Which of the following is the PRIMARY benefit of aligning AI risk management with existing organizational governance frameworks?
Correct Answer: C
Organizational governance frameworks provide the structures, processes, and oversight mechanisms through which enterprises manage their activities and risks. Aligning AI risk management with these frameworks ensures AI activities receive the same level of strategic oversight as other organizational functions. Why C is Correct: The ISACA AAIR curriculum identifies enterprise-level oversight and strategic alignment as the primary benefit of governance framework integration. When AI risk management operates within established governance structures, AI decisions are subject to the same approval authorities, risk escalation pathways, and strategic alignment checks that govern all major organizational decisions. This produces coherent, enterprise-aware AI governance. Why A is Wrong: Role development and responsibility clarification are governance activities that may result from alignment, but they represent structural outputs rather than the primary benefit. The benefit is the oversight quality, not the organizational structure itself. Why B is Wrong: Expediting compliance approvals is an efficiency benefit that may arise from better- organized governance. However, speed of approval is not the primary purpose of framework alignment-the purpose is quality and consistency of oversight. Why D is Wrong: Standardizing acquisition processes is a procurement function benefit. While governance alignment may improve procurement consistency, standardization is a narrow operational benefit compared to the strategic oversight value of full governance integration.
Question 22
A risk practitioner learns that an AI system used by a manufacturer for quality control (QC) has produced inaccurate responses that could potentially impact user safety. Which of the following is the risk practitioner's BEST recommendation to mitigate this risk?
Correct Answer: A
When an AI system used for safety-critical quality control produces inaccurate responses that could harm users, the most immediate and effective safeguard is inserting human judgment into the decision process before unsafe outputs can reach production or end users. Why A is Correct: The ISACA AAIR human oversight guidance identifies human-in-the-loop reviews as the most effective mitigation when AI outputs pose safety risks. In safety-critical applications like manufacturing quality control, human reviewers can catch and correct AI errors before they result in unsafe products reaching consumers. This control is immediately implementable, does not require model retraining, and directly addresses the safety risk. It is the appropriate response when AI accuracy cannot be fully trusted. Why B is Wrong: Bias and fairness testing is a model evaluation activity that assesses whether outputs are systematically skewed. While useful for improving the model, it does not provide immediate protection against the safety risk of current inaccurate outputs. Why C is Wrong: Synthetic data augmentation may improve model quality over time but requires model retraining and does not prevent currently inaccurate outputs from causing harm in the interim. Why D is Wrong: Prompt engineering training improves how users interact with AI systems to elicit better outputs. It is useful for generative AI applications but does not directly address safety risks from QC system inaccuracies, which require operational oversight rather than improved prompting.
Question 23
Which of the following is the PRIMARY benefit of integrating AI risk processes into an enterprise risk framework?
Correct Answer: D
Enterprise risk framework integration elevates AI risk management from a technical discipline to a strategic organizational function, ensuring AI risks are considered alongside all other enterprise risks in strategic planning and decision-making. Why D is Correct: The ISACA AAIR curriculum identifies enterprise integration as the mechanism that enables organization-level oversight and ensures AI risk management aligns with strategic objectives, risk appetite, and governance structures. This integration allows the board and senior management to make informed decisions about AI investment, deployment, and risk acceptance with full awareness of AI's contribution to the organizational risk profile. Why A is Wrong: KPI benchmarking is an operational performance management activity. While integration may improve KPI accuracy, this is a secondary operational benefit rather than the primary strategic benefit of ERM integration. Why B is Wrong: Regulatory compliance is improved by integration but represents a specific compliance benefit rather than the primary organizational value. Compliance is an output of good governance, not the purpose of ERM integration. Why C is Wrong: Cyber threat identification is a security function that benefits from integration but is not the primary benefit. Many AI risks are non-cyber in nature-fairness, accuracy, transparency-and would not be captured by a cyber-focused framing.
Question 24
A risk practitioner is assessing risk in a newly implemented AI system integrated into an organization's business processes. Which of the following is the MOST important consideration for the risk practitioner?
Correct Answer: D
AI risk assessment must be calibrated to the potential consequences of AI-driven decisions. The criticality and impact of AI-driven decisions directly determine the magnitude of risk exposure and the appropriate level of risk treatment. Why D is Correct: According to ISACA AAIR principles, the most fundamental risk assessment consideration is the nature and impact of decisions driven by the AI system. Systems making high-stakes decisions-affecting employment, credit, healthcare, or public safety-carry significantly greater risk than those supporting low-impact tasks. Understanding decision criticality frames all other risk assessment activities and drives proportionate control selection. Why A is Wrong: Escalation protocols are governance process elements that should be designed after understanding the risk profile. They are outputs of risk assessment, not inputs to the primary assessment consideration. Why B is Wrong: Prior automation levels provide contextual background but do not determine the risk profile of the new AI system. The relevant risk driver is forward-looking, not historical. Why C is Wrong: Internal expertise levels affect assessment capability but represent an organizational constraint rather than the primary risk consideration. The risk lies in the system's potential impact, not in who assesses it.
Question 25
An organization is designing an enterprise dashboard to support governance of its AI program. Which of the following is the risk practitioner's BEST recommendation?
Correct Answer: B
An enterprise AI governance dashboard must provide decision-makers with a comprehensive, integrated view of AI program health across all dimensions-risk, performance, compliance, ethics, and operations. Fragmenting this view or focusing on narrow metrics produces an incomplete governance picture. Why B is Correct: The ISACA AAIR governance reporting guidance recommends aggregating diverse metrics from all AI life cycle stages as the best approach for an enterprise governance dashboard. This comprehensive aggregation enables decision-makers to see the full AI risk and performance picture-from data quality in training through deployment performance, bias monitoring, security incidents, and compliance status-in a single, actionable view. This unified perspective supports informed enterprise-level governance decisions. Why A is Wrong: Uptime and availability metrics are operational infrastructure indicators that represent only one dimension of AI governance. Focusing primarily on availability misses critical governance concerns including model fairness, accuracy, bias, and ethical compliance. Why C is Wrong: Risk heat maps based solely on training variance are narrow technical performance indicators. A governance dashboard requires breadth across risk types and life cycle stages, not depth on one specific technical metric. Why D is Wrong: Assigning dashboard responsibility exclusively to IT centralizes governance reporting in one function that may lack visibility into business risk, ethical compliance, and strategic alignment dimensions of AI governance. Enterprise dashboards require cross-functional input and ownership.