ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 17 )

Updated On: 10-Sep-2026

An organization has deployed a generative AI system for customer support that includes frequent updates to the AI model after deployment.
Which of the following represents the GREATEST risk?

  1. Lack of a change management policy specific to AI
  2. Overreliance on manual review of AI model outputs
  3. Lack of continuous monitoring for model changes
  4. Lack of a dedicated AI governance committee

Answer(s): C

Explanation:

Frequent post-deployment model updates require continuous monitoring to detect drifts, errors, or unintended behaviors introduced by new versions. Without continuous monitoring, risks introduced by updates can go unnoticed, directly affecting reliability, safety, and compliance.



An organization is developing an AI system that integrates data from multiple external sources without clearly defined data ownership policies.
Which of the following is the GREATEST concern in this situation?

  1. Deficiencies in policies and procedures validating AI model accuracy
  2. Limited documentation of user access permissions
  3. Excessive dependence on automated data collection and cleansing
  4. Gaps in AI privacy compliance and accountability

Answer(s): D

Explanation:

When data ownership is unclear across multiple external sources, the primary risk is noncompliance with privacy requirements and unclear accountability for how data is collected, used, and protected. This directly threatens AI privacy governance and regulatory adherence.



An organization is using a large language model (LLM) to assist in evaluating loan applications, but the training data used is known to be incomplete.
Which of the following is the GREATEST associated risk?

  1. Unfair loan decisions
  2. Delays in loan approval
  3. Reduced customer satisfaction
  4. Increased manual processing of applications

Answer(s): A

Explanation:

Incomplete training data can cause the model to learn patterns that do not represent all applicant groups, increasing the likelihood of unfair or biased loan decisions, which is the most significant governance and ethical risk.



Which of the following is the MOST important reason to establish AI governance structures that extend beyond regulatory compliance?

  1. To align with global AI data privacy standards
  2. To mitigate reputational risk associated with public scrutiny of AI systems
  3. To ensure ethical integrity throughout the AI life cycle
  4. To establish guardrails limiting AI system functionality to approved use cases

Answer(s): C

Explanation:

Establishing governance structures that go beyond compliance ensures ethical integrity across the AI life cycle, addressing fairness, accountability, and responsible use — areas not fully covered by regulatory requirements but essential for trustworthy AI.



Which of the following should be an IS auditor's GREATEST concern when reviewing an anomaly detection process implemented for a high-risk AI system?

  1. Failure to identify anomalies that can bias training data
  2. Lack of regular quality reviews for training data
  3. Infrequent updates to anomaly detection algorithms
  4. Inadequate staff training on the use of the system

Answer(s): A

Explanation:

If anomalies that can bias training data go undetected, the AI system may learn incorrect or harmful patterns, directly compromising the integrity and reliability of a high-risk AI system. This poses the greatest governance and risk concern because biased training data affects all downstream model behavior.



Viewing page 17 of 113
Viewing questions 81 - 85 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!