An IS auditor finds that an AI model's outputs are not being reviewed. Which of the following would BEST address this risk?
Which metric is MOST important to consider when reviewing the performance of a machine learning model in avoiding false positive results?
When converting data categories before training an AI model, which of the following scenarios represents the GREATEST risk?
Which metric should an IS auditor review to evaluate issues with data collection that could impact AI model training?
During audit planning, an IS auditor reviews the correlation matrix. Which variable pair from an electrical generation facility has the MOST significant correlation?
Which of the following is the BEST way to ensure data fed into an AI model aligns with business objectives?
After AI training data has been tested for biases, which of the following is MOST important to check to validate the effectiveness of the testing?
Which of the following is the MOST effective control to safeguard a model’s architecture, weights, and hyperparameters?
Which of the following is an IS auditor MOST likely to use in order to ensure an AI model has the ability to make correct predictions?
While evaluating a complex machine learning (ML) model used for regulatory compliance in a financial institution, which of the following should the IS auditor do to BEST ensure transparency?
Which of the following is an IS auditor's MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?
Which of the following metrics are the BEST indication of a mature and effective approach to an organization's data governance program for its AI systems?
An IS auditor uses an internally developed generative AI tool to prepare a status update for audit stakeholders. Which of the following is the auditor’s MOST appropriate course of action?
An organization is training a skin cancer recognition model. Photographs collected from which of the following sources would present the GREATEST risk associated with data integrity?
Which of the following should be done FIRST when developing an incident management process for AI threats?
An IS auditor is evaluating an organization's incident management program to ensure it is sufficiently prepared to manage AI-related incidents. Which of the following is MOST important for the auditor to validate?
Which of the following should be an IS auditor's GREATEST concern when using a predictive AI tool to analyze data abnormalities?
An organization is developing an AI system that integrates data from multiple external sources without clearly defined data ownership policies. Which of the following is the GREATEST concern in this situation?
Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?
An IS auditor is reviewing an AI application that uses customer data to refine the organization’s marketing outreach strategies. Which of the following should be the auditor’s PRIMARY focus during this review?
Which use case for an AI model to be used by a food delivery service would pose ethical risk to the organization?
Which of the following techniques would be MOST effective as part of incident management procedures for a prompt injection attack?
Which of the following is the BEST reason that recurrent neural networks enable language translation of documents?
The BEST way to prevent sensitive information disclosure by large language model (LLM) chatbots is through:
An organization uses an AI-powered tool to detect and respond to cybersecurity threats in real time. An IS auditor finds that the tool produces excessive false positives, increasing the workload of the security team. Which of the following techniques should the auditor recommend to BEST evaluate the tool's effectiveness in managing this issue?
An insurance company uses an AI model to set premium rates. To align with AI-related policies on fairness, which of the following is the FIRST course of action?
A bank uses a video-based know your customer (KYC) verification process. Cybercriminals exploit this process by using deepfake technology to impersonate bank customers. Which of the following countermeasures is the BEST way for the bank to mitigate this risk?
An IS auditor is testing an AI model used for determining insurance premiums and eligibility. Which of the following is the MOST effective testing method to identify bias in algorithm outputs?
What should be done FIRST when an AI-powered chatbot starts giving incorrect financial advice after a backend API change?
Which of the following should be done FIRST when an attacker exfiltrates sensitive information from an AI model?
A car manufacturer uses an AI model to predict maintenance needs for its vehicles. Which of the following techniques can an IS auditor apply to MOST effectively verify the AI model's decisions to stakeholders?
An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?
An organization's system development process has been enhanced with AI. Which of the following features presents the GREATEST risk?
An IS auditor notes the combined number of records utilized within the training, validation, and testing data sets exceeds the total number of records in the original data set. Which of the following is MOST important for the auditor to determine?
From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?
Which of the following is the BEST use of AI to audit relationships for conflicts of interest or collusion?
Which of the following controls would MOST effectively mitigate worst-case service disruption scenarios affecting an AI-based application system?
Which of the following BEST ensures that an AI system complies with user data ownership rights under privacy regulations?
An IS auditor is looking to expedite reporting for an audit with complex issues. Which of the following would be the MOST effective way for the auditor to use generative AI?
When an IS auditor is reviewing results from an AI system, which of the following would cause the GREATEST risk?
An IS auditor is testing an AI-based fraud detection system that flags suspicious transactions and finds that the system has a high false positive rate. Which of the following testing methods should be prioritized to BEST optimize the detection rate?
Which of the following is the GREATEST data quality risk when using an AI tool to assist with audit procedures?
An IS auditor is assessing the implementation of AI tools for evidence collection involving multiple data sources. Which of the following outcomes BEST indicates that AI-driven evidence collection has improved the audit process?
A generative AI system has a validation control in place to reject inappropriate questions by checking them against built-in ethical standards. Which of the following enables malicious actors to circumvent this control through prompt engineering?
Which of the following is the MOST important reason to perform regular ethical reviews of AI systems?
When an IS auditor uses generative AI with external RAG (retrieval-augmented generation) to gather evidence during an audit, which of the following poses the GREATEST data security risk?
During an audit of an investment organization's AI-powered software, an IS auditor identifies a potential security risk. What is the GREATEST risk associated with staff exfiltrating organizational data to a generative AI tool?
An IS auditor is evaluating an organization’s data governance controls for its AI system. Which of the following represents the GREATEST risk in this context?
What is the MOST important reason government organizations should provide regular AI training programs for all staff?
An organization deploys an AI recruitment platform to screen job applicants. The IS auditor identifies that the platform's decisions may be influenced by model bias. Which of the following risk mitigation strategies is BEST for the auditor to recommend?