ISACA AAIA Exam Questions
ISACA Advanced in AI Audit (Page 4 )

Updated On: 12-May-2026

A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the

BEST way for the bank to mitigate this risk?

  1. Discontinuing the use of the video-based verification process
  2. Encrypting all customer data and communication
  3. Requesting additional identity and address documents for verification
  4. Leveraging AI-based liveness detection during video verification

Answer(s): D

Explanation:

The best countermeasure is to leverage AI-based liveness detection during video verification. This technology can detect whether the video feed comes from a real, live person rather than a pre-recorded or deepfake video, effectively mitigating impersonation risks.



Which of the following is an IS auditor's MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?

  1. Validate that the tool is leveraging the latest model.
  2. Validate that the tool provides a privacy notice.
  3. Determine whether the information is reliable.
  4. Determine whether any AI model hallucinations have occurred.

Answer(s): C

Explanation:

The most important course of action is to determine whether the information is reliable before entering source data into generative AI tools. Ensuring data reliability safeguards audit integrity and helps prevent the propagation of errors or unauthorized disclosures in AI-assisted analysis.



An AI social media platform uses an algorithm to increase user engagement that could unintentionally promote divisive content. Which of the following is the BEST course of action to mitigate this risk?

  1. Introduce controls allowing individuals to customize content preferences.
  2. Regularly audit and adjust algorithms to reduce biases.
  3. Obtain users' consent for the content they wish to view.
  4. Suspend the algorithm until concerns are addressed.

Answer(s): B

Explanation:

The best course of action to mitigate the risk of unintentionally promoting divisive content is to regularly audit and adjust algorithms to reduce biases. This proactive approach helps ensure that engagement-driven algorithms align with ethical standards and do not amplify harmful or polarizing material.



Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?

  1. Using customer service metrics for service speed and food quality to predict customer retention and forecast revenue
  2. Comparing total food preparation and delivery time to an industry benchmark to set key performance and
    risk indicators for individual restaurants
  3. Basing driver retention and termination decisions on the number of delivered orders per total hours worked as compared to an industry benchmark
  4. Correlating time, cost, delivery distance, and customer satisfaction metrics to issue coupons to customers receiving substandard service

Answer(s): C

Explanation:

Basing driver retention and termination decisions on the number of delivered orders per total hours worked compared to an industry benchmark poses the greatest ethical risk. This practice may unfairly penalize workers without accounting for contextual factors (e.g., traffic, order volume, location), leading to biased or discriminatory employment outcomes.



Which of the following BEST ensures that an AI system complies with user data ownership rights under privacy regulations?

  1. Applying data clustering techniques to anonymize data sets
  2. Regularly conducting AI system performance testing for accuracy
  3. Implementing a transparent data consent management process
  4. Enforcing strict data retention policies to limit storage duration

Answer(s): C

Explanation:

The best way to ensure compliance with user data ownership rights under privacy regulations is by implementing a transparent data consent management process. This ensures users are informed, can give or withdraw consent, and retain control over how their data is collected and used by AI systems.



An IS auditor is auditing an organization's data governance framework. The primary objective is to provide assurance that data management practices are standardized to support a trustworthy AI system. Which of the following should be the auditor's MOST important consideration?

  1. Retention of stored data
  2. Accountability for data management
  3. Data practices for training models
  4. Portability of data

Answer(s): B

Explanation:

The most important consideration is accountability for data management. Clear ownership and responsibility ensure that data governance practices are consistently applied, monitored, and enforced -- supporting the development and operation of a trustworthy AI system.



An organization's system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?

  1. All codes are generated by AI without human oversight.
  2. Non-technical users are validating AI results.
  3. The AI personalizes applications for the user.
  4. The AI allocates resources for new system development projects.

Answer(s): A

Explanation:

The greatest risk is when all codes are generated by AI without human oversight. This can lead to undetected errors, insecure code, or non-compliance with development standards, posing serious risks to system integrity and security.



A retail organization uses an AI model to analyze customers' purchase history in order to offer personalized discounts. Which of the following practices represents the MOST ethical use of customer data?

  1. Retaining and analyzing all available customer data to ensure unbiased recommendations
  2. Providing the public with access to review and audit the data set of collected customer information
  3. Sharing customer purchase data with third-party vendors to improve advertising and communication
  4. Utilizing customer purchase data only after obtaining explicit consent and allowing customers to opt out

Answer(s): D

Explanation:

The most ethical use of customer data is to utilize it only after obtaining explicit consent and allowing customers to opt out. This approach respects data privacy rights, supports transparency, and aligns with ethical and legal standards for responsible AI use.



Viewing page 4 of 57
Viewing questions 25 - 32 out of 445 questions


AAIA Exam Discussions & Posts (Share your experience with others)

AI Tutor AI Tutor 👋 I’m here to help!