Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Question # 4

Scenario 7 (continued):

Scenario 7: ICure, headquartered in Bratislava, is a medical institution known for its use of the latest technologies in medical practices. Ithas introduced groundbreaking Al-driven diagnostics and treatment planning tools that have fundamentally transformed patient care.

ICure has integrated a robust artificial intelligence management system AIMS to manage its Al systems effectively. This holisticmanagement framework ensures that ICure's Al applications are not only developed but also deployed and maintained to adhere to the

highest industry standards, thereby enhancing efficiency and reliability.

ICure has initiated a comprehensive auditing process to validate its AIMS's effectiveness in alignment with ISO/IEC 42001. The stage 1audit involved an on-site evaluation by the audit team. The team evaluated the site-specific conditions, interacted with ICure's personnel,

observed the deployed technologies, and reviewed the operations that support the AIMS. Following these observations, the findings weredocumented and communicated to ICure. setting the stage for subsequent actions.

Unforeseen delays and resource allocation issues introduced a significant gap between the completion of stage 1 and the onset of stage2 audits. This interval, while unplanned, provided an opportunity for reflection and preparation for upcoming challenges.

After four months, the audit team initiated the stage 2 audit. They evaluated AIMS's compliance with ISO/IEC 42001 requirements, payingspecial attention to the complexity of processes and their documentation. It was during this phase that a critical observation was made:

ICure had not fully considered the complexity of its processes and their interactions when determining the extent of documentedinformation. Essential processes related to Al model training, validation, and deployment were not documented accurately, hinderingeffective control and management of these critical activities. This issue was recorded as a minor nonconformity, signaling a need forenhanced control and management of these vital activities.

Simultaneously, the auditor evaluated the appropriateness and effectiveness of the "AIMS Insight Strategy," a procedure developed by

ICure to determine the AIMS internal and external challenges. This examination identified specific areas for improvement, particularly in

the way stakeholder input was integrated into the system. It highlighted how this could significantly enhance the contribution of relevant

parties in strengthening the system's resilience and effectiveness.

The audit team determined the audit findings by taking into consideration the requirements of ICure, the previous audit records and

conclusions, the accuracy, sufficiency, and appropriateness of evidence, the extent to which planned audit activities are realized and

planned results achieved, the sample size, and the categorization of the audit findings. The audit team decided to first record all the

requirements met; then they proceeded to record the nonconformities.

Based on the scenario above, answer the following question:

Question:

Based on Scenario 7, the audit team conducted a Stage 2 audit after a considerable time from Stage 1. Is this recommended?

A.

No, the gap between Stage 1 and Stage 2 audits should be minimal (usually two weeks) to ensurethat the AIMS remains consistent and relevant during the audit process

B.

Yes, a bigger gap between Stage 1 and Stage 2 audits allows the audit team time for reflection and preparation in addressing the findings

C.

No, the Stage 2 audit should be conducted immediately after the Stage 1 audit to quickly address any identified issues

Full Access
Question # 5

Scenario 6:

Scenario 6: HappilyAI is a pioneering enterprise dedicated to developing and deploying artificial intelligence Al solutions tailored toenhance customer service experiences across various industries. The company offers innovative products like virtual assistants,predictive analytics tools, and personalized customer interaction platforms. As part of its commitment to operational excellence andinnovation, HappilyAI has implemented a robust Al management system AIMS to oversee its Al operations effectively. Currently.HappilyAI is undergoing a comprehensive audit process of its AIMS to evaluate its compliance with ISO/IEC 42001.

Under the leadership of Jess, the audit team began the audit process with meticulous planning and coordination, setting the groundworkfor the extensive on-site activities of the stage 1 audit. This initial phase was marked by a comprehensive documentation review. Theaudit scope encompassed a critical review of HappilyAI's core departments, including Research and Development (R&D), CustomerService, and Data Security, aiming to assess the conformity of HappilyAI's AIMS to the requirements of ISO/IEC 42001.

Afterward, Jess and the team conducted a formal opening meeting with HappilyAI to introduce the audit team and outline the auditactivities. The meeting set a collaborative tone for the subsequent phases, where the team engaged in information collection, executedaudit tests, identified findings, and prepared draft nonconformity reports while maintaining a strict quality review process.

In gathering evidence, the audit team employed a sampling method, which involved dividing the population into homogeneous groups toensure a comprehensive and representative data collection by drawing samples from each segment. Furthermore, the team employedobservation to deepen their understanding of the Al management processes. They verified the availability of essential documentation,including Al-related policies, and evaluated the communication channels established for reporting incidents.

Additionally, they scrutinized specific monitoring tools designed to track the performance of data acquisition processes, ensuring thesetools effectively identify and respond to errors or anomalies. However, a notable challenge emerged as the team encountered a lack ofaccess to documented information that describes how tasks about AIMS are executed. In addition to this, the team identified a potentialnonconformity within the Sales Department. They decided not to record this as a nonconformity in the audit report but onlycommunicated it to the HappilyAI's representatives.

During the stage 2 audit, the certification body, in collaboration with HappilyAI, assigned the roles of technical experts within the auditteam. Recognized for their specialized knowledge and expertise in artificial intelligence and its applications, these technical experts aretasked with the thorough assessment of the AIMS framework to ensure its alignment with industry standards and best practices,focusing on areas such as data ethics, algorithmic transparency, and Al system security.

Question:

Which level of documented information could the audit team NOT access?

A.

Level 1

B.

Level 2

C.

Level 3

Full Access
Question # 6

Question:

Which of the following should be considered when determining the feasibility of the audit?

A.

The auditee's ability to negotiate the terms and conditions

B.

The auditee's cooperation

C.

The motivation of the audit team members

Full Access
Question # 7

Audit evidence must be:

A.

Verifiable

B.

Physical

C.

Refutable

D.

Structured

Full Access
Question # 8

Question:

For which of the following activities are certification bodies responsible?

A.

Certifying management systems, persons, products, processes, and services

B.

Verifying whether a conformity assessment body meets established criteria to carry out conformity assessment tasks

C.

Implementing and managing the certified systems, processes, products, and services

D.

Conducting internal audits on behalf of clients

Full Access
Question # 9

Scenario 3 (continued):

ArBank is a financial institution located in Brussels, Belgium, which offers a diverse range of banking and investment servicesto its clients. To ensure the continual improvement of its operations, ArBank has implemented a quality management system QMS based

on ISO 9001 and an artificial intelligence management system AIMS based on the requirements of ISO/IEC 42001.

Audrey, an experienced auditor, led an internal audit focused on the AIMS within ArBank. She assessed the chatbots integrated into thebank's website and mobile app, analyzing communications using big data technology to identify potential noncompliance, fraud, orunethical conduct. Instead of relying solely on the information provided by the chatbots, Audrey sought out evidence that would eitherconfirm or challenge the validity of the data, ensuring her conclusions were based on reliable and accurate information. Her review ofselected chatbot interactions confirmed they met their intended purpose.

For the specific context of ArBank's operations, Audrey utilized an Al system to assess the efficiency of the bank's digital infrastructure,focusing on tasks critical to the Finance Department. This Al system was able to analyze the functionality of chatbots integrated intoArBank's website and mobile app to determine if it adheres to ISO/IEC 42001 requirements and internal policies governing customerservice in the banking sector.

In addition, Audrey conducted a deeper assessment of the bank’s AIMS. Her evaluation included observing different stages of the AIMSlife cycle, from development to deployment, to ensure that roles and responsibilities were clearly defined and aligned with ArBank’soperational goals. She also evaluated the tools used to monitor and measure the performance of the AIMS.

Audrey continued the audit process by auditing ArBank's outsourced operations. Upon checking the contractual agreements between thetwo parties, Audrey decided that there was no need to gather audit evidence regarding the contractual agreement. She reviewed thecompany's processes for monitoring the quality of outsourced operations, determined whether appropriate governance processes are inplace with regard to the engagement of outsourced persons or organizations, and reviewed and evaluated the company's plans in case ofexpected or unexpected termination of theoutsourcing agreement.

Based on the scenario above, answer the following question:

Question:

What big data technology did Audrey utilize? Refer to Scenario 3.

A.

Data management

B.

Predictive analytics

C.

Text analytics

D.

Visual analytics

Full Access
Question # 10

What is the main goal of the 'Transparency and Explainability' core element in AI?

A.

To ensure AI systems are user-friendly

B.

To improve the speed of AI systems

C.

To reduce the cost of AI development

D.

To make AI operations understandable to users and stakeholders

Full Access
Question # 11

Scenario 3 (continued):

ArBank is a financial institution located in Brussels, Belgium, which offers a diverse range of banking and investment servicesto its clients. To ensure the continual improvement of its operations, ArBank has implemented a quality management system QMS based

on ISO 9001 and an artificial intelligence management system AIMS based on the requirements of ISO/IEC 42001.

Audrey, an experienced auditor, led an internal audit focused on the AIMS within ArBank. She assessed the chatbots integrated into thebank's website and mobile app, analyzing communications using big data technology to identify potential noncompliance, fraud, orunethical conduct. Instead of relying solely on the information provided by the chatbots, Audrey sought out evidence that would eitherconfirm or challenge the validity of the data, ensuring her conclusions were based on reliable and accurate information. Her review ofselected chatbot interactions confirmed they met their intended purpose.

For the specific context of ArBank's operations, Audrey utilized an Al system to assess the efficiency of the bank's digital infrastructure,focusing on tasks critical to the Finance Department. This Al system was able to analyze the functionality of chatbots integrated intoArBank's website and mobile app to determine if it adheres to ISO/IEC 42001 requirements and internal policies governing customerservice in the banking sector.

In addition, Audrey conducted a deeper assessment of the bank’s AIMS. Her evaluation included observing different stages of the AIMSlife cycle, from development to deployment, to ensure that roles and responsibilities were clearly defined and aligned with ArBank’soperational goals. She also evaluated the tools used to monitor and measure the performance of the AIMS.

Audrey continued the audit process by auditing ArBank's outsourced operations. Upon checking the contractual agreements between thetwo parties, Audrey decided that there was no need to gather audit evidence regarding the contractual agreement. She reviewed thecompany's processes for monitoring the quality of outsourced operations, determined whether appropriate governance processes are inplace with regard to the engagement of outsourced persons or organizations, and reviewed and evaluated the company's plans in case ofexpected or unexpected termination of the outsourcing agreement.

Based on the scenario above, answer the following question:

Question:

Based on Scenario 3, which of the following AI technologies did Audrey employ to assess the efficiency of the bank's digital infrastructure?

A.

An expert system

B.

An autonomous system

C.

Artificial neural networks

D.

Semantic algorithms

Full Access
Question # 12

A social media platform wants to automatically detect and remove inappropriate content from images and videos uploaded by users. Which AI concept is most appropriate for this task?

A.

Natural Language Processing (NLP)

B.

Computer Vision

C.

Machine Learning (ML)

D.

Deep Learning (DL)

Full Access
Question # 13

How are auditors expected to handle conflicts of interest during an audit?

A.

By disclosing any potential conflicts and avoiding auditing the affected area

B.

By excluding the affected area from the audit scope

C.

By assigning an external auditor to handle the conflict

D.

By ignoring conflicts to maintain impartiality

Full Access
Question # 14

Question:

During an audit, the auditor employed data analytic technology to identify anomalies and unusualpatterns in the decision-making processes of an AI system used by a financial institution to approve or reject loan applications. Which data analytic technology did the auditor use?

A.

Predictive analytics

B.

Text analytics

C.

Data mining

D.

Visual analytics

Full Access
Question # 15

A healthcare provider wants to develop a system that can analyze medical images, such as X-rays and MRIs, to assist doctors in diagnosing diseases. Which AI concept is most relevant for this application?

A.

Natural Language Processing (NLP)

B.

Computer Vision

C.

Machine Learning (ML)

D.

Deep Learning (DL)

Full Access
Question # 16

Question:

Which of the following are the core functions of the NIST AI Risk Management Framework that help with addressing AI risks in practice?

A.

Identify, analyze, monitor, and control

B.

Plan, implement, test, and audit

C.

Govern, map, measure, and manage

D.

Discover, define, develop, and deploy

Full Access
Question # 17

Scenario 1:

To ensure the integrity of the AI system, Future Horizon Academy has implemented measures to ensure that training data remain isolated from data that could lead to harmful or undesirable outcomes. The institution adds significant data elements as metadata, transforms the data into a format usable by the AI system, and uses data from one or more trusted sources.

Committed to standardization and continual improvement, Future Horizon Academy decided to implement an artificial intelligence management system (AIMS) based on ISO/IEC 42001 that would help the institution increase operational efficiency, resulting in improved processes.

After having the AIMS in place for a year, the institution decided to apply for a certification audit to get certified against ISO/IEC 42001. Prior to the certification audit, the institution conducted an internal audit and management review to ensure that the AIMS aligns with the institution’s own requirements and that the system is being maintained effectively.

Question:

Which of the following AI principles has Future Horizon Academy applied?

A.

Reliability and safety

B.

Accountability

C.

Human control

D.

Transparency

Full Access
Question # 18

What type of evidence is an external audit report?

A.

Physical

B.

Confirmative

C.

Analytical

D.

Technical

Full Access
Question # 19

What is the right series of AI system lifecycle?

A.

System Verification & validation, System design & development, System Deployment, System Requirements & specification finalization, System Operation & monitoring

B.

System design & development, System Operation & monitoring, System Requirements & specification finalization, System Verification & validation, System Deployment

C.

System Requirements & specification finalization, System design & development, System Verification & validation, System Deployment, System Operation & monitoring

D.

System Requirements & specification finalization, System design & development, System Deployment, System Verification & validation, System Operation & monitoring

Full Access
Question # 20

A financial institution uses an AI system to approve loan applications. Recently, there have been complaints that the system disproportionately denies loans to applicants from certain minority groups. Which core element should the institution prioritize to address these complaints?

A.

Fairness and Non-Discrimination

B.

Transparency and Explainability

C.

Accountability

D.

Privacy and Security

Full Access
Question # 21

An auditor is reviewing an AI system used for hiring processes at a tech company and discovers that the system disproportionately rejects candidates from certain ethnic backgrounds. The auditor previously consulted for this company on diversity strategies. Which management system auditing principle (as per ISO 19011) is at risk of being compromised in this scenario?

A.

Confidentiality

B.

Independence

C.

Due Professional Care

D.

Fair Presentation

Full Access
Question # 22

The process to assess the potential consequences for individuals or groups of individuals, or both, and societies that can result from the AI system throughout its life cycle is known as:

A.

AI System Risk Assessment

B.

AI System Impact Assessment

C.

Documentation of AI Systems

D.

None of the above

Full Access
Question # 23

Question:

While auditing a company’s AIMS, the audit team reviewed policies, objectives, and communications to evaluate the involvement of top management. They also conducted interviews with staff to assess the engagement of leaders at various levels in ensuring the system’s effectiveness.

Based on this approach, what level of management should the auditors prioritize when assessing leadership and commitment?

A.

They should focus on leadership at the top management level

B.

They should focus on leadership at all levels of management

C.

They should focus on the leadership of department heads

Full Access
Question # 24

Scenario 1 (continued):

To ensure the integrity of the AI system, Future Horizon Academy has implemented measures to ensure that training data remain isolated from data that could lead to harmful or undesirable outcomes. The institution adds significant data elements as metadata, transforms the data into a format usable by the AI system, and uses data from one or more trusted sources.

Committed to standardization and continual improvement, Future Horizon Academy decided to implement an artificial intelligence management system (AIMS) based on ISO/IEC 42001 that would help the institution increase operational efficiency, resulting in improved processes.

After having the AIMS in place for a year, the institution decided to apply for a certification audit to get certified against ISO/IEC 42001. Prior to the certification audit, the institution conducted an internal audit and management review to ensure that the AIMS aligns with the institution’s own requirements and that the system is being maintained effectively.

Question:

Prior to the certification audit, the institution conducted an internal audit and management review. Is this acceptable?

A.

No, only an internal audit should be conducted before the initial audit

B.

Yes, an internal audit and management review can be conducted before the certification audit

C.

No, the internal audit should be conducted after the certification audit to ensure any recommendations from the audit team are addressed

D.

No, internal audits are only required for recertification audits

Full Access
Question # 25

Question:

Which of the following standards emphasizes the importance of conducting AI system impact assessments to evaluate the potential effects on individuals and societies affected by the AI system?

A.

ISO/IEC 42005

B.

ISO/IEC 42006

C.

ISO/IEC 22989

D.

ISO/IEC 27001

Full Access
Question # 26

What among the below list of steps comes before the other ones in the management system audit process?

A.

Conducting the opening meeting

B.

Preparing the audit report

C.

Initiating the audit

D.

Performing document review

Full Access
Question # 27

Scenario 6 (continued):

Scenario 6: HappilyAI is a pioneering enterprise dedicated to developing and deploying artificial intelligence Al solutions tailored toenhance customer service experiences across various industries. The company offers innovative products like virtual assistants,predictive analytics tools, and personalized customer interaction platforms. As part of its commitment to operational excellence andinnovation, HappilyAI has implemented a robust Al management system AIMS to oversee its Al operations effectively. Currently.HappilyAI is undergoing a comprehensive audit process of its AIMS to evaluate its compliance with ISO/IEC 42001.

Under the leadership of Jess, the audit team began the audit process with meticulous planning and coordination, setting the groundworkfor the extensive on-site activities of the stage 1 audit. This initial phase was marked by a comprehensive documentation review. Theaudit scope encompassed a critical review of HappilyAI's core departments, including Research and Development (R&D), CustomerService, and Data Security, aiming to assess the conformity of HappilyAI's AIMS to the requirements of ISO/IEC 42001.

Afterward, Jess and the team conducted a formal opening meeting with HappilyAI to introduce the audit team and outline the auditactivities. The meeting set a collaborative tone for the subsequent phases, where the team engaged in information collection, executedaudit tests, identified findings, and prepared draft nonconformity reports while maintaining a strict quality review process.

In gathering evidence, the audit team employed a sampling method, which involved dividing the population into homogeneous groups toensure a comprehensive and representative data collection by drawing samples from each segment. Furthermore, the team employedobservation to deepen their understanding of the Al management processes. They verified the availability of essential documentation,including Al-related policies, and evaluated the communication channels established for reporting incidents.

Additionally, they scrutinized specific monitoring tools designed to track the performance of data acquisition processes, ensuring thesetools effectively identify and respond to errors or anomalies. However, a notable challenge emerged as the team encountered a lack ofaccess to documented information that describes how tasks about AIMS are executed. In addition to this, the team identified a potentialnonconformity within the Sales Department. They decided not to record this as a nonconformity in the audit report but onlycommunicated it to the HappilyAI's representatives.

During the stage 2 audit, the certification body, in collaboration with HappilyAI, assigned the roles of technical experts within the auditteam. Recognized for their specialized knowledge and expertise in artificial intelligence and its applications, these technical experts aretasked with the thorough assessment of the AIMS framework to ensure its alignment with industry standards and best practices,focusing on areas such as data ethics, algorithmic transparency, and Al system security.

Question:

Based on Scenario 6, the auditor did not include the potential nonconformity of the Sales Department in the audit report. Is this acceptable?

A.

Yes, because the Sales Department is not included in the audit scope

B.

No, problems, within or outside the scope of the audit, must be included in the audit report

C.

Yes, because auditors have the discretion to omit any findings they deem insignificant, regardless of the audit scope

Full Access
Question # 28

Scenario 8 (continued):

Scenario 8:

Scenario 8: InnovateSoft, headquartered in Berlin, Germany, is a software development company known for its innovative solutions andcommitment to excellence. It specializes in custom software solutions, development, design, testing, maintenance, and consulting,covering both mobile apps and web development. Recently, the company underwent an audit to evaluate the effectiveness and

compliance of its artificial intelligence management system AIMS against ISO/IEC 42001.

The audit team engaged with the auditee to discuss their findings and observations during the audit's final phases. After evaluating theevidence, the audit team presented their audit findings to InnovateSoft, highlighting the identified nonconformities.

Upon receiving the audit findings, InnovateSoft accepted the conclusions but expressed concerns about some findings inaccuratelyreflecting the efficiency of their software development processes. In response, the company provided new evidence and additionalinformation to alter the audit conclusions for a couple of minor nonconformities identified. After thorough consideration, theaudit teamleader clarified that the new evidence did not significantly alter the core conclusions drawn for the nonconformities. Therefore, thecertification body issued a certification recommendation conditional upon the filing of corrective action plans without a prior visit.

InnovateSoft accepted the decision of the certification body. The top management of the company also sought suggestions from theaudit team on resolving the identified nonconformities. The audit team leader offered solutions to address the issues, fostering acollaborative effort between the auditors and InnovateSoft.During the closing meeting, the audit team covered key topics to enhance transparency. They clarified to InnovateSoft that the auditevidence was based on a sample, acknowledging the inherent uncertainty. The method and time frame of reporting and grading findingswere discussed to provide a structured overview of nonconformities. The certification body's process for handling nonconformities,including potential consequences, guided InnovateSoft on corrective actions. The time frame for presenting a plan for correction was

communicated, emphasizing urgency. Insights into the certification body’s post-audit activities were provided, ensuring ongoing support.

Lastly, the audit team briefed InnovateSoft on complaint and appeal handling.

InnovateSoft submitted the action plans for each nonconformity separately, describing only the detected issues and the correctiveactions planned to address the detected nonconformities. However, the submission slightly exceeded the specified period of 45 days setby the certification body, arriving three days later. InnovateSoft explained this by attributing the delay to unexpected challengesencountered during the compilation of the action plans.

After being recommended for certification (pending submission of corrective actions), InnovateSoft did not notify the auditor about completion of corrections and corrective actions.

Question:

Is this acceptable?

A.

No, the auditee is required to inform the auditor about the completion status of the corrections and corrective actions

B.

Yes, since the auditee was recommended for certification upon the submission of corrective action plans without a prior visit

C.

No, audit team leader must be informed to evaluate the effectiveness of the actions with a visit on the auditee’s site

Full Access
Question # 29

Scenario 1 (continued):

To ensure the integrity of the AI system, Future Horizon Academy has implemented measures to ensure that training data remain isolated from data that could lead to harmful or undesirable outcomes. The institution adds significant data elements as metadata, transforms the data into a format usable by the AI system, and uses data from one or more trusted sources.

Committed to standardization and continual improvement, Future Horizon Academy decided to implement an artificial intelligence management system (AIMS) based on ISO/IEC 42001 that would help the institution increase operational efficiency, resulting in improved processes.

After having the AIMS in place for a year, the institution decided to apply for a certification audit to get certified against ISO/IEC 42001. Prior to the certification audit, the institution conducted an internal audit and management review to ensure that the AIMS aligns with the institution’s own requirements and that the system is being maintained effectively.

Question:

Based on Scenario 1, which of the following processes regarding data did Future Horizon Academy NOT conduct?

A.

Data acquisition

B.

Data annotation

C.

Data augmentation

D.

Data verification

Full Access
Question # 30

How does ISO 19011 recommend auditors select audit criteria?

A.

By choosing criteria that are easiest to measure

B.

Based on the organization's industry reputation

C.

According to the requirements of the management system standards and objectives

D.

By using random selection methods

Full Access
Question # 31

A financial institution needs to develop a system that can understand and process large volumes of unstructured text data from financial reports to extract key information and insights. Which AI concept would be best suited for this task?

A.

Natural Language Processing (NLP)

B.

Computer Vision

C.

Machine Learning (ML)

D.

Deep Learning (DL)

Full Access
Question # 32

Why is it important to have a clear and agreed audit scope?

A.

To reduce the time required for the audit

B.

To prevent any legal liabilities

C.

To maintain confidentiality of audit findings

D.

To ensure all aspects of the management system are audited

Full Access
Question # 33

Scenario 2 (continued):

Empsy HR Solutions is a human resources consulting company that provides innovative HR solutions to diverse industries.Recognizing the significant impact of artificial intelligence Al in HR processes, including its ability to automate repetitive tasks, analyzevast amounts of data for insights, improve recruitment and talent management strategies, and personalize employee experiences, thecompany has initiated the implementation of an artificial intelligence management system AIMS based on ISO/IEC 42001.

Initially, the top management established an Al policy that was aligned with the company's objectives. The Al policy provided a frameworkfor defining Al objectives, a commitment to meeting relevant requirements, and a dedication to continually improve the AIMS. However, it

did not refer to other organizational policies, although some were relevant to the AIMS. Afterward, the top management documented thepolicy, communicated it internally, and made it accessible to interested parties.

The top management designated specific individuals to ensure that the AIMS meets the standard's requirements. Additionally, theyensured that these individuals were responsible for overseeing the AIMS, reporting its performance to the top management, andfacilitating continual improvement. Moreover, in its awareness sessions, the company focused exclusively on ensuring that all personnel

were informed about the Al policy, emphasizing their role in ensuring the effectiveness of the AIMS and the benefits of enhanced Alperformance.

The company also planned, implemented, and monitored processes to meet AIMS requirements. Additionally, it set clear criteria andimplemented controls based on them, ensuring effective operation, alignment with organizational objectives, and continual improvement.Empsy HR Solutions decided to implement strict measures to control changes to documented information within the AIMS. To ensure theintegrity and accuracy of documentation, the company adopted version control practices. Each document update was tracked using aversioning system, with clear records of what was modified, who made the changes, and when the updates occurred. Access to makechanges was restricted to authorized personnel, and any proposed modifications required approval from the designated managementteam before being implemented.

Moreover, considering past experiences where the company encountered unforeseen risks, Empsy HR Solutions established acomprehensive Al risk assessment process. This process involved identifying, analyzing, and evaluating Al risks to determine if it isnecessary to implement additional controls than those specified in Annex A. The company also referred to Annex B for guidance onimplementing controls and, ultimately, produced a Statement of Applicability SoA. The SoA contained the necessary controls, including allthe controls of Annex A and justifications for their inclusion or exclusion.

Lastly. Empsy HR Solutions decided to establish an internal audit program to ensure the AIMS conforms to both the company'srequirements and ISO/IEC 42001. It defined the audit objectives, criteria, and scope for each audit, selected auditors, and ensuredobjectivity and impartiality during the audit process. The results of the first audit were documented and reported only to the top

management of the company.

Question:

Based on Scenario 2, has Empsy HR Solutions established a suitable internal audit program?

A.

No, results of audits should also be reported to the relevant managers

B.

Yes, the internal audit program was established in accordance with ISO/IEC 42001 requirements

C.

No, the company should outsource the internal audit function to ensure objectivity and impartiality

D.

Yes, provided results are communicated only to top management

Full Access
Question # 34

What is one of the key objectives of conducting an audit according to ISO 19011?

A.

Issuing certificates of compliance

B.

Imposing penalties on non-compliant organizations

C.

Training employees on audit techniques

D.

Evaluating the effectiveness of the management system

Full Access
Question # 35

Scenario 6 (continued):

Scenario 6: HappilyAI is a pioneering enterprise dedicated to developing and deploying artificial intelligence Al solutions tailored toenhance customer service experiences across various industries. The company offers innovative products like virtual assistants,predictive analytics tools, and personalized customer interaction platforms. As part of its commitment to operational excellence andinnovation, HappilyAI has implemented a robust Al management system AIMS to oversee its Al operations effectively. Currently.HappilyAI is undergoing a comprehensive audit process of its AIMS to evaluate its compliance with ISO/IEC 42001.

Under the leadership of Jess, the audit team began the audit process with meticulous planning and coordination, setting the groundworkfor the extensive on-site activities of the stage 1 audit. This initial phase was marked by a comprehensive documentation review. Theaudit scope encompassed a critical review of HappilyAI's core departments, including Research and Development (R&D), CustomerService, and Data Security, aiming to assess the conformity of HappilyAI's AIMS to the requirements of ISO/IEC 42001.

Afterward, Jess and the team conducted a formal opening meeting with HappilyAI to introduce the audit team and outline the auditactivities. The meeting set a collaborative tone for the subsequent phases, where the team engaged in information collection, executedaudit tests, identified findings, and prepared draft nonconformity reports while maintaining a strict quality review process.

In gathering evidence, the audit team employed a sampling method, which involved dividing thepopulation into homogeneous groups toensure a comprehensive and representative data collection by drawing samples from each segment. Furthermore, the team employedobservation to deepen their understanding of the Al management processes. They verified the availability of essential documentation,including Al-related policies, and evaluated the communication channels established for reporting incidents.

Additionally, they scrutinized specific monitoring tools designed to track the performance of data acquisition processes, ensuring thesetools effectively identify and respond to errors or anomalies. However, a notable challenge emerged as the team encountered a lack ofaccess to documented information that describes how tasks about AIMS are executed. In addition to this, the team identified a potentialnonconformity within the Sales Department. They decided not to record this as a nonconformity in the audit report but onlycommunicated it to the HappilyAI's representatives.

During the stage 2 audit, the certification body, in collaboration with HappilyAI, assigned the roles of technical experts within the auditteam. Recognized for their specialized knowledge and expertise in artificial intelligence and its applications, these technical experts aretasked with the thorough assessment of the AIMS framework to ensure its alignment with industry standards and best practices,focusing on areas such as data ethics, algorithmic transparency, and Al system security.

Question:

According to Scenario 6, which sampling method did the audit team use?

A.

Random

B.

Systematic

C.

Stratified

Full Access
Question # 36

An AI system is being developed to assist elderly people in their daily activities. The system needs to be intuitive and align with the needs and values of its users. Which core element of AI should guide the design and development of this AI system?

A.

Fairness and Non-Discrimination

B.

Transparency and Explainability

C.

Accountability

D.

Human-Centered Design

Full Access