Free ISACA Advanced in AI Risk (AAIR) practice — 6 questions on AI Risk Program Management, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 3: AI Risk Program Management
A financial services company is establishing an AI risk governance framework for multiple business units deploying AI systems independently. The Chief Risk Officer requires a structure that enforces consistent risk assessment across units while allowing unit-specific risk appetite calibration. The framework must integrate with existing enterprise risk management (ERM) processes and provide board-level visibility into aggregate AI risk exposure. Which governance structure BEST meets these requirements?
Federated governance balances central standard-setting with business unit autonomy for risk appetite calibration. The unified risk registry enables board-level aggregate visibility while ERM integration ensures consistency with enterprise processes. This structure scales across multiple units without creating bottlenecks.
Question 2 of 6 · Domain 3: AI Risk Program Management
An AI risk program manager discovers that a deployed credit scoring model exhibits demographic performance disparity that wasn't detected during pre-deployment testing. The model shows 8% lower accuracy for applicants aged 18-25 compared to other age groups. Legal review confirms this doesn't violate fair lending laws as age isn't a protected class in this jurisdiction, and the model doesn't use age as a direct feature. The business unit reports that retraining would cost $200K and delay a product launch. What is the MOST appropriate risk management action?
This balances proportionate risk response with ethical responsibility. Continuous monitoring prevents disparity widening, threshold triggers enable evidence-based retraining decisions, and transparency through disclosure demonstrates responsible AI practices. The approach addresses both performance and reputational risk without overreacting to a non-legal violation.
Question 3 of 6 · Domain 3: AI Risk Program Management
A healthcare AI risk program includes model cards documenting training data, performance metrics, and known limitations. During an incident investigation, the risk team discovers that a diagnostic AI system's model card listed 'dermatological images from 15 medical centers' but didn't specify that 92% of images came from patients with Fitzpatrick skin types I-III. This data imbalance contributed to missed diagnoses in patients with darker skin tones. Which root cause analysis finding represents the MOST significant governance gap?
Pre-deployment validation is the critical control gate that should have detected the performance disparity before deployment. The gap isn't in documentation (the data WAS available) but in the validation process not analyzing subgroup performance. This represents a fundamental risk assessment failure rather than a documentation issue.
Question 4 of 6 · Domain 3: AI Risk Program Management
An organization's AI risk inventory identifies 47 AI systems across 8 business units. The risk program manager must prioritize 12 systems for in-depth risk assessment this quarter due to resource constraints. The inventory data includes: deployment date, user volume, decision autonomy level (fully automated/human-in-loop/decision support), regulatory applicability, and business criticality ratings. Which prioritization framework BEST aligns with risk-based resource allocation principles?
Composite risk scoring captures multiple risk dimensions and enables objective, defensible prioritization. Weighting autonomy level, regulatory exposure, business impact, and user scale creates a holistic risk view. This methodology is auditable and can be adjusted as risk appetite evolves. It ensures highest-risk systems get scrutiny first.
Question 5 of 6 · Domain 3: AI Risk Program Management
A multinational corporation operates an AI risk program across EU, US, and APAC regions. The EU subsidiary reports an AI system incident requiring notification under the EU AI Act's high-risk system provisions. The same system operates in all three regions with identical configuration. The global AI risk officer must determine notification obligations. US operations fall under voluntary AI Risk Management Framework (NIST), and APAC operations have no AI-specific regulation. What is the CORRECT notification approach?
Legal obligations are jurisdiction-specific. EU AI Act notification is mandatory for EU deployment meeting high-risk criteria. US NIST AI RMF is voluntary, creating no legal notification obligation. APAC has no applicable requirement. Over-notifying creates unnecessary regulatory attention and potential liability admissions in jurisdictions without legal protection for voluntary disclosures.
Question 6 of 6 · Domain 3: AI Risk Program Management
An AI risk program tracks key risk indicators (KRIs) for deployed AI systems. The program manager observes that the 'model prediction drift' KRI for a fraud detection system has remained stable at 2.3% for 9 months, well below the 5% escalation threshold. However, fraud losses increased 18% over the same period. Investigation reveals the model correctly predicts fraud patterns but criminals shifted to attack vectors outside the model's training distribution. Which risk management process failure does this scenario illustrate?
The scenario demonstrates technical KRIs (drift) appearing healthy while business outcomes (fraud losses) deteriorate. Effective AI risk monitoring requires both technical metrics AND business outcome metrics to detect when model performance becomes misaligned with business objectives. Technical health doesn't guarantee business value.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
$109.99$34.99 with code FREETEST33 — valid through August 23.