Which of the following is a risk practitioner's BEST justification for embedding AI risk considerations into acceptable use policies?
Correct Answer: C
Acceptable use policies (AUPs) govern how employees interact with organizational systems and tools. Embedding AI risk considerations into AUPs ensures that AI-related behaviors align with the organization's risk appetite and tolerance thresholds. Why C is Correct: According to ISACA AAIR governance principles, the best justification for embedding AI risk in AUPs is maintaining consistent enterprise risk tolerance across all AI-driven decision-making. When risk tolerances are codified in AUPs, employees understand what AI behaviors are permissible, and deviation from these boundaries triggers escalation. This enterprise-wide alignment prevents individual business units from accepting risks that exceed organizational thresholds. Why A is Wrong: Shadow AI mitigation through allow lists is a specific technical control mechanism, not the primary governance justification for AUP integration. It addresses unauthorized tool use rather than risk tolerance alignment. Why B is Wrong: Applying uniform risk controls across diverse business functions is a compliance approach that may not be appropriate-different functions may legitimately have different risk profiles. The goal is tolerance alignment, not control uniformity. Why D is Wrong: Assigning accountability to business unit leadership is a governance structure decision. AUPs define behavioral expectations, not organizational accountability assignments, which are addressed through RACI frameworks and policy governance.
Question 17
Which of the following information is MOST important to add to an organizational business continuity plan (BCP) when adopting a customer-facing AI solution?
Correct Answer: B
Business continuity planning for customer-facing AI solutions must ensure service availability and resilience under failure conditions. The BCP must specify the technical and operational mechanisms that maintain service continuity when primary systems are disrupted. Why B is Correct: The ISACA AAIR business continuity guidance identifies secure access to alternate resources, multi-region failover, and load balancing as the most important additions to a BCP for customer- facing AI. These mechanisms ensure that service disruptions-whether from technical failures, cyber incidents, or regional outages-do not result in total unavailability. For customer-facing solutions, maintaining service continuity directly affects customer trust, revenue, and regulatory compliance with service availability obligations. Why A is Wrong: Post-incident audits of recovery times and accuracy metrics are monitoring activities that occur after incidents. While valuable for improvement planning, they do not define the recovery mechanisms that the BCP must specify to ensure continuity during disruptions. Why C is Wrong: Centralizing failover under a single cloud provider creates a concentration risk-if that provider experiences an outage, all failover mechanisms fail simultaneously. Good BCP design requires geographic and provider diversification, not concentration. Why D is Wrong: Breach containment criteria address security incident response, not service continuity. While related to incident management, breach response procedures are typically documented in the incident response plan rather than the BCP, which focuses on maintaining or restoring business operations.
Question 18
An organization adopts a third-party AI service under a shared responsibility model. Which of the following is the MOST important area of focus for the risk practitioner?
Correct Answer: D
The shared responsibility model creates complexity in AI governance because control obligations are distributed between the organization and the vendor. The most critical risk is ambiguity about who owns specific controls and who makes decisions when issues arise. Why D is Correct: The ISACA AAIR framework identifies documented assignment of control ownership as the cornerstone of shared responsibility governance. Without explicit documentation of which controls the organization owns versus which the vendor owns, and who has decision authority in each scenario, gaps and overlaps emerge that allow risks to go unmanaged. Named ownership ensures accountability persists across the shared boundary. Why A is Wrong: Staff training on procedures is important but addresses operational readiness rather than the fundamental governance challenge of shared responsibility. Training supports a well-structured model but cannot substitute for defined ownership. Why B is Wrong: Contractual liability clauses are legal protections that determine financial recourse after incidents. While essential, they do not prevent governance gaps from forming during normal operations. Why C is Wrong: Data pathway testing is a security assurance activity addressing technical controls. It verifies control function but does not establish who owns those controls or what authority they have in the shared model.
Question 19
An organization uses AI to generate procedure documents for operational processes. Which of the following would be of GREATEST concern to a risk practitioner?
Correct Answer: A
AI-generated content-including operational procedures-can contain errors, omissions, hallucinations, and contextually inappropriate guidance. Human review is a critical quality control and accountability mechanism that ensures generated procedures are accurate, complete, and appropriate for actual operational use. Why A is Correct: The ISACA AAIR guidance on human oversight identifies the absence of human review as the greatest risk in AI-generated documentation. Without review, errors and AI hallucinations are propagated directly into operational use, potentially causing safety incidents, compliance violations, or operational failures. Human review is the last line of defense against AI output quality failures, particularly in operational procedure contexts where incorrect instructions can have serious consequences. Why B is Wrong: Outdated procedures are a content quality issue that would typically be caught during human review. The greater concern is that no review is occurring, which allows all types of errors-including outdated content-to reach operational use unchallenged. Why C is Wrong: Policy misalignment is a governance concern but represents a specific type of error that would be identified if adequate human review were performed. The absence of review is the root governance failure. Why D is Wrong: Using AI to generate procedures for high-risk activities is a deployment scope concern that raises the stakes of errors. However, the fundamental governance failure-and the greatest concern-is that no human verification occurs regardless of the risk level of the activity.
Question 20
Which of the following is the PRIMARY benefit of incorporating new AI-specific controls?
Correct Answer: C
AI systems introduce new categories of risk-model drift, adversarial attacks, algorithmic bias, hallucination-that conventional IT controls were not designed to address. AI-specific controls must complement existing controls to create comprehensive coverage across both traditional and emerging risk domains. Why C is Correct: The ISACA AAIR curriculum identifies the holistic, comprehensive coverage of both conventional governance exposures and emerging AI vulnerabilities as the primary benefit of AI-specific controls. By designing controls that address AI-unique risks while integrating with existing governance structures, organizations achieve end-to-end risk management without creating coverage gaps between the old and new control environments. Why A is Wrong: Compliance reporting prioritization is a governance administration activity. While AI- specific controls may clarify compliance requirements, identifying and prioritizing reporting requirements is not the primary purpose of implementing new controls. Why B is Wrong: Cost reduction through control consolidation is an efficiency benefit that may result from control rationalization but is not the primary benefit of incorporating AI-specific controls. Adding necessary controls may actually increase costs in the short term. Why D is Wrong: Accelerating deployment through efficient pre-deployment analysis is an operational efficiency benefit. The primary governance purpose of AI-specific controls is comprehensive risk coverage, not deployment speed.