AAIR Exam Questions & Answers
ISACA Advanced in AI Risk • Isaca
100% money-back guarantee
Sample AAIR Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
A credit-scoring AI solution exhibits steadily declining accuracy despite unchanged input distributions. Which of the following should a risk practitioner consider to be the GREATEST risk?
When an AI model's accuracy declines despite stable input distributions, the most likely cause is concept drift---where the underlying relationship between inputs and the target variable changes over time. In credit scoring, this may occur when economic conditions, consumer behavior, or risk patterns shift in ways not captured in the original training data.
Why C is Correct: The ISACA AAIR model drift guidance identifies concept drift as the greatest risk in this scenario because it means the model is making credit decisions based on relationships that no longer hold in the current environment. Faulty credit decisions can lead to incorrect denials of creditworthy applicants, incorrect approvals of high-risk applicants, regulatory violations, financial losses, and harm to individuals---all high-severity consequences for a credit-scoring application.
Why A is Wrong: Technical delays in credit score updates are an operational performance concern. Delays create business friction but do not cause the fundamental accuracy problem described in the scenario.
Why B is Wrong: Underfitting from shortened training cycles is a model development quality issue. The scenario specifies stable input distributions and declining accuracy---characteristic of drift, not underfitting, which would manifest differently.
Why D is Wrong: Increased retraining costs represent a financial efficiency concern. While budgetary impacts are real, they are secondary to the risk of faulty credit decisions affecting individuals and regulatory compliance.
An organization embeds AI into existing processes without integrating AI risk practices into enterprise governance. Which of the following should a risk practitioner regard as the GREATEST organizational risk?
When AI is deployed without governance integration, no formal structure exists to assign control ownership, coordinate risk management activities, or align AI decision-making with organizational objectives. This structural void produces divergent, fragmented, and potentially conflicting risk management efforts.
Why C is Correct: According to ISACA AAIR, unclear ownership is the greatest organizational risk from AI operating outside governance structures. Without designated owners, controls may be applied inconsistently across business units, different teams may implement conflicting approaches, and no one is responsible for ensuring AI activities align with enterprise objectives. This governance vacuum creates unmanaged risks and organizational incoherence.
Why A is Wrong: Regulatory compliance documentation gaps are significant but are a downstream symptom of poor governance rather than the root organizational risk. Documentation failures can be remediated more easily than fundamental ownership gaps.
Why B is Wrong: Technical-business alignment is an important concern but represents a strategic planning challenge rather than the greatest organizational risk from absent governance. Alignment can be achieved through business case processes without full governance integration.
Why D is Wrong: Executive approval difficulty is an organizational change management challenge. It reflects organizational politics rather than a structural risk from absent governance. Approval processes function independently of AI governance integration.
Which of the following is the PRIMARY benefit of integrating AI risk processes into an enterprise risk framework?
Enterprise risk framework integration elevates AI risk management from a technical discipline to a strategic organizational function, ensuring AI risks are considered alongside all other enterprise risks in strategic planning and decision-making.
Why D is Correct: The ISACA AAIR curriculum identifies enterprise integration as the mechanism that enables organization-level oversight and ensures AI risk management aligns with strategic objectives, risk appetite, and governance structures. This integration allows the board and senior management to make informed decisions about AI investment, deployment, and risk acceptance with full awareness of AI's contribution to the organizational risk profile.
Why A is Wrong: KPI benchmarking is an operational performance management activity. While integration may improve KPI accuracy, this is a secondary operational benefit rather than the primary strategic benefit of ERM integration.
Why B is Wrong: Regulatory compliance is improved by integration but represents a specific compliance benefit rather than the primary organizational value. Compliance is an output of good governance, not the purpose of ERM integration.
Why C is Wrong: Cyber threat identification is a security function that benefits from integration but is not the primary benefit. Many AI risks are non-cyber in nature---fairness, accuracy, transparency---and would not be captured by a cyber-focused framing.
Which of the following is the BEST course of action to mitigate risk during model selection of supervised or unsupervised algorithms?
Algorithm selection is a foundational risk management decision in AI development. The wrong algorithm for a given use case can produce inaccurate, unreliable, or harmful outputs regardless of the quality of training data or computational resources applied.
Why D is Correct: The ISACA AAIR model development guidance identifies use case alignment as the most critical algorithm selection criterion. Supervised and unsupervised learning are suited to fundamentally different problem types---supervised learning requires labeled training data and learns mappings to known outputs; unsupervised learning discovers patterns in unlabeled data. Selecting algorithms whose capabilities match the use case's structure and objectives prevents systematic performance failures and misapplied AI.
Why A is Wrong: Generalization capability is an important model quality criterion but represents one of many algorithmic properties. Strong generalization on the wrong problem type still produces poor results. Use case alignment precedes generalization as a selection criterion.
Why B is Wrong: Requiring supervised learning for all training projects is an inappropriate blanket policy. Many valuable use cases---anomaly detection, customer segmentation, exploratory analytics---are better served by unsupervised approaches. Mandating supervised learning prevents optimal use case matching.
Why C is Wrong: Computational cost is a resource management consideration. Optimizing for cost at the expense of use case fit risks deploying inappropriate models that produce unreliable outputs, creating far greater costs through remediation or harm.
An organization uses multiple external data sources to train its AI models. Which of the following is the risk practitioner's BEST recommendation to protect the organization from data poisoning attacks?
Data poisoning attacks involve malicious modification of training data to degrade model performance or introduce backdoors. With multiple external data sources, the attack surface for introducing poisoned data is broad and requires proactive, continuous detection at the ingestion stage.
Why B is Correct: The ISACA AAIR adversarial AI guidance identifies continuous monitoring and anomaly detection at the data ingestion pipeline as the most effective defense against data poisoning. By monitoring incoming data in real time for statistical anomalies, unexpected distributions, or known poisoning patterns, organizations can detect and block malicious data before it contaminates training datasets. This preventive approach is superior to reactive detection after poisoning has occurred.
Why A is Wrong: Reactive data integrity reviews triggered by model drift occur after poisoning has already affected model behavior. By this stage, the model may have been deployed and made harmful decisions. Prevention during ingestion is superior to post-drift investigation.
Why C is Wrong: Model code and deployment artifact controls address security of the software pipeline but do not protect training data from external poisoning. Data integrity requires data-layer controls, not code security.
Why D is Wrong: Regularization reduces overfitting to training noise but does not detect or prevent deliberate poisoning attacks. A sufficiently targeted poisoning attack can introduce systematic bias that regularization techniques cannot mitigate.
Get access to all 90 verified questions with detailed answers.
Unlock All AAIR Questions