
AAIA exam practice question: daily practice for the ISACA Advanced in AI Audit (AAIA) exam — domain: AI Governance and Risk.
Question
An AI audit team discovers that a production model's training dataset contains personal data retained long after the original collection purpose. Which control is the most effective first step to reduce the organization's regulatory and privacy risk related to unnecessary data retention?
Show the answer and explanation
Correct answer: A. Deploy a documented data retention policy that tags datasets with purpose and retention periods and enforces automated secure deletion when the period expires.
Implementing a documented retention policy with dataset-level tagging and automated secure deletion directly addresses unnecessary retention by removing data when its legal or business purpose ends. This control enforces minimization and reduces exposure. Pseudonymization (option 2) reduces identifiability but does not eliminate the risk of retaining data beyond purpose and can still be subject to retention rules. Annual access reviews with manual deletion (option 3) are weaker operationally; they rely on human action and can leave expired data in place for long periods. Encryption (option 4) protects confidentiality but does not mitigate the compliance risk from keeping data longer than allowed.
Want more practice?
Prepare for the ISACA Advanced in AI Audit (AAIA) exam with AI Audit & Compliance Framework: Practical Methods & Evaluation.
