AAIA Question of the Day: Model Decommissioning Controls

AI audit training by expert Yazan Abu Ghosh for auditors with certifications.

AAIA exam practice question — AAIA Question of the Day: Model Decommissioning Controls

AAIA exam practice question: daily practice for the ISACA Advanced in AI Audit (AAIA) exam — domain: AI Governance and Risk.

Question

Your organization is retiring a credit-scoring model after replacement by a modern alternative. Compliance requires evidence that the retired model can be audited and that risks from residual artifacts are managed. Which control is most important to implement at decommissioning?

  • A. Create a secure, immutable archive that captures model artifacts, versioned code, training-data hashes, metadata, approval records, and access controls retained per policy.
  • B. Permanently delete all training data and model artifacts immediately to minimize residual legal and operational risk.
  • C. Disable the model’s outputs but keep the live production instance running in read-only mode so auditors can inspect behavior on demand.
  • D. Transfer the model files and related materials to an external storage vendor for long-term custody without additional documentation or access restrictions.
Show the answer and explanation

Correct answer: A. Create a secure, immutable archive that captures model artifacts, versioned code, training-data hashes, metadata, approval records, and access controls retained per policy.

The best control is a secure, immutable archive containing model artifacts, code, training-data hashes, metadata and approval records with enforced access controls and retention per policy. This preserves auditability, reproducibility and a verifiable chain of custody while limiting access. Permanent deletion prevents later audit, forensic review, or regulatory inquiries and may conflict with retention obligations. Keeping a live production instance increases operational and security risk and is unnecessary if archived artifacts are preserved. Transferring materials to an external vendor without documentation or access controls breaks traceability and accountability and risks loss, unauthorized access, or noncompliance.

Want more practice?

Prepare for the ISACA Advanced in AI Audit (AAIA) exam with AI Audit & Compliance Framework: Practical Methods & Evaluation.