Free AAIA AI Governance and Risk Practice Questions
This 10-question domain test represents 33% of the ISACA AAIA exam and covers AI governance structures, policy, accountability, risk assessment, ethics, privacy, and regulatory considerations. Work through each question, then review the explanation to identify the audit principle or control behind the answer.
Return to the AAIA practice-test hub or try the 10-question mixed test.
10 Sample Questions with Answers
Sample Question 1 — AI Governance and Risk
A large financial services organization has an approved AI policy requiring all AI use cases to be registered and risk-tiered before production use. The central AI inventory is populated through business unit self-reporting. During audit planning, procurement records show several AI-related subscriptions not listed in the inventory, and SSO logs show active users of those applications. Management states the missing items are likely low-risk drafting tools. Which control deficiency is MOST significant?
- A. The AI policy has not been refreshed since several business units adopted generative AI tools.
- B. The AI inventory is not reconciled to procurement and access records before oversight reporting. (Correct answer)
- C. The steering committee minutes do not consistently record discussion of low-risk AI use cases.
- D. The risk-tiering template does not require a separate field for vendor model ownership.
Correct answer: B
Explanation: B is correct because inventory completeness is the foundational governance control. If the inventory relies on self-reporting and is not reconciled to independent sources such as procurement and access records, the organization cannot demonstrate that all AI use cases were registered and risk-tiered before production. That weakness undermines committee oversight, reporting, and downstream control reliance. A is relevant but less significant because a policy can be current and still be ineffective if completeness is not validated. C is a downstream issue; committee discussion cannot cover use cases that never entered the inventory. D may improve classification detail, but it is less critical than the failure to identify the full population of AI use cases.
Sample Question 2 — AI Governance and Risk
An auditor is evaluating whether a post-deployment monitoring control for a credit risk AI model operated effectively during the audit period. The control requires threshold breaches to be investigated, approved, and tracked to closure. Which evidence BEST supports the conclusion?
- A. Monitoring logs reconciled to incident tickets showing breach review, approval, and closure dates. (Correct answer)
- B. A dashboard screenshot showing current model accuracy and stability metrics within tolerance.
- C. A quarterly attestation from the model owner stating that monitoring was performed as required.
- D. A validation report issued before deployment showing that baseline model performance was acceptable.
Correct answer: A
Explanation: A is the best evidence because it directly supports operating effectiveness during the audit period. Reconciliation of monitoring logs to incident tickets demonstrates that breaches were detected completely and that each required step—investigation, approval, and closure—occurred. B shows only current status at a point in time and does not prove that breaches during the period were handled as required. C is weaker evidence because management attestation does not independently demonstrate control execution. D relates to predeployment validation, not post-deployment monitoring performance during the period under review.
Sample Question 3 — AI Governance and Risk
A financial services firm requires material AI model changes to be approved by the model risk committee before release. Management states that no unauthorized model changes occurred during the audit period. Which evidence BEST supports the conclusion?
- A. Change tickets reconciled to deployment logs with committee approvals for all material releases. (Correct answer)
- B. A management representation letter stating that all material changes followed the approval process.
- C. Meeting minutes showing the committee discussed several AI model changes during the period.
- D. A release calendar listing planned model updates and responsible teams for the audit period.
Correct answer: A
Explanation: A is best because the conclusion requires evidence of both completeness and authorization: the auditor must know what was actually deployed and whether each material release had committee approval. Reconciling change tickets to deployment logs, then tracing them to approvals, provides that assurance. B is weaker because a representation letter is not independent evidence of actual deployments. C may show that some changes were discussed, but it does not demonstrate that all material deployed changes were approved. D reflects planned activity rather than what was actually released, so it cannot support a conclusion that no unauthorized changes occurred.
Sample Question 4 — AI Governance and Risk
An auditor is assessing whether management actively monitors AI risk appetite limits for a credit underwriting model. Management provides policy statements, a quarterly dashboard, and meeting materials. Which evidence BEST supports the conclusion?
- A. Risk committee minutes showing reviewed limit breaches, assigned actions, and tracked closure status. (Correct answer)
- B. The approved AI risk appetite statement defining acceptable thresholds for credit model outcomes.
- C. A management attestation stating that no unresolved AI risk appetite breaches remain open.
- D. A model performance dashboard showing monthly trends for approval rates and default indicators.
Correct answer: A
Explanation: A is the strongest evidence because it demonstrates operating effectiveness of governance oversight: breaches were reviewed, accountability was assigned, and remediation was tracked to closure. B supports control design by showing thresholds exist, but it does not show active monitoring. C is weaker because attestation is management representation rather than direct evidence of review and follow-up. D shows monitoring data exists, but not that management reviewed breaches, escalated issues, or ensured corrective action.
Sample Question 5 — AI Governance and Risk
An enterprise AI policy requires material model changes to be independently reviewed before implementation. Management states that all changes followed the policy, but the change log shows several emergency updates to a fraud detection model during a high-volume attack. Which audit procedure is MOST appropriate?
- A. Select emergency changes and verify independent review, approval timing, and post-implementation ratification. (Correct answer)
- B. Interview the fraud operations manager to confirm the business need for emergency model updates.
- C. Inspect the AI policy to confirm whether emergency changes are permitted under defined conditions.
- D. Compare fraud loss trends before and after the emergency updates to assess business effectiveness.
Correct answer: A
Explanation: A is best because it directly tests operating effectiveness of the exception process for the highest-risk population: emergency changes. Verifying whether independent review occurred, whether approval timing complied with policy, and whether required ratification happened provides direct audit evidence. B is only inquiry and does not confirm the control operated. C evaluates policy design, not whether the control actually functioned for the emergency updates. D evaluates business outcome, which may be relevant operationally but does not evidence compliance with change governance requirements.
Sample Question 6 — AI Governance and Risk
A global manufacturing company maintains an enterprise AI inventory that lists approved AI tools, owners, and risk ratings. During planning, the auditor notes several AI-related software subscriptions in expense records and sign-on logs that do not appear in the inventory. Management states these tools are only used for experimentation and are not part of production processes. Which audit procedure is MOST appropriate?
- A. Reconcile the AI inventory to procurement, expense, and access records, then test how unmatched items were assessed. (Correct answer)
- B. Review the AI inventory policy and confirm whether it requires business units to register experimental tools.
- C. Inspect approvals for the listed high-risk AI systems and determine whether owners completed required reviews.
- D. Interview business unit leaders to determine whether unlisted tools are used only for limited experimentation.
Correct answer: A
Explanation: A is best because the auditor has indications that the governed population may be incomplete. Reconciling the inventory to independent sources such as procurement, expense, and access records provides stronger evidence of completeness and operating effectiveness than relying on the inventory itself or management statements. The key audit judgment is that downstream AI governance controls cannot be relied upon if relevant AI tools are excluded from the inventory.
Why the other options are weaker:
B) Reviewing the AI inventory policy tests control design, while the scenario raises an operating effectiveness issue involving potentially unregistered AI tools.
C) Inspecting approvals for listed high-risk AI systems is a relevant procedure, but it does not address whether the inventory excludes tools that should be subject to governance.
D) Interviews may provide useful context, but they are weaker evidence than reconciliations and do not independently verify the completeness of the AI inventory.
Sample Question 7 — AI Governance and Risk
A retail bank deploys a vendor-hosted generative AI assistant to support customer service agents. Procurement completed a standard vendor security review, and the service has met availability targets for six months. The contract allows the vendor to change the underlying model and service behavior without prior notice, and it does not specify AI-related audit rights or data-use restrictions. What is the PRIMARY audit concern?
- A. The organization may lack enforceable oversight of vendor changes, data use, and AI-specific assurance obligations. (Correct answer)
- B. The organization may be relying on availability results instead of validating the assistant's response accuracy.
- C. The organization may not have sufficient internal expertise to independently review the vendor's model design.
- D. The organization may be using a standard procurement workflow instead of a technology-specific onboarding path.
Correct answer: A
Explanation: A is best because the main governance risk is the absence of enforceable third-party AI obligations. A standard security review and good availability performance do not address AI-specific risks such as provider model changes, data usage, audit rights, notification duties, and assurance access. The subtle distinction is that the deficiency is not simply poor vendor performance; it is weak control design over outsourced AI risk.
Why the other options are weaker:
B) Response quality matters, but the scenario's strongest concern is the inability to govern vendor-controlled changes and obligations.
C) Lack of internal model-design expertise may be relevant for some AI audits, but it is not the primary issue when contractual governance rights are absent.
D) The audit issue is not the workflow label; it is the lack of AI-specific contractual controls and oversight rights.
Sample Question 8 — AI Governance and Risk
A lender uses AI-generated risk summaries to support credit analysts reviewing small business loan applications. The procedure states that analysts make the final decision and must escalate cases when specified risk indicators appear. Management reports a low complaint rate and states that analysts can override AI-generated recommendations. Which evidence BEST supports the conclusion that human oversight is operating effectively?
- A. Sampled case records showing analyst rationale, documented overrides, and escalations consistent with defined criteria. (Correct answer)
- B. Training completion records showing analysts acknowledged procedures for review, override, and escalation.
- C. Management reports showing low complaint volumes and stable approval rates after AI deployment.
- D. Workflow configuration records showing analysts have system permissions to override AI recommendations.
Correct answer: A
Explanation: A is best because it provides direct, case-level evidence that reviewers exercised judgment and followed escalation criteria in actual decisions. For operating effectiveness, documented execution of the control is stronger than evidence that staff were trained, outcomes were favorable, or system functionality existed. The key distinction is between the presence of an oversight capability and evidence that meaningful oversight occurred.
Why the other options are weaker:
B) Training records support control readiness more than operating effectiveness; training does not prove analysts actually challenged or escalated AI outputs.
C) Outcome metrics like complaints and approval rates are useful contextual evidence but indirect — they may not reveal whether the required human review control operated.
D) Permission to override supports control design or system capability, but it does not demonstrate that analysts performed meaningful oversight.
Sample Question 9 — AI Governance and Risk
A financial services organization has moved a customer-facing AI assistant and several internal analyst copilots into production. Different executives claim partial ownership, and the innovation policy mentions oversight but does not define AI-specific accountability. What should the auditor evaluate FIRST?
- A. Whether model quality metrics have remained within approved tolerance levels
- B. Whether accountable owners and approval authority are formally established (Correct answer)
- C. Whether business units report user satisfaction with deployed AI tools
- D. Whether committee meetings include regular updates on AI adoption
Correct answer: B
Explanation: B is correct because the scenario indicates a governance design gap: AI systems are in production, ownership is unclear, and policy does not define AI-specific accountability. The auditor should first determine whether formal ownership and approval authority exist, because those controls establish who can accept risk, approve deployment, and receive escalations. A is less appropriate because performance metrics do not address whether governance authority exists. C is weaker because user satisfaction is an outcome measure, not evidence of accountability or control design. D is relevant to oversight activity, but regular committee updates do not by themselves establish formal ownership, decision rights, or approval thresholds.
Sample Question 10 — AI Governance and Risk
A retail bank deployed an AI-based customer complaint triage tool that can affect regulatory response timelines. The business unit accelerated release after a successful pilot. Compliance staff attended informal project meetings, but the auditor finds no formal AI risk classification or governance committee approval before production deployment. Which control deficiency is MOST significant?
- A. The pilot benefits were not reconciled to post-deployment efficiency targets.
- B. The AI use case lacked documented risk classification and approval. (Correct answer)
- C. Compliance involvement was evidenced mainly through informal meeting attendance.
- D. The technology policy did not separately define AI development practices.
Correct answer: B
Explanation: B is correct because the key governance design failure is the absence of a formal control requiring risk classification and approval before a high-risk AI use case is deployed. That gap leaves accountability, risk ownership, and authorization unresolved. C is relevant, but informal compliance participation is weaker evidence of oversight and is secondary to the missing approval control itself. D may indicate a broader policy weakness, but it is less significant than the specific failure to classify and approve this production deployment. A is a benefits-realization issue and does not address the primary pre-deployment governance risk.
AAIA Practice Test FAQs
What is the ISACA Advanced in AI Audit (AAIA) exam?
AAIA is an ISACA certification exam focused on auditing artificial intelligence systems. It covers AI governance and risk, AI operations, and AI auditing tools and techniques.
How many questions and how much time does the AAIA exam have?
The AAIA exam configuration is 90 questions in 150 minutes across three domains.
What score is required for AAIA?
ISACA uses a scaled score, with 450 on an 800-point scale listed as the passing score in the exam configuration. Practice-test percentages are not equivalent to an official ISACA scaled score.
How should I use AAIA practice questions?
Use mixed questions to find broad knowledge gaps, then use domain practice to review the concepts and explanations behind incorrect answers. FlashGenius readiness thresholds are study guidance, not official ISACA passing scores.
Which AAIA domain has the greatest weight?
AI Operations has the largest listed weight at 46%, followed by AI Governance and Risk at 33% and AI Auditing Tools and Techniques at 21%.
Explore AAIA Tests