditor notes that there are no clear governance policies defining how viewers should be informed that content is generated by AI.
Which of the following recommendations would BEST ensure the ethical use of AI within this platform?

  1. Establish a policy requiring all AI-generated content to be labeled as such for transparency.
  2. Improve the production quality of AI-generated content to match industry standards.
  3. Conduct regular content accuracy checks to ensure AI-generated videos meet quality expectations.
  4. Limit access to the video generation platform to approved users within the organization.

Answer(s): A

Explanation:

Establishing a policy requiring all AI-generated content to be labeled ensures transparency and ethical use by informing viewers that the content is AI-generated. This directly addresses governance concerns and aligns with responsible AI practices.



Which of the following would be of GREATEST concern to an IS auditor reviewing an organization’s AI policies and procedures?

  1. The documentation of AI models does not address business resiliency and disaster recovery.
  2. The AI model does not have an approval process for production changes.
  3. External validation is not required for AI systems before deployment.
  4. The data privacy policy has not been reviewed in the past three years.

Answer(s): B



An IS auditor is participating in a task force to select an AI solution vendor. The vendor states that their product is only functional with web integration activated.
Which of the following is the GREATEST concern?

  1. AI training model environment
  2. Inappropriate algorithms used by the vendor
  3. Data hallucinations and biases
  4. Impacts on employee and contractor workforces

Answer(s): A

Explanation:

The greatest concern is the AI training model environment, since requiring web integration may expose sensitive training or operational data to external networks. This raises significant risks related to data security, privacy, and compliance.



Viewing page 10 of 113
Viewing questions 46 - 50 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!