ISACA Advanced in AI Audit (AAIA) Questions and Answers
An organization uses an AI-powered tool to detect and respond to cybersecurity threats in real time. An IS auditor finds that the tool produces excessive false positives, increasing the workload of the security team. Which of the following techniques should the auditor recommend to BEST evaluate the tool ' s effectiveness in managing this issue?
Which of the following is the MOST important reason to conduct regular threat modeling exercises for AI systems and data?
An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?
Which of the following is the BEST recommendation to mitigate excessive agency when implementing an AI system as a browser extension?
Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?
Which of the following techniques would be MOST effective as part of incident management procedures for a prompt injection attack?
An organization is developing an AI system that integrates data from multiple external sources without clearly defined data ownership policies. Which of the following is the GREATEST concern in this situation?
When developing an audit plan, which of the following is MOST important specifically for the transparency of an AI application?
An IS auditor reviewing the latest AI chatbot release identifies that, despite high accuracy rates, non-English users complain about the model ' s poor accuracy. Which of the following controls is BEST at ensuring detection of subgroup regressions?
Which of the following is the GREATEST risk associated with using AI in audit planning?
An IS auditor reviewed an AI-enabled software for processing a bank ' s financial information and discovered errors in the training data. Which of the following would BEST mitigate this risk?
An IS auditor notes the combined number of records utilized within the training, validation, and testing data sets exceeds the total number of records in the original data set. Which of the following is MOST important for the auditor to determine?
Which of the following is the MOST important task when gathering data during the AI system development process?
Which of the following is the MOST important consideration when auditing the data used for training an AI model?
Which of the following do supervised AI learning models PRIMARILY use to train algorithms?
When initiating an AI governance program, which of the following is MOST critical to ensure the AI system aligns with organizational objectives and stakeholder needs?
Which of the following AI documents would support an IS auditor assessing hyperparameter tuning records?
Which of the following techniques BEST supports machine learning (ML) training in sentiment analysis?
A retail organization uses an AI model to forecast inventory based on customer purchasing trends and updates the model quarterly. The model recently failed to recognize a surge in demand during a popular shopping season. Which of the following issues does this situation BEST demonstrate?
A car rental company is developing an AI system to dynamically adjust rental pricing based on demand, location, and customer profiles. Which of the following is the MOST important reason to conduct specific testing during development?
Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?
What is the MOST important reason government organizations should provide regular AI training programs for all staff?
A health organization has deployed an AI model to analyze chest X-rays. The model reports high accuracy, but thresholds are unclear and performance is not broken down by patient demographics. Why is accuracy alone insufficient to evaluate this model?
Which of the following is the MOST significant benefit of performing frequent AI model testing and retraining?
Which of the following is an IS auditor ' s MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?
An organization has exhausted its internal data sources to train an AI model. Which of the following is the BEST source to obtain new data?
Which of the following is the GREATEST risk associated with normalizing a data set before splitting it into training, testing, and validation sets?
Which of the following should be done FIRST when developing an incident management process for AI threats?
Which of the following is the GREATEST challenge facing IS auditors evaluating the explainability of generative AI models?
During a pre-implementation risk assessment, an AI model is determined to present a significant risk of bias and potential harm in excess of the organization’s risk tolerance. Which of the following is the MOST appropriate response?
An organization is conducting an audit of an AI decision-making system being used for talent recruitment. Which of the following is MOST critical to evaluate in order to ensure the system meets stakeholder needs?
During a walk-through, an IS auditor observes an AI engineer entering a prompt that manipulates the AI model’s behavior. Which of the following is the BEST control to prevent this?
An IS auditor observes that an AI-based fraud detection system used by an insurance organization produces inconsistent outcomes when processing similar cases. Which of the following is the auditor ' s MOST efficient recommendation?
From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?
An IS auditor is testing an AI-based fraud detection system that flags suspicious transactions and finds that the system has a high false positive rate. Which of the following testing methods should be prioritized to BEST optimize the detection rate?
Which of the following is MOST important for an IS auditor to consider when collecting data for analysis by AI tools?
Which of the following should be done FIRST when an AI chatbot has been identified as giving harmful advice?
Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?
Which role is BEST suited to define the implementation roadmaps for adopting AI solutions?
An insurance company uses an AI model to set premium rates. To align with AI-related policies on fairness, which of the following is the FIRST course of action?
An organization is training a skin cancer recognition model. Photographs collected from which of the following sources would present the GREATEST risk associated with data integrity?
Which of the following is the GREATEST risk when a generative AI tool used for threat detection produces inaccurate or misleading information?
An IS auditor is evaluating an organization’s data governance controls for its AI system. Which of the following represents the GREATEST risk in this context?
A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?
Which of the following BEST helps in detecting AI model drift?
Which of the following BEST ensures representativeness in AI systems when assessing training data periodically?
An IS auditor uses an internally developed generative AI tool to prepare a status update for audit stakeholders. Which of the following is the auditor’s MOST appropriate course of action?
Which of the following is the MOST essential attribute of an AI-driven audit tool?
An IS auditor is testing an AI model used for determining insurance premiums and eligibility. Which of the following is the MOST effective testing method to identify bias in algorithm outputs?
Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?
Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?
Which of the following BEST detects model drift or unexpected changes in AI model outputs?
Which of the following presents the GREATEST risk when an organization deploys a machine learning model in a public cloud environment for real-time predictions?
Which of the following should be an IS auditor ' s GREATEST concern when using a predictive AI tool to analyze data abnormalities?
Which of the following techniques is BEST to use when there is a limited dataset of detailed images available to train a convolutional neural network (CNN) model?
When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?
An organization plans to implement an AI search and chatbot solution provided by an external vendor. Which of the following is MOST important for an IS auditor to confirm?
An IS auditor is reviewing a dataset used by a university to train a predictive machine learning model. Which of the following MOST likely indicates risk that the model could not process all data and make necessary correlations?
Which of the following testing techniques would BEST validate whether an organization ' s data governance program effectively ensures data quality and integrity for AI model training and deployment?
An IS auditor is auditing an AI system that predicts inventory needs. The system recently failed to predict a stock outage for a key product. Which of the following audit tests would BEST validate the system ' s accuracy?
Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?
A healthcare AI tool recommends treatments with high success rates but significant risk. The hospital prioritizes patient safety over innovation. What is the BEST course of action?
Which of the following will provide the BEST evidence to support the alignment of an AI model with an organization ' s business objectives?
Which of the following strategies used by modelers to enhance data accuracy has the GREATEST risk of bias and information loss?
An IS auditor identifies that an AI model occasionally invents nonexistent medical test results. Which of the following recommendations would BEST mitigate this risk?
A manufacturing company installs an AI system to control robotic arms on its assembly line. The system learns over time, adjusting its movements based on production results to improve accuracy. What type of learning is the robot MOST likely using?
An organization using AI to create digital content faces challenges in protecting its intellectual property. Which of the following is the BEST way to mitigate this risk?
Which of the following would be MOST useful for an IS auditor when testing high-impact rare scenarios that have not yet occurred in a production environment?
Which of the following is the MOST important reason to establish AI governance structures that extend beyond regulatory compliance?
An IS auditor for a veterinary clinic was informed that the dog breed categorical variable is necessary for the predictive model. Which of the following introduces the MOST risk?
A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?
Which of the following is MOST important for an IS auditor to consider when identifying AI risk in a know your customer (KYC) application within a banking organization?
Which of the following is the MOST important step in an AI incident management process to ensure continuous improvement?
A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model ' s predictions?
Which of the following is the BEST recommendation for an organization that has adopted " vibe coding " (using AI to generate code based on high-level natural language prompts)?
Which of the following is the BEST use of AI to audit relationships for conflicts of interest or collusion?
After AI training data has been tested for biases, which of the following is MOST important to check to validate the effectiveness of the testing?
An IS auditor notes that an AI modelachieved significantly better results on training data than on test data. After the development, a quality assurance (QA) team checks that all input variables and parameters match the technical design. Which of the following BEST describes this activity?
An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?
An organization ' s system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?
An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model’s outputs. Which of the following is the IS auditor ' s BEST recommendation?
An IS auditor is evaluating a cybersecurity system that uses agentic AI for autonomous threat detection and incident response. Which of the following is MOST important for the auditor to consider?