Free AAIA sample questions with answers

Updated September 20, 2026

These follow ISACA’s style: scenario-led, from the auditor’s perspective, with a qualifier that decides the answer. Three of the five come from AI Operations, matching the real weighting.

Question 1. An auditor is reviewing a credit-scoring model. Management asserts the model was validated before release. Which is the BEST audit evidence of that assertion?

  • A. A written statement from the lead developer confirming validation
  • B. The model’s source code and training scripts
  • C. Dated validation results against defined acceptance thresholds, with evidence of approval
  • D. The vendor’s product documentation describing the model’s accuracy
Show answer

Answer: C

Dated validation results measured against pre-defined acceptance thresholds, with evidence of approval, directly support the assertion and can be re-examined. A developer’s statement is unverified testimony, source code shows implementation rather than validation outcomes, and a vendor brochure is marketing material rather than evidence about this deployment.

Question 2. A hosted model used in a production process is updated by its provider. The organisation's change management records show no change. Which is the MOST significant control weakness?

  • A. Insufficient documentation of the original model selection
  • B. Change management does not cover provider-initiated model updates, so changes occur without assessment or revalidation
  • C. Inadequate training for staff using the model
  • D. Lack of encryption on the model endpoint
Show answer

Answer: B

Provider-initiated model updates fall outside the change management process, so behaviour can change in production with no assessment, approval or revalidation. Insufficient documentation and inadequate training are secondary, and a lack of encryption addresses confidentiality rather than uncontrolled behavioural change.

Question 3. An auditor must test whether an AI system's decisions are subject to meaningful human oversight. Which testing approach is MOST appropriate?

  • A. Sample decisions and examine review records, including evidence of overrides
  • B. Obtain the policy stating that human oversight is required
  • C. Interview the model vendor about their oversight recommendations
  • D. Re-perform a sample of inferences and compare outputs
Show answer

Answer: A

Sampling decisions and examining records of review, including cases where a human actually overrode the system, tests whether oversight is meaningful rather than nominal. A policy states intent rather than operation, interviewing the vendor addresses the wrong party, and re-performing inferences tests the model rather than the oversight control.

Question 4. An organisation cannot produce records showing where the training data for a production model originated. Which risk should the auditor report as MOST significant?

  • A. Increased storage costs for undocumented datasets
  • B. Slower retraining cycles in future
  • C. Reduced portability of the model to other platforms
  • D. Inability to demonstrate the data was lawfully obtained and suitable, undermining regulatory defensibility
Show answer

Answer: D

Without provenance the organisation cannot demonstrate the data was lawfully obtained or suitable, which undermines both regulatory defensibility and any assurance over the model’s behaviour. Storage cost, slower retraining and reduced portability are operational consequences rather than the principal risk.

Question 5. Six months after deployment, a model's accuracy has declined although no code or configuration has changed. Which should the auditor examine FIRST?

  • A. Access logs for the model endpoint
  • B. Whether drift monitoring and periodic revalidation controls operated as designed
  • C. Network capacity between the application and the model
  • D. The terms of the software licence agreement
Show answer

Answer: B

Declining performance with no change to code or configuration is the signature of drift, so the first examination is whether monitoring and periodic revalidation were operating as designed. Access logs, network capacity and the licence agreement would not explain a gradual change in decision quality.

How did you do?

Notice how many of these turn on evidence rather than opinion. That is the defining characteristic of AAIA: you are not asked whether an AI practice is good, but what you would request to demonstrate it, and whether what exists is sufficient.

If you found the operations questions harder than the audit-framed ones, that is the expected pattern and it matches the weighting — operations is 46% of the exam. See weeks 3 to 5 of the study plan.