Courseiva

CRISC Information Technology and Security Practice Question

An organization is implementing an AI/ML model for credit approval decisions subject to regulatory oversight. Which TWO of the following are the most significant risk considerations?

⚠ Common exam trap

CRISC often tests whether candidates can distinguish the most significant regulatory risks from general operational or security risks, so the trap is selecting data privacy or compute cost when the question is specifically about a regulated credit decision where bias and explainability are the legally material concerns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Model bias causing discriminatory outcomes

Option A (Model bias causing discriminatory outcomes) is correct because credit approval is a legally regulated decision domain where biased models can produce discriminatory lending practices, violating fair-lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act, exposing the organization to enforcement actions and reputational harm. Option B (Model explainability for regulatory compliance) is correct because regulators in credit decisions require the ability to understand and justify adverse action reasons, typically under regulations like the Equal Credit Opportunity Act (ECOA) and the Fair Credit Reporting Act (FCRA), making explainability essential for compliance and auditability. Options C, D, and E, while relevant to AI/ML generally, are not the most significant risk considerations in this specific regulated credit-approval scenario: data privacy (C) matters but is secondary to fairness and explainability in lending regulation, high computational cost (D) is an operational efficiency concern rather than a regulatory risk, and adversarial attacks on training data (E) are a security concern that is less directly tied to the regulatory oversight governing credit decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Model bias causing discriminatory outcomes

    Why this is correct

    Discriminatory outcomes breach fair-lending legislation and expose the organisation to enforcement action and litigation. Bias arises from unrepresentative training data or proxy variables, so testing for disparate impact across protected groups is a governance control that directly addresses the stem's regulatory oversight constraint.

  • ✓

    Model explainability for regulatory compliance

    Why this is correct

    Credit decisions fall under fair-lending and model-risk rules, so regulators must be able to inspect how each decision was reached. Explainability techniques such as SHAP or surrogate models let the organisation justify adverse-action outcomes, directly satisfying the stem's regulatory oversight constraint rather than merely improving accuracy.

  • ✗

    Data privacy in AI training

    Why it's wrong here

    Data privacy is a genuine AI concern, yet for credit approval the regulator's focus falls on discriminatory outcomes, explainability and documented decision trails rather than training-data privacy alone. It is tempting because privacy regulation is prominent, and it would be the leading consideration for models processing sensitive health or biometric data.

  • ✗

    High computational cost of model retraining

    Why it's wrong here

    Retraining cost is a budget and resource concern, not a regulatory or decision-integrity risk, so it does not drive credit-approval oversight. It is tempting because compute spend is a genuine AI/ML governance topic, but that matters most in cost-optimisation scenarios rather than regulated lending decisions.

  • ✗

    Adversarial attacks on the training data

    Why it's wrong here

    Adversarial manipulation of training data is a real AI security issue, but in a regulated credit model the dominant risks are explainability, bias and auditability rather than data poisoning. It is tempting because poisoning attacks are a recognised threat class, and they would be the priority for fraud-detection or autonomous systems.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.