
ISACAAdvanced in AI Risk
Domain 3Objective 3
AI Controls Management (e.g., Evaluation, Selection, Validation) AAIR Practice Questions (Page 5)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
30questions here
6free pages
6concepts
42%of the exam
Questions 21–25
- 21
When evaluating an AI control for potential adoption, which criterion focuses on whether the control achieves its intended risk-reduction objective without introducing excessive operational burden?
Select an answer first - 22
A government agency is evaluating a control that redacts personally identifiable information (PII) from AI-generated summaries before they are released to the public. The agency's risk appetite is very low for privacy breaches, but the control must not significantly delay the release of time-sensitive information. Which evaluation criterion should be weighted most heavily?
Select an answer first - 23
An energy company is evaluating controls for its AI-based grid load forecasting system. The system is critical for preventing blackouts, and the company has a very low risk appetite for forecast errors. However, the company also has a limited budget for AI risk management. Which control evaluation approach best balances these constraints?
Select an answer first - 24
Which validation method involves executing the AI control under controlled conditions to verify it behaves as expected?
Select an answer first - 25
Which factor is most important to consider when selecting an AI control, according to the structured selection process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.