AAIA · domain
AI Governance And Risk
Practise ISACA Advanced in AI Audit (AAIA) (AAIA) AI Governance And Risk practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice AI Governance And Risk questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about AI Governance And Risk
AI Governance And Risk questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common AI Governance And Risk exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All AI Governance And Risk questions (66)
Click any question to see the full explanation, or start a practice session above.
During an audit of Google Cloud Vertex AI, you discover that sensitive PII is being logged during model inference. You need to implement a control that enforces privacy at the model serving layer. Which configuration should you verify?
Hard2You are auditing a model's 'Robustness' against adversarial attacks. Which test is most appropriate?
Hard3Which THREE risks should be explicitly managed in an 'AI Governance' program?
Hard4A company's AI governance policy requires 'Model explainability'. Which tool or technique best satisfies this requirement for complex deep learning models?
Medium5Which THREE components are critical for a robust 'AI Governance' framework?
Hard6You are auditing a model's 'Data Pre-processing' step. Which practice is a major concern regarding data privacy?
Medium7You are auditing an organization's AI deployment in Microsoft Azure. The Chief Risk Officer requires a central dashboard to monitor AI model performance drift and data quality metrics across all deployed services. Which tool should you confirm is configured to provide these insights?
Medium8An organization uses AWS SageMaker. As an auditor, you need to verify that model lineage and versioning are being captured to satisfy the AI risk assessment requirement for reproducibility. Which feature ensures that every model training job is recorded with its data sources?
Medium9During an audit, you find that the AI training data includes personally identifiable information (PII) that was not anonymized. Which regulation does this most likely violate?
Medium10Which TWO of the following are core components of an AI incident response strategy?
Easy11When auditing an 'AI Model Lifecycle', which phase occurs immediately after the 'Model Training' phase?
Medium12Which TWO of the following are typical 'Model Risk Management' (MRM) pillars?
Medium13Which TWO of the following are examples of 'Model Risk Management' (MRM) controls that must be validated during an audit?
Hard14What is the goal of a 'Human-in-the-loop' (HITL) control in an AI system?
Easy15Which TWO of the following are primary components of an AI model risk management inventory?
Medium16In the context of 'AI Compliance', what is a 'Model Card'?
Hard17An organization is using 'Federated Learning' to maintain data privacy while training models. What is the primary audit risk associated with this architecture?
Hard18During an AI risk assessment, you notice that the 'Model Risk Management' (MRM) framework does not mandate independent validation for models categorized as 'High Impact'. What is the most significant consequence?
Hard19You are auditing a firm using LLMs (Large Language Models). Which risk is most specific to generative AI compared to traditional predictive models?
Hard20What is the purpose of an 'AI Policy' within an organization?
Easy21Which component of an AI policy is most important for establishing organizational accountability?
Easy22What is the key difference between 'AI Ethics' and 'AI Compliance'?
Easy23A board of directors asks you to define the 'AI Risk Appetite'. Which approach best satisfies the governance requirement?
Easy24During an audit of AI procurement, you find that the 'Vendor AI Assessment' questionnaire is missing. What is the correct next step?
Medium25Which THREE of the following are potential risks associated with AI model 'Drift' that an auditor must account for?
Medium26As part of an AI audit, you are checking the 'AI Transparency' requirement. Which documentation artifact is essential to provide to external regulators to explain the model's design, intended use, and limitations?
Easy27You are assessing the risk of 'Data Poisoning' in a retail AI model. Which control should you implement during the data ingestion pipeline to mitigate this risk?
Medium28When drafting an AI policy, you need to define the 'Human-in-the-Loop' (HITL) requirement. Which of the following represents a best-practice control for HITL?
Easy29Which 'AI Risk Mitigation' strategy is most effective for reducing 'Data Leakage' in training sets?
Medium30Which TWO of the following are examples of AI governance 'Inputs'?
Medium31What is the primary function of an 'AI Ethics Board'?
Easy32Which THREE of the following are core components of a robust AI Governance and Risk Assessment Framework?
Medium33What is the primary function of an 'AI Audit Log'?
Easy34A board of directors requests a quarterly report on AI risk exposure. Which component of the NIST AI Risk Management Framework should you prioritize to demonstrate that the board's AI policy is being operationally enforced?
Easy35Which TWO of the following are essential when performing an 'AI Risk Assessment'?
Medium36You are auditing a 'Model Lifecycle' and find that the decommissioning process is not defined. What is the impact?
Hard37Which AI risk is best mitigated by conducting a 'bias audit' on the training dataset?
Hard38Which THREE factors must be evaluated when assessing the 'Fairness' of an AI model?
Hard39You are assessing 'Model Security'. Which attack vector specifically exploits the AI training phase?
Hard40You are auditing a 'Model Monitoring' dashboard. Which metric is most indicative of a potential degradation in the model's reliability over time?
Hard41When auditing model fairness in a production environment using IBM Watson OpenScale, which metric would you specifically validate to ensure the model is not violating protected class regulations?
Hard42An organization is scaling its AI governance program. You need to automate the identification of 'Shadow AI' in the corporate network. Which tool would be the most effective to gain visibility into unauthorized AI model API usage?
Medium43During an audit of an AI system, you notice that 'Model validation' is performed by the same team that developed the model. Why is this a concern?
Medium44Which action is required when a model is found to be 'Non-compliant' with the internal AI Governance policy?
Hard45Which role is primarily responsible for ensuring that the AI governance framework is followed in daily operations?
Easy46A firm uses a third-party AI service. Which control is most critical to ensure compliance with the firm's own AI governance policy?
Medium47In a financial services firm, you are auditing the 'Explainability' of a credit scoring model. The model uses complex non-linear features. Which technique should you verify is being used to provide local explanations for individual credit decisions?
Hard48What is the main role of the 'AI Risk Assessment' document in a project lifecycle?
Easy49A firm uses a 'Federated Learning' approach. Which governance benefit does this provide?
Medium50Which document is the primary source for establishing the scope of an AI audit?
Easy51Which THREE of the following should be included in an AI Policy document to ensure compliance and ethical alignment?
Medium52A data scientist proposes using a 'black-box' model for a high-stakes loan approval process. Which action does your AI audit framework require?
Medium53You are reviewing a model risk management (MRM) framework for an AI system using NVIDIA NeMo Guardrails. What is the primary purpose of this tool in a risk mitigation strategy?
Medium54You are reviewing the 'AI Incident Response Plan'. Which element is essential for compliance?
Medium55When auditing an AI system for regulatory compliance, you find that data lineage is broken between the feature store and the training pipeline. Which control is most likely deficient?
Hard56You are auditing a firm's AI policy and find that the 'Model Inventory' in the enterprise risk management platform lacks versioning metadata. Which specific control gap should be prioritized to align with NIST AI RMF?
Medium57Which technique is most appropriate for mitigating 'Concept Drift' in a production model?
Hard58Which TWO of the following are legitimate 'AI Governance' concerns regarding third-party AI service providers (SaaS)?
Hard59An auditor is asked to review the AI model inventory. What information must be present in the inventory for every model to satisfy basic regulatory requirements?
Easy60You find that the 'Inference API' for a model allows 'Prompt Injection' attacks. Which governance failure is most likely?
Hard61Which THREE criteria are necessary for an AI system to be deemed 'Trustworthy' under most governance frameworks?
Hard62What is the purpose of 'Model Versioning' in an AI audit context?
Easy63What is the primary objective of 'Board-level AI Governance'?
Easy64You are assessing a company's 'AI Governance Committee'. Which action best demonstrates effective board-level oversight?
Medium65Which artifact should an auditor request to verify 'Model Governance' during the model life cycle?
Medium66You are reviewing the AI Incident Response Plan. Which scenario constitutes a 'High' severity AI incident that requires immediate board notification under most enterprise risk frameworks?
MediumOther domains
All AAIA exam domains
Frequently asked questions
- What does the AI Governance And Risk domain cover on the AAIA exam?
- AI Governance And Risk questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 66 AI Governance And Risk questions in the AAIA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only AI Governance And Risk questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.