ISACA AAIR Exam Actual Questions
Advanced in AI Risk (Page 6 )

Updated On: 3-Aug-2026

A risk practitioner is developing risk scenarios related to successful data poisoning attacks on an AI model used across the organization.
Which of the following is the BEST approach to help ensure the scenarios are relevant?

  1. Perform adversarial testing in a sandbox environment.
  2. Gather information on similar attacks impacting industry peers
  3. Create comprehensive data flow diagrams.
  4. Engage key stakeholders in risk scenario development.

Answer(s): D

Explanation:

Risk scenario development in AI requires that scenarios be grounded in organizational context, business processes, and actual threat landscapes. Risk scenarios must reflect the specific systems, data flows, and stakeholder concerns relevant to the organization.
Why D is Correct: According to the ISACA AAIR Study Guide, engaging key stakeholders is the cornerstone of effective risk scenario development. Stakeholders bring domain knowledge, business context, and awareness of operational dependencies that technical practitioners may lack. This collaborative approach ensures scenarios address real-world consequences, organizational risk appetite, and business-critical functions—making them actionable and relevant.
Why A is Wrong: Adversarial testing in a sandbox validates controls but does not by itself produce contextually relevant risk scenarios. It is a technical activity, not a scenario development process.
Why B is Wrong: Peer benchmarking provides useful threat intelligence but cannot replace stakeholder engagement. Industry peer data may not reflect the organization's specific AI architecture or risk tolerance.
Why C is Wrong: Data flow diagrams are useful supporting artifacts but describe technical pathways rather than capturing the organizational and business context required for relevant risk scenarios.



Which of the following is a risk practitioner's BEST recommendation to establish accountability for AI system outputs and decisions?

  1. Centralized governance task force for model decision authority
  2. Continuous monitoring and key performance indicators (KPIs)
  3. Regular reviews of resource allocation for AI projects
  4. Formal documented role assignments with named owners

Answer(s): D

Explanation:

Accountability in AI governance requires that specific individuals or roles be clearly designated as responsible for AI system outputs, decisions, and associated risks. Without formal documentation of ownership, accountability gaps emerge.
Why D is Correct: The ISACA AAIR framework emphasizes that accountability must be explicit and documented, with named individuals assigned to own AI outcomes. Formal role assignments create a traceable chain of responsibility that supports auditability, regulatory compliance, and effective escalation when issues arise. Named ownership prevents diffusion of responsibility.
Why A is Wrong: A centralized task force creates collective responsibility, which can dilute individual accountability. Governance bodies support oversight but do not replace individual role ownership for specific outputs.
Why B is Wrong: Continuous monitoring and KPIs are valuable operational controls but represent monitoring mechanisms, not accountability structures. Monitoring detects issues but does not assign responsibility for them.
Why C is Wrong: Resource allocation reviews address investment efficiency rather than accountability for AI decisions and outputs. This is a management activity, not an accountability framework.



Which of the following is the PRIMARY purpose of maintaining comprehensive model cards and documentation?

  1. Justifying model use cases
  2. Preserving audit trails
  3. Listing technical specifications
  4. Providing model transparency

Answer(s): D

Explanation:

Model cards are standardized documents that communicate key information about AI models, including their intended use, training data, performance characteristics, limitations, and ethical considerations. They serve as a primary transparency instrument in AI governance.
Why D is Correct: According to the ISACA AAIR curriculum, the primary purpose of model cards is to provide transparency to stakeholders—including developers, users, auditors, and regulators. Transparency enables informed decision-making about model deployment, helps identify potential misuse, and supports responsible AI governance across the life cycle.
Why A is Wrong: Justifying use cases is a secondary benefit. Model cards are not primarily advocacy documents; their core function is objective disclosure of model characteristics and limitations.
Why B is Wrong: Preserving audit trails is a governance function served by version control and change management systems.
While model cards contribute to audit readiness, it is not their primary purpose.
Why C is Wrong: Technical specifications represent only a subset of model card content. Model cards go beyond technical detail to address fairness, bias, intended use boundaries, and societal impact considerations.



Which of the following BEST enables an organization adopting AI solutions to foster an ethical and risk-aware culture?

  1. All business units use checklists to ensure AI risk and ethical concerns are addressed.
  2. Senior management representatives actively participate in industry conferences related to AI ethics.
  3. AI policies include clear disciplinary actions for violations of risk and ethical standards.
  4. Leadership consistently models ethical behavior and values for AI development and use.

Answer(s): D

Explanation:

Organizational culture is primarily shaped by leadership behavior and tone at the top. In AI governance, an ethical culture cannot be mandated through documentation alone—it must be demonstrated through the actions and values of organizational leaders.
Why D is Correct: The ISACA AAIR Study Guide emphasizes that tone at the top is the most powerful driver of ethical culture.
When leaders consistently model ethical behavior in AI development and usage, they create a normative environment where employees internalize values rather than merely complying with rules. This authentic leadership approach produces sustainable cultural change.
Why A is Wrong: Checklists are compliance tools that address process adherence, not cultural transformation. A checklist culture can produce box-ticking behavior without genuine ethical commitment.
Why B is Wrong: Conference participation raises awareness but has minimal impact on day-to-day organizational behavior. External networking does not directly shape internal culture.
Why C is Wrong: Disciplinary actions represent reactive compliance enforcement.
While necessary, punitive measures create a compliance-driven rather than values-driven culture, which is less robust and sustainable.



To reinforce organization-wide ethical norms and risk recognition, which of the following is MOST important to integrate into AI user training?

  1. Acceptable use policy and acknowledgment
  2. Ethical risk indicators and reporting
  3. Cyber threat identification and AI incident handling
  4. External regulations and compliance checklists

Answer(s): B

Explanation:

Effective AI user training must go beyond policy acknowledgment and compliance instruction to equip employees with the practical skills needed to identify ethical risks and report them appropriately. This builds an active risk-aware workforce.
Why B is Correct: The ISACA AAIR framework identifies that training on ethical risk indicators and reporting mechanisms directly reinforces ethical norms by enabling employees to recognize real-world signs of AI misuse, bias, or harmful outputs.
When staff can identify specific risk signals and know how to escalate them, the organization builds a proactive risk culture grounded in practical ethical literacy.
Why A is Wrong: Acceptable use policy acknowledgment is a compliance activity, not a culture-building measure. Acknowledging a document does not ensure employees understand how to apply ethical principles in practice.
Why C is Wrong: Cyber threat identification addresses security risk, which is narrower than the full scope of ethical AI risk. Security training does not develop ethical judgment regarding fairness, bias, or societal impact.
Why D is Wrong: Regulatory compliance checklists address legal obligations but do not develop the ethical reasoning and risk recognition skills needed to reinforce organizational norms.



A risk practitioner is assessing risk in a newly implemented AI system integrated into an organization's business processes.
Which of the following is the MOST important consideration for the risk practitioner?

  1. Escalation and approval protocols for AI mitigation measures
  2. Level of existing business process automation prior to AI adoption
  3. AI expertise within the organization's risk management function
  4. Criticality and impact of decision-making driven by the AI system

Answer(s): D

Explanation:

AI risk assessment must be calibrated to the potential consequences of AI-driven decisions. The criticality and impact of AI-driven decisions directly determine the magnitude of risk exposure and the appropriate level of risk treatment.
Why D is Correct: According to ISACA AAIR principles, the most fundamental risk assessment consideration is the nature and impact of decisions driven by the AI system. Systems making high-stakes decisions—affecting employment, credit, healthcare, or public safety—carry significantly greater risk than those supporting low-impact tasks. Understanding decision criticality frames all other risk assessment activities and drives proportionate control selection.
Why A is Wrong: Escalation protocols are governance process elements that should be designed after understanding the risk profile. They are outputs of risk assessment, not inputs to the primary assessment consideration.
Why B is Wrong: Prior automation levels provide contextual background but do not determine the risk profile of the new AI system. The relevant risk driver is forward-looking, not historical.
Why C is Wrong: Internal expertise levels affect assessment capability but represent an organizational constraint rather than the primary risk consideration. The risk lies in the system's potential impact, not in who assesses it.



Which of the following is the GREATEST concern when AI risk management operates separately from enterprise risk management (ERM)?

  1. Lack of strategic control alignment
  2. Inconsistent regulatory reporting
  3. Reduced return on investment (ROI) due to increased model training costs
  4. Redundant risk documentation and scoring

Answer(s): A

Explanation:

Enterprise Risk Management (ERM) provides the strategic framework within which all organizational risks—including AI risks—should be managed.
When AI risk management operates in isolation, it loses connection to enterprise strategy, risk appetite, and cross-functional control objectives.
Why A is Correct: The ISACA AAIR curriculum identifies strategic control alignment as a foundational ERM integration requirement.
When AI risk operates independently, controls may conflict with or duplicate enterprise controls, risk appetite thresholds may differ, and AI risks cannot be aggregated or prioritized alongside other organizational risks. This misalignment creates blind spots at the enterprise level and undermines coherent strategic risk management.
Why B is Wrong: Inconsistent regulatory reporting is a compliance concern but is a downstream consequence of poor governance rather than the greatest organizational risk from separation. Regulatory gaps can often be patched operationally without full integration.
Why C is Wrong: Training cost increases represent a financial efficiency concern unrelated to the governance challenge of separate risk management functions. ROI impacts are not driven by organizational structure of risk management.
Why D is Wrong: Redundant documentation is an operational inefficiency, not a strategic risk. Duplicated records are wasteful but do not threaten organizational strategy or expose the enterprise to unmanaged risk.



Which of the following is the PRIMARY reason to include contractual requirements for model updates and disclosures from third-party AI suppliers?

  1. To guarantee that existing availability targets will be achieved following each update
  2. To ensure timely detection and mitigation of new system risks that could harm individuals
  3. To ensure internal trust in the model's reliability before launching AI-driven innovation efforts
  4. To determine appropriate access to vendor staff for datasets containing sensitive information

Answer(s): B

Explanation:

Third-party AI suppliers introduce significant risk through model updates, changes in training data, and modifications to system behavior. Contractual disclosure requirements ensure the acquiring organization can maintain active risk oversight despite not controlling the vendor's development processes.
Why B is Correct: The ISACA AAIR framework emphasizes that third-party AI contracts must protect against harms arising from undisclosed changes.
When vendors make silent updates to models, the acquiring organization cannot assess new risks before they affect users, decisions, or regulated outcomes. Timely disclosure requirements enable proactive risk detection and mitigation before individuals are harmed.
Why A is Wrong: Availability guarantees are service-level concerns addressed by SLA provisions.
While important operationally, they do not address the risk management imperative of understanding what changes have been made to AI models.
Why C is Wrong: Internal trust-building is a change management consideration, not the primary purpose of contractual disclosure requirements. Contracts address risk obligations, not organizational confidence.
Why D is Wrong: Vendor staff access to sensitive datasets is a data access and privacy concern addressed through data processing agreements and access controls, not model update disclosure requirements.



Viewing page 6 of 13
Viewing questions 41 - 48 out of 90 questions


Post your Comments and Discuss ISACA AAIR exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!