ISACA Advanced in AI Audit (AAIA) Questions and Answers
Which of the following is the PRIMARY objective of AI governance?
An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?
Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?
A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model's predictions?
The PRIMARY objective of auditing AI systems is to:
Which of the following is the BEST way to support the development and design of high-risk AI systems?
An IS auditor is performing an inventory audit for a manufacturing organization. Which of the following would BEST enable the auditor to identify types of products without assistance from organizational staff?
An IS auditor is looking to expedite reporting for an audit with complex issues. Which of the following would be the MOST effective way for the auditor to use generative AI?
A retail organization uses an AI model to forecast inventory based on customer purchasing trends and updates the model quarterly. The model recently failed to recognize a surge in demand during a popular shopping season. Which of the following issues does this situation BEST demonstrate?
When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?
The BEST way to prevent sensitive information disclosure by large language model (LLM) chatbots is through:
Which of the following is an IS auditor's MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?
When auditing an AI system, which of the following steps ensures that AI model behavior is aligned with organizational objectives?
An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor's BEST recommendation to address this issue?
An IS auditor reviewing documentation for an AI model notes that the modeler utilized a K-means clustering algorithm, which clusters data into categories for correlations and analysis. Which of the following is the MOST important risk for the auditor to consider?
A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?
Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?
Which of the following is MOST important to consider when deciding whether to implement an AI solution?
In the context of an AI implementation, which of the following actions is MOST critical for an organization's change management program?
A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?
An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?
An organization is adopting AI for its procurement and inventory teams, raising concern from stakeholders that they will lose their jobs due to AI. Which of the following is the BEST way for the IS auditor to assess whether the potential negative impacts were minimized?
An organization's system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?
Which of the following is the MOST important task when gathering data during the AI system development process?
Which of the following is the GREATEST risk associated with using AI in audit planning?
Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?
An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?