Isaca AAIR - Advanced in AI Risk Exam
Page: 3 / 18
Total 90 questions
Question #11 (Topic: Exam A)
A risk practitioner learns that an organization's AI inventory includes separate listings of AI systems, models, and datasets. Which of the following is the risk practitioner's BEST recommendation to improve AI governance?
A. Map interdependencies between AI assets continuously.
B. Include information about model training frequency.
C. Automate inventory reconciliation steps.
D. Assign inventory oversight to the AI risk committee.
Answer: A
Question #12 (Topic: Exam A)
An organization plans to deploy a generative AI system that processes sensitive personal data across multiple countries with varying privacy laws. Which of the following is the BEST course of action to manage legal and regulatory exposure?
A. Remediate regulatory gaps in each jurisdiction through iterative post-deployment updates and model retraining.
B. Tailor organizational controls to relevant statutory requirements and preserve audit trails to prove adherence.
C. Adopt uniform global policies and implement strong encryption of personal data for all cross-border transfers.
D. Prioritize protection of intellectual property and restrict disclosure of model operations to safeguard assets.
Answer: B
Question #13 (Topic: Exam A)
Which of the following is the PRIMARY benefit of integrating AI risk processes into an enterprise risk framework?
A. More accurate benchmarking of AI key performance indicators (KPIs)
B. Improved compliance with regulatory requirements
C. Rapid identification of cyber threats and risks
D. Organization-level oversight and strategic alignment
Answer: D
Question #14 (Topic: Exam A)
Which of the following is MOST important to evaluate when selecting a vendor for a third-party large language model (LLM)?
A. Whether the vendor's service level agreements (SLAs) align with corporate strategy
B. How the vendor selects machine learning (ML) methods
C. Whether the vendor offers subscription-based service options
D. How the vendor handles data during model training and inference
Answer: D
Question #15 (Topic: Exam A)
An organization intends to implement an AI system that poses significant societal risk and interfaces with critical infrastructure and public services. Which of the following is the BEST course of action?
A. Conduct a comprehensive pre-launch evaluation of potential adverse impacts and compliance obligations.
B. Engage external consultants with expertise on measuring broad societal impacts.
C. Restrict disclosure of model internal operations to safeguard proprietary algorithms and protect trade secrets.
D. Conduct parallel model evaluation to quantify the impact of system operations.
Answer: A