
AAIA exam practice question: daily practice for the ISACA Advanced in AI Audit (AAIA) exam — domain: AI Governance and Risk.
Question
A mid-sized bank's internal audit finds that the same ML engineer builds models, approves change requests, and performs production deployments for a credit-scoring model. Which governance control would most effectively reduce the segregation-of-duties risk in this workflow?
Show the answer and explanation
Correct answer: C. Enforce role-based access controls and automated deployment gates so development, approval, and production deployment are performed by separate roles.
The best control is enforcing role-based access controls with automated deployment gates because it prevents a single individual from performing conflicting duties in real time and blocks unauthorized deployments. Comprehensive audit logs (option 1) are useful for detection and investigation but are detective and retrospective, not preventive. Manager approval recorded in change tickets (option 2) provides oversight but can be bypassed or colluded and still allows one person to hold multiple operational privileges. Independent external reviews (option 4) provide assurance but are periodic and cannot prevent immediate misuse or accidental deployment errors.
Want more practice?
Prepare for the ISACA Advanced in AI Audit (AAIA) exam with AI Audit & Compliance Framework: Practical Methods & Evaluation.
