Isaca ISACA Advanced in AI Risk AAIR Question # 43 Topic 5 Discussion
AAIR Exam Topic 5 Question 43 Discussion:
Question #: 43
Topic #: 5
Which of the following is the GREATEST organizational risk when privacy, cybersecurity, and legal teams are not integrated into the AI oversight committee?
A.
Decentralized approval of changes to AI strategic initiatives
B.
Redundant AI acceptable use policies and guidelines
C.
Operational inefficiency due to reluctance to accept non-critical risk
D.
Unclear accountability for AI control implementation
Within the ISACA Advanced in AI Risk framework, governance decisions should align AI use with policy, accountability, stakeholder expectations, risk appetite, and applicable legal or ethical obligations. When privacy, cybersecurity, and legal functions are absent from integrated oversight, responsibilities can fall between organizational silos. The greatest risk is unclear accountability for control ownership, implementation, escalation, and remediation. This makes option D, Unclear accountability for AI control implementation, the strongest answer. The other choices describe narrower technical, operational, performance, or administrative considerations and do not address the primary risk-management objective in the scenario as directly. A risk practitioner should select the response that most effectively reduces the stated exposure while preserving appropriate oversight, traceability, and alignment with organizational risk tolerance and business requirements.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit