Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q1 Right-to-audit clauses in AI vendor contracts are valuable PRIMARILY because they:
- A. Enable the enterprise to independently verify vendor controls rather than relying solely on vendor self-attestation
- B. Guarantee that the vendor will never experience a security incident
- C. Transfer full legal liability for AI-related harm from the enterprise to the vendor
- D. Remove the enterprise's own obligation to perform risk assessment of the vendor
Answer: A
Audit rights provide independent verification of controls; they don't guarantee zero incidents, transfer liability (addressed by indemnification/liability clauses), or remove the enterprise's own due-diligence obligations.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q2 A rollback plan for a failed AI deployment should BEST ensure:
- A. The failure is hidden from stakeholders until resolved
- B. The enterprise can quickly revert to a known-good prior state to limit impact
- C. No further testing of the system is required afterward
- D. The root cause of the failure is permanently fixed before redeployment
Answer: B
Rollback is a containment control that limits impact by reverting to a known-good state; it does not itself fix the root cause, hide failures, or remove the need for further testing.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q3 An enterprise evaluating AI use-case prioritization should PRIMARILY ensure that:
- A. Prioritize use cases strictly by projected return on investment, independent of risk exposure
- B. Prioritize by lowest cost regardless of value
- C. Prioritize use cases by combined business value and risk exposure
- D. Prioritize by whichever team requests first
Answer: C
Prioritization must weigh value against risk exposure together; ROI alone ignores risk, and cost- or request-order-driven prioritization ignores both value and risk.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q4 When selecting an AI governance framework, what should an enterprise consider FIRST?
- A. Popularity of the framework among industry peers
- B. The breadth of controls the framework covers, regardless of fit with the enterprise's risk appetite
- C. Cost of achieving formal certification
- D. Alignment of the framework with the enterprise's business strategy and risk appetite
Answer: D
Framework selection should serve the enterprise's actual strategy and risk appetite; breadth of coverage without fit, peer popularity, and certification cost are secondary or irrelevant.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q5 An enterprise evaluating AI incident response team composition should PRIMARILY ensure that:
- A. Technical, risk, legal, and communications representatives are included from the outset
- B. Limit the team to technical staff only
- C. A core team of technical and legal staff only, expanding to other functions if the incident becomes public
- D. Rely on the original model developer alone to manage incident response
Answer: A
Effective incident response needs cross-functional composition from the start, not a narrow team expanded only once an incident becomes public, nor a technical- or developer-only team.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q6 An enterprise evaluating integration of AI risk metrics into enterprise reporting should PRIMARILY ensure that:
- A. Report AI risk metrics only within the AI development team
- B. Integrate AI risk metrics into existing enterprise risk reporting rather than maintaining a fully separate report
- C. Combine AI risk metrics into a single unexplained composite score for executives
- D. Maintain a separate AI-specific risk report, reviewed independently of enterprise risk reporting
Answer: B
AI risk metrics should be integrated into enterprise reporting, not kept in a parallel report, confined to the development team, or compressed into an unexplained score.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q7 Data lineage tracking for AI training data is valuable PRIMARILY because it:
- A. Primarily improves model accuracy by automatically cleaning poor-quality data
- B. Reduces data storage costs
- C. Enables tracing data from source through transformation to model use, supporting audit and quality control
- D. Is relevant only for marketing analytics use cases
Answer: C
Lineage tracking supports traceability for audit and quality control; it does not itself clean data or improve accuracy, and it is not limited to storage savings or marketing use.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q8 In the context of segregation of duties in AI operations, which of the following represents sound AI risk management?
- A. Rely on informal trust instead of segregation of duties
- B. Rotate a single individual through development, validation, and approval roles over time to build broad expertise
- C. Apply segregation of duties only for financial-reporting-related AI
- D. Apply segregation of duties between AI model development, validation, and deployment approval
Answer: D
Segregation of duties requires different people performing development, validation, and approval concurrently; rotating one person through all three over time does not achieve segregation.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q9 In the context of control testing frequency for AI systems, which of the following represents sound AI risk management?
- A. Test AI controls at a frequency proportionate to the risk level of the system they protect
- B. Test controls only when requested by internal audit
- C. Test all AI controls annually as part of one consolidated review cycle, regardless of risk level
- D. Test controls once at implementation and not again
Answer: A
Testing frequency should scale with risk; a uniform annual cycle, audit-triggered testing, and one-time testing all fail to reflect risk-proportionate oversight.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q10 In the context of process alignment for AI change management, which of the following represents sound AI risk management?
- A. Treat AI changes as exempt from standard change management
- B. Integrate AI initiatives into existing change management processes
- C. Use ad hoc approval for AI changes outside formal processes
- D. Create a separate AI-specific change management process that runs independently of the enterprise's standard process
Answer: B
AI changes should flow through existing, integrated change management; a parallel AI-only process, exemption, and ad hoc approval all undermine consistent governance.