ISACA · Free Practice Questions · Last reviewed May 2026
18real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
During the AI lifecycle, when should a 'Data Quality' assessment be performed to minimize long-term risk?
After model deployment in production.
During the final model sign-off.
During the decommission phase.
During the data ingestion and preprocessing stage.
Performing quality checks before the model sees the data prevents propagation of errors into model weights.
Which AI lifecycle stage is most susceptible to the risk of 'data leakage' where training data inadvertently contains information from the future/target?
Model monitoring phase.
Model decommission phase.
Deployment phase.
Data preparation and training phase.
This is where features are created and datasets are split, making it the primary site for leakage risk.
A practitioner is setting up a model monitoring service in AWS SageMaker Model Monitor. They observe that the ground truth data is significantly delayed. What action ensures risk identification remains effective?
Configure Data Quality Monitoring on input features only.
Input feature monitoring serves as a proxy for performance when ground truth labels are missing.
Disable monitoring until ground truth is available.
Manually force a model redeployment.
Reduce the sampling rate of the inference logs.
You are utilizing Azure Machine Learning to manage a deployment. You detect a sudden drop in model performance due to 'concept drift'. Which specific configuration in the Azure ML Model Monitoring dashboard should be adjusted to better detect this?
Increase the retraining frequency of the pipeline.
Disable the data lineage capture to improve latency.
Adjust the feature drift sensitivity threshold for categorical variables.
Concept drift often manifests as changes in the distribution of target variables relative to inputs, requiring sensitive drift monitoring.
Switch the model to a higher-capacity compute instance.
You are managing a model that utilizes 'Online Learning'. What is the most critical risk requiring constant lifecycle vigilance?
Hardware failure in the training cluster.
Adversarial data poisoning and instability.
Because the model learns from every input, a malicious actor can influence the model's logic through carefully crafted inputs.
Data drift from batch updates.
Memory exhaustion due to high throughput.
A financial institution uses an AI model to approve loans. After deployment, they notice the model is rejecting loan applications from a specific region at a rate 30% higher than historical human benchmarks. What is the most appropriate next step in the risk lifecycle?
Ignore the shift as it may be a temporary market trend.
Conduct a bias investigation by comparing input distribution shifts between training data and current inference requests.
This identifies if the model is responding to a shift in input population or if the bias is inherent to the model logic.
Immediately shut down the system.
Train a secondary model to override the primary one.
Want more AI Lifecycle Risk Management practice?
Practice this domainYou are mapping AI risks to the NIST AI RMF. Which step is essential when documenting the 'Map' function for a high-risk autonomous system?
Identifying and documenting the context and intended use
The 'Map' function focuses on understanding the context to prioritize risks.
Updating the SOC2 Type II report
Automating the model deployment pipeline
Conducting a quarterly penetration test
A firm is establishing an AI Governance Committee. Which TWO groups should be represented to ensure comprehensive oversight?
Data Privacy Office
Crucial for handling PII within AI datasets.
Public relations
Legal and Compliance
Ensures adherence to evolving regulations.
Hardware vendors
External marketing agencies
A financial institution is integrating AI risk into its ERM framework. Which action most effectively aligns AI risk appetite with enterprise risk appetite?
Defining quantitative risk thresholds in the AI governance policy
This establishes clear boundaries that align with the broader ERM appetite.
Purchasing cybersecurity insurance for AI systems
Assigning AI risk ownership to the IT department
Implementing a standalone AI audit program
You are integrating AI risk into the NIST Risk Management Framework (RMF). Which step requires an explicit evaluation of AI model lineage and data provenance to satisfy the 'Govern' function?
Step 2: Select controls
Step 1: Categorize system
Continuous Monitoring phase
Governance mapping during 'Govern' function analysis
The NIST AI RMF emphasizes establishing governance early by tracking provenance and lineage.
When configuring the Microsoft Purview AI hub for risk management, which setting must be enabled to ensure AI prompt logs are captured for enterprise risk reporting?
Enable Audit (Premium)
Set up Data Loss Prevention (DLP) policies
Enable sensitivity labels
Configure Microsoft Purview AI activity logging
This setting directly captures prompt interactions for audit logs.
During a board meeting, the Chief Risk Officer needs to present AI model performance trends. Which metric is most critical for board-level reporting?
Data scientists' training hours per quarter
Computational resource utilization percentage
Model latency in milliseconds
Frequency and severity of model drift incidents
This metric highlights the stability and risk exposure of the models.
Want more AI Risk Governance And Framework Integration practice?
Practice this domainWhen setting KPIs for an AI risk program, which metric is a leading indicator of potential model bias?
Average model inference latency
Percentage of customer complaints regarding AI decisions
Number of model updates per quarter
Demographic parity ratio in training data samples
Analyzing training data for representativeness identifies bias before the model is deployed.
An organization is establishing an AI governance framework. Which approach is most effective for aligning AI risk appetite with enterprise-wide risk management (ERM)?
Map AI-specific risk metrics to existing enterprise risk categories like operational, financial, and reputational risk.
Mapping ensures AI risk is treated as an extension of existing enterprise risks.
Establish a top-down mandate that ignores business unit input to ensure uniformity.
Focus solely on technical model performance metrics to define the organizational risk appetite.
Create a separate AI-specific risk register that operates independently of the corporate risk register.
The AI Risk Governance Committee is defining the risk appetite for a new generative AI chatbot. Which THREE factors must be considered to align with organizational risk tolerance?
The speed of the development team's sprint cycles
Data privacy and residency requirements for training sets
Compliance with data regulations is critical to risk appetite.
The likelihood of model drift impacting output accuracy
Operational reliability is a key indicator of AI risk.
The impact of potential hallucination on brand reputation
Reputational risk is a core component of AI risk appetite.
The total cost of GPU infrastructure
A firm is using the NIST AI Risk Management Framework to document its AI risk program. Which approach best ensures that AI risk metrics are dynamic?
Conducting annual risk assessments
Setting static thresholds for model accuracy
Limiting AI deployment to offline systems
Integrating model performance metrics into operational dashboards
Continuous monitoring and dashboarding provide the real-time visibility needed for dynamic risk management.
An enterprise is establishing its AI Governance Committee. Which stakeholder is most critical to include to ensure alignment between AI technical capabilities and the organization's enterprise risk appetite?
Head of Legal
Chief Information Security Officer
Chief Risk Officer
The CRO is responsible for enterprise-wide risk strategy, making them the primary stakeholder for AI risk appetite.
Lead Data Scientist
A cross-functional committee is evaluating the deployment of a high-impact AI model. Which TWO factors are critical to include in the initial AI risk assessment to ensure comprehensive coverage?
The frequency of software patching for the underlying cloud infrastructure.
The socio-technical implications and potential impact on protected groups.
Socio-technical impact is a core requirement for high-impact AI risk assessments.
The underlying training data lineage, including provenance and potential bias sources.
Data lineage is essential for auditing and understanding potential bias.
The name of the vendor providing the cloud compute resources.
The specific programming language used for the model development.
Want more AI Risk Program Management practice?
Practice this domainThe AAIR exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 3 domains: AI Lifecycle Risk Management, AI Risk Governance And Framework Integration, AI Risk Program Management. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA AAIR exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.