Free ISACA Advanced in AI Risk (AAIR) practice — 6 questions on AI Risk Governance and Framework Integration, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 1: AI Risk Governance and Framework Integration
A global pharmaceutical company is implementing an AI system to predict drug interaction risks across multiple international markets. The system will process patient data from the EU, health records from the US, and clinical trial data from Japan. The AI governance team must ensure compliance with region-specific regulations while maintaining a unified risk framework. Which governance approach BEST addresses these multi-jurisdictional requirements?
ISO/IEC 42001 (AI Management System standard) provides an internationally recognized baseline that can accommodate region-specific legal requirements through control mapping while maintaining unified governance. This approach prevents duplication, ensures consistent risk assessment methodology, and allows for localized compliance overlays without fragmenting the governance structure.
Question 2 of 6 · Domain 1: AI Risk Governance and Framework Integration
An AI risk committee is evaluating a proposed generative AI system for automated financial reporting. During framework integration assessment, they discover the system's training data lineage cannot be fully reconstructed due to third-party data acquisitions from 2023-2024. The vendor claims the model meets current accuracy benchmarks. Which risk governance action is MOST appropriate?
Data lineage and traceability are foundational requirements in all major AI governance frameworks (ISO/IEC 42001, NIST AI RMF, EU AI Act). For financial reporting systems (high-risk use case), inability to trace training data prevents bias assessment, limits explainability, creates audit trail gaps, and violates most financial regulatory requirements. This is a non-negotiable governance requirement regardless of current performance.
Question 3 of 6 · Domain 1: AI Risk Governance and Framework Integration
A healthcare organization's AI governance framework requires quarterly risk assessments for all deployed AI systems. After the latest assessment, the AI risk score for a diagnostic imaging system increased from 'Medium' to 'High' due to drift detection in prediction patterns, though diagnostic accuracy remains within acceptable thresholds. Which framework integration principle should guide the immediate response?
When risk classification changes to 'High' in a healthcare AI system, governance frameworks require escalation to appropriate authority (governance committee) for risk acceptance decisions. However, immediate suspension without evidence of patient harm would disrupt care. The correct response is escalation + compensating controls (dual review) until the committee assesses whether the risk is acceptable, needs mitigation, or requires suspension. This balances patient safety with continuity of care.
Question 4 of 6 · Domain 1: AI Risk Governance and Framework Integration
An enterprise is integrating the NIST AI Risk Management Framework with their existing ISO 27001 information security management system. The integration team identifies that NIST AI RMF's 'Govern' function overlaps with ISO 27001's governance controls, while NIST's 'Measure' function has no direct ISO 27001 equivalent. What integration approach BEST maintains both frameworks' integrity?
Framework integration requires mapping overlapping controls to prevent duplication while adding new controls for gaps. ISO 27001 provides mature governance for information security; NIST AI RMF extends this to AI-specific risks. Mapping Govern functions shows how AI governance fits within existing security governance, while new control families for Map/Measure/Manage address AI-specific requirements (model testing, fairness metrics, AI incident response) not covered by ISO 27001. This preserves both frameworks' value.
Question 5 of 6 · Domain 1: AI Risk Governance and Framework Integration
A financial services firm's AI governance policy states: 'High-risk AI systems require independent validation before deployment.' An internal team has developed a credit decisioning model classified as high-risk. The Chief Data Scientist, who did not work on this specific model but reports to the same SVP as the development team and manages the firm's model validation group, proposes that her validation team conduct the required independent validation. Does this meet the governance policy's independence requirement?
In AI governance frameworks, 'independent validation' means organizational independence from the development function, not just individual separation. When both development and validation report to the same executive (SVP), that executive has incentive to approve models for business reasons, creating structural conflict of interest. True independence requires the validator to report through a different executive chain (e.g., Chief Risk Officer rather than Chief Data/Technology Officer) to ensure objective assessment without business pressure.
Question 6 of 6 · Domain 1: AI Risk Governance and Framework Integration
An AI governance framework defines five risk tiers (Critical, High, Medium, Low, Minimal) with different approval authorities for each tier. A natural language processing system for customer service chat was initially classified as 'Medium' risk and approved by the department director. After six months of operation, a framework review identifies that the system now processes PII during conversations and provides information that could be considered financial advice in 15% of interactions. No changes were made to the model itself. What governance action is required?
Risk classification in AI governance frameworks is based on actual use and impact, not just technical characteristics. When a system's operational use evolves to include PII processing and financial advice (both high-risk domains in most regulatory frameworks), the risk tier must be reclassified regardless of whether the model changed. The new risk tier triggers different approval requirements—'High' risk typically requires governance committee approval rather than department director approval, so re-approval at the appropriate level is mandatory.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
$109.99$34.99 with code FREETEST33 — valid through August 23.