nerdexam
IsacaIsaca

CISA · Question #444

CISA Question #444: Real Exam Question with Answer & Explanation

The correct answer is D: It may be difficult to audit the model due to the lack of a suitable framework. When AI chatbots learn autonomously from diverse sources, their decision-making processes become opaque (“black box”). Without an established audit framework for such models, the IS auditor cannot effectively evaluate controls, data lineage, or compliance, posing the greatest ris

Submitted by rachelw· Apr 18, 2026Information System Auditing Process

Question

An organization has replaced its call center with AI chatbots that autonomously learn new responses through internet queries and customer conversation history. Which of the following would an IS auditor tasked with verifying IT controls consider to be the GREATEST risk?

Options

  • AThe model may not result in expected efficiencies
  • BThe model's operations may be difficult for the IT team to document
  • CThe model may not generate accurate responses due to overfitting
  • DIt may be difficult to audit the model due to the lack of a suitable framework

Explanation

When AI chatbots learn autonomously from diverse sources, their decision-making processes become opaque (“black box”). Without an established audit framework for such models, the IS auditor cannot effectively evaluate controls, data lineage, or compliance, posing the greatest risk to governance and oversight.

Topics

#AI auditing#IT controls#Audit frameworks#Risk assessment

Community Discussion

No community discussion yet for this question.

Full CISA PracticeBrowse All CISA Questions