An AI model predicts vehicle component failures using data collected at different frequencies and formats based on car type. Which of the following is the BEST course of action when evaluating data input requirements for the model?
An IS auditor identified data quality issues as a result of insufficient availability of minority data to address diverse class representation. Which of the following is the BEST recommendation to resolve this issue?
From an audit perspective, which of the following BEST supports the objectives of an AI governance program?
Which of the following is MOST effective in analyzing unlabeled datasets to identify anomalies?
Which of the following is MOST important to have in place when initially populating data into a data frame for an AI model?
Which of the following AI system characteristics would BEST help an IS auditor evaluate the system ' s algorithm?
An IS auditor is interviewing management about implemented controls around machine learning (ML) models deployed in the production environment. Which of the following schedules for reviewing the performance of a deployed model would be of GREATEST concern to the auditor?
Which of the following is the MOST important course of action for an organization prior to allowing end users to utilize an AI tool?
An IS auditor is reviewing a dataset used by a university. Which of the following MOST likely indicates a risk that the model could not process all data and make necessary correlations?
During a pre-implementation risk assessment, an AI model is determined to present a significant risk of bias and potential harm in excess of the organization’s risk tolerance. Which of the following is the MOST appropriate response?
Which of the following is the GREATEST concern when an audit team relies on generative AI to create audit reports?
A healthcare organization uses data clustering to group patients by medical history for personalized treatment recommendations. Which of the following is the GREATEST privacy risk associated with this practice?
Which of the following BEST demonstrates effective coordination to ensure comprehensive oversight of an AI system deployed across multiple jurisdictions?
When converting data categories before training an AI model, which of the following scenarios represents the GREATEST risk?
Which of the following is the GREATEST risk associated with deploying an AI system with ineffective anomaly detection?
Which of the following correctly summarizes the conclusions of the model card excerpt provided?
Model Card – Electrical Grid Predictive Maintenance Model
Model Information:
Description: AI model designed to predict maintenance needs for electrical grid components, reduce unplanned downtime, and improve grid reliability.
Inputs: Real-time sensor data, historical maintenance records, and operational logs.
Outputs: Maintenance needs predictions for 60 & 90 days. Evaluation:
Approach: Cross-validation and validation of accuracy, precision, and recall.
Results: Accuracy 72%; Precision 60%; Recall 95%; F1 76%
Which of the following techniques BEST assesses an AI model’s ability to generalize to new data?
Which of the following BEST ensures representativeness in AI systems when assessing training data periodically?
Which of the following sampling strategies would MOST likely involve the use of AI?
Which of the following BEST enables an AI model to solve complex problems involving the analysis of large volumes of unstructured data?
Which of the following is the MOST important purpose of conducting a risk assessment for AI models within an organization?
Which of the following provides the BEST evidence that an organization’s AI integration is aligned with its overall technology strategy?
An IS auditor reviewing the latest AI chatbot release identifies that, despite high accuracy rates, non-English users complain about the model ' s poor accuracy. Which of the following controls is BEST at ensuring detection of subgroup regressions?
An IS auditor is auditing an organization’s data governance framework. The primary objective is to provide assurance that data management practices are standardized to support a trustworthy AI system. Which of the following should be the auditor ' s MOST important consideration?
While evaluating a complex machine learning (ML) model used for regulatory compliance in a financial institution, which of the following should the IS auditor do to BEST ensure transparency?
An IS auditor has discovered that an organization ' s AI system is less accurate than the required threshold and recommends management implement cross-referencing multiple models in order to produce more accurate results. This is an example of which type of risk response?
Which of the following is the MOST important AI data governance method to protect privacy and data security?
An IS auditor observes that an AI-based fraud detection system used by an insurance organization produces inconsistent outcomes when processing similar cases. Which of the following is the auditor ' s MOST efficient recommendation?
An organization deploys an AI recruitment platform to screen job applicants. The IS auditor identifies that the platform ' s decisions may be influenced by model bias. Which of the following risk mitigation strategies is BEST for the auditor to recommend?
Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?
An organization developed an AI model trained on its monthly data. Which of the following would be the BEST validation method to avoid data drift?
Which of the following is the BEST use of AI to audit relationships for conflicts of interest or collusion?
An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?
The BEST way to prevent sensitive information disclosure by large language model (LLM) chatbots is through:
Which of the following is the MOST important reason to perform regular ethical reviews of AI systems?
Which of the following is the BEST key performance indicator (KPI) to measure a model ' s performance on imbalanced datasets?
Which of the following BEST ensures that an AI system complies with user data ownership rights under privacy regulations?
Which of the following is the GREATEST risk associated with the use of AI coding tools by software developers?
Which of the following should be done FIRST when developing an incident management process for AI threats?
An organization plans to implement an AI search and chatbot solution provided by an external vendor. Which of the following is MOST important for an IS auditor to confirm?
During a risk assessment for an AI system, data drift was identified as a key risk. Which of the following is the BEST course of action?
Which of the following is the MOST important consideration when auditing the data used for training an AI model?
Which of the following testing techniques would BEST validate whether an organization ' s data governance program effectively ensures data quality and integrity for AI model training and deployment?
When auditing a research agency ' s use of generative AI models for analyzing scientific data, which of the following is MOST critical to evaluate in order to prevent hallucinatory results and ensure the accuracy of outputs?
Which of the following is MOST important to review in order to gain assurance that an AI model is performing without biases?
An organization is adopting AI for its procurement and inventory teams, raising concern from stakeholders that they will lose their jobs due to AI. Which of the following is the BEST way for the IS auditor to assess whether the potential negative impacts were minimized?
Which of the following AI solutions is BEST used to generate standardized reports using unstructured customer feedback?
Which of the following should be applied to an AI system but are not typically used in traditional systems?
An organization ' s system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?
What should be the IS auditor ' s GREATEST concern when an organization is mixing AI-generated content into training data without labeling?
An organization is training a skin cancer recognition model. Photographs collected from which of the following sources would present the GREATEST risk associated with data integrity?
An organization is using a large language model (LLM) to assist in evaluating loan applications, but the training data used is known to be incomplete. Which of the following is the GREATEST associated risk?
Which of the following is the MOST significant benefit of performing frequent AI model testing and retraining?
Which of the following considerations should be prioritized when using an AI tool to select a sample for conducting an audit of a financial institution ' s transaction processing system?
When developing an audit plan, which of the following is MOST important specifically for the transparency of an AI application?
Which of the following is the MOST important risk for an IS auditor to consider when reviewing the adoption of an AI system?
Which of the following is the GREATEST risk when training data is not separated into distinct training and testing sets?
A bank ' s fraud detection model achieves high accuracy on its initial dataset but performs poorly in production. The data science team needs to tune hyperparameters and select the best model architecture. Which dataset is BEST to use for this selection process?
An AI tool is being implemented for a regional healthcare organization. Which of the following training methods BEST ensures the AI output does not reveal whether someone ' s personal data was used?
Which of the following is the BEST approach to mitigate the risk of " AI model degradation " ?
An IS auditor is considering using a web-based AI tool to update an audit report. What should be the MOST important consideration before inputting the report?
Which of the following is the GREATEST risk associated with normalizing a data set before splitting it into training, testing, and validation sets?
Which of the following is the BEST way to ensure data fed into an AI model aligns with business objectives?
Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?
An organization uses an AI-powered tool to detect and respond to cybersecurity threats in real time. An IS auditor finds that the tool produces excessive false positives, increasing the workload of the security team. Which of the following techniques should the auditor recommend to BEST evaluate the tool ' s effectiveness in managing this issue?
The GREATEST benefit of using AI auditing techniques over traditional methods is that AI auditing techniques can:
Which of the following represents the PRIMARY benefit of reviewing model cards during AI model acquisition and risk assessment?
An IS auditor notes that the combined number of records in the training, validation, and testing sets exceeds the total number of records in the original data set. What is the GREATEST risk?
An IS auditor identifies that an AI model occasionally invents nonexistent medical test results. Which of the following recommendations would BEST mitigate this risk?
Which of the following is the BEST way to mitigate data poisoning in an AI model?
An AI social media platform uses an algorithm to increase user engagement that could unintentionally promote divisive content. Which of the following is the BEST course of action to mitigate this risk?
An IS auditor is reviewing the company ' s AI procedure. Which of the following would be the MOST critical gap?
Which of the following is the MOST important step in an AI incident management process to ensure continuous improvement?
A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?
An organization deploys an AI-based image recognition system that is vulnerable to evasion attacks. Which of the following approaches BEST helps to ensure the system mitigates these evasion attempts?
Which of the following metrics are the BEST indication of a mature and effective approach to an organization ' s data governance program for its AI systems?