ISACA AI Audit practice questions
ISACA · AAIR · 300 questions
Original practice questions for ISACA AI Audit.
This course contains the use of artificial intelligence.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Domain 3: AI Model Risk Management · 53 questions
- A financial institution deploys a credit-scoring AI model. Six months after deployment, the model's Gini coefficient drops from 0.62 to 0.44. The risk team suspects the model has degraded but is unsure of the cause. Which action should be taken FIRST?
- An organization's model risk management team is performing validation on a neural network that classifies transaction fraud. The team cannot explain why specific transactions are flagged. Which validation technique should the team employ to address explainability requirements under SR 11-7?
- During an AI system audit, an auditor discovers that the organization lacks a formal model inventory. What is the MOST significant risk associated with the absence of a model inventory?
- A bank's AI model governance policy requires all high-risk models to undergo independent validation before production deployment. An internal validation team reports that the fraud detection model passes performance benchmarks. However, the team that built the model also performs ongoing monitoring. Which governance gap does this reveal?
- A data scientist reports that an AI model for customer churn prediction achieves 89% accuracy on the training set but only 67% on an independent holdout set. Which model risk does this MOST indicate?
- An AI model monitoring program reports that population stability index (PSI) values for several key input features have exceeded 0.25 over the past quarter. What action is MOST appropriate?
- During an AI audit, the team finds that an AI-based insurance underwriting model was retrained with new data but the new version was deployed without a change impact assessment or validation. What MOST accurately describes the governance failure?
- In an AI risk management context, what does 'concept drift' refer to?
- An organization is establishing its AI model validation program. Which activity is MOST important to include in independent validation of a predictive model?
- A bank's model risk officer is reviewing an AI model that predicts small business loan defaults. The model was trained on data from 2015–2019 and deployed in early 2020. During a post-deployment audit, performance has deteriorated sharply. The most plausible explanation is that the COVID-19 pandemic drastically changed default patterns. What type of model risk does this MOST represent?
- A model validation team is reviewing an AI scoring model and finds that the model developer used the full dataset to select features before splitting into training and test sets. What is the primary problem with this approach?
- An AI audit team is reviewing an MLOps pipeline for a recommendation model. The team discovers that model retraining is fully automated and that new model versions are automatically promoted to production if they exceed a certain accuracy threshold. Which control deficiency does this represent?
- An AI risk assessment reveals that a fraud detection model's performance varies significantly depending on which data engineer prepared the training dataset. Upon investigation, the team finds no standardized data preprocessing pipeline. What category of AI risk does this MOST represent?
- A model risk manager is creating a materiality threshold for AI model risk classification. Which factor MOST justifies classifying an AI model as 'high materiality'?
- Which MLOps control BEST ensures that only validated model versions are deployed to the production environment?
- A model validation team is assessing whether a gradient-boosted model used for anti-money laundering (AML) detection is stable. Which technique BEST evaluates the stability of model predictions to small changes in input data?
- An AI model for supply chain disruption prediction is retrained quarterly using recent data. After the latest retraining, the model's predictions become significantly more conservative, flagging 40% fewer disruptions than the previous version. Before promoting the new version, what validation step is MOST important?
- In AI governance, what does 'model lifecycle management' encompass?
- A major insurer uses an AI model to detect claims fraud. The model's recall for actual fraudulent claims is 72%, meaning 28% of real fraud goes undetected. The insurer's leadership argues this is acceptable because 'no model is perfect.' What should the AI risk manager consider when evaluating this performance level?
- An AI audit team reviews a reinforcement learning model deployed in an algorithmic trading system. The model executes trades autonomously within defined risk parameters. Which is the MOST significant governance risk specific to reinforcement learning models compared to supervised learning models?
- An organization is implementing its first AI model inventory. Which data element is MOST important to capture for each model to enable effective risk-based prioritization of validation and monitoring resources?
- An AI governance policy requires model owners to reassess AI risk when a 'trigger event' occurs. Which of the following would MOST appropriately constitute a trigger event requiring reassessment?
- Which statement BEST describes the primary difference between model validation and model monitoring?
- During an AI model audit, the auditor discovers that the model's predictions are disproportionately influenced by a single feature that accounts for 68% of total SHAP value contribution. What risk does this finding indicate?
- Under SR 11-7 guidance on model risk management, what is the key distinction between a 'model limitation' and a 'model error'?
- An AI model uses transaction metadata to classify whether an online purchase is likely fraudulent. The model was originally designed for credit card transactions but is now being applied to peer-to-peer digital currency transfers without modification. Which AI risk is MOST prominent?
- An AI model for underwriting commercial property insurance is found to have been developed using 10 years of historical data. The risk team notes that climate-related loss events have increased significantly in the last three years, accounting for 40% of recent losses. Which risk management action is MOST appropriate?
- An organization's AI model monitoring system shows stable AUC and F1 scores for a consumer lending model over 12 months. However, the risk team receives complaints from relationship managers that the model's recommendations are increasingly inconsistent with their expert judgment on similar cases. What does this discrepancy MOST suggest?
- A model risk manager is reviewing a newly developed credit risk model. According to SR 11-7 guidance, which activity represents the MINIMUM acceptable validation requirement before a model enters production?
- An MLOps team implements automated model retraining triggered by data drift detection. From a model risk management perspective, what control is MOST critical to include in this retraining pipeline?
- A model inventory for a large bank lists 400 models. Risk managers want to prioritize validation resources. Which factor should receive the HIGHEST weight in a model tiering framework?
- During model validation, the validator discovers that the model development team used the same dataset for both feature selection and model training, without a separate hold-out set. What risk does this introduce?
- A model risk officer receives a report showing that a production model's Gini coefficient has declined from 0.72 to 0.54 over 18 months. What action is MOST appropriate under standard model risk management practice?
- Which of the following BEST describes the purpose of a model use limitation in a model risk management framework?
- An organization wants to implement continuous model monitoring for a production AI system. Which combination of metrics provides the MOST comprehensive coverage of model health?
- Under SR 11-7, what distinguishes a 'model' from a 'tool' for purposes of model risk management scope?
- A risk team is implementing a data lineage tracking system for AI training data. Which risk does this control PRIMARILY address?
- A model validation team is challenged by a model owner who argues that an explainable AI technique (LIME) used during validation is itself imperfect and therefore the validation findings are invalid. How should the validation team respond?
- An organization implements a champion-challenger framework for its AI credit models. What is the PRIMARY risk management benefit of this approach?
- Which of the following model risk management controls is MOST effective at detecting gradual label drift in a supervised classification model?
- A model owner argues that a newly developed neural network model does not require formal model risk management treatment because it assists decisions but humans make the final call. How should a model risk officer respond?
- A financial institution's model risk team discovers that a third-party AI vendor has updated their credit scoring model without notification. What control should the model risk framework include to prevent this risk?
- An AI risk manager is reviewing an organization's process for handling AI system incidents. Which component is MOST critical to include in an AI incident response plan that differs from a traditional IT incident response plan?
- A model risk team is evaluating whether a new AI system constitutes a 'model' under SR 11-7 or a 'business tool.' The system applies rules-based logic developed by domain experts to route customer inquiries. What conclusion is MOST defensible?
- Which of the following controls BEST addresses the risk that an AI model vendor will discontinue the model or its API, leaving dependent business processes without a functioning system?
- A model risk team is reviewing a customer lifetime value prediction model. They find the model was developed using only customers who remained with the company for at least two years, excluding churned customers. What model risk does this introduce?
- Under SR 11-7, what is the MINIMUM recommended frequency for validating models classified as high risk due to their materiality to the institution?
- A model validation team challenges a model based on finding that its training error is significantly lower than validation error. What model risk does this finding indicate?
- A financial institution is building its first AI model inventory. Which attribute is MOST critical to capture for each model entry to support effective risk-tiering?
- A model risk officer reviews a vendor's documentation for a purchased AI model and finds no information about the training data's demographic composition. What risk management action is MOST appropriate?
- An AI model deployed for customer segmentation has been in production for three years. A risk review reveals no validation has occurred since initial deployment. Under SR 11-7 principles, what is the MOST appropriate immediate action?
- An AI risk manager is reviewing an organization's AI procurement process. The organization plans to use a cloud-hosted AI API from a major provider for sensitive HR decisions. Which risk requires the MOST specific contractual attention?
- A risk committee is reviewing an AI model that produces a continuous risk score for each loan applicant. The committee wants to ensure the model is well-calibrated. Which test BEST assesses calibration?
Domain 1: AI Risk Identification & Assessment · 49 questions
- An AI risk manager is evaluating a new computer vision model used to detect manufacturing defects. The model achieves 97% overall accuracy, but the risk manager is concerned about performance on rare defect types. Which metric BEST captures risk related to rare defect classes?
- A healthcare AI system predicts patient readmission risk. An audit reveals the model performs significantly worse for patients from low-income zip codes compared to high-income ones, though both groups are represented in the training data. What type of bias is MOST likely present?
- A risk assessment team discovers that an AI model used for employee performance reviews was trained using data from only one regional office, which is predominantly male. What is the PRIMARY risk this introduces?
- An AI audit team is reviewing a natural language processing model used to screen resumes. The team discovers the model assigns lower scores to resumes containing words statistically associated with women's colleges and female-dominated extracurricular activities. This is an example of which risk?
- An AI risk manager is prioritizing which AI models in a large enterprise portfolio require immediate attention. Which combination of factors should drive the HIGHEST risk rating?
- An organization's AI risk framework includes a requirement for 'AI system resilience.' Which risk scenario BEST tests AI system resilience?
- An insurance company's AI model for auto insurance pricing uses telematics data from policyholders' smartphones to calculate risk scores. The model was trained on data from early adopters of the telematics program, who skewed younger, more tech-savvy, and more safety-conscious than the general population. Now the model is applied to all new policyholders. What AI-specific risk does this deployment scenario create?
- An AI risk team is assessing a computer vision system used at airport security to flag prohibited items. The system flags passengers from certain ethnic backgrounds at a rate 2.3 times higher than the overall population, controlling for actual prohibited item carry rates. This finding is BEST described as:
- A compliance officer discovers that the organization's AI hiring tool was trained on application data where the offer/no-offer label was determined by the previous hiring manager, who had documented complaints of gender discrimination. Which data integrity issue is MOST critical?
- An AI model for predicting equipment failure in a nuclear facility is flagged for review because its training data was collected over only six months, during summer operations. The facility also operates during winter with significantly different temperature and load conditions. What risk does this introduce?
- An organization's AI risk team wants to assess the attack surface of an AI system before deployment. Which framework provides the MOST comprehensive vocabulary for cataloguing adversarial threats specific to AI and ML systems?
- An AI system generates personalized pricing for e-commerce customers. Regulatory investigators find that older customers consistently receive higher prices for identical products. The company argues the model uses purchase history and browsing behavior, not age, as inputs. What concept BEST describes the mechanism by which age discrimination could still occur?
- A multinational company uses a single AI model for credit underwriting across 40 countries. An AI risk assessment identifies that the model was trained primarily on North American and Western European data. Which risk is MOST significant for operations in sub-Saharan African markets?
- An AI governance audit finds that an organization's AI risk assessments are performed once at model inception and never updated. What is the MOST significant risk this practice creates?
- An AI system is trained to classify satellite images for urban planning applications. The system incorrectly classifies solar panels as rooftop HVAC units at a high rate. The training dataset contains 50,000 HVAC unit images and 200 solar panel images. Which risk does this illustrate?
- An AI tool used in a criminal justice risk assessment is found to assign substantially different recidivism risk scores to defendants with identical criminal histories when race is inferred from names. Which technical root cause MOST likely explains this finding?
- An AI system is used by a bank to recommend investment products to wealth management clients. During a model review, the team discovers the model consistently recommends higher-fee products to clients with lower financial literacy scores, regardless of suitability. Which risk does this MOST represent?
- An AI model used for clinical trial participant selection achieves excellent overall performance but the audit team discovers it excludes patients with multiple comorbidities at a disproportionately high rate. The model was trained on historically enrolled trial participants, who typically had fewer comorbidities. What AI risk does this BEST illustrate?
- A company uses an AI system to dynamically price ride-sharing services during periods of high demand. During a natural disaster evacuation, the system prices rides at 6x the normal rate, triggering public backlash. Which AI risk category does this MOST represent?
- An AI model used for automated content moderation on a social media platform has a false positive rate for hate speech detection that is three times higher for posts written in African American Vernacular English (AAVE) compared to Standard American English. What type of bias does this illustrate?
- An organization conducts an AI system risk assessment using a heat map that plots likelihood of harm against severity of harm. An AI model for internal employee scheduling scores 'low likelihood, high severity.' How should this risk be managed?
- An AI governance committee is evaluating whether to permit the use of synthetic training data generated by a generative AI model to supplement scarce real training data for a medical diagnosis AI. Which risk should receive the HIGHEST priority in this evaluation?
- An AI system used to screen loan applications for a community development financial institution (CDFI) rejects applications from applicants with thin credit files at a high rate. The CDFI's mission is specifically to serve underbanked populations who typically have thin credit files. What is the MOST appropriate AI risk management response?
- An AI system for automated email phishing detection incorrectly classifies legitimate vendor invoices as phishing attempts at a rate of 12%, causing operational disruptions. The security team defends the high false positive rate as necessary to maintain the system's 99.2% detection rate for actual phishing. How should the AI risk manager evaluate this trade-off?
- A risk analyst discovers that an AI-powered loan approval model produces significantly higher denial rates for applicants from zip codes with large minority populations. Which type of AI risk does this most directly represent?
- During a threat modeling exercise for an AI fraud detection system, the team identifies that an attacker could submit carefully crafted transactions designed to evade detection. What attack category does this represent?
- An AI system used for medical image analysis begins producing incorrect diagnoses six months after deployment despite unchanged inputs. Root cause analysis reveals the model's training data was collected from a different patient population. This scenario best illustrates which risk?
- A bank's AI credit scoring model was trained primarily on data from economically stable periods. Risk managers are concerned about performance during an economic downturn. Which assessment technique is MOST appropriate to evaluate this risk?
- Which of the following BEST describes the risk of model staleness in a deployed machine learning system?
- A threat actor gains access to a publicly available AI model's API and uses it to determine whether specific individuals' records were used in training. Which attack does this describe?
- An organization deploys an AI system to screen job applications. A risk assessment identifies that the model assigns lower scores to resumes containing terms associated with women's colleges. Which risk category does this represent?
- During a risk identification workshop for a new AI deployment, a risk manager proposes using a bow-tie analysis. What is the PRIMARY advantage of this technique for AI risk?
- A data scientist notices that a sentiment analysis model trained on product reviews performs well in testing but poorly on customer service transcripts. Which AI risk concept BEST explains this failure?
- An AI system used for public benefits eligibility determination denies benefits to 15% more applicants from rural areas compared to urban areas, despite similar economic profiles. The model was trained exclusively on urban data. What governance failure does this MOST directly represent?
- A risk manager reviewing an AI-powered insurance underwriting system notices that the model assigns lower premiums to customers whose web browsing activity suggests interest in healthy lifestyle content. Which risk does this MOST directly raise?
- An attacker with access to a company's AI model API submits thousands of carefully chosen queries to reconstruct the model's decision boundary and build a functional replica. Which attack type is this?
- A predictive maintenance AI system at a manufacturing facility fails to flag an imminent equipment failure that caused a production shutdown. Post-incident analysis finds the failure mode was underrepresented in training data. How should this risk be classified?
- A risk assessment team is evaluating an AI system that uses facial recognition to grant physical access to secure facilities. Beyond accuracy, which risk category deserves the MOST emphasis in the risk assessment for this use case?
- An AI risk analyst is preparing a risk register for a content recommendation system. The analyst identifies that the algorithm may create filter bubbles by repeatedly showing users content similar to what they have previously engaged with. How should this risk be categorized?
- An organization is developing an AI risk taxonomy. Which classification BEST organizes AI risks for comprehensive enterprise risk management integration?
- A risk committee is evaluating whether to deploy an AI system for automated debt collection communications. The system was trained primarily on historical communications from accounts that were successfully resolved. What dataset bias risk does this create?
- A retail bank's AI model for mortgage origination has been in production for 14 months. The risk team runs a quarterly performance review and notices the model's Gini coefficient has declined from 0.72 to 0.61. What action is MOST appropriate?
- An AI governance team is conducting a risk assessment of an AI system that scores job applicants for a technology company. Historical hiring data used for training reflects a decade of predominantly male hiring in technical roles. Which risk does this create beyond ordinary model error?
- A risk manager is evaluating an AI system that assigns individual risk scores to millions of customers daily. The system uses an ensemble of 47 models. Which risk does this level of complexity introduce that a simpler model would not?
- An organization's AI risk assessment identifies that a sentiment analysis model produces significantly different results when input text contains non-standard English dialects or code-switching. How should this risk be classified?
- During an AI risk assessment of a clinical decision support system, risk analysts debate whether the AI's recommendation errors are more harmful than equivalent errors by human clinicians. Which risk concept does this debate MOST engage?
- An adversary injects subtle, imperceptible perturbations into medical scan images before submitting them to a diagnostic AI system, causing the system to misclassify cancerous findings as benign. Which attack type does this represent?
- A risk manager identifies that an AI model used for real-time trading decisions has a 200-millisecond inference latency that occasionally spikes to 2,000 milliseconds under load. In this context, what risk does latency variability create?
- An AI risk practitioner is assessing the risks of deploying an AI summarization tool for legal documents. The tool occasionally omits material terms from contract summaries. Which risk category MOST specifically captures the downstream business consequence of this failure?
Domain 6: Emerging AI Risks · 48 questions
- During an AI governance review, an auditor finds that the organization uses an open-source LLM fine-tuned on proprietary customer data. The model weights are stored externally on a cloud provider's infrastructure. Which AI supply chain risk is MOST relevant?
- A company implements a generative AI chatbot for customer service. Users discover they can override the chatbot's safety guidelines by embedding instructions in customer support tickets. What attack vector does this represent?
- A manufacturing company deploys an agentic AI system that autonomously places orders with suppliers when inventory levels fall below a threshold. The system placed $2.3 million in orders incorrectly due to a sensor data error. Which control would MOST effectively prevent this type of incident?
- An attacker sends thousands of queries to a deployed machine learning API, recording the inputs and outputs. Over time, the attacker constructs a replica of the model. What type of attack is this?
- A large language model deployed as a customer service agent begins providing factually incorrect information about product warranties with high confidence. Which inherent LLM risk does this BEST illustrate?
- A penetration tester discovers that by appending a specific sequence of characters to any input, a content moderation AI model consistently fails to classify harmful content. This is an example of which AI security vulnerability?
- A company's AI risk team is asked to assess the risk of deploying a generative AI system for creating marketing copy. The legal team flags a concern about the system potentially reproducing copyrighted material from its training data. What is the MOST appropriate technical control to mitigate this risk?
- An organization's AI red team is tasked with finding vulnerabilities in an LLM-powered agent that has access to internal databases and can execute SQL queries. Which attack scenario represents the HIGHEST severity risk?
- An organization's AI risk committee is debating whether to implement a 'human-in-the-loop' or 'human-on-the-loop' oversight model for their AI-driven medical diagnosis support system. Which statement BEST describes the key risk difference between these two approaches?
- Which control is MOST effective at preventing training data poisoning in a federated learning environment where multiple hospital systems contribute patient data to a shared AI model?
- A cybersecurity team discovers that a competitor has released a near-identical version of their proprietary fraud detection model. The internal model was never publicly released. Which attack is the MOST likely explanation?
- A company is building an AI orchestration layer that coordinates multiple AI agents to complete complex tasks, including browsing the web, reading emails, and executing code. What is the MOST significant new risk category introduced by this multi-agent architecture?
- Which control BEST addresses the risk of unauthorized access to sensitive information when deploying an LLM with retrieval-augmented generation (RAG) connected to a corporate document repository?
- An agentic AI system is deployed to manage a company's cloud infrastructure. A red team test shows that by sending a crafted request to the AI system, an attacker can cause it to deprovision production servers. Which of the following controls BEST addresses this vulnerability?
- An AI deployment pipeline uses automated vulnerability scanning on the model container images before deployment. A security team lead argues this is sufficient security validation for the AI system. What does this approach FAIL to address?
- A pharmaceutical company is using an AI model to identify potential drug candidates from molecular structure data. The model was trained on published research and proprietary lab assay data. An AI risk assessment flags that the model may be unintentionally optimizing for patent-protected molecular configurations. Which risk does this represent?
- An AI risk manager discovers that a deployed sentiment analysis model was updated by the vendor to 'improve performance' without notifying the deploying organization. The model's change manifested as a shift in how it classified certain political language. Which AI supply chain risk does this represent?
- A large language model is used to generate summaries of customer calls for a financial services firm's complaint management system. Regulators request access to a specific customer's complaint records. The AI-generated summaries are available, but the original call recordings have been deleted per retention policy. What AI-specific governance risk does this scenario illustrate?
- A bank deploys an AI fraud detection model. After six months, the fraud team notes that the model's flagging rate has dropped by 40% while actual fraud losses have increased by 15%. Model performance metrics (AUC, precision) appear stable on the monitoring dashboard. How should this apparent contradiction be explained and addressed?
- A company is building an AI system that will access multiple enterprise systems (email, calendar, CRM, ERP) to autonomously complete tasks on behalf of employees. The CISO flags that the AI agent's access permissions are as broad as the highest-privileged user in the system. Which security principle is being violated?
- During a red team exercise for an enterprise AI system, the red team successfully causes the AI to reveal the system prompt by asking it to 'repeat all previous instructions.' What type of vulnerability does this represent, and what control should be implemented?
- An AI system generates automated responses to tax authority inquiries on behalf of a business. During testing, the AI confidently provides an incorrect statutory reference that could result in an underpayment of taxes. Which risk control framework element should be applied to prevent this from reaching regulators?
- A large language model deployed as a customer service chatbot occasionally generates factually incorrect responses presented with high confidence. Which emerging AI risk category does this BEST represent?
- An organization deploys an AI agent that autonomously browses the internet, reads emails, and executes code to complete tasks. A user instructs the agent to summarize a web page, but the page contains hidden text instructing the agent to exfiltrate all contacts. What attack does this illustrate?
- A risk manager is assessing risks specific to retrieval-augmented generation (RAG) systems. Which risk is MOST unique to RAG architectures compared to standard LLM deployments?
- A company is deploying a multi-agent AI system in which one AI model acts as an orchestrator that directs specialized sub-agents. Which risk is MOST elevated in this architecture compared to a single-model deployment?
- When assessing risks of a generative AI system used for marketing content creation, which risk requires the MOST urgent policy response from an intellectual property perspective?
- Which control BEST mitigates the risk that an autonomous AI agent will take irreversible actions with significant consequences before a human can intervene?
- A financial institution adopts a large language model to assist compliance analysts in reviewing suspicious activity reports (SARs). The model flags potential omissions in analyst-drafted SARs. Six months after deployment, analysts report they trust the model's flags completely and no longer apply independent judgment. What emerging AI risk has materialized?
- A large language model deployed in a legal research application generates a case citation that appears authoritative but does not exist. A lawyer relies on the citation in court documents. Which risk category does this PRIMARILY represent?
- An organization is implementing a generative AI system for internal knowledge management. Employees can ask the system questions and receive answers synthesized from company documents. Which security control is MOST critical to prevent data classification boundary violations?
- A security researcher demonstrates that by prefixing inputs to a customer service chatbot with 'Ignore previous instructions and instead...', the chatbot reveals its system prompt. What vulnerability does this exploit?
- A company is evaluating the risk profile of deploying an AI agent with tool-use capabilities (file system access, email sending, code execution). Which principle from agentic AI safety frameworks MOST reduces the blast radius of a compromised or hallucinating agent?
- An organization is assessing the risks of using a foundation model fine-tuned on proprietary data for customer interactions. Which emerging risk is MOST specific to fine-tuned models compared to using the base foundation model?
- A risk officer is preparing a board briefing on AI deepfake risks. Which business scenario represents the HIGHEST risk from synthetic media generation capabilities?
- Which of the following BEST characterizes the 'alignment problem' in the context of advanced AI risk?
- Which control MOST effectively prevents an AI model from being retrained on data that has been contaminated by a data poisoning attack?
- An AI risk manager is reviewing a new generative AI product that creates synthetic patient records for medical research. The product's vendor claims the synthetic records are 'fully anonymized' because they are AI-generated and not copied from real patient records. What is the PRIMARY risk assessment concern with this claim?
- A company is assessing the risk of deploying a large language model that may have been trained on copyrighted web content. Which risk requires IMMEDIATE legal review before production deployment?
- An organization has deployed an AI coding assistant for software developers. Security researchers report that the assistant occasionally suggests code with known vulnerabilities. What risk does this represent?
- A risk analyst is evaluating an AI system in which multiple LLM agents collaborate: a planning agent decomposes tasks, execution agents carry them out, and a critic agent reviews outputs. Which failure mode is MOST unique to this multi-agent collaborative architecture?
- An organization wants to evaluate an LLM's safety properties before deployment. Which evaluation methodology MOST directly tests whether the model can be manipulated into violating its safety guidelines?
- A risk team is assessing the AI supply chain risks of procuring a pre-trained foundation model from an open-source repository. Which risk is MOST difficult to mitigate after the model has been integrated into a production system?
- Which of the following BEST describes the risk management challenge posed by 'emergent capabilities' in large foundation models?
- An AI assistant deployed for internal employee use begins producing outputs that reference confidential merger discussions after being connected to the company's document management system. What type of AI risk does this represent?
- A risk officer is drafting an AI-specific addition to the organization's business continuity plan. Which scenario is MOST unique to AI system failures compared to traditional IT system failures?
- Which of the following BEST describes the risk introduced when an organization uses an AI model's output as a feature input to a second AI model in a pipeline?
- An organization's AI red team discovers that a deployed LLM can be made to ignore its system prompt and generate harmful outputs by prefixing requests with a specific multi-token sequence. What risk management response is MOST appropriate?
Domain 2: AI Governance Frameworks · 52 questions
- An organization is mapping its AI systems to the NIST AI Risk Management Framework (AI RMF). The team is determining which organizational units should own specific AI risk functions. Which AI RMF core function is PRIMARILY concerned with establishing accountability structures and policies?
- ISO/IEC 42001 is the international standard specifically addressing which domain?
- An AI governance committee is assessing which framework to adopt for managing AI-related risks alongside existing enterprise risk management. Which statement BEST describes how COBIT 2019 can be applied to AI governance?
- The OECD AI Principles include a principle requiring AI actors to be accountable for the proper functioning of AI systems. Which organizational mechanism BEST operationalizes this accountability principle?
- A governance committee is reviewing AI system risk classifications. An AI system schedules job interviews by ranking candidate profiles using a scoring algorithm. Under the EU AI Act Annex III, how should this system MOST likely be classified?
- An AI system governance review reveals that an AI model produces accurate predictions but uses features that encode protected characteristics through non-obvious proxies. What type of control should be implemented?
- An AI governance board is reviewing the organization's AI risk appetite statement. Which element MOST appropriately belongs in an AI-specific risk appetite statement?
- Which statement BEST describes the relationship between AI risk management and traditional enterprise risk management (ERM)?
- An organization adopts the NIST AI RMF MEASURE function. A key activity within MEASURE is quantifying AI risks. Which method BEST supports the quantification of AI trustworthiness characteristics?
- An organization developing AI systems for healthcare wants to align with the NIST AI RMF MAP function. Which activity is MOST aligned with the MAP function?
- Under the EU AI Act, a GPAI (General-Purpose AI) model is classified as having 'systemic risk' if it meets which criterion?
- Which element of the OECD AI Principles requires AI systems to function appropriately, safely, and securely across different situations and to have safeguards to minimize and address potential harms?
- A Chief Risk Officer is implementing an AI governance structure. She proposes that AI risk oversight be embedded within the existing Three Lines of Defense model. How should AI risk oversight MOST appropriately map to this model?
- An organization is evaluating whether to adopt ISO/IEC 42001 as its AI management system standard. A senior manager argues that the organization's existing ISO 27001 certification already covers AI systems. How should the AI risk manager respond?
- A board of directors is being briefed on AI risks. Which framing of AI risk MOST effectively connects AI risk to the board's existing fiduciary responsibilities?
- An AI product team argues that their machine learning model does not need governance oversight because it is a 'recommendation system,' not a decision-making system. How should the AI risk manager respond?
- A Chief Risk Officer is concerned that AI models are being deployed without adequate documentation of their limitations. Which policy control MOST directly addresses this concern?
- An AI governance team is reviewing whether their organization's AI development practices align with the 'accountability' principle of the OECD AI Principles. Which practice MOST demonstrates accountability alignment?
- An AI governance team is designing the oversight structure for the organization's AI systems. They want to apply proportionate oversight based on risk. Which framework characteristic of the EU AI Act's risk-tiered approach BEST guides this design?
- Under ISO/IEC 42001, what is the purpose of the 'AI system impact assessment'?
- The NIST AI RMF MANAGE function includes the activity of 'responding to and recovering from AI risks.' Which action BEST exemplifies this activity?
- A company's AI policy requires all AI systems to maintain a 'human override capability.' An AI system for automated invoice processing has a human override button that routes invoices to a human reviewer. However, the reviewer queue is always backlogged by more than 2,000 items, and 95% of invoiced items expire before a human reviews them. What governance gap does this represent?
- A financial institution is subject to both the EU AI Act and the Basel AI Risk Principles. A high-risk AI model used in credit risk management must comply with both frameworks. Which control would MOST effectively address requirements under both frameworks simultaneously?
- A multi-national company is deploying the same AI hiring model across operations in the United States, European Union, and Brazil. The AI risk team must ensure compliance with employment AI regulations in all jurisdictions. Which approach BEST manages cross-jurisdictional AI compliance risk?
- An AI governance committee is reviewing the organization's AI ethics principles and wants to align them with an internationally recognized framework. Which document provides the MOST widely referenced set of principles for trustworthy AI developed by a multilateral organization?
- A healthcare AI company is developing a model that predicts sepsis onset 6 hours before clinical presentation. The model will recommend prophylactic antibiotic administration when it detects high sepsis risk. What governance structure is MOST appropriate for this model given its clinical impact?
- Under the NIST AI Risk Management Framework (AI RMF), which core function is responsible for establishing organizational policies, accountability structures, and culture that support responsible AI use?
- An organization subject to the EU AI Act is deploying an AI system to evaluate employee performance for promotion decisions. Under the Act, how is this system likely classified?
- ISO/IEC 42001 requires organizations to establish an AI management system. Which element MOST distinguishes it from general information security management systems like ISO/IEC 27001?
- A financial institution uses the COBIT for AI framework to assess its AI governance maturity. The assessment reveals that AI-related risks are tracked informally by individual teams without enterprise-level visibility. Which maturity level does this MOST likely represent?
- Under the NIST AI RMF, the MAP function includes categorizing AI systems by their risk level. Which factor is LEAST relevant when categorizing AI risk in the MAP function?
- Which EU AI Act provision requires providers of general-purpose AI models with systemic risk to perform adversarial testing and notify the European AI Office of serious incidents?
- An AI governance committee is designing an accountability structure. Which principle from the OECD AI Principles BEST supports assigning clear responsibility for AI outcomes?
- A technology company asks its legal team to compare ISO/IEC 42001 and the NIST AI RMF for adoption. Which statement BEST describes a key structural difference between the two frameworks?
- A financial services firm's Chief AI Officer is presenting AI risks to the board. Which risk communication approach BEST conveys the significance of AI model risk to a non-technical board?
- Which component of the NIST AI RMF MEASURE function is MOST directly concerned with tracking AI risk over time after deployment?
- Under the EU AI Act, providers of high-risk AI systems must implement a quality management system. Which element is EXPLICITLY required in the quality management system?
- An organization adopting ISO/IEC 42001 as its AI management system standard wants to establish AI-specific objectives. Which statement BEST describes how AI objectives under ISO/IEC 42001 differ from general business objectives?
- A company's AI governance committee is evaluating whether to use COBIT for AI or the NIST AI RMF as its primary governance framework. Which factor MOST strongly favors COBIT for AI?
- Which of the following BEST describes the relationship between the NIST AI RMF Playbook and the core AI RMF document?
- A newly appointed Chief AI Risk Officer wants to establish a consistent enterprise-wide approach to AI risk appetite. Which artifact is MOST foundational for this purpose?
- An AI governance framework requires all deployed AI systems to maintain a 'model card.' Which information is MOST important to include in a model card for risk management purposes?
- An organization's AI governance framework requires that all AI systems have an 'AI System Owner' accountable for the system's lifecycle. A recently acquired subsidiary has 23 AI systems but has not assigned owners. What is the FIRST governance action the parent organization should take?
- An organization's AI policy states that AI systems must comply with 'applicable laws and regulations.' A risk manager notes this language is insufficient for an effective AI governance policy. What specific gap does this general language create?
- Under the NIST AI RMF, which subcategory of the GOVERN function addresses the development and use of AI systems in a manner consistent with the organization's values and applicable law?
- A multinational corporation subject to the EU AI Act is establishing an AI governance program. Which obligation applies to ALL providers of AI systems placed on the EU market, regardless of risk classification?
- An AI governance committee wants to assess organizational AI culture and awareness. Which NIST AI RMF function most directly addresses building organizational culture that supports trustworthy AI?
- A company is adopting ISO/IEC 42001 and needs to determine the scope of its AI management system. Which factor is MOST important when defining the scope boundary?
- The EU AI Act requires providers of high-risk AI systems to conduct a fundamental rights impact assessment. Which entity is PRIMARILY responsible for this assessment?
- A Chief Risk Officer is building an AI risk committee structure. Which governance body composition BEST ensures comprehensive oversight of AI risk?
- A risk analyst asks a model developer to explain why the AI rejected a specific insurance claim. The developer says the model is a 'black box' and individual predictions cannot be explained. From a governance perspective, what is the MOST appropriate organizational response?
- An AI governance audit of a multinational reveals that the organization has separate AI risk committees in Europe, North America, and Asia-Pacific that operate independently with no global coordination mechanism. Each region applies different risk thresholds, fairness standards, and approval criteria. What governance risk does this structure create?
Domain 5: Regulatory Compliance & Ethics · 48 questions
- Under the EU AI Act, a biometric categorization system used by law enforcement to classify individuals by political opinion would be classified as which risk tier?
- An organization processes personal data to train an AI model for targeted advertising. Under GDPR, which legal basis is MOST appropriate for this processing activity?
- Under the EU AI Act, which AI system category requires a Fundamental Rights Impact Assessment (FRIA) to be conducted by deployers?
- Which fairness metric measures whether a model's positive prediction rate is equal across demographic groups, regardless of actual outcomes?
- A GDPR Data Protection Officer reviews an AI system that uses automated profiling to determine insurance premiums. Which GDPR right is MOST directly implicated?
- An AI system used in parole decisions is challenged in court because it cannot provide the basis for individual recommendations. Which AI ethics principle is MOST at stake?
- A financial services firm uses an AI model to detect money laundering patterns. A new regulation requires that all automated suspicious activity reports (SARs) be explainable to the regulator. The current model is a deep neural network with no built-in explainability. Which approach presents the GREATEST risk to the firm?
- A retail bank is deploying an AI system that automatically denies credit card applications. Under ECOA and Regulation B, what notification requirement applies to each automated denial?
- An insurance company deploys a telematics-based AI model that sets auto insurance premiums based on real-time driving behavior. A regulator inquires about the model's compliance with the California Consumer Privacy Act (CCPA). Which CCPA concern is MOST relevant?
- An AI ethics board is reviewing an AI system that predicts student dropout risk in higher education. Students flagged as high dropout risk receive additional academic support. However, the AI risk team identifies that the model also shares flags with scholarship committees. Which ethical concern is MOST critical?
- An AI system generates loan modification recommendations for distressed borrowers. A fair lending audit reveals that the model recommends less favorable modification terms for borrowers in predominantly Black zip codes, even after controlling for credit score and loan-to-value ratio. Under which legal framework would this finding MOST likely be investigated?
- An organization's AI policy states that all AI systems processing sensitive personal data must conduct a Data Protection Impact Assessment (DPIA). An AI system analyzes employee emails to detect insider threats. Which DPIA finding would MOST likely require escalation to the supervisory authority under GDPR?
- A financial regulator issues guidance stating that AI models used in credit underwriting must be 'explainable' to regulators on request. A bank uses a deep learning model for underwriting and argues that SHAP explanations satisfy this requirement. The regulator disagrees. What is the regulator's MOST likely concern with SHAP-based explanations?
- An AI model for mortgage servicing determines which delinquent borrowers receive proactive outreach. The model has a 15% higher probability of recommending outreach for White borrowers than Black borrowers with identical financial profiles. Under which framework is this MOST likely a violation?
- An AI ethics review identifies that a social media content recommendation AI maximizes user engagement metrics, leading to increased consumption of emotionally charged and divisive content. Which ethical principle is MOST directly at issue?
- A technology company's legal team advises that their AI system must comply with the EU AI Act's transparency obligations for limited-risk AI systems. Which obligation is SPECIFICALLY required for AI systems that interact with natural persons (such as chatbots)?
- An AI model flags customers for churn risk and triggers automated retention offers. The model audit team discovers that customers who received retention offers have slightly lower churn rates, but wealthier customers receive more generous offers (higher discounts) because their historical lifetime value is used as a feature. What ethical concern should be prioritized in the audit report?
- An AI ethics committee is reviewing a proposal to use facial recognition AI to verify customer identity for bank account access. Which risk requires HIGHEST priority in the ethics review?
- A telecommunications company plans to use an AI model to predict customer lifetime value (CLV) and offer service upgrades preferentially to high-CLV customers. An AI risk team conducts a disparate impact assessment and finds that high-CLV customers are disproportionately White and high-income. What recommendation should the AI risk team make?
- An AI governance team is conducting a privacy risk assessment for a new AI-powered employee monitoring system that tracks keystrokes, screen content, and application usage to detect potential insider threats. Which privacy principle is MOST threatened?
- An AI model for predictive policing is challenged by civil liberties advocates because it uses historical arrest data to predict future crime. The primary AI ethics concern with this application is:
- An AI risk manager at a large insurance company receives a request to deploy an AI model that uses telematics data from smartphones to assess driver risk for auto insurance. The model uses 47 features derived from smartphone accelerometer and GPS data. Which privacy risk assessment step is MOST important before deployment?
- An AI audit team is reviewing the data governance practices for an AI model used in hiring. The team discovers that training data containing demographic information was retained after model development without documented justification. Under GDPR, which principle is MOST likely violated?
- An organization processes personal data using AI systems for targeted advertising. Under GDPR, what is the MOST important compliance requirement when using solely automated decision-making that produces legal or similarly significant effects on individuals?
- A data ethics officer is reviewing fairness metrics for a recidivism prediction model used in bail decisions. The model achieves equal accuracy across racial groups but has different false positive rates. Which fairness criterion is violated?
- A healthcare AI company is subject to both HIPAA and GDPR because it serves US and EU patients. When an AI model trained on patient data is later used in a new clinical setting, which compliance obligation is MOST critical to address FIRST?
- An AI ethics board is reviewing a proposed AI system that allocates organ transplant priority scores. Which ethical principle creates the MOST tension when designing this system?
- Under the EU AI Act, which of the following is classified as a prohibited AI practice?
- Which accountability mechanism BEST addresses the 'black box' problem for high-stakes AI decisions affecting individuals?
- A privacy regulator is investigating an organization's AI-based emotion recognition system deployed in a call center to assess customer satisfaction in real time. Under the EU AI Act, which provision is MOST directly applicable to this system?
- A company processes personal data using AI to make automated decisions about individual credit eligibility. Under GDPR, what right allows individuals to obtain a human review of the decision?
- An AI ethics review board is evaluating a predictive policing system. Which ethical framework would MOST strongly counsel against deployment of this system in high-risk communities?
- A company trains an AI model on customer support chat logs that include sensitive personal information. The company did not obtain explicit consent for AI training as a purpose. Under GDPR, which legal basis would MOST plausibly support this use?
- A data scientist proposes using 'equal accuracy' as the sole fairness metric for a healthcare AI triage system. Why is this approach INSUFFICIENT from a fairness perspective?
- Which of the following BEST describes the concept of 'meaningful human oversight' as applied to high-risk AI systems?
- An organization's AI ethics policy states that all AI systems must be 'transparent.' A business unit argues their proprietary fraud detection algorithm cannot be disclosed to fraud perpetrators without defeating its purpose. How should this tension be resolved?
- A bank's AI governance policy requires that all high-impact AI models undergo an ethical impact assessment before deployment. The assessment for a mortgage pricing model reveals that the model relies heavily on neighborhood characteristics that correlate with race. What is the MOST appropriate next step?
- An AI system is trained using data collected through a mobile app. Users agreed to terms of service but were not explicitly told their data would be used for AI model training. From a data ethics perspective, which principle is MOST directly implicated?
- An AI auditor needs to test whether an AI-assisted lending decision system satisfies the Equal Credit Opportunity Act (ECOA)'s adverse action notice requirement. What audit procedure is MOST direct?
- A privacy officer is reviewing an AI system that uses biometric data to authenticate employees for access to secure areas. Under GDPR, how is biometric data classified?
- An AI ethics review identifies that a student loan refinancing model assigns lower interest rates to graduates of highly-ranked universities. Which ethical concern does this MOST directly raise?
- A company's AI ethics policy requires that AI systems affecting individuals must be contestable. In practice, what does effective contestability require?
- Under the GDPR, when an organization uses AI for solely automated profiling that significantly affects individuals, which principle MOST directly requires the organization to be able to demonstrate lawfulness and proper safeguards to the supervisory authority?
- An AI risk practitioner is evaluating AI systems under the lens of 'responsible AI.' Which of the following formulations BEST captures the intersection of ethics and risk management in responsible AI?
- A hospital is considering deploying an AI triage system that would prioritize emergency room patients based on predicted clinical outcomes. From an ethical standpoint, which consideration is MOST critical before deployment?
- A government agency is considering using AI to automatically flag welfare benefit applications for fraud investigation. Which combination of risks requires the MOST urgent policy and governance attention before deployment?
- A technology vendor markets an AI system capable of predicting employees' 'flight risk' using behavioral data including keystrokes, email metadata, and application usage. Which risk is MOST significant for an employer considering deploying this system?
- An organization is developing an AI ethics review process. At which stage of the AI development lifecycle should ethics review occur to be MOST effective?
Domain 4: AI Audit & Assurance · 50 questions
- An AI auditor is designing a testing protocol for a loan underwriting model. Which approach BEST demonstrates that the model does not violate fair lending laws by using protected characteristics as proxies?
- An AI auditor is asked to evaluate the robustness of a recommendation system used in a streaming platform. Which test would BEST assess the model's vulnerability to adversarial manipulation?
- When conducting an AI system audit, which document provides the MOST essential baseline for assessing whether an AI system is operating within its intended scope?
- An organization wants to create an AI audit trail that satisfies regulatory requirements. Which data should be captured at minimum in the audit log for each AI decision?
- A CISO asks the AI risk team to assess the risks of using a third-party AI vendor for employee performance evaluation. Which due diligence element is MOST critical from an AI risk perspective?
- An AI model used for predicting hospital no-shows achieves 78% accuracy overall, but the AI risk team discovers it has a false negative rate of 35% for elderly patients. What action is MOST appropriate?
- An AI risk team is reviewing a third-party vendor's AI model. The vendor provides performance metrics but refuses to share training data, model architecture, or validation methodology. How should the team assess this situation?
- An AI audit program is being developed for a large bank. Which sequence of activities represents the CORRECT logical order for conducting an AI model audit?
- An AI model's validation report notes that the model performs well overall but fails on a specific edge case: when all optional fields in the input form are left blank. In an AI audit, how should this finding be classified?
- An AI auditor reviewing a sentiment analysis model used for customer complaint triage discovers that the model consistently misclassifies complaints written in informal language, slang, or non-standard spelling. This primarily impacts low-income and younger customers. What audit finding should be documented?
- A risk officer conducts a vendor assessment for a third-party AI fraud detection system. The vendor claims the model has been independently audited. Which follow-up question is MOST important?
- A healthcare organization is auditing an AI clinical decision support system. The auditors want to verify that the system was developed following responsible AI principles. Which documentation artifact provides the STRONGEST evidence that bias was assessed during development?
- An AI system for public benefits eligibility determination is suspected of denying benefits to eligible applicants at a higher rate than similar manual processes. Which AI audit procedure BEST assesses this concern?
- An organization is preparing its first AI audit program. The Chief Audit Executive asks what skills AI auditors need that traditional IT auditors may lack. Which capability is MOST uniquely required for AI auditing?
- A risk manager is reviewing an organization's AI incident response plan. Which element is MOST critical to include specifically for AI-related incidents that would not necessarily be required in a traditional cybersecurity incident response plan?
- An internal AI audit team at a bank is evaluating the scope of their AI model audit universe. A business unit argues that their rule-based credit scoring system, which was built by data scientists using statistical analysis, should be excluded because it is 'not really AI.' How should the audit team respond?
- An internal AI audit finds that a customer service AI model was promoted to production based solely on a business unit manager's sign-off, bypassing the formal validation process. The model governance policy requires independent validation for all customer-facing AI. Which audit finding classification is MOST appropriate?
- A risk committee is reviewing an AI model used to score job applicants for a technology company. The model was trained on profiles of historically successful employees, the majority of whom are male. The model's top scoring threshold accepts 28% of male applicants and only 14% of female applicants. Under the EEOC's uniform guidelines and the 4/5ths rule, what is the correct assessment?
- An auditor is reviewing the model validation report for a natural language processing model used in automated contract review. The validation report shows high performance on the vendor's internal test set but the deploying organization has not conducted its own independent testing. What is the MOST significant validation gap?
- During an internal AI audit, the team finds that a document summarization model deployed for legal discovery support occasionally omits key sentences from legal documents when the documents contain complex multi-clause sentences. What type of AI risk does this MOST represent, and what is the appropriate audit finding?
- An AI audit team is testing a credit decision model for stability. They create 1,000 synthetic applicant profiles that differ from real applicants by only one feature at a time and compare predicted scores. What technique is this?
- An AI auditor is reviewing evidence that an organization's AI model governance practices comply with their stated policy. Which audit evidence is MOST persuasive for demonstrating that model validation independence is maintained?
- An AI product team is developing a generative AI system that will produce patient education materials for a hospital. The team proposes releasing the system without formal validation because 'it's just generating text, not making medical decisions.' How should the AI risk manager respond?
- An AI system used by a government agency to assess eligibility for public housing produces systematically lower scores for families with non-English surnames. The agency's AI vendor claims the model does not use ethnicity or national origin as input features. Which investigation approach would BEST determine whether discrimination is occurring?
- Which element of the AI audit report is MOST important for ensuring that the organization's leadership can take informed corrective action following an AI audit?
- During an AI audit of a digital health platform, the auditor discovers that the AI model's outputs are stored in a non-auditable database with no query history, and logs are overwritten every 48 hours. What is the PRIMARY audit concern?
- An AI model audit team wants to verify that a model's published performance metrics accurately reflect its real-world performance. The model was built and evaluated by the same team. Which validation approach provides the STRONGEST evidence of real-world performance?
- An internal AI audit team is planning an audit of a natural language processing system used for contract review. Which approach BEST ensures audit coverage of model bias risk?
- During an AI system audit, the auditor wants to assess whether a training dataset used for a customer churn model is representative of the current customer population. Which audit procedure is MOST appropriate?
- An AI auditor is reviewing an organization's AI governance documentation. Which document type provides the STRONGEST evidence that an AI system's risks have been formally identified and accepted by accountable management?
- An audit of an AI-assisted underwriting system reveals that the model outputs a probability score, but underwriters must document their reasoning only when they override the model's recommendation. What control weakness does this reveal?
- When auditing a machine learning pipeline, which activity in the data preprocessing stage poses the HIGHEST risk of introducing systematic bias into the model?
- An AI auditor uses counterfactual testing during an audit of a hiring algorithm. Which of the following BEST describes what this testing technique reveals?
- An AI audit report identifies a finding that an organization lacks a documented AI model inventory. Under which audit reporting criterion should this finding be classified?
- An AI audit team is reviewing an organization's process for decommissioning retired AI models. Which risk is MOST critical to address in the decommissioning process?
- An AI auditor is assessing an organization's AI training data governance. The auditor finds that data scientists can modify training datasets without requiring documented approval. Which audit finding does this represent?
- When conducting an AI system audit, what is the MOST important reason to review the model's feature engineering documentation?
- An AI audit of a document classification system reveals the model achieves 95% accuracy overall but only 71% accuracy on documents from a specific business unit. What audit follow-up action is MOST appropriate?
- Which of the following BEST describes an adversarial test (red team exercise) in the context of AI system auditing?
- An AI auditor reviewing a model's post-deployment monitoring program finds that alerts are configured only for API error rates and latency. What significant monitoring gap does this reveal?
- Which principle BEST guides an auditor assessing whether an AI system's outputs are sufficiently explainable for the use case?
- During an AI model audit, the auditor requests access to the model's training data but is told it was deleted after training to reduce storage costs. What risk does this create for ongoing model governance?
- An AI audit plan is being developed for an organization that uses AI in three high-risk areas: credit underwriting, anti-money laundering transaction monitoring, and HR performance evaluation. Resources are insufficient to fully audit all three in one cycle. How should audit prioritization be determined?
- An AI audit team is evaluating the adequacy of a model's governance documentation. Which document would BEST provide evidence that a model was reviewed and approved for production use by an independent party?
- During an AI system audit, the auditor discovers that model outputs are reviewed by humans before being acted upon, but the human reviewers are processing 800 cases per day — far exceeding what one person could meaningfully review. What audit finding does this represent?
- An AI auditor is testing an AI model's robustness as part of an assurance engagement. Which test BEST evaluates the model's stability under minor input perturbations?
- When auditing an AI system's data pipeline, the auditor discovers that the final training dataset has a much higher proportion of positive class labels than the actual population. What risk does this create?
- An AI auditor is examining an organization's AI incident log. The log contains 47 entries over 12 months, all classified as 'minor.' The auditor interviews business units and discovers several significant AI failures that were not reported. What control failure does this reveal?
- Which of the following BEST describes the purpose of a 'bias bounty' program for a deployed AI system?
- A financial regulator asks a bank to explain why its AI credit model denied a specific customer's application. The model is a deep neural network with 50 layers. Which approach BEST satisfies the regulator's request while remaining technically honest?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.