Which of the following is the PRIMARY benefit of defining and documenting a RACI matrix for AI solution development and deployment?
Correct Answer: D
A RACI (Responsible, Accountable, Consulted, Informed) matrix is a governance tool that explicitly maps roles and decision authority across project activities. For AI systems, RACI frameworks ensure that accountability for decisions, outputs, and risk management is clearly defined and documented. Why D is Correct: The ISACA AAIR curriculum identifies the RACI matrix as a foundational accountability instrument. Its primary benefit is establishing unambiguous responsibility and decision authority, which is essential for AI governance where multiple stakeholders-technical teams, business owners, risk practitioners, compliance officers-must work together with clear lanes of authority. This clarity prevents accountability gaps and ensures risk management actions are owned. Why A is Wrong: Facilitating collaboration is a secondary benefit. While RACI does support cross-functional coordination, collaboration enablement is not its defining purpose. Collaboration can occur without a RACI through other mechanisms. Why B is Wrong: Consolidating governance authority in senior leadership describes centralization, which is not the purpose of RACI. In fact, RACI typically distributes responsibility across multiple levels rather than consolidating it. Why C is Wrong: Strengthening technical development governance is an application of the RACI, not its primary benefit. The RACI benefit is accountability clarity, which then supports technical and architectural governance.
AAIR Exam Question 32
Which of the following is the GREATEST risk when an AI system requires a specific safeguard that cannot be put in place because of technical constraints?
Correct Answer: A
When required safeguards cannot be technically implemented, the risk they were designed to mitigate remains unaddressed. This creates a residual exposure gap where the AI system operates with known, unmitigated vulnerabilities-a fundamental risk management failure for the identified threat. Why A is Correct: The ISACA AAIR risk treatment guidance identifies elevated residual exposure from absent controls as the greatest risk when required safeguards cannot be implemented. Every required safeguard addresses a specific risk exposure. When that safeguard is technically infeasible, the risk it was designed to prevent remains fully present. This unmitigated exposure may exceed the organization's risk tolerance and require escalation to senior management for risk acceptance or alternative treatment decisions. Why B is Wrong: Training dataset restrictions relate to model development constraints, not directly to the inability to implement a specific runtime safeguard. This is a separate concern that may arise in some technical constraint scenarios but is not the primary risk of an absent safeguard. Why C is Wrong: User experience degradation is an operational quality concern. Performance impacts from technical constraints are a usability issue rather than a risk exposure representing the greatest organizational concern. Why D is Wrong: Operational inefficiency and manual process dependencies are resource and process concerns. While relevant to operational cost and effectiveness, they do not represent the primary risk of an unmitigated security or safety exposure from an absent safeguard.
AAIR Exam Question 33
Which of the following poses the GREATEST challenge when performing root cause analysis for incidents involving AI systems and data?
Correct Answer: A
Root cause analysis for AI incidents requires the ability to trace system behavior back through decision logic, data processing steps, and model internals to identify what caused the incident. AI systems-particularly deep learning models-often operate as black boxes, making this tracing extremely difficult. Why A is Correct: According to ISACA AAIR incident management guidance, the lack of transparency in AI systems is the greatest root cause analysis challenge. When decision logic cannot be inspected, when data lineage is unclear, or when model internals are opaque, analysts cannot determine why the system behaved as it did. This transparency deficit prevents accurate root cause identification, perpetuates recurrence, and makes it impossible to demonstrate corrective action to regulators. Why B is Wrong: Unclear system objectives represent a design and governance problem that should be addressed before deployment. While unclear objectives can contribute to incidents, they are typically knowable and addressable. Lack of transparency during an incident is a more immediate analytical barrier. Why C is Wrong: Automation bias-the tendency to over-trust automated systems-is a human factors risk that affects decision-making during normal operations. While it may contribute to incidents, it is a behavioral phenomenon rather than the primary technical barrier to root cause analysis. Why D is Wrong: Privacy compliance requirements may restrict access to certain data needed for analysis, creating constraints on investigation. However, these are governance constraints that can often be addressed through appropriate authorization, not fundamental analytical barriers.
AAIR Exam Question 34
A manufacturing organization has implemented an autonomous navigation system for warehouse operations. Which of the following should a risk practitioner regard as the MOST significant concern?
Correct Answer: A
Autonomous navigation systems in physical environments like warehouses operate in complex, dynamic spaces where unexpected situations arise regularly. Systems trained on limited scenarios may behave unpredictably-or dangerously-when confronted with conditions outside their training distribution. Why A is Correct: The ISACA AAIR guidance on autonomous systems identifies the inability to generalize beyond training scenarios as the most significant concern because it creates direct physical safety risks. In a warehouse, an autonomous system that cannot adapt to novel situations-unexpected obstacles, unusual layouts, human workers in unexpected locations-may collide with equipment or personnel, causing injury or property damage. This operational safety risk is the highest priority concern. Why B is Wrong: Proprietary datasets in the neural network represent an intellectual property and data privacy concern. While relevant, it is a data governance issue that does not create the same magnitude of physical safety risk. Why C is Wrong: Using AI to accelerate just-in-time processes is an intended operational use. Process acceleration is the value proposition, not a risk concern. The risk lies in how reliably and safely that acceleration is achieved. Why D is Wrong: Reliance on outside contractors reflects a workforce capability gap but represents a manageable governance risk through appropriate vendor oversight. It does not create the direct physical safety exposure of a system that cannot handle novel situations.
AAIR Exam Question 35
An organization is integrating AI systems into core business operations and has decided to establish a formal process to align AI initiatives with corporate values. Which of the following is the GREATEST benefit of this decision?
Correct Answer: D
Aligning AI initiatives with corporate values establishes ethical foundations that directly influence how models are designed, deployed, and governed. This alignment is most powerfully expressed through enhanced transparency and explainability of AI decisions. Why D is Correct: The ISACA AAIR Study Guide identifies transparency and explainability as core benefits of value-aligned AI governance. When AI processes are formally anchored to corporate values, organizations build systems that can explain their decisions to regulators, customers, employees, and the public. This fosters trust, enables accountability, and supports compliance across all stakeholder groups-producing the most broadly impactful organizational benefit. Why A is Wrong: This option suggests a sequential approach where ethics are retrofitted after deployment, which is actually a risk and poor practice. The formal alignment process prevents this problem rather than enabling it. Why B is Wrong: ROI evaluation is a financial management function. While valuable, it is a narrow benefit compared to the enterprise-wide stakeholder value created by transparency and explainability. Why C is Wrong: Obtaining executive support for training is an organizational change management benefit. While useful, it is a means to an end rather than the primary organizational benefit of value alignment.