Domain 2: AI Governance Frameworks
ISACA AI Audit · 52 questions
- An organization is mapping its AI systems to the NIST AI Risk Management Framework (AI RMF). The team is determining which organizational units should own specific AI risk functions. Which AI RMF core function is PRIMARILY concerned with establishing accountability structures and policies?
- ISO/IEC 42001 is the international standard specifically addressing which domain?
- An AI governance committee is assessing which framework to adopt for managing AI-related risks alongside existing enterprise risk management. Which statement BEST describes how COBIT 2019 can be applied to AI governance?
- The OECD AI Principles include a principle requiring AI actors to be accountable for the proper functioning of AI systems. Which organizational mechanism BEST operationalizes this accountability principle?
- A governance committee is reviewing AI system risk classifications. An AI system schedules job interviews by ranking candidate profiles using a scoring algorithm. Under the EU AI Act Annex III, how should this system MOST likely be classified?
- An AI system governance review reveals that an AI model produces accurate predictions but uses features that encode protected characteristics through non-obvious proxies. What type of control should be implemented?
- An AI governance board is reviewing the organization's AI risk appetite statement. Which element MOST appropriately belongs in an AI-specific risk appetite statement?
- Which statement BEST describes the relationship between AI risk management and traditional enterprise risk management (ERM)?
- An organization adopts the NIST AI RMF MEASURE function. A key activity within MEASURE is quantifying AI risks. Which method BEST supports the quantification of AI trustworthiness characteristics?
- An organization developing AI systems for healthcare wants to align with the NIST AI RMF MAP function. Which activity is MOST aligned with the MAP function?
- Under the EU AI Act, a GPAI (General-Purpose AI) model is classified as having 'systemic risk' if it meets which criterion?
- Which element of the OECD AI Principles requires AI systems to function appropriately, safely, and securely across different situations and to have safeguards to minimize and address potential harms?
- A Chief Risk Officer is implementing an AI governance structure. She proposes that AI risk oversight be embedded within the existing Three Lines of Defense model. How should AI risk oversight MOST appropriately map to this model?
- An organization is evaluating whether to adopt ISO/IEC 42001 as its AI management system standard. A senior manager argues that the organization's existing ISO 27001 certification already covers AI systems. How should the AI risk manager respond?
- A board of directors is being briefed on AI risks. Which framing of AI risk MOST effectively connects AI risk to the board's existing fiduciary responsibilities?
- An AI product team argues that their machine learning model does not need governance oversight because it is a 'recommendation system,' not a decision-making system. How should the AI risk manager respond?
- A Chief Risk Officer is concerned that AI models are being deployed without adequate documentation of their limitations. Which policy control MOST directly addresses this concern?
- An AI governance team is reviewing whether their organization's AI development practices align with the 'accountability' principle of the OECD AI Principles. Which practice MOST demonstrates accountability alignment?
- An AI governance team is designing the oversight structure for the organization's AI systems. They want to apply proportionate oversight based on risk. Which framework characteristic of the EU AI Act's risk-tiered approach BEST guides this design?
- Under ISO/IEC 42001, what is the purpose of the 'AI system impact assessment'?
- The NIST AI RMF MANAGE function includes the activity of 'responding to and recovering from AI risks.' Which action BEST exemplifies this activity?
- A company's AI policy requires all AI systems to maintain a 'human override capability.' An AI system for automated invoice processing has a human override button that routes invoices to a human reviewer. However, the reviewer queue is always backlogged by more than 2,000 items, and 95% of invoiced items expire before a human reviews them. What governance gap does this represent?
- A financial institution is subject to both the EU AI Act and the Basel AI Risk Principles. A high-risk AI model used in credit risk management must comply with both frameworks. Which control would MOST effectively address requirements under both frameworks simultaneously?
- A multi-national company is deploying the same AI hiring model across operations in the United States, European Union, and Brazil. The AI risk team must ensure compliance with employment AI regulations in all jurisdictions. Which approach BEST manages cross-jurisdictional AI compliance risk?
- An AI governance committee is reviewing the organization's AI ethics principles and wants to align them with an internationally recognized framework. Which document provides the MOST widely referenced set of principles for trustworthy AI developed by a multilateral organization?
- A healthcare AI company is developing a model that predicts sepsis onset 6 hours before clinical presentation. The model will recommend prophylactic antibiotic administration when it detects high sepsis risk. What governance structure is MOST appropriate for this model given its clinical impact?
- Under the NIST AI Risk Management Framework (AI RMF), which core function is responsible for establishing organizational policies, accountability structures, and culture that support responsible AI use?
- An organization subject to the EU AI Act is deploying an AI system to evaluate employee performance for promotion decisions. Under the Act, how is this system likely classified?
- ISO/IEC 42001 requires organizations to establish an AI management system. Which element MOST distinguishes it from general information security management systems like ISO/IEC 27001?
- A financial institution uses the COBIT for AI framework to assess its AI governance maturity. The assessment reveals that AI-related risks are tracked informally by individual teams without enterprise-level visibility. Which maturity level does this MOST likely represent?
- Under the NIST AI RMF, the MAP function includes categorizing AI systems by their risk level. Which factor is LEAST relevant when categorizing AI risk in the MAP function?
- Which EU AI Act provision requires providers of general-purpose AI models with systemic risk to perform adversarial testing and notify the European AI Office of serious incidents?
- An AI governance committee is designing an accountability structure. Which principle from the OECD AI Principles BEST supports assigning clear responsibility for AI outcomes?
- A technology company asks its legal team to compare ISO/IEC 42001 and the NIST AI RMF for adoption. Which statement BEST describes a key structural difference between the two frameworks?
- A financial services firm's Chief AI Officer is presenting AI risks to the board. Which risk communication approach BEST conveys the significance of AI model risk to a non-technical board?
- Which component of the NIST AI RMF MEASURE function is MOST directly concerned with tracking AI risk over time after deployment?
- Under the EU AI Act, providers of high-risk AI systems must implement a quality management system. Which element is EXPLICITLY required in the quality management system?
- An organization adopting ISO/IEC 42001 as its AI management system standard wants to establish AI-specific objectives. Which statement BEST describes how AI objectives under ISO/IEC 42001 differ from general business objectives?
- A company's AI governance committee is evaluating whether to use COBIT for AI or the NIST AI RMF as its primary governance framework. Which factor MOST strongly favors COBIT for AI?
- Which of the following BEST describes the relationship between the NIST AI RMF Playbook and the core AI RMF document?
- A newly appointed Chief AI Risk Officer wants to establish a consistent enterprise-wide approach to AI risk appetite. Which artifact is MOST foundational for this purpose?
- An AI governance framework requires all deployed AI systems to maintain a 'model card.' Which information is MOST important to include in a model card for risk management purposes?
- An organization's AI governance framework requires that all AI systems have an 'AI System Owner' accountable for the system's lifecycle. A recently acquired subsidiary has 23 AI systems but has not assigned owners. What is the FIRST governance action the parent organization should take?
- An organization's AI policy states that AI systems must comply with 'applicable laws and regulations.' A risk manager notes this language is insufficient for an effective AI governance policy. What specific gap does this general language create?
- Under the NIST AI RMF, which subcategory of the GOVERN function addresses the development and use of AI systems in a manner consistent with the organization's values and applicable law?
- A multinational corporation subject to the EU AI Act is establishing an AI governance program. Which obligation applies to ALL providers of AI systems placed on the EU market, regardless of risk classification?
- An AI governance committee wants to assess organizational AI culture and awareness. Which NIST AI RMF function most directly addresses building organizational culture that supports trustworthy AI?
- A company is adopting ISO/IEC 42001 and needs to determine the scope of its AI management system. Which factor is MOST important when defining the scope boundary?
- The EU AI Act requires providers of high-risk AI systems to conduct a fundamental rights impact assessment. Which entity is PRIMARILY responsible for this assessment?
- A Chief Risk Officer is building an AI risk committee structure. Which governance body composition BEST ensures comprehensive oversight of AI risk?
- A risk analyst asks a model developer to explain why the AI rejected a specific insurance claim. The developer says the model is a 'black box' and individual predictions cannot be explained. From a governance perspective, what is the MOST appropriate organizational response?
- An AI governance audit of a multinational reveals that the organization has separate AI risk committees in Europe, North America, and Asia-Pacific that operate independently with no global coordination mechanism. Each region applies different risk thresholds, fairness standards, and approval criteria. What governance risk does this structure create?