AAIA ISACA Advanced in AI Audit (AAIA) Questions and Answers
An AI social media platform uses an algorithm to increase user engagement that could unintentionally promote divisive content. Which of the following is the BEST course of action to mitigate this risk?
Which of the following is the MOST important consideration when auditing the data used for training an AI model?
Which of the following is the MOST important risk for an IS auditor to consider when reviewing the adoption of an AI system?
After AI training data has been tested for biases, which of the following is MOST important to check to validate the effectiveness of the testing?
Which of the following is the GREATEST risk associated with the use of AI coding tools by software developers?
An organization uses an AI-powered tool to detect and respond to cybersecurity threats in real time. An IS auditor finds that the tool produces excessive false positives, increasing the workload of the security team. Which of the following techniques should the auditor recommend to BEST evaluate the tool's effectiveness in managing this issue?
Which of the following is the MOST important reason to conduct regular threat modeling exercises for AI systems and data?
Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?
Which of the following key performance indicators (KPIs) are MOST important when evaluating whether an AI model meets business objectives?
Which of the following is the GREATEST risk of using AI to generate audit reports?
An AI healthcare diagnostic tool requires large volumes of patient data, raising concerns about privacy and data breaches. Which of the following is the MOST effective strategy to mitigate this risk?
Which of the following initially provides assurance that the developer correctly interprets and identifies numerical data for balancing prior to inserting into the model?
Which role is BEST suited to define the implementation roadmaps for adopting AI solutions?
An IS auditor uses an internally developed generative AI tool to prepare a status update for audit stakeholders. Which of the following is the auditor’s MOST appropriate course of action?
Which of the following strategies used by modelers to enhance data accuracy has the GREATEST risk of bias and information loss?
An IS auditor finds that an AI model's outputs are not being reviewed. Which of the following would BEST address this risk?
An IS auditor is considering the integration of AI techniques into the audit sampling process. Which of the following BEST enables the auditor to identify high-risk transactions within large data sets for targeted sampling?
Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?
Which of the following is the MOST important course of action for an organization prior to allowing end users to utilize an AI tool?
For a sales promotion, an AI system sorts customer attributes into several categories by analyzing transaction history. Verifying which of the following would BEST validate the effectiveness of this process?
Which of the following is the GREATEST challenge facing IS auditors evaluating the explainability of generative AI models?
The GREATEST benefit of using AI auditing techniques over traditional methods is that AI auditing techniques can:
An IS auditor notes that an AI model achieved significantly better results on training data than on test data. Which of the following problems with the model has the IS auditor identified?
While evaluating a complex machine learning (ML) model used for regulatory compliance in a financial institution, which of the following should the IS auditor do to BEST ensure transparency?
When utilizing a machine learning (ML) model to predict whether a wind turbine electricity generator will fail, which model evaluation metric should be the PRIMARY focus?
When developing an audit plan, which of the following is MOST important specifically for the transparency of an AI application?
An IS auditor is looking to expedite reporting for an audit with complex issues. Which of the following would be the MOST effective way for the auditor to use generative AI?
An IS auditor reviews an AI tool using K-means to cluster customers. One cluster shows very high spending but low product diversity. What should the auditor recommend?
When an IS auditor uses generative AI with external RAG (retrieval-augmented generation) to gather evidence during an audit, which of the following poses the GREATEST data security risk?
During a risk assessment for an AI system, data drift was identified as a key risk. Which of the following is the BEST course of action?
Which of the following should be an IS auditor's GREATEST concern if class imbalance is identified in training data for an AI model?
Which of the following is the BEST way to ensure data fed into an AI model aligns with business objectives?
During a pre-implementation risk assessment, an AI model is determined to present a significant risk of bias and potential harm in excess of the organization’s risk tolerance. Which of the following is the MOST appropriate response?
Which of the following is the BEST use of AI to audit relationships for conflicts of interest or collusion?
An organization deploys a complex AI model to support credit risk assessments. Stakeholders find the model’s output difficult to interpret. Which of the following BEST improves interpretability?
Which of the following is the MOST important purpose of conducting a risk assessment for AI models within an organization?
A healthcare organization uses patient data to train an AI model for early disease detection. Which of the following practices provides the BEST assurance that personal data is secure and its integrity is maintained?
Which of the following is the BEST way to mitigate data poisoning in an AI model?
Which of the following BEST ensures representativeness in AI systems when assessing training data periodically?
When using off-the-shelf AI models, which of the following is the MOST appropriate way for organizations to approach vendor management?
Which of the following controls MOST effectively helps to ensure an AI model is resilient against external threats?
To confirm the fairness of AI model decisions, the BEST way to collect reliable evidence during an AI audit is by:
An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model’s outputs. Which of the following is the IS auditor's BEST recommendation?
An organization deployed an AI-powered customer service chatbot trained using customer chat logs. During a risk assessment, which issue should be the IS auditor’s GREATEST concern?
An organization is reviewing its existing data governance framework after implementing an AI-based document repository solution. Which of the following should be the PRIMARY consideration?
An IS auditor for a veterinary clinic was informed that the dog breed categorical variable is necessary for the predictive model. Which of the following introduces the MOST risk?
A healthcare AI tool recommends treatments with high success rates but significant risk. The hospital prioritizes patient safety over innovation. What is the BEST course of action?
Which of the following is the MOST effective control to safeguard a model’s architecture, weights, and hyperparameters?
An organization has introduced an AI chat system where customers can enter their preferences and the system returns the best product selections. Which of the following is the BEST way to mitigate the risk of the system providing suggestions that may upset customers?
Which of the following would provide the BEST evidence to an IS auditor that an AI model’s outputs are effectively controlled for bias?