Topic module

AI Risk Assessment and Treatment

Risk management requires identifying AI threats, business impacts, likelihood, inherent risk, residual risk, treatment options, and risk acceptance.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for ISACA AAISM

Treat each item as a management decision: identify the AI asset and stakeholder, assess risk, select governance or control action, then document evidence and accountability.

Core concepts

Concept 1

AI risk assessment evaluates threats, vulnerabilities, impact, likelihood, control effectiveness, and residual risk.

Exam cue: Use inherent risk before controls and residual risk after controls.

Concept 2

Risk treatment options include mitigate, transfer, avoid, accept, monitor, or escalate based on risk appetite and business need.

Exam cue: Use risk treatment when the assessment shows risk outside appetite.

Concept 3

Residual risk should be accepted only by authorized decision makers with clear evidence and conditions.

Exam cue: Use formal acceptance when residual risk remains after treatment.

Risk pitfalls and guardrails

Accepting risk at the technical team level without business authority.

Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.

Ignoring model behavior risk because infrastructure controls are strong.

Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.

Treating risk assessment as a one-time predeployment task.

Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.

Memory anchors

Inherent Risk

Inherent risk is risk before considering current controls.

Residual Risk

Residual risk is risk remaining after controls and treatment are considered.

Risk Treatment

Risk treatment selects mitigation, transfer, avoidance, acceptance, monitoring, or escalation.

Risk Acceptance

Risk acceptance is an authorized decision to tolerate residual risk under defined conditions.

Impact

Impact estimates harm to business, users, compliance, safety, operations, or reputation.

Likelihood

Likelihood estimates how probable an AI security event is in the scenario.

Control Effectiveness

Control effectiveness measures whether controls reduce AI risk as intended.

Risk Register

A risk register records AI risks, owners, ratings, treatments, due dates, and acceptance decisions.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A meeting summarizer and an automated eligibility model receive the same brief risk assessment. Which control is MOST appropriate?

Which evidence BEST demonstrates that controls over use-case classification operated throughout the review period?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.