ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 14 )

Updated On: 10-Sep-2026

An organization uses an AI-based chatbot that collects customer data during interactions.
Which of the following is MOST important to ensure compliance with data consent requirements?

  1. Obtaining consent each time queries are processed by the chatbot
  2. Deleting data immediately following customer interactions with the chatbot
  3. Anonymizing user interaction data after three months
  4. Embedding a consent mechanism that provides clear options before data collection begins

Answer(s): D

Explanation:

Embedding a consent mechanism that provides clear options before data collection begins is most important. It ensures compliance with privacy regulations by securing informed consent from customers prior to processing their data.



A large organization is implementing a new AI system that uses customer data.
Which of the following is the BEST approach for risk mitigation to protect customer privacy?

  1. Implement a mechanism for customers to opt out of the use of their data.
  2. Assign sole responsibility for risk mitigation to the development team.
  3. Implement data anonymization and impact assessments.
  4. Conduct periodic risk and vulnerability assessments.

Answer(s): C

Explanation:

Implementing data anonymization and impact assessments is the best approach to mitigate risks to customer privacy. Anonymization protects sensitive information, while impact assessments ensure compliance and help identify potential privacy risks before deployment.



An IS auditor learns that the organization’s AI solution is configured with web integration enabled.
Which of the following is the MOST important control for the auditor to validate?

  1. Data augmentation activities prior to model building
  2. Key performance indicator (KPI) metrics for model inference time
  3. Activity logging with integration to the organization’s SIEM system
  4. Separation of duties between the model creator and the model tester

Answer(s): C

Explanation:

Validating activity logging with integration to the organization’s SIEM system is most important when AI solutions have web integration enabled. This ensures monitoring of data flows and potential security incidents, reducing risks of unauthorized access or malicious activity.



Which of the following is the GREATEST risk resulting from excessive agency in AI systems?

  1. Inefficient prioritization of tasks
  2. Uncontrolled access and unauthorized actions
  3. Slower AI system responses and performance
  4. Increased need for oversight of model actions

Answer(s): B

Explanation:

The greatest risk from excessive agency in AI systems is uncontrolled access and unauthorized actions.
When AI operates with too much autonomy, it can make unmonitored decisions that compromise security, compliance, and organizational control.



During an audit of an organization that has adopted AI, it was discovered that data ownership responsibilities were not clearly defined.
Which of the following is the MOST likely consequence of this gap?

  1. Higher operational costs for managing data storage solutions
  2. Reduced organizational reliance on AI solutions
  3. Decreased performance of AI models due to redundant data ownership
  4. Increased risk of data breaches due to lack of accountability

Answer(s): D

Explanation:

The most likely consequence of unclear data ownership is an increased risk of data breaches due to lack of accountability. Without defined ownership, responsibilities for protecting, monitoring, and governing data are unclear, weakening security and compliance.



Viewing page 14 of 113
Viewing questions 66 - 70 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!