Courseiva

ISACA Advanced in AI Risk (AAIR) (AAIR) (AAIR) — Questions 76150

199 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQhard

An organization discovers that an AI model has learned a bias from training data. Per the AI Risk framework, what should be the immediate priority of the Governance function?

A.Suspend the model's usage and conduct a formal root cause analysis.
B.Wait for the quarterly board report to inform the board.
C.Fire the AI development team.
D.Retrain the model on the same data set to see if it fixes itself.
AnswerA

Suspending the model prevents further harm while an investigation occurs.

Why this answer

Stopping the risk is the priority, followed by a root cause analysis to adjust the governance or training processes.

77
Multi-Selecteasy

Which TWO items are considered 'AI Infrastructure' risks?

Select 2 answers
A.The color of the server room walls
B.The type of desk chair in the office
C.The number of windows in the office
D.Unauthorized access to the model environment
E.System uptime/availability
AnswersD, E

Security breach is a major infrastructure risk.

Why this answer

Infrastructure risks focus on availability and security of the compute environment.

78
MCQmedium

Which metric is useful for measuring the 'Efficiency' of an AI risk program?

A.Number of emails sent
B.Total weight of the hardware
C.Number of meetings held
D.Time to complete a risk assessment for new models
AnswerD

This measures the speed and process maturity of the risk program.

Why this answer

The time required to complete a risk assessment for a new model tracks how streamlined the governance process is.

79
MCQmedium

What is the primary risk associated with 'Shadow AI' in an organization?

A.It makes the network run slower.
B.It costs too much.
C.It makes the developers work too hard.
D.It bypasses established AI risk governance and compliance controls.
AnswerD

The lack of governance is the core risk of shadow IT/AI.

Why this answer

Shadow AI refers to AI tools deployed without the knowledge or oversight of the governance team, creating invisible, unmanaged risks.

80
MCQmedium

You are performing a 'Model Drift' analysis. Which metric is most indicative of performance degradation without access to real-time ground truth?

A.The number of concurrent API requests.
B.The memory consumption of the container.
C.Kullback-Leibler (KL) Divergence between training and inference feature distributions.
D.Model accuracy on historical data.
AnswerC

KL divergence measures how much the current input distribution has drifted from the training distribution.

Why this answer

Statistical distribution shifts (like KL Divergence) in input data serve as a proxy for performance degradation.

81
MCQhard

You are auditing a model's lifecycle and discover that the training data distribution changes every time the model retrains. What is the biggest risk here?

A.The model will require more compute power.
B.The model will be too secure.
C.The model will be too small.
D.The model's behavior will be inconsistent and difficult to reproduce, making debugging impossible.
AnswerD

Lack of reproducibility is a critical failure in AI governance and risk management.

Why this answer

Non-deterministic training data results in unstable models where performance can fluctuate unpredictably.

82
Multi-Selecthard

Which THREE components must be included in an AI Model 'Control Framework' to ensure effective risk mitigation?

Select 3 answers
A.Hardware power usage tracking.
B.Access management controls restricting model usage.
C.Public disclosure of all model architecture details.
D.Manual approval gates for model deployment.
E.Automated version control for model training code.
AnswersB, D, E

Limiting who can trigger or modify models is a foundational security control.

Why this answer

Controls must cover the lifecycle, from development integrity to ongoing monitoring and access management.

83
Multi-Selecthard

Which TWO items are considered 'AI Model Artifacts' that should be kept for audit purposes?

Select 2 answers
A.The training dataset version
B.The lunch menu for the developers
C.Model hyperparameters and architecture configuration
D.The name of the company's favorite mascot
E.The local weather report from last week
AnswersA, C

Data provenance is essential for auditing.

Why this answer

Documentation and training parameters are crucial for reproducing and auditing model behavior.

84
MCQhard

You are assessing risk for an AI model that uses 'Transfer Learning'. What is the most critical risk to manage regarding the pre-trained base model?

A.The base model cannot be used with custom datasets.
B.The base model may have been trained on data that contains inherent, unidentifiable biases.
C.The base model will always run out of memory.
D.The base model requires a proprietary operating system.
AnswerB

Inherited bias is the most critical and hardest-to-detect risk in transfer learning.

Why this answer

Transfer learning risks include the inheritance of latent biases from the pre-trained weights.

85
MCQeasy

Which department is primarily responsible for ensuring AI models comply with data protection regulations like GDPR?

A.The Sales force.
B.The Accounting Department.
C.The Compliance/Legal Department and the Data Protection Officer.
D.The Janitorial staff.
AnswerC

These functions are tasked with regulatory alignment and legal risk management.

Why this answer

The Data Protection Officer (DPO) and Legal/Compliance teams are responsible for regulatory compliance.

86
Multi-Selectmedium

When designing an AI Risk Committee, which TWO of the following roles are essential for ensuring a holistic view of risk?

Select 2 answers
A.Chief Legal Counsel.
B.Office Assistant.
C.Lead Data Scientist.
D.Social Media Manager.
E.Facilities Manager.
AnswersA, C

Essential for regulatory and compliance guidance.

Why this answer

Legal ensures compliance with evolving regulations, while Data Science/Engineering provides the technical understanding of how the model functions.

87
MCQhard

In the context of AI model risk management, what is the role of an 'AI Model Inventory' within the governance framework?

A.To track model metadata, risk ratings, and owners for oversight and audit purposes.
B.To store the actual training data sets for backup.
C.To limit the number of AI developers in the company.
D.To serve as a marketing catalog for external clients.
AnswerA

An inventory provides the visibility necessary for effective governance and audit.

Why this answer

An inventory is the foundational requirement for knowing what models exist, their criticality, and their risk profile.

88
Multi-Selecteasy

Which TWO teams should define the 'Risk Appetite' for a new AI project?

Select 2 answers
A.Senior Leadership/Business Owners
B.The Risk Management/Compliance Office
C.The local weather station
D.The office landscaping team
E.The company's mascot
AnswersA, B

They decide the acceptable risk for business goals.

Why this answer

Risk appetite is a strategic decision involving both business leaders (who own the risk) and risk managers (who define the framework).

89
MCQeasy

Which document defines the 'AI Risk Appetite' for an organization?

A.The Employee Training Manual.
B.The IT Service Catalog.
C.The AI Project Status Report.
D.The AI Risk Appetite Statement.
AnswerD

The Appetite Statement is the official policy document for risk tolerance.

Why this answer

The AI Risk Appetite Statement is the document approved by the Board that defines the risk tolerance for AI activities.

90
MCQhard

You are auditing an AI project. Which finding suggests a failure in AI risk management governance?

A.The model was trained on historical data.
B.No individual is designated as the accountable owner for the model's production outcomes.
C.The team uses a cloud-based GPU provider.
D.The model has a 2% prediction error rate.
AnswerB

Lack of accountability is a fundamental failure of AI governance.

Why this answer

If no one is designated as accountable for the model's outcomes, the governance structure is non-existent or dysfunctional.

91
Multi-Selecteasy

Which TWO tasks are part of the 'AI Risk Assessment' process?

Select 2 answers
A.Evaluating the likelihood and impact of identified risks
B.Choosing the font color for the dashboard
C.Writing marketing copy for the AI product
D.Identifying potential AI-related threats
E.Hiring new office staff
AnswersA, D

Quantifying risk is the core of the assessment.

Why this answer

Risk assessment involves identifying risks and then evaluating them based on impact/likelihood.

92
MCQmedium

Which document is the most appropriate starting point for an AI Risk assessment for a new machine learning project?

A.The marketing slide deck for the AI feature.
B.The technical API documentation.
C.An AI Risk Assessment Protocol/Template.
D.The project budget spreadsheet.
AnswerC

A formal protocol ensures that all systemic risks are considered at the start of the project.

Why this answer

A Data Protection Impact Assessment (DPIA) or an AI-specific Risk Assessment protocol is the formal process for identifying risks early.

93
Multi-Selecthard

Which THREE considerations must be addressed when designing a 'Training' pipeline to minimize data quality risk?

Select 3 answers
A.Ensuring the training server has a high-end monitor.
B.Recording full data lineage for every training run.
C.Using a specific brand of server hardware.
D.Automated outlier detection to identify noisy or corrupted records.
E.Implementing strict schema validation to catch data type errors.
AnswersB, D, E

Necessary for auditability and debugging.

Why this answer

Data lineage, schema validation, and outlier detection are standard data engineering controls.

94
MCQmedium

Which action should be taken if a model's performance consistently falls outside the 'Risk Appetite' threshold?

A.Only inform the IT team
B.Take the model offline for remediation
C.Ignore the result as it is just a statistical outlier
D.Increase the threshold to match current performance
AnswerB

Stopping the risk-producing activity is the correct risk management response.

Why this answer

Once a threshold is breached, the model should be taken offline or placed under remediation until it is back within acceptable risk parameters.

95
Multi-Selecthard

Which THREE activities are part of the 'AI Risk Management' lifecycle?

Select 3 answers
A.Manual approval of all company emails.
B.Risk Treatment/Mitigation.
C.Risk Identification.
D.Ongoing Monitoring and Review.
E.Writing press releases about AI success.
AnswersB, C, D

Treating identified risks is central to the lifecycle.

Why this answer

The cycle consists of identification, assessment/treatment, and ongoing monitoring.

96
MCQeasy

During the 'Training' phase, why is 'Data Splitting' (train/validation/test) crucial for risk management?

A.To save disk space on the server.
B.To increase the training speed.
C.To evaluate the model's generalization capabilities and mitigate the risk of overfitting.
D.To make the model easier to read.
AnswerC

Without a hold-out test set, one cannot know if the model will perform well in the real world.

Why this answer

Data splitting prevents overfitting and provides an unbiased estimate of the model's performance on unseen data.

97
MCQeasy

A multinational corporation is establishing an AI Risk Governance Committee. Who should chair this committee to ensure alignment with enterprise-wide risk appetite?

A.The Chief Technology Officer (CTO).
B.The Chief Risk Officer (CRO).
C.The Lead AI Data Scientist.
D.The Head of Marketing.
AnswerB

The CRO ensures that AI risks are mapped to the enterprise risk appetite.

Why this answer

The Chief Risk Officer (CRO) or equivalent enterprise risk lead ensures AI risk is treated as a component of overall enterprise risk.

98
MCQhard

You are configuring the NIST AI Risk Management Framework (AI RMF) 'Govern' function for a high-risk autonomous system. Which activity specifically fulfills the 'Govern' function's requirement for establishing accountability?

A.Performing a red-teaming exercise on the model inputs.
B.Configuring automated PII scrubbing in the data pipeline.
C.Reviewing the training dataset for bias using statistical sampling.
D.Formalizing the AI System Model Owner role with defined risk acceptance and oversight accountabilities.
AnswerD

This directly addresses the requirement for organizational accountability within the Govern function.

Why this answer

NIST AI RMF 'Govern' function involves establishing the culture and processes for AI risk management, including clear definition of roles and accountability. Documenting the designated 'Model Owner' and their specific risk accountabilities is a core component.

99
MCQmedium

A practitioner is managing AI risk in a CI/CD pipeline. What should be the final gate before model promotion to production?

A.Increasing the memory of the production server.
B.Updating the project's documentation.
C.Automated performance validation against a hold-out test set with defined threshold gates.
D.A peer review of the training code.
AnswerC

This ensures the model satisfies quantitative quality criteria before reaching production.

Why this answer

Automated validation of performance metrics against a 'golden dataset' ensures the model meets the required threshold.

100
MCQeasy

Why is 'AI Literacy' for the board of directors a key component of AI Governance?

A.To allow directors to code their own AI models.
B.To enable effective decision-making regarding AI adoption and risk management.
C.To replace the need for the Chief Risk Officer.
D.To reduce the cost of IT infrastructure.
AnswerB

Literacy ensures directors understand the implications of their governance decisions.

Why this answer

Directors must understand AI risks and benefits to provide informed oversight and define the organization's risk appetite.

101
MCQeasy

Which activity is a foundational requirement for building a sustainable AI risk program?

A.Creating an enterprise AI inventory
B.Signing contracts with AI vendors
C.Automating all model retraining cycles
D.Purchasing third-party AI auditing tools
AnswerA

Identifying and logging all AI assets is the mandatory first step.

Why this answer

An AI inventory is the starting point for any risk program, as you cannot manage risks for models you haven't identified.

102
MCQeasy

When drafting an AI risk policy, which element must be defined to provide clear guidance on acceptable AI outcomes?

A.AI model training data source list
B.Vendor procurement list
C.Technical architecture diagram
D.Risk appetite statement
AnswerD

The risk appetite defines the level of risk the organization is willing to accept for AI initiatives.

Why this answer

Risk appetite statements provide the boundary of acceptable risk, which is foundational to any AI risk management program.

103
MCQhard

A firm is using a 'Red Teaming' exercise for its AI model. How does this fit into the AI Risk Governance framework?

A.It serves as a validation technique to identify vulnerabilities and edge-case risks.
B.It is the only requirement for model governance.
C.It is a marketing exercise to show off model robustness.
D.It should be performed by the same team that developed the model.
E.It is the only requirement for model governance.
AnswerA

Proactive testing (Red Teaming) is a key control in advanced AI risk frameworks.

Why this answer

Red Teaming is an advanced 'Measure' or 'Verification' activity designed to find weaknesses, bias, or safety risks in a model.

104
MCQhard

An organization is using 'AI Model Monitoring' to track 'Concept Drift'. Why is this a risk governance issue?

A.It indicates the model is running out of memory.
B.It is not a risk issue; it is a maintenance issue.
C.It signals that the model's predictive accuracy is degrading due to changes in the data context.
D.It shows that the model is 'thinking' too slowly.
AnswerC

Drift is a performance risk that requires management intervention.

Why this answer

Concept drift indicates that the model is no longer operating in the environment it was trained for, leading to inaccurate predictions and potential risk.

105
MCQmedium

An enterprise is establishing its AI Governance Committee. Which stakeholder is most critical to include to ensure alignment between AI technical capabilities and the organization's enterprise risk appetite?

A.Head of Legal
B.Chief Information Security Officer
C.Chief Risk Officer
D.Lead Data Scientist
AnswerC

The CRO is responsible for enterprise-wide risk strategy, making them the primary stakeholder for AI risk appetite.

Why this answer

The Chief Risk Officer (CRO) ensures that AI development aligns with the risk appetite and risk management framework, acting as the bridge between technical execution and business oversight.

106
MCQeasy

Which phase of the AI lifecycle is most critical for initial risk mitigation?

A.Deployment.
B.Decommissioning.
C.Model Monitoring.
D.Design and Problem Formulation.
AnswerD

Addressing risks at the design stage is the most efficient way to ensure safety and ethical alignment.

Why this answer

Risk mitigation is most effective during the Design phase, before the model is developed, to avoid costly re-engineering.

107
MCQeasy

Which document is the primary reference for defining an organization's AI Risk Governance structure?

A.The IT hardware inventory report.
B.The employee handbook.
C.The AI Governance Charter/Policy.
D.The AI project development backlog.
AnswerC

The Charter outlines the authority, membership, and mandates of the governance body.

Why this answer

The AI Governance Policy or Charter establishes the roles, responsibilities, and decision-making authorities for AI risk.

108
MCQhard

When deploying a generative AI model, what 'Governance Control' is most critical for preventing the generation of harmful/inappropriate content?

A.Increase the number of GPUs to make it faster.
B.Only use the model in an internal environment without internet access.
C.Implement output guardrails and moderation layers.
D.Allow users to provide feedback directly to the model.
AnswerC

Guardrails are the standard control for managing generative AI risk.

Why this answer

Guardrails are technical controls placed on top of models to intercept and filter output, which is a vital part of risk governance.

109
Multi-Selectmedium

When building an AI Governance framework, which TWO of the following are essential for ensuring enterprise adoption?

Select 2 answers
A.Providing mandatory 40-hour weekly training sessions.
B.Integration with existing GRC and software delivery workflows.
C.Establishing a clear, collaborative engagement model between risk teams and developers.
D.Using only manual, spreadsheet-based tracking.
E.Requiring all developers to be lawyers.
AnswersB, C

Integration makes governance feel like part of the work, not an add-on.

Why this answer

Adoption requires alignment with existing processes and clear communication.

110
MCQeasy

An organization is integrating AI risk into its enterprise risk management (ERM) framework. What is the first step in this integration process?

A.Assign a Chief AI Officer.
B.Identify and classify all AI applications by criticality and risk level.
C.Install automated model monitoring tools.
D.Create an AI acceptable use policy.
AnswerB

Establishing a baseline inventory and classification is mandatory for effective risk management integration.

Why this answer

Before integrating, the organization must understand the AI scope and criticality relative to existing assets.

111
MCQhard

An organization is evaluating 'Model Risk Management' (MRM) tools for its AI governance. What is the most critical feature to look for to ensure compliance with external regulatory requirements?

A.Automatic social media integration.
B.Comprehensive audit trails of model lineage, versions, and validation results.
C.The ability to run models on mobile devices.
D.The ability to add custom skins to the UI.
AnswerB

Regulatory requirements focus on transparency and evidence of validation.

Why this answer

Audit trails and model lineage are critical for meeting regulatory transparency and accountability standards.

112
Multi-Selectmedium

Which TWO of the following techniques help mitigate bias in the AI lifecycle?

Select 2 answers
A.Switching the programming language to Java.
B.Reducing the frequency of model monitoring.
C.Conducting fairness audits using specialized metrics (e.g., Disparate Impact).
D.Sourcing training data from diverse, representative populations.
E.Increasing the number of features in the model.
AnswersC, D

Provides quantitative evidence of bias.

Why this answer

Diverse data sourcing and fairness evaluation are standard methods for bias mitigation.

113
MCQhard

A project lead argues that AI model performance metrics alone are sufficient for risk management. Why is this incorrect?

A.They change too quickly to report
B.They are too difficult to calculate for small models
C.They are too subjective
D.They do not capture social and compliance risk dimensions
AnswerD

AI risk management requires a holistic view that includes non-technical factors.

Why this answer

Performance metrics do not account for external risks such as legal exposure, compliance violations, or social impact.

114
Multi-Selectmedium

Which TWO of the following scenarios represent 'Data Quality Risk'?

Select 2 answers
A.Training data is from a 5-year-old dataset that is no longer representative.
B.The model is deployed on a slow network.
C.The model is written in a new programming language.
D.Training data features have inconsistent units (e.g., mixed meters and feet).
E.The model uses a popular open-source library.
AnswersA, D

Lack of temporal relevance renders the data low-quality for current needs.

Why this answer

Inconsistent formatting and lack of temporal relevance are clear data quality issues.

115
Multi-Selecthard

Which THREE actions should be taken when integrating AI risk into the broader ERM (Enterprise Risk Management) framework?

Select 3 answers
A.Outsource all AI risk management to a third-party consultant.
B.Establish aligned risk scoring criteria across all business functions.
C.Prohibit all AI initiatives that carry any inherent risk.
D.Define a common risk taxonomy that includes AI-specific concepts like bias and drift.
E.Ensure that AI risk owners report into the same governance channels as other risk owners.
AnswersB, D, E

Standardized criteria allow for accurate prioritization across the organization.

Why this answer

Standardizing risk language, establishing clear reporting lines, and aligning risk criteria are essential for ERM integration.

116
MCQmedium

You are establishing an AI risk appetite framework using the NIST AI RMF. Which action best ensures alignment between AI innovation velocity and organizational risk tolerance?

A.Set a static threshold for model accuracy at 95% across all AI projects.
B.Define risk tolerance levels based on potential impact to human rights and safety, differentiated by model deployment context.
C.Require all AI teams to use exclusively open-source models to mitigate vendor-related risks.
D.Delegate all AI risk acceptance decisions to the lead data scientist.
AnswerB

Differentiating by context is a core requirement of the NIST AI RMF for tailored risk management.

Why this answer

Aligning risk appetite requires mapping technical AI performance metrics to business-level risk registers, ensuring that performance trade-offs are explicitly approved by stakeholders.

117
MCQmedium

How should an 'AI Ethics Committee' interact with the 'AI Risk Governance' body?

A.The Ethics Committee should be responsible for coding the AI.
B.The Ethics Committee should have final veto power over all projects.
C.The Ethics Committee should serve as an advisory body to the governance framework.
D.The Ethics Committee should replace the Risk Governance body.
AnswerC

Advisory support ensures that human and ethical factors are considered in risk decisions.

Why this answer

The Ethics Committee provides advisory, values-based guidance, while the Governance body maintains decision-making authority for risk.

118
MCQhard

When setting up an AI risk monitoring dashboard, what is the most important consideration for ensuring executive buy-in?

A.Map AI performance metrics to business impact indicators like customer churn or operational downtime.
B.Include the number of GPU hours utilized.
C.Display the raw training error rates.
D.Show a comparison of the organization's AI progress against competitors.
AnswerA

Linking technical risk to business outcomes is essential for executive decision-making.

Why this answer

Executives need to see how AI risk affects business outcomes (e.g., financial impact, reputation) rather than just technical performance.

119
MCQhard

When managing AI lifecycle risk for a model in a regulated industry, which artifact serves as the most important audit trail for the model's provenance?

A.The user access logs for the dashboard.
B.The model's current latency metrics.
C.The cloud provider's billing statement.
D.The end-to-end model lineage and version control logs.
AnswerD

Lineage logs document exactly how a model was built, providing the trail necessary for regulatory audits.

Why this answer

Model lineage/provenance trackers record the exact data versions and training parameters used for a specific model version.

120
MCQhard

During a board-level review, a bank needs to demonstrate the effectiveness of its AI Risk Governance. Which metric should be presented to the board to align with the 'Accountability' principle of the AI RMF?

A.The total computational cost of running the models.
B.The percentage of AI models with documented, independent model risk management (MRM) validation.
C.The number of lines of code written for the AI model.
D.The frequency of model retraining cycles.
AnswerB

Independent MRM validation is the industry standard for demonstrating institutional accountability.

Why this answer

Board oversight requires metrics on accountability, such as the auditability of model decision-making trails.

121
MCQeasy

Which stage of the AI lifecycle should risk management activities begin?

A.When the budget is exhausted
B.After the model is fully deployed
C.During the design and requirements phase
D.Only when a bug is reported
AnswerC

Early integration is key to effective and cost-efficient risk management.

Why this answer

Risk management must be integrated at the beginning (Design/Requirement) to avoid costly redesigns later.

122
MCQhard

When configuring the Microsoft Purview AI hub for risk management, which setting must be enabled to ensure AI prompt logs are captured for enterprise risk reporting?

A.Enable Audit (Premium)
B.Set up Data Loss Prevention (DLP) policies
C.Enable sensitivity labels
D.Configure Microsoft Purview AI activity logging
AnswerD

This setting directly captures prompt interactions for audit logs.

Why this answer

Microsoft Purview's AI hub requires activity logging to be enabled to audit interactions with generative AI applications.

123
MCQmedium

You are integrating AI risk into the NIST Risk Management Framework (RMF). Which step requires an explicit evaluation of AI model lineage and data provenance to satisfy the 'Govern' function?

A.Step 2: Select controls
B.Step 1: Categorize system
C.Continuous Monitoring phase
D.Governance mapping during 'Govern' function analysis
AnswerD

The NIST AI RMF emphasizes establishing governance early by tracking provenance and lineage.

Why this answer

The NIST AI RMF 'Govern' function prioritizes understanding the provenance and lineage to establish accountability and transparency.

124
Multi-Selectmedium

The board requires a new reporting structure for AI risk. Which TWO of the following should be included in the quarterly AI Risk Report to effectively communicate risk posture?

Select 2 answers
A.The raw output from the model's most recent training iteration.
B.The daily CPU and memory metrics for the inference clusters.
C.The status of the AI risk control roadmap and effectiveness of implemented mitigations.
D.A list of all individual model parameters and weights.
E.An overview of current AI-related residual risks exceeding the organization's defined risk appetite.
AnswersC, E

This provides insight into the maturity of the risk management program.

Why this answer

Board reports need to focus on strategic risk alignment and the efficacy of the oversight process, specifically tracking the risk management pipeline and significant residual risks.

125
MCQmedium

An organization is updating its risk appetite statement for AI. Which specific element should be addressed to manage the 'hallucination' risk of LLMs?

A.Set a performance goal to reduce the model parameter count.
B.Require human-in-the-loop for any AI-generated output used in customer-facing content.
C.Increase the frequency of periodic penetration testing.
D.Limit the training dataset to under 10GB.
AnswerB

Human-in-the-loop is the primary control for mitigating the impact of generative AI hallucinations.

Why this answer

Establishing clear boundaries for where generative AI is acceptable versus prohibited is a key aspect of risk appetite.

126
MCQmedium

When coordinating AI risk across a global organization, why is it critical to include local legal counsel in the AI steering committee?

A.To audit the training datasets for copyright infringement.
B.To handle administrative tasks for the committee.
C.To interpret the varied regulatory landscapes in different operational regions.
D.To approve the technical architecture of the AI models.
AnswerC

Local counsel ensures that global AI strategies do not conflict with regional legal requirements.

Why this answer

AI regulations, such as the EU AI Act, differ significantly by jurisdiction, making local legal expertise essential for compliance risk management.

127
MCQmedium

What is the key purpose of the 'Govern' function in the NIST AI RMF?

A.To troubleshoot hardware issues.
B.To establish the organizational culture, policy, and procedures for AI risk management.
C.To define the marketing strategy for the AI products.
D.To code the AI algorithms.
AnswerB

Governance is about the rules, culture, and oversight of AI activities.

Why this answer

The 'Govern' function focuses on the culture, policies, and structures that foster a risk-aware AI lifecycle.

128
MCQhard

Why is 'Model Validation' (distinct from testing) essential in an AI Governance framework?

A.To ensure the developers have followed the coding standards.
B.To save money on cloud hosting.
C.To provide independent assurance that the model performs as expected and within risk thresholds.
D.To speed up the coding process.
AnswerC

Independence is the defining feature of validation vs testing.

Why this answer

Validation is the independent verification that a model meets its intended purpose and risk performance requirements.

129
MCQmedium

What is the primary purpose of an 'AI Risk Dashboard' for executive leadership?

A.To replace the need for an AI ethics committee
B.To provide raw model logs to the public
C.To monitor individual developer productivity
D.To provide high-level visibility into AI risk posture and trends
AnswerD

Dashboards facilitate decision-making by summarizing complex risks.

Why this answer

Dashboards allow leadership to see aggregated risk trends across the enterprise, not just individual project metrics.

130
Multi-Selectmedium

Which TWO metrics are standard in 'Monitoring' for identifying performance-related AI risks?

Select 2 answers
A.The number of lines of documentation.
B.Inference request latency.
C.The color of the deployment dashboard.
D.Prediction error rate (or failure rate).
E.The total number of servers available.
AnswersB, D

High latency can impact user experience or business processes.

Why this answer

Latency and error rates are the primary operational indicators of model performance risk.

131
MCQmedium

Which documentation is necessary to provide to auditors for an AI system?

A.A list of all employees who attended a conference
B.The login credentials for the production environment
C.The model card or model documentation
D.The complete source code without comments
AnswerC

Model cards document performance, limitations, and use cases, which are key for auditing.

Why this answer

A model card provides the necessary metadata, performance limitations, and intended use cases required for auditability.

132
MCQmedium

A firm is integrating AI into its ERM (Enterprise Risk Management). What is the primary benefit of a 'Common Risk Taxonomy' for AI?

A.It forces all AI models to be identical.
B.It ensures consistent risk identification, communication, and reporting across the organization.
C.It makes AI code easier to write.
D.It eliminates the need for risk assessments.
AnswerB

Consistency is vital for managing risk at scale.

Why this answer

A common taxonomy ensures that AI risk is understood and communicated consistently across the enterprise.

133
MCQmedium

An organization is establishing an AI governance framework. Which approach is most effective for aligning AI risk appetite with enterprise-wide risk management (ERM)?

A.Map AI-specific risk metrics to existing enterprise risk categories like operational, financial, and reputational risk.
B.Establish a top-down mandate that ignores business unit input to ensure uniformity.
C.Focus solely on technical model performance metrics to define the organizational risk appetite.
D.Create a separate AI-specific risk register that operates independently of the corporate risk register.
AnswerA

Mapping ensures AI risk is treated as an extension of existing enterprise risks.

Why this answer

Integrating AI risk appetite into the existing ERM framework ensures consistency and avoids silos.

134
MCQmedium

A team is designing an AI lifecycle monitoring system. Which metric is most effective for detecting 'Out-of-Distribution' (OOD) risks?

A.Anomaly scores derived from the model's embedding space or activation layers.
B.Total number of users accessing the model.
C.Average request latency.
D.The number of lines of code in the model file.
AnswerA

Inputs that produce unusual activations in the internal layers suggest the model is processing data it doesn't recognize.

Why this answer

OOD detection identifies inputs that are fundamentally different from the distribution the model was trained on.

135
MCQmedium

An organization is considering outsourcing its AI development. How should the 'AI Risk Governance' policy be adjusted for third-party vendors?

A.Include mandatory audit rights, model validation requirements, and risk-sharing clauses in the vendor contract.
B.Assume that the vendor's own governance is sufficient.
C.Only evaluate the vendor for financial stability.
D.Exclude outsourced AI from the internal risk assessment.
AnswerA

Vendor oversight is a critical part of a robust AI governance strategy.

Why this answer

Third-party risk management must include audit rights and clear accountability for the vendor's models.

136
Multi-Selecthard

Which THREE components must be included in an AI Risk Register to satisfy ISO/IEC 42001 requirements?

Select 3 answers
A.Hardware procurement schedules
B.Technical documentation of model architecture
C.Identification of relevant stakeholders
D.Assessment of AI risk levels (likelihood and impact)
E.AI system description and intended use
AnswersC, D, E

ISO 42001 emphasizes stakeholder communication and consultation.

Why this answer

ISO 42001 requires systematic risk identification, analysis, and treatment planning.

137
Multi-Selecthard

Which THREE factors contribute to 'Data Quality Risk' during the training phase?

Select 3 answers
A.Incomplete datasets with many missing values.
B.Systematic errors in the target label annotations.
C.The model is too large for the GPU memory.
D.Selection bias in the training set creation process.
E.Using the wrong cloud vendor.
AnswersA, B, D

Missing data leads to unreliable predictions.

Why this answer

Incomplete data, selection bias, and incorrect labeling all directly degrade the model's foundation.

138
MCQhard

You are managing AI supply chain risk. Which control is most critical for third-party AI models?

A.Requiring a documented 'AI Bill of Materials' to understand data lineage and model provenance.
B.Conducting a manual audit of the vendor's source code.
C.Requiring the vendor to submit a monthly performance report.
D.Setting a limit on the number of third-party vendors allowed.
AnswerA

An AI BOM (or equivalent documentation) is essential for assessing third-party model risk.

Why this answer

Vendor/Model transparency (Software Bill of Materials for AI) is critical for understanding dependencies and hidden risks in black-box models.

139
MCQmedium

What is the primary risk of 'Model Complexity' in the context of the AI lifecycle?

A.The model is too fast for the hardware.
B.It becomes increasingly difficult to interpret decisions and perform root cause analysis during incidents.
C.The model will always produce the same result.
D.It forces the team to use more expensive software licenses.
AnswerB

Complexity reduces the explainability needed for risk verification.

Why this answer

Extremely complex models (e.g., deep neural networks) are often 'black boxes', making them hard to interpret and verify.

140
MCQeasy

Which AI lifecycle stage is most susceptible to the risk of 'data leakage' where training data inadvertently contains information from the future/target?

A.Model monitoring phase.
B.Model decommission phase.
C.Deployment phase.
D.Data preparation and training phase.
AnswerD

This is where features are created and datasets are split, making it the primary site for leakage risk.

Why this answer

Data leakage typically occurs during the data preparation and feature engineering stages of the AI lifecycle.

141
MCQmedium

During a board meeting, the Chief Risk Officer needs to present AI model performance trends. Which metric is most critical for board-level reporting?

A.Data scientists' training hours per quarter
B.Computational resource utilization percentage
C.Model latency in milliseconds
D.Frequency and severity of model drift incidents
AnswerD

This metric highlights the stability and risk exposure of the models.

Why this answer

The frequency and severity of model drift incidents are direct indicators of operational and reputational risk, which are board-level concerns.

142
MCQmedium

To ensure cross-functional coordination, you are designing a workflow for AI incident reporting. Which group should be the first point of contact upon detecting an AI model bias issue?

A.AI Governance/Ethics Committee
B.IT Help Desk
C.Customer Support
D.External Regulators
AnswerA

This body is designed to oversee and resolve AI-specific operational risks such as model bias.

Why this answer

The AI Governance team or AI Ethics office is tasked with immediate triage of AI-specific risks before escalation to legal or IT operations.

143
MCQhard

An organization is integrating AI risk into its existing ISO 31000 framework. How should the 'Risk Assessment' process be modified to account for AI-specific 'black box' issues?

A.Remove the risk identification step, as AI risks are too unpredictable.
B.Replace the qualitative assessment with a purely quantitative financial impact model.
C.Add a model explainability and interpretability assessment step to the process.
D.Delegate all risk assessments to the external software vendor.
AnswerC

Explainability is a key AI risk control that ensures transparency in decision-making.

Why this answer

Inclusion of model explainability assessments is necessary to address the opacity inherent in deep learning models.

144
Multi-Selecthard

Which TWO strategies are recommended for 'Mitigating' AI model bias?

Select 2 answers
A.Removing all data from the database
B.Asking the user to manually fix the bias
C.Applying fairness constraints during model training
D.Ignoring the bias and hoping it goes away
E.Training on more diverse and representative datasets
AnswersC, E

Fairness algorithms directly mitigate bias during the build phase.

Why this answer

Mitigation involves both pre-processing (data) and in-processing (training) techniques.

145
MCQmedium

An organization is using a centralized AI Governance structure. What is the biggest risk of this approach compared to a decentralized one?

A.Higher infrastructure costs.
B.Lack of standardized policy.
C.Operational bottlenecks and delayed AI project timelines.
D.Increased risk of shadow AI.
AnswerC

Centralized oversight teams often become overburdened, slowing down delivery.

Why this answer

Centralization can create 'bottlenecks' that slow down innovation and delay deployment.

146
MCQmedium

A bank's AI Governance policy requires a 'bias test' for all customer-facing models. What is the most important element to document in the audit trail?

A.The number of hours the test took to run.
B.The test methodology, criteria for success, and the specific mitigation steps taken.
C.The salary of the testers.
D.The name of the software used for the test.
AnswerB

This provides the 'proof' of due diligence and governance compliance.

Why this answer

Documenting the bias test methodology and results is essential to demonstrate due diligence to regulators.

147
MCQhard

If an AI model relies on an open-source library that is found to have a security vulnerability, who is responsible for managing this risk?

A.The government regulators
B.The AI Risk Manager and Security team
C.The library's author
D.The public at large
AnswerB

Collaborative risk management is needed to address the dependency vulnerability.

Why this answer

The AI Risk Manager, working with the security team, must assess the risk and ensure the library is updated or the dependency is mitigated.

148
MCQmedium

When reporting to the Board, what is the best way to present 'AI Risk'?

A.State that AI is completely safe and requires no oversight.
B.Provide a list of all model parameters.
C.Link AI risks to overall business impact, strategic goals, and current risk appetite.
D.Give a 4-hour technical lecture on deep learning.
AnswerC

Strategic context allows the Board to make governance decisions.

Why this answer

Risk should be linked to strategic objectives and the organization's appetite to ensure the Board understands the impact.

149
MCQeasy

What is the primary risk objective of 'Model Versioning' in the AI lifecycle?

A.To prevent unauthorized users from viewing the code.
B.To reduce the amount of disk space used.
C.To increase the model's speed in production.
D.To ensure auditability, reproducibility, and the ability to roll back to a known stable state.
AnswerD

Versioning provides the governance needed to manage changes securely.

Why this answer

Version control is essential for reproducibility and rollback, minimizing the risk of unrecoverable failures.

150
MCQhard

What is the 'Accountability' principle in the NIST AI RMF intended to address?

A.Ensuring the AI can explain itself.
B.Ensuring that there is clear ownership and responsibility for AI system performance and safety.
C.Making sure the model is free of bugs.
D.Ensuring that the AI system is fast.
AnswerB

Accountability focuses on who is responsible for the system's impact.

Why this answer

Accountability ensures that individuals or teams are responsible for the outcomes of AI systems, preventing a 'blame-free' environment for AI failures.

Page 1

Page 2 of 3

Page 3

All pages