ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 19 )

Updated On: 10-Sep-2026

Which of the following provides the BEST evidence that an organization's AI integration is aligned with its overall technology strategy?

  1. Key performance indicators (KPIs) have been defined for AI systems.
  2. The organization has developed and socialized AI use policies.
  3. Management promotes a culture of innovation.
  4. The IT department includes many individual contributors with AI expertise.

Answer(s): A

Explanation:

Defined KPIs for AI systems provide direct, measurable evidence that AI initiatives support and align with the organization’s broader technology strategy by linking AI performance to strategic objectives.



An organization has deployed an AI-powered customer service chatbot trained using customer chat logs.
When reviewing AI risk assessment documentation, which of the following should be the IS auditor's GREATEST concern?

  1. Limited AI model capability to incorporate and adapt to new data
  2. Obsolete procedures leading to inadequate data integrity validation
  3. Reputational impacts resulting from inaccurate chatbot responses
  4. Insufficient access controls leading to unauthorized customer data exposure

Answer(s): D

Explanation:

Insufficient access controls create the highest risk because they can lead to unauthorized exposure of customer chat logs, which contain sensitive personal data. This represents a major privacy, compliance, and security threat that outweighs performance or reputational concerns.



Which of the following is the GREATEST risk associated with deploying an AI system with ineffective anomaly detection?

  1. Inconsistent AI system configuration management
  2. Undetected data poisoning that impacts AI decision quality
  3. Delayed incident response to AI model drift
  4. Failure to comply with AI reporting standards

Answer(s): B

Explanation:

Ineffective anomaly detection can allow data poisoning to go unnoticed, corrupting training or operational data and directly degrading the quality and integrity of AI decisions. This poses the greatest governance and risk impact because it compromises the fundamental reliability of the AI system.



An IS auditor is considering using a web-based AI tool to update an audit report.
What should be the MOST important consideration before inputting the report?

  1. The AI tool alignment with organizational report formatting
  2. Safeguard measures of the AI tool
  3. Impact on the audit budget
  4. Compliance with organizational data protection requirements

Answer(s): D

Explanation:

Before entering audit report content — which may include sensitive, confidential, or regulated information — into a web-based AI tool, the auditor must ensure compliance with organizational data protection requirements. This is essential to avoid unauthorized disclosure or improper handling of sensitive audit data.



When an IS auditor uses generative AI with external retrieval-augmented generation (RAG) to gather evidence during an audit, which of the following poses the GREATEST data security risk?

  1. Sensitive internal context may be included in queries sent to external services.
  2. Personal information may be shared based on model training data.
  3. External search engines only respond to public data.
  4. The model might fail to retrieve data from the vector.

Answer(s): A

Explanation:

Sending queries containing sensitive internal context to an external RAG service creates a significant risk of exposing confidential information outside the organization, making it the greatest data security concern.



Viewing page 19 of 113
Viewing questions 91 - 95 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!