CRISC Information Technology and Security Practice Question
A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?
⚠ Common exam trap
CRISC often tests the distinction between AI/ML risk categories (bias, adversarial attacks, explainability, privacy), so candidates who pick explainability or privacy miss that the question is about unfair outcomes, which is bias.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Model bias
Model bias occurs when an AI/ML model produces systematically unfair outcomes against certain demographic groups, often because training data reflects historical discrimination or underrepresentation. In credit scoring, if the model learns from historical lending data that excluded or disadvantaged certain groups, it will replicate and even amplify that bias. This is the risk most directly associated with biased outcomes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Model bias
Why this is correct
Model bias is the AI/ML risk where training data or algorithm design produces systematically unfair outcomes for particular demographic groups. It directly matches the stem's concern about biased credit-scoring decisions against protected groups, distinguishing it from other risks such as drift, opacity or overfitting.
- ✗
Adversarial attacks
Why it's wrong here
Adversarial attacks involve deliberately crafted inputs that manipulate model predictions, not unintentional bias against demographic groups. It tempts because both are model-integrity concerns, and adversarial robustness would be the right focus when the threat is malicious actors attempting to evade or poison a credit-scoring model.
- ✗
Explainability requirements
Why it's wrong here
Explainability concerns understanding how a model reaches decisions, not whether those decisions discriminate against demographic groups. It tempts because opaque models can conceal bias, and explainability tooling would be the right focus when regulators demand justification of individual credit decisions rather than when the concern is discriminatory outcomes.
- ✗
Data privacy in AI training
Why it's wrong here
Data privacy addresses lawful handling and protection of personal training data, not discriminatory model outputs. It tempts because biased outcomes often stem from unrepresentative training data, and privacy controls would be correct when the concern is consent, retention or exposure of customer information used to train the model.
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.