Courseiva

CRISC Information Technology and Security Practice Question

A bank is considering adopting artificial intelligence for credit scoring. The risk manager identifies that the AI model might produce biased outcomes against certain demographic groups. Which AI/ML risk is most directly associated with this concern?

⚠ Common exam trap

CRISC often tests the distinction between AI/ML risk categories (bias, adversarial attacks, explainability, privacy), so candidates who pick explainability or privacy miss that the question is about unfair outcomes, which is bias.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Model bias

Model bias occurs when an AI/ML model produces systematically unfair outcomes against certain demographic groups, often because training data reflects historical discrimination or underrepresentation. In credit scoring, if the model learns from historical lending data that excluded or disadvantaged certain groups, it will replicate and even amplify that bias. This is the risk most directly associated with biased outcomes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Model bias

    Why this is correct

    Model bias is the AI/ML risk where training data or algorithm design produces systematically unfair outcomes for particular demographic groups. It directly matches the stem's concern about biased credit-scoring decisions against protected groups, distinguishing it from other risks such as drift, opacity or overfitting.

  • ✗

    Adversarial attacks

    Why it's wrong here

    Adversarial attacks involve deliberately crafted inputs that manipulate model predictions, not unintentional bias against demographic groups. It tempts because both are model-integrity concerns, and adversarial robustness would be the right focus when the threat is malicious actors attempting to evade or poison a credit-scoring model.

  • ✗

    Explainability requirements

    Why it's wrong here

    Explainability concerns understanding how a model reaches decisions, not whether those decisions discriminate against demographic groups. It tempts because opaque models can conceal bias, and explainability tooling would be the right focus when regulators demand justification of individual credit decisions rather than when the concern is discriminatory outcomes.

  • ✗

    Data privacy in AI training

    Why it's wrong here

    Data privacy addresses lawful handling and protection of personal training data, not discriminatory model outputs. It tempts because biased outcomes often stem from unrepresentative training data, and privacy controls would be correct when the concern is consent, retention or exposure of customer information used to train the model.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.