Q: 11
[Conducting an ISO/IEC 42001 Audit]
What is the purpose of conducting an opening meeting in the audit process?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
[Managing an ISO/IEC 42001 Audit Program]
Scenario 9 (continued):
Scenario 9: Securisai, located in Tallinn.Estonia, specializes in the development of automated
cybersecurity solutions that utilize AIsystems. The company recently implemented an artificial
intelligence management system AIMS in accordance with ISO/IEC 42001. Indoing so, the company
aimed to manage its Al-driven systems’ capabilities to detect and mitigate cyber threats more
efficiently andethically. As part of its commitment to upholding the highest standards of Al use and
management, Securisai underwent a certificationaudit to demonstrate compliance with ISO/IEC
42001.
The audit process comprised two main stages: the initial or stage 1 audit focused on
reviewingSecurisai's documentation, policies, andprocedures related to its AIMS. This review laid the
groundwork for the stage 2 audit, which involved a comprehensive, on-site evaluation
of the actual implementation and effectiveness of the AIMS within Securisai's operations. The goal
was to observe the AIMS in operation,ensuring that it not only existed on paper but was effectively
integrated into the company's daily activities and cybersecurity strategies.
After the audit, Roger, Securisai's internal auditor, addressed the action plans devised to rectify
nonconformities identified during thecertification audit. He developed a long term strategy,
highlighting key AIMS processes for triennial audits. Roger's internal audits play a
key role in advancing Securisai's goals by employing a systematic and disciplined method to assess
and boost the efficiency of risk
management, governance processes, and strategic decision-making. Roger reported his findings
directly to Securisai's top management.
Following the successful rectification of nonconformities, Securisai was officially certified against
ISO/IEC 42001.
Recently, the company decided to transfer its ISO/IEC 42001 certification registration from one
certification body to another despitebeing initially bound by a long-term agreement with the current
certification body. This decision was motivated by the desire to partnerwith a certification body that
offers deeper insights and expertise in the rapidly evolving field of artificial intelligence in
cybersecurity.
To ensure a smooth transition and uphold its certification status, Securisai is diligently compiling the
required documentation forsubmission to the new certification body. This includes a formal request,
the most recent audit report underscoring its adherence toISO/IEC 42001, the latest corrective action
plan that highlights its continuous efforts toward improvement, and a copy of its current
validcertification registration.
A year following Securisai's initial certification audit, a subsequent audit was carried out by the
certification body on its AIMS. The
purpose of this audit was to assess compliance with ISO/IEC 42001 and verify the ongoing
improvement of the AIMS. The audit team
concluded that Securisai's AIMS consistently meets the requirements set by ISO/IEC 42001.
Roger followed up on action plans after the external audit at Securisai, but he was directly involved in
strategic decision-making processes, potentially affecting his audit objectivity.
Based on Scenario 9, which principle of internal auditing did Roger violate?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
[Fundamental Principles and Concepts of an AI Management System]
What is the right series of AI system lifecycle?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
[Conducting an ISO/IEC 42001 Audit]
Which phase involves the collection of objective evidence through interviews, observations, and
examination of documents?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
[Conducting an ISO/IEC 42001 Audit]
Which of the following is NOT a guide’s responsibility?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
[AI Management System Requirements]
Scenario 2 (continued):
Empsy HR Solutions is a human resources consulting company that provides innovative HR solutions
to diverse industries.Recognizing the significant impact of artificial intelligence Al in HR processes,
including its ability to automate repetitive tasks, analyzevast amounts of data for insights, improve
recruitment and talent management strategies, and personalize employee experiences, thecompany
has initiated the implementation of an artificial intelligence management system AIMS based on
ISO/IEC 42001.
Initially, the top management established an Al policy that was aligned with the company's
objectives. The Al policy provided a frameworkfor defining Al objectives, a commitment to meeting
relevant requirements, and a dedication to continually improve the AIMS. However, it
did not refer to other organizational policies, although some were relevant to the AIMS. Afterward,
the top management documented thepolicy, communicated it internally, and made it accessible to
interested parties.
The top management designated specific individuals to ensure that the AIMS meets the standard's
requirements. Additionally, theyensured that these individuals were responsible for overseeing the
AIMS, reporting its performance to the top management, andfacilitating continual improvement.
Moreover, in its awareness sessions, the company focused exclusively on ensuring that all personnel
were informed about the Al policy, emphasizing their role in ensuring the effectiveness of the AIMS
and the benefits of enhanced Alperformance.
The company also planned, implemented, and monitored processes to meet AIMS requirements.
Additionally, it set clear criteria andimplemented controls based on them, ensuring effective
operation, alignment with organizational objectives, and continual improvement.Empsy HR Solutions
decided to implement strict measures to control changes to documented information within the
AIMS. To ensure theintegrity and accuracy of documentation, the company adopted version control
practices. Each document update was tracked using aversioning system, with clear records of what
was modified, who made the changes, and when the updates occurred. Access to makechanges was
restricted to authorized personnel, and any proposed modifications required approval from the
designated managementteam before being implemented.
Moreover, considering past experiences where the company encountered unforeseen risks, Empsy
HR Solutions established acomprehensive Al risk assessment process. This process involved
identifying, analyzing, and evaluating Al risks to determine if it isnecessary to implement additional
controls than those specified in Annex
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
[Fundamental Principles and Concepts of an AI Management System]
Scenario 1 (continued):
To ensure the integrity of the AI system, Future Horizon Academy has implemented measures to
ensure that training data remain isolated from data that could lead to harmful or undesirable
outcomes. The institution adds significant data elements as metadata, transforms the data into a
format usable by the AI system, and uses data from one or more trusted sources.
Committed to standardization and continual improvement, Future Horizon Academy decided to
implement an artificial intelligence management system (AIMS) based on ISO/IEC 42001 that would
help the institution increase operational efficiency, resulting in improved processes.
After having the AIMS in place for a year, the institution decided to apply for a certification audit to
get certified against ISO/IEC 42001. Prior to the certification audit, the institution conducted an
internal audit and management review to ensure that the AIMS aligns with the institution’s own
requirements and that the system is being maintained effectively.
Based on Scenario 1, which of the following processes regarding data did Future Horizon Academy
NOT conduct?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
[AI Management System Requirements]
Which of the following statements regarding the organization's requirement to address risks and
opportunities based on ISO/IEC 42001 is correct?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
[Managing an ISO/IEC 42001 Audit Program]
Scenario 9 (continued):
Scenario 9: Securisai, located in Tallinn.Estonia, specializes in the development of automated
cybersecurity solutions that utilize AIsystems. The company recently implemented an artificial
intelligence management system AIMS in accordance with ISO/IEC 42001. Indoing so, the company
aimed to manage its Al-driven systems’ capabilities to detect and mitigate cyber threats more
efficiently andethically. As part of its commitment to upholding the highest standards of Al use and
management, Securisai underwent a certificationaudit to demonstrate compliance with ISO/IEC
42001.
The audit process comprised two main stages: the initial or stage 1 audit focused on reviewing
Securisai's documentation, policies, andprocedures related to its AIMS. This review laid the
groundwork for the stage 2 audit, which involved a comprehensive, on-site evaluation
of the actual implementation and effectiveness of the AIMS within Securisai's operations. The goal
was to observe the AIMS in operation,ensuring that it not only existed on paper but was effectively
integrated into the company's daily activities and cybersecurity strategies.
After the audit, Roger, Securisai's internal auditor, addressed the action plans devised to rectify
nonconformities identified during thecertification audit. He developed a long term strategy,
highlighting key AIMS processes for triennial audits. Roger's internal audits play a
key role in advancing Securisai's goals by employing a systematic and disciplined method to assess
and boost the efficiency of risk
management, governance processes, and strategic decision-making. Roger reported his findings
directly to Securisai's top management.
Following the successful rectification of nonconformities, Securisai was officially certified against
ISO/IEC 42001.
Recently, the company decided to transfer its ISO/IEC 42001 certification registration from
onecertification body to another despitebeing initially bound by a long-term agreement with the
current certification body. This decision was motivated by the desire to partnerwith a certification
body that offers deeper insights and expertise in the rapidly evolving field of artificial intelligence in
cybersecurity.
To ensure a smooth transition and uphold its certification status, Securisai is diligently compiling the
required documentation forsubmission to the new certification body. This includes a formal request,
the most recent audit report underscoring its adherence toISO/IEC 42001, the latest corrective action
plan that highlights its continuous efforts toward improvement, and a copy of its current
validcertification registration.
A year following Securisai's initial certification audit, a subsequent audit was carried out by the
certification body on its AIMS. The
purpose of this audit was to assess compliance with ISO/IEC 42001 and verify the ongoing
improvement of the AIMS. The audit team
concluded that Securisai's AIMS consistently meets the requirements set by ISO/IEC 42001.
What type of audit is described in the last paragraph of Scenario 9?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
[Fundamental Principles and Concepts of an AI Management System]
Scenario 1:
To ensure the integrity of the AI system, Future Horizon Academy has implemented measures to
ensure that training data remain isolated from data that could lead to harmful or undesirable
outcomes. The institution adds significant data elements as metadata, transforms the data into a
format usable by the AI system, and uses data from one or more trusted sources.
Committed to standardization and continual improvement, Future Horizon Academy decided to
implement an artificial intelligence management system (AIMS) based on ISO/IEC 42001 that would
help the institution increase operational efficiency, resulting in improved processes.
After having the AIMS in place for a year, the institution decided to apply for a certification audit to
get certified against ISO/IEC 42001. Prior to the certification audit, the institution conducted an
internal audit and management review to ensure that the AIMS aligns with the institution’s own
requirements and that the system is being maintained effectively.
Which of the following AI principles has Future Horizon Academy applied?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2