Isaca ISACA Advanced in AI Audit (AAIA) AAIA Question # 24 Topic 3 Discussion
AAIA Exam Topic 3 Question 24 Discussion:
Question #: 24
Topic #: 3
During an audit of a bank ' s AI credit scoring system, an IS auditor discovers that applicants were not informed about automated decision-making. Which of the following should the auditor do FIRST?
Transparency is a fundamental legal and ethical requirement for AI systems, particularly under regulations like GDPR, which mandate that data subjects be informed of automated decision-making. If an auditor finds that applicants were not informed, the immediate " First " step is to " Evaluate transparency controls " to determine why the notification process failed and to assess the scope of the non-compliance. This includes reviewing user agreements, privacy notices, and communication procedures. Once the failure is understood and the risk assessed, the auditor can move on to evaluating the appeal process (Option C) or preparing the final report (Option B).
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit