
ISACAAdvanced in AI Audit
Domain 1Objective 4
Privacy and Data Governance Programs AAIA Practice Questions (Page 3)
Part of the AI Governance and Risk domain, which accounts for 33% of the AAIA exam.
42questions here
9free pages
14concepts
33%of the exam
Questions 11–15
- 11
A financial services firm uses an AI system for credit scoring. A customer submits a data subject access request (DSAR) to obtain a copy of all personal data the firm holds about them, including the data used to train the AI model. The firm's data inventory shows that the training dataset contains the customer's data, but it is stored in a backup archive. What is the firm's primary obligation regarding this DSAR?
Select an answer first - 12
What is the purpose of regulatory compliance mapping in the context of AI systems?
Select an answer first - 13
Which of the following is a key element of a data processing agreement (DPA) with a third-party vendor?
Select an answer first - 14
A multinational retail company is deploying an AI-powered customer recommendation engine. The data governance team needs to create a complete record of all customer data assets used by the system, including where they are stored, who owns them, and their sensitivity level. The company operates in both the EU and the US. What is the most effective first step for the team to take?
Select an answer first - 15
Which data governance principle is most directly supported by implementing data lifecycle management?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIA” is a trademark of its owner, used for identification only.