During an audit of an investment organization's AI-powered software, an IS auditor identifies a potential security risk. What is the GREATEST risk associated with staff exfiltrating organizational data to a generative AI tool?
An IS auditor is auditing an organization’s data governance framework. The primary objective is to provide assurance that data management practices are standardized to support a trustworthy AI system. Which of the following should be the auditor's MOST important consideration?
Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?
An organization deploys an AI recruitment platform to screen job applicants. The IS auditor identifies that the platform's decisions may be influenced by model bias. Which of the following risk mitigation strategies is BEST for the auditor to recommend?
Which of the following should be done FIRST when an attacker exfiltrates sensitive information from an AI model?
An AI social media platform uses an algorithm to increase user engagement that could unintentionally promote divisive content. Which of the following is the BEST course of action to mitigate this risk?
Which of the following controls would MOST effectively mitigate worst-case service disruption scenarios affecting an AI-based application system?
A digital bank utilizes an AI system to generate credit scores. Which of the following would BEST mitigate the risk of sudden and unexplained changes in a borrower’s credit score?
Which of the following is the MOST important consideration when auditing the data used for training an AI model?
Which of the following is the MOST important reason to perform regular ethical reviews of AI systems?
Which of the following do supervised AI learning models PRIMARILY use to train algorithms?
A healthcare organization uses patient data to train an AI model for early disease detection. Which of the following practices provides the BEST assurance that personal data is secure and its integrity is maintained?
When auditing an AI system, which of the following steps ensures that AI model behavior is aligned with organizational objectives?
Which of the following is the MOST important task when gathering data during the AI system development process?
When auditing a machine learning (ML) solution, false positives can BEST be assessed by examining the level of:
Which of the following is the PRIMARY reason IS auditors must be aware that generative AI may return different investment recommendations from the same set of data?
Which of the following BEST ensures that an AI system complies with user data ownership rights under privacy regulations?
Which of the following will provide the BEST evidence to support the alignment of an AI model with an organization's business objectives?
An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor's BEST recommendation to address this issue?
A healthcare organization uses an AI model to analyze patient data and provide diagnostic recommendations. Which of the following MOST effectively detects data drift related to the model's predictions?
When using off-the-shelf AI models, which of the following is the MOST appropriate way for organizations to approach vendor management?
When utilizing a machine learning (ML) model to predict whether a wind turbine electricity generator will fail, which model evaluation metric should be the PRIMARY focus?
An organization is adopting AI for its procurement and inventory teams, raising concern from stakeholders that they will lose their jobs due to AI. Which of the following is the BEST way for the IS auditor to assess whether the potential negative impacts were minimized?