CRISC Information Technology and Security Practice Question
An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?
⚠ Common exam trap
CRISC often tests whether candidates can distinguish the most significant regulatory risks from general operational or security risks, so the trap is selecting data privacy or compute cost when the question is specifically about a regulated credit decision where bias and explainability are the legally material concerns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Model bias causing discriminatory outcomes
Option A (Model bias causing discriminatory outcomes) is correct because credit approval is a legally regulated decision domain where biased models can produce discriminatory lending practices, violating fair-lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act, exposing the organization to enforcement actions and reputational harm. Option B (Model explainability for regulatory compliance) is correct because regulators in credit decisions require the ability to understand and justify adverse action reasons, typically under regulations like the Equal Credit Opportunity Act (ECOA) and the Fair Credit Reporting Act (FCRA), making explainability essential for compliance and auditability. Options C, D, and E, while relevant to AI/ML generally, are not the most significant risk considerations in this specific regulated credit-approval scenario: data privacy (C) matters but is secondary to fairness and explainability in lending regulation, high computational cost (D) is an operational efficiency concern rather than a regulatory risk, and adversarial attacks on training data (E) are a security concern that is less directly tied to the regulatory oversight governing credit decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Model bias causing discriminatory outcomes
Why this is correct
Discriminatory outcomes breach fair-lending legislation and expose the organisation to enforcement action and litigation. Bias arises from unrepresentative training data or proxy variables, so testing for disparate impact across protected groups is a governance control that directly addresses the stem's regulatory oversight constraint.
- ✓
Model explainability for regulatory compliance
Why this is correct
Credit decisions fall under fair-lending and model-risk rules, so regulators must be able to inspect how each decision was reached. Explainability techniques such as SHAP or surrogate models let the organisation justify adverse-action outcomes, directly satisfying the stem's regulatory oversight constraint rather than merely improving accuracy.
- ✗
Data privacy in AI training
Why it's wrong here
Data privacy is a genuine AI concern, yet for credit approval the regulator's focus falls on discriminatory outcomes, explainability and documented decision trails rather than training-data privacy alone. It is tempting because privacy regulation is prominent, and it would be the leading consideration for models processing sensitive health or biometric data.
- ✗
High computational cost of model retraining
Why it's wrong here
Retraining cost is a budget and resource concern, not a regulatory or decision-integrity risk, so it does not drive credit-approval oversight. It is tempting because compute spend is a genuine AI/ML governance topic, but that matters most in cost-optimisation scenarios rather than regulated lending decisions.
- ✗
Adversarial attacks on the training data
Why it's wrong here
Adversarial manipulation of training data is a real AI security issue, but in a regulated credit model the dominant risks are explainability, bias and auditability rather than data poisoning. It is tempting because poisoning attacks are a recognised threat class, and they would be the priority for fraud-detection or autonomous systems.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.