ISACA Advanced in AI Audit (AAIA) Questions and Answers
Which of the following insider threats involving the use of AI would present the GREATEST risk?
An organization seeks to sustain effective AI governance and risk management amid rapidly evolving AI technologies. Which of the following represents the MOST effective course of action?
Which of the following is the MOST important purpose of conducting a risk assessment for AI models within an organization?
Which of the following is MOST important for an IS auditor to consider when collecting data for analysis by AI tools?
When auditing the transparency of an AI system, which of the following would be the MOST effective way to understand the model's decision-making process?
Which of the following is MOST important to consider when evaluating ethical risk related to data used for training an AI model?
An IS auditor examining change management procedures for an AI system observes inconsistent training data validation and verification protocols prior to model retraining. Which of the following is the MOST significant risk in this context?
The PRIMARY objective of auditing AI systems is to:
Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?
Which of the following strategies used by modelers to enhance data accuracy has the GREATEST risk of bias and information loss?
An IS auditor is evaluating an organization's incident management program to ensure it is sufficiently prepared to manage AI-related incidents. Which of the following is MOST important for the auditor to validate?
An IS auditor is assessing the implementation of AI tools for evidence collection involving multiple data sources. Which of the following outcomes BEST indicates that AI-driven evidence collection has improved the audit process?
When auditing a research agency's use of generative AI models for analyzing scientific data, which of the following is MOST critical to evaluate in order to prevent hallucinatory results and ensure the accuracy of outputs?
An IS auditor is considering the integration of AI techniques into the audit sampling process. Which of the following BEST enables the auditor to identify high-risk transactions within large data sets for targeted sampling?
Which of the following is the BEST way to ensure data fed into an AI model aligns with business objectives?
Which of the following is the BEST way to support the development and design of high-risk AI systems?
An AI healthcare diagnostic tool requires large volumes of patient data, raising concerns about privacy and data breaches. Which of the following is the MOST effective strategy to mitigate this risk?
An AI social media platform uses an algorithm to increase user engagement that could unintentionally promote divisive content. Which of the following is the BEST course of action to mitigate this risk?
Which of the following BEST detects model drift or unexpected changes in AI model outputs?
Which of the following is MOST important to have in place when initially populating data into a data frame for an AI model?
The PRIMARY purpose of utilizing neural networks in AI is to:
During an audit of an investment organization's AI-powered software, an IS auditor identifies a potential security risk. What is the GREATEST risk associated with staff exfiltrating organizational data to a generative AI tool?
Which of the following is the MOST important task when gathering data during the AI system development process?
Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?
In order to streamline operations, a bank has deployed an AI application to automatically detect and prevent further fraud on accounts. However, customers have voiced concerns that their usual transactions are being rejected. Which of the following is the MOST likely cause of the false positives?
Which of the following is MOST important for an IS auditor to consider when identifying AI risk in a know your customer (KYC) application within a banking organization?
Which of the following is the GREATEST risk when training data is not separated into distinct training and testing sets?
Which of the following is the MOST important step in an AI incident management process to ensure continuous improvement?
When developing an audit plan, which of the following is MOST important specifically for the transparency of an AI application?
The PRIMARY objective of machine learning (ML) in data processing is to:
A healthcare organization uses data clustering to group patients by medical history for personalized treatment recommendations. Which of the following is the GREATEST privacy risk associated with this practice?
An organization is developing an AI system that integrates data from multiple external sources without clearly defined data ownership policies. Which of the following is the GREATEST concern in this situation?
An IS auditor is performing an inventory audit for a manufacturing organization. Which of the following would BEST enable the auditor to identify types of products without assistance from organizational staff?
Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?
An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?
An organization has introduced an AI chat system where customers can enter their preferences and the system returns the best product selections. Which of the following is the BEST way to mitigate the risk of the system providing suggestions that may upset customers?
An organization deployed an AI-powered customer service chatbot trained using customer chat logs. During a risk assessment, which issue should be the IS auditor’s GREATEST concern?
Which of the following should be an IS auditor’s GREATEST concern when reviewing an anomaly detection process implemented for a high-risk AI system?
During a walk-through, an IS auditor observes an AI engineer entering a prompt that manipulates the AI model’s behavior. Which of the following is the BEST control to prevent this?
Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?
Which of the following presents the MOST significant barrier to generative AI model explainability?
An organization deploys a complex AI model to support credit risk assessments. Stakeholders find the model’s output difficult to interpret. Which of the following BEST improves interpretability?
Which of the following should be done FIRST when developing an incident management process for AI threats?
From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?
Which of the following is the MOST important consideration for change management related to the organization-wide adoption of AI systems and tools?
Which of the following is the PRIMARY objective of AI governance?
An IS auditor finds that an AI model's outputs are not being reviewed. Which of the following would BEST address this risk?
When converting data categories before training an AI model, which of the following scenarios represents the GREATEST risk?
Which of the following is the PRIMARY advantage of using K-fold cross validation when evaluating the performance of a machine learning (ML) model?
Which of the following is the MOST important reason to perform regular ethical reviews of AI systems?
When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?
An IS auditor is auditing an AI system that predicts inventory needs. The system recently failed to predict a stock outage for a key product. Which of the following audit tests would BEST validate the system's accuracy?
An IS auditor identifies that an AI model occasionally invents nonexistent medical test results. Which of the following recommendations would BEST mitigate this risk?
An IS auditor for a veterinary clinic was informed that the dog breed categorical variable is necessary for the predictive model. Which of the following introduces the MOST risk?