AI Risk Assessment and Treatment
Risk management requires identifying AI threats, business impacts, likelihood, inherent risk, residual risk, treatment options, and risk acceptance.
How to study for ISACA AAISM
Treat each item as a management decision: identify the AI asset and stakeholder, assess risk, select governance or control action, then document evidence and accountability.
Core concepts
Concept 1
AI risk assessment evaluates threats, vulnerabilities, impact, likelihood, control effectiveness, and residual risk.
Exam cue: Use inherent risk before controls and residual risk after controls.
Concept 2
Risk treatment options include mitigate, transfer, avoid, accept, monitor, or escalate based on risk appetite and business need.
Exam cue: Use risk treatment when the assessment shows risk outside appetite.
Concept 3
Residual risk should be accepted only by authorized decision makers with clear evidence and conditions.
Exam cue: Use formal acceptance when residual risk remains after treatment.
Risk pitfalls and guardrails
Accepting risk at the technical team level without business authority.
Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.
Ignoring model behavior risk because infrastructure controls are strong.
Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.
Treating risk assessment as a one-time predeployment task.
Guardrail: Avoid treating AI security as only a technical scan, accepting risk without authority, or leaving prompts and data outside governance.
Memory anchors
Inherent Risk
Inherent risk is risk before considering current controls.
Residual Risk
Residual risk is risk remaining after controls and treatment are considered.
Risk Treatment
Risk treatment selects mitigation, transfer, avoidance, acceptance, monitoring, or escalation.
Risk Acceptance
Risk acceptance is an authorized decision to tolerate residual risk under defined conditions.
Impact
Impact estimates harm to business, users, compliance, safety, operations, or reputation.
Likelihood
Likelihood estimates how probable an AI security event is in the scenario.
Control Effectiveness
Control effectiveness measures whether controls reduce AI risk as intended.
Risk Register
A risk register records AI risks, owners, ratings, treatments, due dates, and acceptance decisions.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A meeting summarizer and an automated eligibility model receive the same brief risk assessment. Which control is MOST appropriate?
Which evidence BEST demonstrates that controls over use-case classification operated throughout the review period?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
