Sample questions
ISACA Advanced in AI Risk (AAIR) (AAIR) practice questions
A developer is using 'Shadow Deployments' for a new AI model. What is the main risk being addressed?
A company is integrating an AI model that uses 'Online Inference'. What is the most significant risk regarding model security?
A practitioner is managing AI risk in a CI/CD pipeline. What should be the final gate before model promotion to production?
Which TWO metrics are standard in 'Monitoring' for identifying performance-related AI risks?
A company is implementing 'Human-in-the-Loop' (HITL) for its AI decision system. What is the primary risk of relying on HITL?
Why is 'AI Literacy' for the board of directors a key component of AI Governance?
AI Risk Governance And Framework IntegrationeasySee the answer and why each option is right or wrong →When deploying a generative AI model, what 'Governance Control' is most critical for preventing the generation of harmful/inappropriate content?
AI Risk Governance And Framework IntegrationhardSee the answer and why each option is right or wrong →You are mapping AI risks to the NIST AI RMF. Which step is essential when documenting the 'Map' function for a high-risk autonomous system?
AI Risk Governance And Framework IntegrationhardSee the answer and why each option is right or wrong →An organization is considering outsourcing its AI development. How should the 'AI Risk Governance' policy be adjusted for third-party vendors?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →When building an AI Governance framework, which TWO of the following are essential for ensuring enterprise adoption?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →When assessing the organizational readiness for AI risk governance, which TWO areas must be evaluated to ensure the framework is sustainable?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →Which THREE factors should be monitored to detect 'Model Drift' in the deployment phase?
When reporting AI risks to the Board of Directors, which THREE elements should be included to ensure informed decision-making?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →Which document defines the 'AI Risk Appetite' for an organization?
AI Risk Governance And Framework IntegrationeasySee the answer and why each option is right or wrong →What is the primary risk associated with 'Shadow AI' in an organization?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →A firm is integrating AI into its ERM (Enterprise Risk Management). What is the primary benefit of a 'Common Risk Taxonomy' for AI?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →You are assessing risk for an AI model that uses 'Transfer Learning'. What is the most critical risk to manage regarding the pre-trained base model?
Which THREE factors contribute to 'Data Quality Risk' during the training phase?
A firm is establishing an AI Governance Committee. Which TWO groups should be represented to ensure comprehensive oversight?
AI Risk Governance And Framework IntegrationmediumSee the answer and why each option is right or wrong →An organization is integrating AI risk into its existing ISO 31000 framework. How should the 'Risk Assessment' process be modified to account for AI-specific 'black box' issues?
AI Risk Governance And Framework IntegrationhardSee the answer and why each option is right or wrong →Which THREE items should be included in an AI 'Risk Assessment' report for a new project?
AI Risk Governance And Framework IntegrationhardSee the answer and why each option is right or wrong →You are performing a 'Model Drift' analysis. Which metric is most indicative of performance degradation without access to real-time ground truth?
When managing AI lifecycle risk for a model in a regulated industry, which artifact serves as the most important audit trail for the model's provenance?
Which of the following is a primary risk during the 'Deployment' stage of the AI lifecycle?