Practice AAIA AI Governance And Risk questions with full explanations on every answer.
Start practicing
AI Governance And Risk — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When auditing an AI system for regulatory compliance, you find that data lineage is broken between the feature store and the training pipeline. Which control is most likely deficient?
2A firm uses a third-party AI service. Which control is most critical to ensure compliance with the firm's own AI governance policy?
3You are auditing a 'Model Monitoring' dashboard. Which metric is most indicative of a potential degradation in the model's reliability over time?
4You are auditing a firm's AI policy and find that the 'Model Inventory' in the enterprise risk management platform lacks versioning metadata. Which specific control gap should be prioritized to align with NIST AI RMF?
5You are assessing a company's 'AI Governance Committee'. Which action best demonstrates effective board-level oversight?
6Which component of an AI policy is most important for establishing organizational accountability?
7During an AI risk assessment, you notice that the 'Model Risk Management' (MRM) framework does not mandate independent validation for models categorized as 'High Impact'. What is the most significant consequence?
8A board of directors asks you to define the 'AI Risk Appetite'. Which approach best satisfies the governance requirement?
9Which TWO of the following are primary components of an AI model risk management inventory?
10Which THREE factors must be evaluated when assessing the 'Fairness' of an AI model?
11A data scientist proposes using a 'black-box' model for a high-stakes loan approval process. Which action does your AI audit framework require?
12What is the goal of a 'Human-in-the-loop' (HITL) control in an AI system?
13Which document is the primary source for establishing the scope of an AI audit?
14During an audit, you find that the AI training data includes personally identifiable information (PII) that was not anonymized. Which regulation does this most likely violate?
15You are reviewing the 'AI Incident Response Plan'. Which element is essential for compliance?
16Which technique is most appropriate for mitigating 'Concept Drift' in a production model?
17You are assessing 'Model Security'. Which attack vector specifically exploits the AI training phase?
18Which artifact should an auditor request to verify 'Model Governance' during the model life cycle?
19What is the primary function of an 'AI Ethics Board'?
20In the context of 'AI Compliance', what is a 'Model Card'?
21Which THREE components are critical for a robust 'AI Governance' framework?
22Which TWO of the following are essential when performing an 'AI Risk Assessment'?
23You are auditing a model's 'Data Pre-processing' step. Which practice is a major concern regarding data privacy?
24Which role is primarily responsible for ensuring that the AI governance framework is followed in daily operations?
25When auditing an 'AI Model Lifecycle', which phase occurs immediately after the 'Model Training' phase?
26What is the purpose of 'Model Versioning' in an AI audit context?
27You find that the 'Inference API' for a model allows 'Prompt Injection' attacks. Which governance failure is most likely?
28Which AI risk is best mitigated by conducting a 'bias audit' on the training dataset?
29A firm uses a 'Federated Learning' approach. Which governance benefit does this provide?
30What is the main role of the 'AI Risk Assessment' document in a project lifecycle?
31Which TWO of the following are typical 'Model Risk Management' (MRM) pillars?
32Which THREE criteria are necessary for an AI system to be deemed 'Trustworthy' under most governance frameworks?
33What is the key difference between 'AI Ethics' and 'AI Compliance'?
34During an audit of AI procurement, you find that the 'Vendor AI Assessment' questionnaire is missing. What is the correct next step?
35What is the primary function of an 'AI Audit Log'?
36What is the purpose of an 'AI Policy' within an organization?
37A company's AI governance policy requires 'Model explainability'. Which tool or technique best satisfies this requirement for complex deep learning models?
38You are auditing a firm using LLMs (Large Language Models). Which risk is most specific to generative AI compared to traditional predictive models?
39Which 'AI Risk Mitigation' strategy is most effective for reducing 'Data Leakage' in training sets?
40Which action is required when a model is found to be 'Non-compliant' with the internal AI Governance policy?
41You are auditing a model's 'Robustness' against adversarial attacks. Which test is most appropriate?
42Which TWO of the following are examples of AI governance 'Inputs'?
43Which THREE risks should be explicitly managed in an 'AI Governance' program?
44What is the primary objective of 'Board-level AI Governance'?
45During an audit of an AI system, you notice that 'Model validation' is performed by the same team that developed the model. Why is this a concern?
46You are auditing a 'Model Lifecycle' and find that the decommissioning process is not defined. What is the impact?
47You are auditing an organization's AI deployment in Microsoft Azure. The Chief Risk Officer requires a central dashboard to monitor AI model performance drift and data quality metrics across all deployed services. Which tool should you confirm is configured to provide these insights?
48An organization uses AWS SageMaker. As an auditor, you need to verify that model lineage and versioning are being captured to satisfy the AI risk assessment requirement for reproducibility. Which feature ensures that every model training job is recorded with its data sources?
49During an audit of Google Cloud Vertex AI, you discover that sensitive PII is being logged during model inference. You need to implement a control that enforces privacy at the model serving layer. Which configuration should you verify?
50A board of directors requests a quarterly report on AI risk exposure. Which component of the NIST AI Risk Management Framework should you prioritize to demonstrate that the board's AI policy is being operationally enforced?
51You are reviewing a model risk management (MRM) framework for an AI system using NVIDIA NeMo Guardrails. What is the primary purpose of this tool in a risk mitigation strategy?
52When auditing model fairness in a production environment using IBM Watson OpenScale, which metric would you specifically validate to ensure the model is not violating protected class regulations?
53An organization is scaling its AI governance program. You need to automate the identification of 'Shadow AI' in the corporate network. Which tool would be the most effective to gain visibility into unauthorized AI model API usage?
54As part of an AI audit, you are checking the 'AI Transparency' requirement. Which documentation artifact is essential to provide to external regulators to explain the model's design, intended use, and limitations?
55In a financial services firm, you are auditing the 'Explainability' of a credit scoring model. The model uses complex non-linear features. Which technique should you verify is being used to provide local explanations for individual credit decisions?
56You are reviewing the AI Incident Response Plan. Which scenario constitutes a 'High' severity AI incident that requires immediate board notification under most enterprise risk frameworks?
57You are assessing the risk of 'Data Poisoning' in a retail AI model. Which control should you implement during the data ingestion pipeline to mitigate this risk?
58An organization is using 'Federated Learning' to maintain data privacy while training models. What is the primary audit risk associated with this architecture?
59When drafting an AI policy, you need to define the 'Human-in-the-Loop' (HITL) requirement. Which of the following represents a best-practice control for HITL?
60An auditor is asked to review the AI model inventory. What information must be present in the inventory for every model to satisfy basic regulatory requirements?
61Which THREE of the following are core components of a robust AI Governance and Risk Assessment Framework?
62Which TWO of the following are examples of 'Model Risk Management' (MRM) controls that must be validated during an audit?
63Which TWO of the following are legitimate 'AI Governance' concerns regarding third-party AI service providers (SaaS)?
64Which THREE of the following should be included in an AI Policy document to ensure compliance and ethical alignment?
65Which THREE of the following are potential risks associated with AI model 'Drift' that an auditor must account for?
66Which TWO of the following are core components of an AI incident response strategy?
The AI Governance And Risk domain covers the key concepts tested in this area of the AAIA exam blueprint published by ISACA. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all AAIA domains — no account required.
The Courseiva AAIA question bank contains 66 questions in the AI Governance And Risk domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the AI Governance And Risk domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included