ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 12 )

Updated On: 10-Sep-2026

A financial services company is developing AI models to predict customer credit risk. To reduce privacy concerns, the company decides to train the models primarily using synthetic data.
Which of the following is an IS auditor's BEST recommendation to evaluate synthetic data risk?

  1. Discontinue the use of synthetic data for model training.
  2. Conduct cluster analysis using synthetic data.
  3. Require validation of synthetic data quality.
  4. Perform regression testing using synthetic data.

Answer(s): C

Explanation:

Requiring validation of synthetic data quality is the best recommendation, as poor-quality or unrepresentative synthetic data can lead to inaccurate or biased credit risk predictions. Validation ensures the synthetic data reliably reflects real-world patterns while protecting privacy.



It was determined that an AI system used for medical diagnoses shows decreased accuracy for minority populations.
Which of the following is the BEST way to address this issue?

  1. Retrain the model with more representative data.
  2. Transition to exclusively using synthetic data generation.
  3. Optimize model hyperparameters for better performance.
  4. Apply anonymization techniques to the training data.

Answer(s): A

Explanation:

Retraining the model with more representative data is the best way to address decreased accuracy for minority populations. Ensuring diverse and inclusive training data reduces bias and improves fairness in medical diagnoses.



An IS auditor has identified that the configuration of a proprietary AI model has been leaked.
Which of the following is the MOST significant risk?

  1. Attackers can disable security systems by analyzing the model’s source code.
  2. Attackers can use the data to degrade the model's performance.
  3. Attackers can train their own improved model for legitimate use.
  4. Attackers can exploit vulnerabilities in the model.

Answer(s): D

Explanation:

The most significant risk is that attackers can exploit vulnerabilities in the model. With access to configuration details, adversaries can identify weaknesses and manipulate the AI system, leading to compromised integrity, security breaches, or malicious misuse.



An AI generated photo showing a catastrophe circulated on social media, impacting the supply chain. This is an example of which type of risk?

  1. Compliance risk
  2. Societal risk
  3. Economic risk
  4. Data privacy risk

Answer(s): B

Explanation:

This is an example of societal risk, as the AI-generated photo spreads misinformation that influences public perception and disrupts social and economic stability, in this case causing supply chain impact.



Which of the following processes is MOST important for an organization to have in place to ensure the credibility of AI outputs?

  1. User consent
  2. Model alignment
  3. Data governance
  4. Data analytics

Answer(s): C

Explanation:

Data governance is most important for ensuring the credibility of AI outputs because well-managed, accurate, and high-quality data directly impacts the reliability, fairness, and trustworthiness of AI model results.



Viewing page 12 of 113
Viewing questions 56 - 60 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!