Isaca ISACA Advanced in AI Risk AAIR Question # 42 Topic 5 Discussion
AAIR Exam Topic 5 Question 42 Discussion:
Question #: 42
Topic #: 5
An organization deploys an autonomous system that makes decisions affecting compliance with regulations. If those decisions could potentially produce regulatory breaches, which of the following BEST helps to manage associated liability exposures?
A.
Creating a separate compliance program for AI obligations and maintaining distinct reporting channels
B.
Retaining documentation that provides explainability for decisions and embedding controls in oversight processes
C.
Restricting AI deployment to use cases with lower impact and delaying broader operational integration
D.
Routing escalations through a single point of contact and prohibiting disclosure of proprietary information
Liability from autonomous AI decisions affecting regulatory compliance requires organizations to demonstrate accountability, oversight, and control. Documentation of decision rationale and embedded oversight controls are the primary mechanisms for demonstrating responsible governance to regulators.
Why B is Correct: The ISACA AAIR framework identifies explainability documentation and embedded oversight controls as the key liability management tools for autonomous AI systems. When the organization can demonstrate that each AI decision was explainable, that controls were in place to detect violations, and that human oversight was embedded in the process, this demonstrates due diligence—which is the legal and regulatory standard for managing liability from automated decisions.
Why A is Wrong: Separate compliance programs fragment governance and may increase rather than reduce liability by suggesting AI compliance is siloed from the enterprise compliance program. Regulators expect integrated governance.
Why C is Wrong: Restricting deployment represents risk avoidance, not liability management for already-deployed systems. If the system is already in production, deployment restriction does not address existing liability.
Why D is Wrong: Single-point escalation and non-disclosure create governance bottlenecks and conflict with regulatory transparency requirements. Restricting disclosure cannot be used to shield the organization from regulatory accountability for automated decisions.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit