A risk practitioner reviews an AI model that ingests diverse external feeds and determines that their reliability is not consistent. Which of the following BEST mitigates this risk?
Inconsistent data reliability from external feeds undermines model accuracy and creates auditability challenges. The solution requires both understanding where data comes from (provenance) and verifying its quality before it enters the model's learning process (stage gate reviews).
Why C is Correct: The ISACA AAIR data quality governance guidance identifies establishing data provenance and implementing stage gate quality reviews as the comprehensive approach to managing inconsistent external data reliability. Provenance tracking records the origin, processing history, and chain of custody of each data source, enabling quality issues to be traced to their source. Stage gate reviews enforce quality standards at defined points in the data pipeline, preventing unreliable data from advancing to model training.
Why A is Wrong: Weighting historical data over recent samples introduces temporal bias and prevents the model from reflecting current real-world conditions---the opposite of what most AI applications require. This trade-off may be appropriate in specific contexts but is not a general mitigation for inconsistent data reliability.
Why B is Wrong: Updating model versions improves model architecture and training processes but does not resolve the underlying external data quality problems. The model update cannot compensate for ingesting unreliable data.
Why D is Wrong: Reducing data source diversity sacrifices the breadth of information that diverse feeds provide, potentially reducing model performance and representativeness. The goal is to ensure consistent quality from diverse sources, not to reduce diversity.
AI tools can BEST help to mitigate supply chain risk by:
Supply chain risk management requires anticipating disruptions before they materialize. AI's most powerful supply chain contribution is its ability to analyze vast datasets---including signals from suppliers, logistics networks, geopolitical indicators, and environmental data---to predict disruptions with accuracy and lead time that human analysts cannot achieve.
Why B is Correct: The ISACA AAIR AI capability guidance identifies predictive disruption identification as the most significant supply chain risk mitigation AI provides. By processing diverse data signals and identifying patterns that precede supply chain failures, AI enables proactive risk management---allowing organizations to pre-position inventory, identify alternative suppliers, or adjust production schedules before disruptions affect operations.
Why A is Wrong: Automating inventory management is an operational efficiency application. While valuable, it manages existing stock levels rather than predicting and preventing supply disruptions. Automation cannot anticipate future risks not embedded in current inventory patterns.
Why C is Wrong: Historical security control gap identification is a security audit function. Identifying past security weaknesses does not directly mitigate supply chain disruption risks, which may arise from entirely different categories of risk.
Why D is Wrong: Sentiment analysis on supplier reputation provides one qualitative input to supplier risk assessment. While useful for monitoring reputational signals, it captures only a narrow dimension of supply chain risk compared to comprehensive predictive disruption modeling.
Which risk treatment is MOST appropriate when an organization's AI system presents residual risk within tolerance and impacts non-critical functions?
Risk treatment decisions are driven by two factors: whether the residual risk falls within or outside tolerance, and the criticality of the affected function. When both conditions---risk within tolerance AND non-critical function impact---are met, formal risk acceptance is the appropriate and proportionate treatment.
Why A is Correct: According to ISACA AAIR risk treatment guidance, documented formal risk acceptance is the appropriate response when residual risk is within defined tolerance for non-critical functions. Risk acceptance acknowledges the identified exposure, documents the organization's conscious decision to accept it, and establishes accountability for that decision. This proportionate response avoids over-investing in controls for risk that the organization has determined is acceptable.
Why B is Wrong: Recommending increases to tolerance thresholds is a governance manipulation rather than a risk treatment. Adjusting thresholds upward to accommodate risk does not address the risk; it merely reclassifies it as acceptable. This approach undermines risk governance integrity.
Why C is Wrong: Enhancing monitoring to detect deviations represents additional control investment that may be disproportionate for risk that is already within tolerance affecting non-critical functions. Enhanced monitoring is more appropriate when risk is near the tolerance boundary or when trends indicate potential future breach.
Why D is Wrong: Periodic vulnerability scanning is a security assurance activity that identifies technical weaknesses. It represents an ongoing control measure rather than the appropriate risk treatment decision for a residual risk that is already within tolerance.
Which of the following is the MOST important reason for a risk practitioner to classify AI risk using threat actor profiles?
Threat actor profiling characterizes the motivations, capabilities, and likely attack methods of potential adversaries. In AI risk management, understanding who the likely attackers are and what they seek enables the design of controls specifically matched to the actual threat landscape.
Why B is Correct: According to ISACA AAIR threat-based risk management guidance, the most important reason for threat actor profiling is to tailor controls to adversary motivations and capabilities. Different threat actors---nation-state attackers, criminal organizations, competitors, insiders, activists---have different objectives (espionage vs. financial gain vs. disruption), capabilities (sophisticated vs. opportunistic), and methods. Controls calibrated to actual threat actor profiles are significantly more effective than generic controls that may not address the specific threats the organization actually faces.
Why A is Wrong: Aligning AI threats with IT control taxonomy is a governance integration activity that improves control consistency but does not capture the threat actor-specific tailoring value of profiling. Taxonomy alignment is an administrative benefit; threat-tailored controls are a security effectiveness benefit.
Why C is Wrong: Response metrics for cybersecurity incidents are developed for incident management planning. Threat actor profiling informs control design and incident response strategies but is not primarily used to develop response metrics.
Why D is Wrong: Prioritizing external threats over internal threats is a security strategy choice that threat actor profiling does not prescribe. Many AI attacks, including insider threats and social engineering, are internal. Profiling should result in appropriate prioritization based on actual threat likelihood, not a blanket prioritization of external threats.
An election oversight body is considering the use of AI to identify irregularities in voting patterns. Which of the following is the MOST important risk to evaluate?
AI systems trained on historical data inherit the biases, patterns, and structural inequities embedded in that data. In electoral contexts, historical voting patterns may reflect systemic disenfranchisement, gerrymandering, or demographic manipulation---biases that an AI system could amplify and legitimize through its outputs.
Why B is Correct: According to ISACA AAIR bias and fairness guidance applied to high-stakes public sector AI, the amplification of historical data biases poses the greatest risk in electoral irregularity detection. If the AI system treats historically suppressed voting patterns as the normal baseline, it may flag legitimate turnout increases in previously underrepresented communities as irregularities---producing discriminatory, biased outputs with severe democratic consequences.
Why A is Wrong: Voter location identification is a privacy concern but represents a specific data element risk. Comprehensive privacy controls can mitigate location exposure without resolving the systemic bias risk.
Why C is Wrong: Contextual drift---the model performing differently in new electoral contexts than in training contexts---is a technical risk that is relevant but addressable through validation testing. Bias amplification is a more fundamental concern embedded in the historical data itself.
Why D is Wrong: Political distrust of AI represents a stakeholder acceptance challenge. While significant for implementation success, it is a communication and change management concern rather than the primary technical and ethical risk from the AI system itself.
Karan Tiwari
19 days agoSumayya Khan
1 month ago