Topic module

Ethical, Legal, Regulatory and Compliance Requirements

Auditors should evaluate how AI systems address ethics, legal duties, regulations, standards, policy requirements, transparency, and accountability.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAIA

Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.

Core concepts

Concept 1

AI compliance maps system purpose, data, users, outputs, jurisdictions, and obligations to laws, regulations, standards, and policies.

Exam cue: Map obligations to the AI use case and jurisdiction before testing controls.

Concept 2

Ethical review considers fairness, transparency, explainability, accountability, human oversight, and potential harm.

Exam cue: Look for explainability and human oversight where decisions affect people.

Concept 3

Auditors verify that compliance obligations are translated into control requirements and evidence.

Exam cue: Verify that compliance monitoring continues after deployment.

Risk pitfalls and guardrails

Relying on a policy statement without testable controls.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Ignoring jurisdiction-specific AI, privacy, or consumer protection duties.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Treating ethics as separate from audit evidence and accountability.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Memory anchors

Obligation Mapping

Obligation mapping connects AI use cases to laws, regulations, standards, policies, and control requirements.

Ethical Review

Ethical review evaluates fairness, transparency, accountability, explainability, human oversight, and harm.

Compliance Control

A compliance control translates an obligation into a repeatable requirement, check, approval, or evidence item.

Transparency

Transparency explains how an AI system is used, what it affects, and what users or subjects should know.

Explainability

Explainability helps stakeholders understand the factors or logic behind AI output or decisions.

Human Oversight

Human oversight keeps accountable review over high-impact or sensitive AI outputs.

Policy Requirement

A policy requirement states an internal AI compliance expectation that auditors can test.

Regulatory Evidence

Regulatory evidence proves the organization considered and met applicable external requirements.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company plans one AI screening model for applicants in several countries. What should the compliance team do FIRST?

A policy promises fair AI decisions but defines no tests, thresholds, or owners. What is the PRIMARY weakness?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.