1 of 15
Question 1 of 10 · AI Governance and Risk
Which is an example of an AI-specific risk for the risk register?
Confident but wrong outputs, or hallucinations, are AI-specific risks.
Question 2 of 10 · AI Operations
Why should AI system logs be retained?
Logs provide evidence for investigation and oversight, subject to privacy limits.
Question 3 of 10 · AI Auditing Tools and Techniques
What should an AI audit report include about limitations?
Readers need to know what was not covered.
Question 4 of 10 · AI Governance and Risk
Which governance body should approve high-risk AI uses?
High-risk uses need approval at a defined level of authority.
Question 5 of 10 · AI Operations
An auditor finds that a model's performance has declined since deployment. What is the MOST likely cause?
Changes in the input distribution degrade performance over time.
Question 6 of 10 · AI Auditing Tools and Techniques
What should an auditor document about prompts used with a generative AI audit tool?
Documentation lets others follow and reperform the work.
Question 7 of 10 · AI Governance and Risk
An auditor is planning a review of AI governance. What should the auditor obtain FIRST?
The inventory defines the population and owners; without it the auditor cannot scope or sample.
Question 8 of 10 · AI Operations
What is the MAIN purpose of monitoring a deployed model?
Monitoring catches performance and behavior changes that emerge in production.
Question 9 of 10 · AI Auditing Tools and Techniques
Which sampling approach is BEST for testing AI decisions for errors?
Auditor-selected samples that represent the population avoid bias.
Question 10 of 10 · AI Governance and Risk
What should an organization do when an AI vendor changes its terms to allow training on customer data?
Term changes affect data risk and require assessment.
0 of 10
AI Governance and Risk
AI Operations
AI Auditing Tools and Techniques