Isaca ISACA Advanced in AI Security Management (AAISM) Exam AAISM Question # 52 Topic 6 Discussion
AAISM Exam Topic 6 Question 52 Discussion:
Question #: 52
Topic #: 6
An organization is planning to commission a third-party AI system to make decisions using sensitive data. Which of the following metrics is MOST important for the organization to consider?
When AI systems make consequential decisions over sensitive data, AAISM requires explicit performance thresholds tied to decision quality—i.e., accuracy (and related error/false-rate limits) aligned to business risk appetite and regulatory expectations. Availability and latency are important service metrics, but decision integrity and error bounds are primary risk drivers in sensitive contexts. Establishing, monitoring, and enforcing minimum accuracy thresholds (with subgroup performance checks) is essential to reduce harm, ensure fairness/compliance, and support auditability.
[References:• AI Security Management™ (AAISM) Body of Knowledge: Risk-aligned performance metrics; decision quality thresholds; harm and error-rate governance in sensitive processing.• AI Security Management™ Study Guide: Metric selection for high-risk AI; accuracy, false positive/negative limits, and acceptance criteria tied to business controls.]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit