An AI tool is being implemented for a regional healthcare organization. Which of the following training methods BEST ensures the AI output does not reveal whether someone's personal data was used?
Differential privacy introduces carefully calibrated noise during training or query responses so that it becomes mathematically difficult to infer whether any specific individual's record is included in the training set. For healthcare data---highly sensitive and subject to strict privacy laws---this technique directly supports privacy-by-design, reducing the risk that model outputs leak membership information or reconstruct personal records.
Option A uses real patient records directly and does not, by itself, mitigate inference risk. Option B (data augmentation) may expand the dataset but does not guarantee resistance to membership inference attacks. Option D (transfer learning using public data) can help, but if any private data is used in fine-tuning, privacy risks remain. Differential privacy, as in option C, is the most appropriate control to ensure that outputs do not reveal whether particular personal data was used.
ISACA, AAIA Exam Content Outline -- Domain 1: Privacy and Data Governance Programs; Domain 2: Data Management Specific to AI (data confidentiality, data security).
ISACA guidance on privacy-by-design and AI risk management concepts reflected in AAIA.
Which of the following pre-processing steps would MOST effectively justify an AI model's decision to a non-technical stakeholder?
While all the listed techniques (except penetration testing) support interpretability, 'LIME' is specifically noted in the ISACA AAIA Study Guide for its ability to explain individual decisions. LIME creates a simpler, interpretable model around a specific prediction to show which features (e.g., high income or low debt) were the primary drivers for that specific case. This 'Local' explanation is much easier for non-technical stakeholders or customers to understand than 'Global' metrics like feature importance (Option A) or partial dependence plots (Option C), which describe the model's behavior as a whole.
The internal audit department of a large global organization is evaluating the use of an AI-based voice-to-speech tool to document interviews during audits. The tool uploads all recordings to a cloud service provider for transcription. Which of the following is the GREATEST risk?
Audit interviews often contain highly sensitive, proprietary, or even non-public information. Uploading these recordings to a cloud provider introduces the 'Risk of unauthorized access' by the vendor's employees or through a security breach at the vendor's site. According to ISACA, the loss of 'Confidentiality' over audit workpapers is a critical failure of professional standards. While inaccurate transcriptions (Option D) are a nuisance, they can be corrected by the auditor; however, once sensitive data is compromised by a third party, the damage is irreversible. Auditors must ensure the vendor has rigorous 'encryption' and 'at-rest' security attestations.
Which control is MOST important to verify in order to ensure proper data management with AI systems?
According to the ISACA AAIA Study Guide, a 'Data Governance Framework' is the foundational control. It provides the policies, roles (stewards, owners), and standards necessary to manage the entire data lifecycle. Without a framework, activities like inventorying (Option C) or labeling (Option D) are ad-hoc and lack accountability. A formal framework ensures that data management is consistent, compliant with privacy laws, and aligned with the organization's risk tolerance. It is the 'enabling' control that makes all other data quality and security metrics meaningful and enforceable.
Which of the following could be used to BEST identify underlying patterns in control effectiveness within unlabeled data elements?
When data is 'unlabeled' (meaning the outcomes or 'answers' are not provided), supervised methods like Random Forest (Option D) or XGBoost (Option A) cannot be used. 'Unsupervised learning' is specifically designed to discover 'underlying patterns,' clusters, or latent structures in data without human guidance. For an auditor, unsupervised techniques (like clustering) are invaluable for exploratory analysis, such as grouping similar control failures or identifying unusual transactional behaviors that have not yet been categorized as fraudulent or legitimate.
Crystal Lee
3 days agoJoshua Baker
20 days agoSarah Green
1 month agoSusan Robinson
2 months agoNancy Flores
2 months agoPatricia Williams
3 months agoDonald Davis
3 months agoFrank Murphy
4 months agoEdward Williams
4 months agoJeffrey Moore
5 months agoTimothy Allen
4 months agoStephanie White
4 months agoMonica Edwards
4 months agoJohn White
4 months agoDorathy
5 months agoJohana
5 months agoCarylon
6 months agoPamella
6 months agoKayleigh
6 months agoNina
7 months agoVan
7 months agoSina
7 months agoKelvin
7 months agoJovita
8 months agoDean
8 months agoCarla
8 months agoKenny
8 months agoLouisa
9 months agoSage
9 months agoSommer
9 months agoMalcolm
9 months agoBrande
10 months agoMakeda
10 months agoCaitlin
10 months agoAleisha
10 months agoLorrie
11 months agoCherry
11 months agoShawnee
11 months agoGarry
11 months agoInocencia
12 months agoLawrence
12 months agoFidelia
12 months agoDorothy
1 year agoKandis
1 year agoKris
1 year agoDeeanna
1 year agoTiara
1 year agoElza
1 year ago