Domain 5: Regulatory Compliance & Ethics
ISACA AI Audit · 48 questions
- Under the EU AI Act, a biometric categorization system used by law enforcement to classify individuals by political opinion would be classified as which risk tier?
- An organization processes personal data to train an AI model for targeted advertising. Under GDPR, which legal basis is MOST appropriate for this processing activity?
- Under the EU AI Act, which AI system category requires a Fundamental Rights Impact Assessment (FRIA) to be conducted by deployers?
- Which fairness metric measures whether a model's positive prediction rate is equal across demographic groups, regardless of actual outcomes?
- A GDPR Data Protection Officer reviews an AI system that uses automated profiling to determine insurance premiums. Which GDPR right is MOST directly implicated?
- An AI system used in parole decisions is challenged in court because it cannot provide the basis for individual recommendations. Which AI ethics principle is MOST at stake?
- A financial services firm uses an AI model to detect money laundering patterns. A new regulation requires that all automated suspicious activity reports (SARs) be explainable to the regulator. The current model is a deep neural network with no built-in explainability. Which approach presents the GREATEST risk to the firm?
- A retail bank is deploying an AI system that automatically denies credit card applications. Under ECOA and Regulation B, what notification requirement applies to each automated denial?
- An insurance company deploys a telematics-based AI model that sets auto insurance premiums based on real-time driving behavior. A regulator inquires about the model's compliance with the California Consumer Privacy Act (CCPA). Which CCPA concern is MOST relevant?
- An AI ethics board is reviewing an AI system that predicts student dropout risk in higher education. Students flagged as high dropout risk receive additional academic support. However, the AI risk team identifies that the model also shares flags with scholarship committees. Which ethical concern is MOST critical?
- An AI system generates loan modification recommendations for distressed borrowers. A fair lending audit reveals that the model recommends less favorable modification terms for borrowers in predominantly Black zip codes, even after controlling for credit score and loan-to-value ratio. Under which legal framework would this finding MOST likely be investigated?
- An organization's AI policy states that all AI systems processing sensitive personal data must conduct a Data Protection Impact Assessment (DPIA). An AI system analyzes employee emails to detect insider threats. Which DPIA finding would MOST likely require escalation to the supervisory authority under GDPR?
- A financial regulator issues guidance stating that AI models used in credit underwriting must be 'explainable' to regulators on request. A bank uses a deep learning model for underwriting and argues that SHAP explanations satisfy this requirement. The regulator disagrees. What is the regulator's MOST likely concern with SHAP-based explanations?
- An AI model for mortgage servicing determines which delinquent borrowers receive proactive outreach. The model has a 15% higher probability of recommending outreach for White borrowers than Black borrowers with identical financial profiles. Under which framework is this MOST likely a violation?
- An AI ethics review identifies that a social media content recommendation AI maximizes user engagement metrics, leading to increased consumption of emotionally charged and divisive content. Which ethical principle is MOST directly at issue?
- A technology company's legal team advises that their AI system must comply with the EU AI Act's transparency obligations for limited-risk AI systems. Which obligation is SPECIFICALLY required for AI systems that interact with natural persons (such as chatbots)?
- An AI model flags customers for churn risk and triggers automated retention offers. The model audit team discovers that customers who received retention offers have slightly lower churn rates, but wealthier customers receive more generous offers (higher discounts) because their historical lifetime value is used as a feature. What ethical concern should be prioritized in the audit report?
- An AI ethics committee is reviewing a proposal to use facial recognition AI to verify customer identity for bank account access. Which risk requires HIGHEST priority in the ethics review?
- A telecommunications company plans to use an AI model to predict customer lifetime value (CLV) and offer service upgrades preferentially to high-CLV customers. An AI risk team conducts a disparate impact assessment and finds that high-CLV customers are disproportionately White and high-income. What recommendation should the AI risk team make?
- An AI governance team is conducting a privacy risk assessment for a new AI-powered employee monitoring system that tracks keystrokes, screen content, and application usage to detect potential insider threats. Which privacy principle is MOST threatened?
- An AI model for predictive policing is challenged by civil liberties advocates because it uses historical arrest data to predict future crime. The primary AI ethics concern with this application is:
- An AI risk manager at a large insurance company receives a request to deploy an AI model that uses telematics data from smartphones to assess driver risk for auto insurance. The model uses 47 features derived from smartphone accelerometer and GPS data. Which privacy risk assessment step is MOST important before deployment?
- An AI audit team is reviewing the data governance practices for an AI model used in hiring. The team discovers that training data containing demographic information was retained after model development without documented justification. Under GDPR, which principle is MOST likely violated?
- An organization processes personal data using AI systems for targeted advertising. Under GDPR, what is the MOST important compliance requirement when using solely automated decision-making that produces legal or similarly significant effects on individuals?
- A data ethics officer is reviewing fairness metrics for a recidivism prediction model used in bail decisions. The model achieves equal accuracy across racial groups but has different false positive rates. Which fairness criterion is violated?
- A healthcare AI company is subject to both HIPAA and GDPR because it serves US and EU patients. When an AI model trained on patient data is later used in a new clinical setting, which compliance obligation is MOST critical to address FIRST?
- An AI ethics board is reviewing a proposed AI system that allocates organ transplant priority scores. Which ethical principle creates the MOST tension when designing this system?
- Under the EU AI Act, which of the following is classified as a prohibited AI practice?
- Which accountability mechanism BEST addresses the 'black box' problem for high-stakes AI decisions affecting individuals?
- A privacy regulator is investigating an organization's AI-based emotion recognition system deployed in a call center to assess customer satisfaction in real time. Under the EU AI Act, which provision is MOST directly applicable to this system?
- A company processes personal data using AI to make automated decisions about individual credit eligibility. Under GDPR, what right allows individuals to obtain a human review of the decision?
- An AI ethics review board is evaluating a predictive policing system. Which ethical framework would MOST strongly counsel against deployment of this system in high-risk communities?
- A company trains an AI model on customer support chat logs that include sensitive personal information. The company did not obtain explicit consent for AI training as a purpose. Under GDPR, which legal basis would MOST plausibly support this use?
- A data scientist proposes using 'equal accuracy' as the sole fairness metric for a healthcare AI triage system. Why is this approach INSUFFICIENT from a fairness perspective?
- Which of the following BEST describes the concept of 'meaningful human oversight' as applied to high-risk AI systems?
- An organization's AI ethics policy states that all AI systems must be 'transparent.' A business unit argues their proprietary fraud detection algorithm cannot be disclosed to fraud perpetrators without defeating its purpose. How should this tension be resolved?
- A bank's AI governance policy requires that all high-impact AI models undergo an ethical impact assessment before deployment. The assessment for a mortgage pricing model reveals that the model relies heavily on neighborhood characteristics that correlate with race. What is the MOST appropriate next step?
- An AI system is trained using data collected through a mobile app. Users agreed to terms of service but were not explicitly told their data would be used for AI model training. From a data ethics perspective, which principle is MOST directly implicated?
- An AI auditor needs to test whether an AI-assisted lending decision system satisfies the Equal Credit Opportunity Act (ECOA)'s adverse action notice requirement. What audit procedure is MOST direct?
- A privacy officer is reviewing an AI system that uses biometric data to authenticate employees for access to secure areas. Under GDPR, how is biometric data classified?
- An AI ethics review identifies that a student loan refinancing model assigns lower interest rates to graduates of highly-ranked universities. Which ethical concern does this MOST directly raise?
- A company's AI ethics policy requires that AI systems affecting individuals must be contestable. In practice, what does effective contestability require?
- Under the GDPR, when an organization uses AI for solely automated profiling that significantly affects individuals, which principle MOST directly requires the organization to be able to demonstrate lawfulness and proper safeguards to the supervisory authority?
- An AI risk practitioner is evaluating AI systems under the lens of 'responsible AI.' Which of the following formulations BEST captures the intersection of ethics and risk management in responsible AI?
- A hospital is considering deploying an AI triage system that would prioritize emergency room patients based on predicted clinical outcomes. From an ethical standpoint, which consideration is MOST critical before deployment?
- A government agency is considering using AI to automatically flag welfare benefit applications for fraud investigation. Which combination of risks requires the MOST urgent policy and governance attention before deployment?
- A technology vendor markets an AI system capable of predicting employees' 'flight risk' using behavioral data including keystrokes, email metadata, and application usage. Which risk is MOST significant for an employer considering deploying this system?
- An organization is developing an AI ethics review process. At which stage of the AI development lifecycle should ethics review occur to be MOST effective?