ISACA AAIA Exam Prep
ISACA Advanced in AI Audit (Page 3 )

Updated On: 10-Sep-2026

A digital bank utilizes an AI system to generate credit scores.
Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower's credit score?

  1. Using only data from the last six months to one year to avoid outdated information affecting the credit score
  2. Ensuring the system is periodically reviewed and calibrated by human experts to maintain stability in predictions
  3. Obtaining and validating the credit scores from third-party agencies to cross-check AI-generated results
  4. Allowing the AI to operate fully autonomously to prevent processing delays

Answer(s): B

Explanation:

The best way to mitigate the risk of sudden and unexplained changes in credit scores is to ensure the system is periodically reviewed and calibrated by human experts. Regular expert oversight helps maintain model stability, ensures predictions remain consistent and fair, and allows for the detection and correction of drift or anomalies in the AI system’s behavior.



Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?

  1. Data performance metrics
  2. Use of open-source intellectual property
  3. Model runtime efficiency logs
  4. Data usage agreements

Answer(s): D

Explanation:

The most important item for an IS auditor to review is the data usage agreements. These agreements define the legal rights and limitations for how data can be collected, used, and shared — ensuring compliance with intellectual property and data rights regulations.



Which of the following is the PRIMARY objective of AI governance?

  1. Implementing compliance and ethics controls for AI initiatives
  2. Promoting a positive return on investment (ROI) from AI projects
  3. Defining clear roles and responsibilities for AI development, use, and oversight
  4. Ensuring controls over AI are designed well and operate effectively

Answer(s): C

Explanation:

The primary objective of AI governance is to define clear roles and responsibilities for AI development, use, and oversight. This ensures accountability, transparency, and structured decision-making throughout the AI lifecycle, forming the foundation for responsible and compliant AI deployment.



A healthcare organization uses patient data to train an AI model for early disease detection.
Which of the following practices provides the BEST assurance that personal data is secure and its integrity is maintained?

  1. Implementing strict data access controls and conducting security tests
  2. Encrypting stored data to reduce exposure and log access
  3. Updating the AI model with new data and tracking changes
  4. Anonymizing patient data and performing regular quality checks

Answer(s): D



An organization deploys an AI recruitment platform to screen job applicants. The IS auditor identifies that the platform’s decisions may be influenced by model bias.
Which of the following risk mitigation strategies is BEST for the auditor to recommend?

  1. Implement a process to periodically test the AI system for biases and adjust parameters as needed.
  2. Suspend the use of the AI system until the training data can be verified for fairness and compliance.
  3. Require manual reviews of all AI-generated recruitment decisions before hiring is finalized.
  4. Retrain the AI model using an external data set certified for inclusivity and fairness.

Answer(s): A

Explanation:

The best risk mitigation strategy is to implement a process to periodically test the AI system for biases and adjust parameters as needed. This proactive and ongoing approach ensures that bias is continuously monitored and addressed without unnecessarily halting operations or relying solely on manual intervention.



Viewing page 3 of 113
Viewing questions 11 - 15 out of 536 questions


Post your Comments and Discuss ISACA AAIA exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!