CRISC - Risk Assessment - Section 2.4

Identify risk arising from emerging technologies including artificial intelligence, large language models and quantum computing.

Identify risk categories arising from the adoption of emerging technologies, including artificial intelligence, large language models, and quantum computing. Distinguish the novel risk characteristics of each - such as model bias or cryptographic obsolescence - from conventional IT risk.

Artificial intelligence riskLarge language modelsQuantum computingEmerging technology

Practice question for this objective

Free sampleRisk Assessmentmedium

A claims team has started using a large language model to summarise lengthy policy documents and is acting on those summaries to make settlement decisions. When assessing the risk of this practice, which exposure is most specific to the large language model itself rather than to document handling in general?

  • AThe policy documents could be intercepted in transit between the claims team and the storage system if the network connection is not encrypted end to end.
  • BThe model can present fabricated or unverifiable statements as confident, fluent facts, so staff may act on summary content that is not actually supported by the source. Correct
  • CStaff might save the summaries to a shared drive that lacks the access restrictions applied to the original signed policy documents in the records system.
  • DThe team could lose productivity if the model is slow to respond during periods of heavy use, delaying the settlement decisions that depend on its summaries.
The risk most specific to large language models is confident, fluent output that is fabricated or unsupported, which can mislead decisions drawn from it. Large language models generate fluent, plausible text that may not be grounded in the source material, so a summary can assert facts the underlying document never contained; when staff act on such output without verifying it against the source, decisions rest on fabricated content, which is the model-specific exposure rather than the transport, access or performance issues that affect any document workflow.

Why A is wrong: Interception in transit is a genuine concern, but it is a generic transport security issue that applies to any document workflow rather than anything specific to the model.

Why B is correct: Plausible but ungrounded output is the distinctive failure mode of large language models, and acting on it without checking the source can drive wrong decisions that look well founded.

Why C is wrong: Weak access control on a shared drive is a real records risk, yet it stems from document handling practices and would arise with any summarisation method.

Why D is wrong: Latency may frustrate users, but availability and performance are general service concerns and do not capture the model-specific reliability problem in its output.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Assessment objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.