AAIA ISACA Advanced in AI Audit (AAIA) Questions and Answers
Which of the following is the BEST approach to mitigate the risk of AI model degradation?
When auditing a research agency ' s use of generative AI models for analyzing scientific data, which of the following is MOST critical to evaluate in order to prevent hallucinatory results and ensure the accuracy of outputs?
When auditing a machine learning (ML) solution, false positives can BEST be assessed by examining the level of:
During audit planning, an IS auditor reviews the correlation matrix. Which variable pair from an electrical generation facility has the MOST significant correlation?
For a sales promotion, an AI system sorts customer attributes into several categories by analyzing transaction history. Verifying which of the following would BEST validate the effectiveness of this process?
What is the MOST important reason government organizations should provide regular AI training programs for all staff?
Which of the following BEST ensures representativeness in AI systems when assessing training data periodically?
Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?
A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model ' s predictions?
Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?
Which of the following is the MOST important task when gathering data during the AI system development process?
An IS auditor is reviewing change management documentation of an AI model. Which of the following would pose the GREATEST risk to the model?
Which of the following controls would MOST effectively mitigate worst-case service disruption scenarios affecting an AI-based application system?
Which of the following should be an IS auditor ' s GREATEST concern when using a predictive AI tool to analyze data abnormalities?
Which of the following initially provides assurance that the developer correctly interprets and identifies numerical data for balancing prior to inserting into the model?
After AI training data has been tested for biases, which of the following is MOST important to check to validate the effectiveness of the testing?
Which of the following is the GREATEST risk associated with using AI in audit planning?
Which of the following key performance indicators (KPIs) are MOST important when evaluating whether an AI model meets business objectives?
An IS auditor uses an AI model to summarize worksheets, but several worksheets contained a " Hidden Cell " instructing the model to ignore control failures. Which solution BEST mitigates the risk?
An IS auditor reviews an AI tool using K-means to cluster customers. One cluster shows very high spending but low product diversity. What should the auditor recommend?
Which of the following would pose the GREATEST risk when reviewing AI acceptable use training content?
An insurance company uses an AI model to set premium rates. To align with AI-related policies on fairness, which of the following is the FIRST course of action?
An IS auditor is testing an AI model used for determining insurance premiums and eligibility. Which of the following is the MOST effective testing method to identify bias in algorithm outputs?
Which of the following is the BEST key performance indicator (KPI) to measure a model ' s performance on imbalanced datasets?
An AI audit tool incorrectly flagged that business decisions were biased, leading to inappropriate management action plans. Which of the following can BEST prevent this risk?
Which of the following techniques would be MOST effective as part of incident management procedures for a prompt injection attack?
An IS auditor is considering the integration of AI techniques into the audit sampling process. Which of the following BEST enables the auditor to identify high-risk transactions within large data sets for targeted sampling?
Which of the following BEST enables an AI model to solve complex problems involving the analysis of large volumes of unstructured data?
Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?
The accuracy of an AI model used for product recommendations, trained on data from a specific year, is declining two years later as customer buying patterns have shifted toward sustainable products. Which of the following is the MOST likely cause?
Which of the following is the GREATEST risk when an organization uses publicly available social media data to train its AI model without obtaining explicit user consent?
Which of the following is the MOST important step in an AI incident management process to ensure continuous improvement?
An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?
Which of the following is the BEST way to ensure an AI model ' s outputs are effectively controlled for bias?
Which of the following is the PRIMARY advantage of using K-fold cross validation when evaluating the performance of a machine learning (ML) model?
An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor ' s BEST recommendation to address this issue?
Which of the following BEST ensures that an AI system complies with user data ownership rights under privacy regulations?
Which of the following is the MOST frequent cause of generative AI model hallucinations?
An AI tool is being implemented for a regional healthcare organization. Which of the following training methods BEST ensures the AI output does not reveal whether someone ' s personal data was used?
Which of the following is the MOST important AI data governance method to protect privacy and data security?
An IS auditor is reviewing change documentation of an AI model. Which of the following would pose the GREATEST risk?
Which of the following sampling strategies would MOST likely involve the use of AI?
Which of the following is the BEST recommendation to mitigate excessive agency when implementing an AI system as a browser extension?
A newly deployed fraud detection model is misclassifying transactions due to inconsistent formatting in the data stream. What is the BEST recommendation?
Which of the following is the MOST effective way an IS auditor could use generative AI to plan an audit of a new database storing transactional data?
Which metric should an IS auditor review to evaluate issues with data collection that could impact AI model training?
An IS auditor reviewing documentation for an AI model notes that the modeler utilized a K-means clustering algorithm, which clusters data into categories for correlations and analysis. Which of the following is the MOST important risk for the auditor to consider?
An internal audit department notices that AI-generated audit reports are producing false conclusions. Which of the following is the BEST way to correct this issue?
To confirm the fairness of AI model decisions, the BEST way to collect reliable evidence during an AI audit is by:
Which of the following is the MOST important reason for measuring the AI system ' s performance against predefined metrics in a staging environment?
Which of the following is the MOST important reason for applying regular software updates to AI systems operating in high-risk environments?
Which of the following is the GREATEST data quality risk when using an AI tool to assist with audit procedures?
Which of the following is the MOST important reason to perform regular ethical reviews of AI systems?
Which of the following BEST detects model drift or unexpected changes in AI model outputs?
A health organization has deployed an AI model to analyze chest X-rays. The model reports high accuracy, but thresholds are unclear and performance is not broken down by patient demographics. Why is accuracy alone insufficient to evaluate this model?
Which of the following components would MOST effectively address cumulative benefits as part of reinforcement learning (RL)?
A retailer ' s AI pricing engine recommends unusually large discounts in certain regions. An audit reveals that most historical sales data used for model training came from large urban areas, while smaller regions were represented by very few or no sales records. Which of the following is the MOST likely cause of this issue?
A healthcare organization uses patient data to train an AI model for early disease detection. Which of the following practices provides the BEST assurance that personal data is secure and its integrity is maintained?
In the context of an AI implementation, which of the following actions is MOST critical for an organization ' s change management program?
An organization is developing an AI system that integrates data from multiple external sources without clearly defined data ownership policies. Which of the following is the GREATEST concern in this situation?
During a walk-through, an IS auditor observes an AI engineer entering a prompt that manipulates the AI model’s behavior. Which of the following is the BEST control to prevent this?
An IS auditor is evaluating a large language model (LLM) before deployment. Which of the following is the MOST secure way to manage agency for the model?
An organization is training a skin cancer recognition model. Photographs collected from which of the following sources would present the GREATEST risk associated with data integrity?
Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?
Which of the following is the GREATEST risk associated with deploying an AI system with ineffective anomaly detection?
An IS auditor is reviewing an AI application that uses customer data to refine the organization’s marketing outreach strategies. Which of the following should be the auditor’s PRIMARY focus during this review?
Which of the following strategies used by modelers to enhance data accuracy has the GREATEST risk of bias and information loss?
What should be the IS auditor ' s GREATEST concern when an organization is mixing AI-generated content into training data without labeling?
Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?
What should be done FIRST when an AI-powered chatbot starts giving incorrect financial advice after a backend API change?
Which of the following could be used to BEST identify underlying patterns in control effectiveness within unlabeled data elements?
Which of the following is the MOST important course of action for an organization prior to allowing end users to utilize an AI tool?
Which of the following BEST helps an organization manage bias in AI model decisions?
An IS auditor is planning an audit covering a vendor-provided and supported AI model used by the organization to predict train track maintenance. Which of the following is the BEST approach for the IS auditor to test the model?
An AI model predicts vehicle component failures using data collected at different frequencies and formats based on car type. Which of the following is the BEST course of action when evaluating data input requirements for the model?
Which of the following is MOST important to perform when testing an AI model for security?
Which of the following techniques is BEST to use when there is a limited dataset of detailed images available to train a convolutional neural network (CNN) model?
Which of the following presents the GREATEST risk when an organization deploys a machine learning model in a public cloud environment for real-time predictions?