ISACA AAIA Exam Questions
ISACA Advanced in AI Audit (Page 2 )

Updated On: 12-May-2026

Which of the following key performance indicators (KPIs) are MOST important when evaluating whether an AI model meets business objectives?

  1. Cost of resources required for AI model training
  2. AI model accuracy in predicting actual outcomes
  3. Frequency of AI model retraining
  4. Number of users interacting with the AI model

Answer(s): B

Explanation:

The most important KPI when evaluating whether an AI model meets business objectives is AI model accuracy in predicting actual outcomes. High accuracy indicates that the model is effectively supporting decision-making and delivering value aligned with business goals.



The BEST way to prevent sensitive information disclosure by large language model (LLM) chatbots is through:

  1. manual monitoring.
  2. data sanitization.
  3. data masking.
  4. access controls.

Answer(s): B

Explanation:

The best way to prevent sensitive information disclosure by LLM chatbots is through data sanitization. This process involves removing or modifying sensitive data before it is used by the model, ensuring that personally identifiable or confidential information cannot be learned or reproduced by the chatbot.



An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?

  1. Transparency
  2. AI model hallucinations
  3. AI bias
  4. Disclosure of personal information

Answer(s): D

Explanation:

The greatest risk is disclosure of personal information. Using customer account data to train an AI chatbot can lead to unintended exposure of sensitive or identifiable information if proper data protection and privacy safeguards are not enforced.



An IS auditor is evaluating an organization's incident management program to ensure it is sufficiently prepared to manage AI-related incidents. Which of the following is MOST important for the auditor to validate?

  1. The program includes processes to respond to AI model drift and data integrity attacks.
  2. The program prioritizes incidents based on alignment with industry leading practices.
  3. The program uses past AI-related incidents and resolutions to categorize current incidents.
  4. The program mandates retraining AI systems after incidents are investigated.

Answer(s): A

Explanation:

The most important aspect for the IS auditor to validate is that the program includes processes to respond to AI model drift and data integrity attacks. These are critical AI-specific risks that can compromise decision-making accuracy and system reliability, so preparedness to detect and respond to them is essential for robust incident management.



Which of the following is MOST important for an IS auditor to consider when identifying AI risk in a know your customer (KYC) application within a banking organization?

  1. Business disruption and financial impact
  2. Intellectual property leakage and invalidation
  3. Benchmarking against peer organizations
  4. Incident response plan

Answer(s): A

Explanation:

The most important consideration for identifying AI risk in a KYC application is the business disruption and financial impact. In banking, KYC failures due to AI errors can lead to compliance violations, reputational damage, and significant financial penalties. Evaluating the potential for disruption and associated costs is critical for effective AI risk assessment in this context.



A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower's credit score?

  1. Using only data from the last six months to one year to avoid outdated information affecting the credit score
  2. Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions
  3. Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results
  4. Allowing the AI to operate fully autonomously to prevent processing delays

Answer(s): B

Explanation:

The best way to mitigate the risk of sudden and unexplained changes in credit scores is to ensure the system is periodically reviewed and calibrated by human experts. Regular expert oversight helps maintain model stability, ensures predictions remain consistent and fair, and allows for the detection and correction of drift or anomalies in the AI system's behavior.



Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?

  1. Data performance metrics
  2. Use of open-source intellectual property
  3. Model runtime efficiency logs
  4. Data usage agreements

Answer(s): D

Explanation:

The most important item for an IS auditor to review is the data usage agreements. These agreements define the legal rights and limitations for how data can be collected, used, and shared -- ensuring compliance with intellectual property and data rights regulations.



Which of the following is the PRIMARY objective of AI governance?

  1. Implementing compliance and ethics controls for AI initiatives
  2. Promoting a positive return on investment (ROI) from AI projects
  3. Defining clear roles and responsibilities for AI development, use, and oversight
  4. Ensuring controls over AI are designed well and operate effectively

Answer(s): C

Explanation:

The primary objective of AI governance is to define clear roles and responsibilities for AI development, use, and oversight. This ensures accountability, transparency, and structured decision-making throughout the AI lifecycle, forming the foundation for responsible and compliant AI deployment.



Viewing page 2 of 57
Viewing questions 9 - 16 out of 445 questions


AAIA Exam Discussions & Posts (Share your experience with others)

AI Tutor AI Tutor 👋 I’m here to help!