Courseiva

AAIA · domain

AI Governance And Risk

Practise ISACA Advanced in AI Audit (AAIA) (AAIA) AI Governance And Risk practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

66 questions17 easy27 medium22 hard

Focused practice

Practice AI Governance And Risk questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about AI Governance And Risk

AI Governance And Risk questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common AI Governance And Risk exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All AI Governance And Risk questions (66)

Click any question to see the full explanation, or start a practice session above.

1

During an audit of Google Cloud Vertex AI, you discover that sensitive PII is being logged during model inference. You need to implement a control that enforces privacy at the model serving layer. Which configuration should you verify?

Hard
2

You are auditing a model's 'Robustness' against adversarial attacks. Which test is most appropriate?

Hard
3

Which THREE risks should be explicitly managed in an 'AI Governance' program?

Hard
4

A company's AI governance policy requires 'Model explainability'. Which tool or technique best satisfies this requirement for complex deep learning models?

Medium
5

Which THREE components are critical for a robust 'AI Governance' framework?

Hard
6

You are auditing a model's 'Data Pre-processing' step. Which practice is a major concern regarding data privacy?

Medium
7

You are auditing an organization's AI deployment in Microsoft Azure. The Chief Risk Officer requires a central dashboard to monitor AI model performance drift and data quality metrics across all deployed services. Which tool should you confirm is configured to provide these insights?

Medium
8

An organization uses AWS SageMaker. As an auditor, you need to verify that model lineage and versioning are being captured to satisfy the AI risk assessment requirement for reproducibility. Which feature ensures that every model training job is recorded with its data sources?

Medium
9

During an audit, you find that the AI training data includes personally identifiable information (PII) that was not anonymized. Which regulation does this most likely violate?

Medium
10

Which TWO of the following are core components of an AI incident response strategy?

Easy
11

When auditing an 'AI Model Lifecycle', which phase occurs immediately after the 'Model Training' phase?

Medium
12

Which TWO of the following are typical 'Model Risk Management' (MRM) pillars?

Medium
13

Which TWO of the following are examples of 'Model Risk Management' (MRM) controls that must be validated during an audit?

Hard
14

What is the goal of a 'Human-in-the-loop' (HITL) control in an AI system?

Easy
15

Which TWO of the following are primary components of an AI model risk management inventory?

Medium
16

In the context of 'AI Compliance', what is a 'Model Card'?

Hard
17

An organization is using 'Federated Learning' to maintain data privacy while training models. What is the primary audit risk associated with this architecture?

Hard
18

During an AI risk assessment, you notice that the 'Model Risk Management' (MRM) framework does not mandate independent validation for models categorized as 'High Impact'. What is the most significant consequence?

Hard
19

You are auditing a firm using LLMs (Large Language Models). Which risk is most specific to generative AI compared to traditional predictive models?

Hard
20

What is the purpose of an 'AI Policy' within an organization?

Easy
21

Which component of an AI policy is most important for establishing organizational accountability?

Easy
22

What is the key difference between 'AI Ethics' and 'AI Compliance'?

Easy
23

A board of directors asks you to define the 'AI Risk Appetite'. Which approach best satisfies the governance requirement?

Easy
24

During an audit of AI procurement, you find that the 'Vendor AI Assessment' questionnaire is missing. What is the correct next step?

Medium
25

Which THREE of the following are potential risks associated with AI model 'Drift' that an auditor must account for?

Medium
26

As part of an AI audit, you are checking the 'AI Transparency' requirement. Which documentation artifact is essential to provide to external regulators to explain the model's design, intended use, and limitations?

Easy
27

You are assessing the risk of 'Data Poisoning' in a retail AI model. Which control should you implement during the data ingestion pipeline to mitigate this risk?

Medium
28

When drafting an AI policy, you need to define the 'Human-in-the-Loop' (HITL) requirement. Which of the following represents a best-practice control for HITL?

Easy
29

Which 'AI Risk Mitigation' strategy is most effective for reducing 'Data Leakage' in training sets?

Medium
30

Which TWO of the following are examples of AI governance 'Inputs'?

Medium
31

What is the primary function of an 'AI Ethics Board'?

Easy
32

Which THREE of the following are core components of a robust AI Governance and Risk Assessment Framework?

Medium
33

What is the primary function of an 'AI Audit Log'?

Easy
34

A board of directors requests a quarterly report on AI risk exposure. Which component of the NIST AI Risk Management Framework should you prioritize to demonstrate that the board's AI policy is being operationally enforced?

Easy
35

Which TWO of the following are essential when performing an 'AI Risk Assessment'?

Medium
36

You are auditing a 'Model Lifecycle' and find that the decommissioning process is not defined. What is the impact?

Hard
37

Which AI risk is best mitigated by conducting a 'bias audit' on the training dataset?

Hard
38

Which THREE factors must be evaluated when assessing the 'Fairness' of an AI model?

Hard
39

You are assessing 'Model Security'. Which attack vector specifically exploits the AI training phase?

Hard
40

You are auditing a 'Model Monitoring' dashboard. Which metric is most indicative of a potential degradation in the model's reliability over time?

Hard
41

When auditing model fairness in a production environment using IBM Watson OpenScale, which metric would you specifically validate to ensure the model is not violating protected class regulations?

Hard
42

An organization is scaling its AI governance program. You need to automate the identification of 'Shadow AI' in the corporate network. Which tool would be the most effective to gain visibility into unauthorized AI model API usage?

Medium
43

During an audit of an AI system, you notice that 'Model validation' is performed by the same team that developed the model. Why is this a concern?

Medium
44

Which action is required when a model is found to be 'Non-compliant' with the internal AI Governance policy?

Hard
45

Which role is primarily responsible for ensuring that the AI governance framework is followed in daily operations?

Easy
46

A firm uses a third-party AI service. Which control is most critical to ensure compliance with the firm's own AI governance policy?

Medium
47

In a financial services firm, you are auditing the 'Explainability' of a credit scoring model. The model uses complex non-linear features. Which technique should you verify is being used to provide local explanations for individual credit decisions?

Hard
48

What is the main role of the 'AI Risk Assessment' document in a project lifecycle?

Easy
49

A firm uses a 'Federated Learning' approach. Which governance benefit does this provide?

Medium
50

Which document is the primary source for establishing the scope of an AI audit?

Easy
51

Which THREE of the following should be included in an AI Policy document to ensure compliance and ethical alignment?

Medium
52

A data scientist proposes using a 'black-box' model for a high-stakes loan approval process. Which action does your AI audit framework require?

Medium
53

You are reviewing a model risk management (MRM) framework for an AI system using NVIDIA NeMo Guardrails. What is the primary purpose of this tool in a risk mitigation strategy?

Medium
54

You are reviewing the 'AI Incident Response Plan'. Which element is essential for compliance?

Medium
55

When auditing an AI system for regulatory compliance, you find that data lineage is broken between the feature store and the training pipeline. Which control is most likely deficient?

Hard
56

You are auditing a firm's AI policy and find that the 'Model Inventory' in the enterprise risk management platform lacks versioning metadata. Which specific control gap should be prioritized to align with NIST AI RMF?

Medium
57

Which technique is most appropriate for mitigating 'Concept Drift' in a production model?

Hard
58

Which TWO of the following are legitimate 'AI Governance' concerns regarding third-party AI service providers (SaaS)?

Hard
59

An auditor is asked to review the AI model inventory. What information must be present in the inventory for every model to satisfy basic regulatory requirements?

Easy
60

You find that the 'Inference API' for a model allows 'Prompt Injection' attacks. Which governance failure is most likely?

Hard
61

Which THREE criteria are necessary for an AI system to be deemed 'Trustworthy' under most governance frameworks?

Hard
62

What is the purpose of 'Model Versioning' in an AI audit context?

Easy
63

What is the primary objective of 'Board-level AI Governance'?

Easy
64

You are assessing a company's 'AI Governance Committee'. Which action best demonstrates effective board-level oversight?

Medium
65

Which artifact should an auditor request to verify 'Model Governance' during the model life cycle?

Medium
66

You are reviewing the AI Incident Response Plan. Which scenario constitutes a 'High' severity AI incident that requires immediate board notification under most enterprise risk frameworks?

Medium

Frequently asked questions

What does the AI Governance And Risk domain cover on the AAIA exam?
AI Governance And Risk questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 66 AI Governance And Risk questions in the AAIA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only AI Governance And Risk questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-aaia ISACA-AAIA ai governance and risk Practice Questions