Topic module

Risk Management

This topic covers AI risk identification, assessment, treatment, monitoring, reporting, risk appetite, residual risk, and control effectiveness.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAIA

Treat each item as an audit decision: understand AI risk, identify criteria, test evidence, assess control effectiveness, then report impact and follow-up.

Core concepts

Concept 1

AI risk management identifies threats, vulnerabilities, impacts, likelihood, inherent risk, controls, residual risk, and treatment decisions.

Exam cue: Separate inherent risk, control effectiveness, and residual risk.

Concept 2

Auditors evaluate whether AI risks are assessed consistently across models, data, vendors, users, and business processes.

Exam cue: Trace risk acceptance to approved authority and documented rationale.

Concept 3

Residual risk should be accepted only by authorized decision makers with clear conditions and supporting evidence.

Exam cue: Use risk metrics and KRIs to monitor AI risk over time.

Risk pitfalls and guardrails

Letting technical teams accept business risk without authority.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Using a generic IT risk register that omits model and data behavior.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Treating a point-in-time assessment as continuous risk management.

Guardrail: Avoid treating AI audit as only a technical scan, accepting management assertions without evidence, or omitting prompts, data, vendors, and monitoring.

Memory anchors

Inherent Risk

Inherent risk is AI exposure before considering the effect of controls.

Residual Risk

Residual risk remains after controls, mitigations, and monitoring are applied.

Risk Treatment

Risk treatment selects mitigation, avoidance, transfer, acceptance, monitoring, or escalation.

Risk Acceptance

Risk acceptance is an authorized decision to tolerate residual risk under documented conditions.

Control Effectiveness

Control effectiveness measures whether a control is suitably designed and operating as intended.

KRI

A key risk indicator is a metric that signals changing AI risk exposure.

Risk Register

A risk register records AI risks, ratings, owners, controls, treatment, dates, and status.

Risk Scenario

A risk scenario describes an AI event, cause, impact, likelihood, and affected stakeholders.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Before evaluating controls, an auditor rates the potential harm from an AI hiring model. Which risk is being assessed?

An enterprise risk register lists cybersecurity and availability but omits model bias and data drift. What is the BEST audit conclusion?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.