An IS auditor is reviewing a dataset related to a restaurant ' s food delivery process. Which of the following data preparation techniques should be used to ensure that no single feature dominates and all fields are weighted appropriately?
Which of the following should be done FIRST when developing an incident management process for AI threats?
Which of the following is the MOST essential attribute of an AI-driven audit tool?
Which of the following should be applied to an AI system but are not typically used in traditional systems?
An organization seeks to sustain effective AI governance and risk management amid rapidly evolving AI technologies. Which of the following represents the MOST effective course of action?
An organization is using a large language model (LLM) to assist in evaluating loan applications, but the training data used is known to be incomplete. Which of the following is the GREATEST associated risk?
Which of the following controls would MOST effectively mitigate worst-case service disruption scenarios affecting an AI-based application system?
A bank is deploying an AI model trained on customer transactions in a multi-cloud environment. Which of the following BEST supports regulatory compliance regarding data security and privacy?
An IS auditor is auditing an organization’s data governance framework. The primary objective is to provide assurance that data management practices are standardized to support a trustworthy AI system. Which of the following should be the auditor ' s MOST important consideration?
Which of the following techniques BEST supports machine learning (ML) training in sentiment analysis?
An organization ' s fraud detection model achieves high accuracy on its initial data set but performs poorly in production. After a complex neural network was trained, the training accuracy was significantly higher than the validation accuracy. Which of the following is the MOST likely cause?
Which of the following is the GREATEST risk associated with the use of AI coding tools by software developers?
Which of the following is MOST important to consider when evaluating ethical risk related to data used for training an AI model?
An insurance organization deployed an AI tool for assigning customer risk levels. An IS auditor discovers that the learning algorithm is vulnerable to adversarial attacks. Which of the following is the BEST course of action?
An IS auditor learns that an organization uses AI facial recognition technology for security purposes. Which of the following is the GREATEST ethical concern with this practice?
An IS auditor is testing an AI-based fraud detection system that flags suspicious transactions and finds that the system has a high false positive rate. Which of the following testing methods should be prioritized to BEST optimize the detection rate?
Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?
An IS auditor examining change management procedures for an AI system observes inconsistent training data validation and verification protocols prior to model retraining. Which of the following is the MOST significant risk in this context?
Which of the following is the BEST way to ensure data fed into an AI model aligns with business objectives?
When an auditor is using AI to test controls, what would be the HIGHEST risk to the audit ' s integrity?
Which of the following considerations should be prioritized when using an AI tool to select a sample for conducting an audit of a financial institution ' s transaction processing system?
What should be done FIRST when an AI-powered chatbot starts giving incorrect financial advice after a backend API change?
Which of the following pre-processing steps would MOST effectively justify an AI model ' s decision to a non-technical stakeholder?
Which of the following should be done FIRST when an AI chatbot has been identified as giving harmful advice?
An IS auditor analyzed an AI model scorecard and identified that training data was imbalanced. Which of the following is the BEST recommendation to remediate risk?
An IS auditor reviews an AI tool using K-means to cluster customers. One cluster shows very high spending but low product diversity. What should the auditor recommend?
Which of the following is MOST important for an IS auditor to review during an AI system audit in order to determine compliance with intellectual property and data rights?
Which of the following is MOST important for an IS auditor to consider when identifying AI risk in a know your customer (KYC) application within a banking organization?
When converting data categories before training an AI model, which of the following scenarios represents the GREATEST risk?
An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?
An IS auditor is evaluating a cybersecurity system that uses agentic AI for autonomous threat detection and incident response. Which of the following is MOST important for the auditor to consider?
An IS auditor is reviewing AI-driven processes that automate financial approvals. Which of the following poses the GREATEST challenge to maintaining separation of duties (SOD)?
When auditing a research agency ' s use of generative AI models for analyzing scientific data, which of the following is MOST critical to evaluate in order to prevent hallucinatory results and ensure the accuracy of outputs?
An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor ' s BEST recommendation to address this issue?
An IS auditor is reviewing a dataset used by a university to train a predictive machine learning model. Which of the following MOST likely indicates risk that the model could not process all data and make necessary correlations?
An IS auditor is evaluating a cybersecurity system that uses " agentic AI " for autonomous response. Which of the following is MOST important to consider?
Which of the following data management practices poses the GREATEST risk to the reliability of an AI model ' s correlations?
When auditing the transparency of an AI system, which of the following would be the MOST effective way to understand the model ' s decision-making process?
An IS auditor identifies that an AI model occasionally invents nonexistent medical test results. Which of the following recommendations would BEST mitigate this risk?
Which of the following BEST helps an organization manage bias in AI model decisions?
A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model ' s predictions?
An organization is training a skin cancer recognition model. Photographs collected from which of the following sources would present the GREATEST risk associated with data integrity?
Which of the following is the BEST way to support the development and design of high-risk AI systems?
Which of the following techniques is MOST appropriate for model hyperparameter tuning?
An AI audit reveals that a loan approval model has a significantly higher rejection rate for a specific demographic group. What should be management ' s PRIMARY response?
Which of the following sampling strategies would MOST likely involve the use of AI?
From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?
An organization has introduced an AI chat system where customers can enter their preferences and the system returns the best product selections. Which of the following is the BEST way to mitigate the risk of the system providing suggestions that may upset customers?
Which of the following components would MOST effectively address cumulative benefits as part of reinforcement learning (RL)?
For a sales promotion, an AI system sorts customer attributes into several categories by analyzing transaction history. Verifying which of the following would BEST validate the effectiveness of this process?
Which of the following techniques BEST assesses an AI model’s ability to generalize to new data?
When using off-the-shelf AI models, which of the following is the MOST appropriate way for organizations to approach vendor management?
An organization deploys an AI-based image recognition system that is vulnerable to evasion attacks. Which of the following approaches BEST helps to ensure the system mitigates these evasion attempts?
Which of the following would pose the GREATEST risk when reviewing AI acceptable use training content?
The internal audit department of a large law firm plans to implement an AI solution to review and analyze contracts stored in its enterprise resource planning (ERP) system. Which of the following AI technologies is MOST suitable for this requirement?
Which of the following represents the PRIMARY benefit of reviewing model cards during AI model acquisition and risk assessment?
An organization using AI to create digital content faces challenges in protecting its intellectual property. Which of the following is the BEST way to mitigate this risk?
An IS auditor is testing an AI model used for determining insurance premiums and eligibility. Which of the following is the MOST effective testing method to identify bias in algorithm outputs?
An IS auditor observes that an AI-based fraud detection system used by an insurance organization produces inconsistent outcomes when processing similar cases. Which of the following is the auditor ' s MOST efficient recommendation?
Which of the following initially provides assurance that the developer correctly interprets and identifies numerical data for balancing prior to inserting into the model?
An IS auditor is reviewing a dataset used by a university. Which of the following MOST likely indicates a risk that the model could not process all data and make necessary correlations?
A car rental company is developing an AI system to dynamically adjust rental pricing based on demand, location, and customer profiles. Which of the following is the MOST important reason to conduct specific testing during development?
An IS auditor is auditing an AI system that predicts inventory needs. The system recently failed to predict a stock outage for a key product. Which of the following audit tests would BEST validate the system ' s accuracy?
From an audit perspective, which of the following BEST supports the objectives of an AI governance program?
An IS auditor is planning an audit covering a vendor-provided and supported AI model used by the organization to predict train track maintenance. Which of the following is the BEST approach for the IS auditor to test the model?
An IS auditor is considering the integration of AI techniques into the audit sampling process. Which of the following BEST enables the auditor to identify high-risk transactions within large data sets for targeted sampling?
An insurance company uses an AI model to set premium rates. To align with AI-related policies on fairness, which of the following is the FIRST course of action?
An IS auditor is evaluating an organization’s data governance controls for its AI system. Which of the following represents the GREATEST risk in this context?
Which of the following is the GREATEST concern when an audit team relies on generative AI to create audit reports?
Which of the following correctly summarizes the conclusions of the model card excerpt provided?
Model Card – Electrical Grid Predictive Maintenance Model
Model Information:
Description: AI model designed to predict maintenance needs for electrical grid components, reduce unplanned downtime, and improve grid reliability.
Inputs: Real-time sensor data, historical maintenance records, and operational logs.
Outputs: Maintenance needs predictions for 60 & 90 days. Evaluation:
Approach: Cross-validation and validation of accuracy, precision, and recall.
Results: Accuracy 72%; Precision 60%; Recall 95%; F1 76%
Which of the following techniques is BEST to use when there is a limited dataset of detailed images available to train a convolutional neural network (CNN) model?
When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?