Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q91 A compensating control for an AI risk should be used when:
- A. It fully replaces the need for any other control
- B. The primary/preferred control cannot be fully implemented, providing equivalent risk mitigation
- C. No risk exists
- D. The enterprise wants to skip documentation
Answer: B
Compensating controls provide equivalent mitigation when the primary control isn't fully feasible.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q92 When addressing AI acceptable use policy scope, an AI risk practitioner should FIRST:
- A. Limit the policy to only prohibit a single named tool
- B. Apply the acceptable use policy only to the IT department
- C. Define an AI acceptable use policy covering permitted tools, data handling, and prohibited uses
- D. Leave AI acceptable use undefined and rely on informal norms
Answer: C
An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q93 When addressing data lineage documentation during development, an AI risk practitioner should FIRST:
- A. Document data lineage only after a data quality incident
- B. Document the lineage of training and input data from source to model use
- C. Assume data lineage is unnecessary if data was purchased
- D. Document data lineage only for personally identifiable data
Answer: B
Full data lineage documentation supports traceability and risk management regardless of data source or incident history.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q94 When addressing AI incident communication to affected stakeholders, an AI risk practitioner should FIRST:
- A. Limit incident communication to internal stakeholders only
- B. Communicate only positive aspects of the incident response
- C. Communicate AI incident impact to affected internal and external stakeholders in a timely, accurate manner
- D. Delay all stakeholder communication until the investigation is fully closed
Answer: C
Timely, accurate communication to all appropriately affected stakeholders is expected, not delayed, internal-only, or selectively positive.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q95 In the context of model performance benchmarking, which of the following represents sound AI risk management?
- A. Release models based on developer confidence alone
- B. Skip benchmarking for minor model updates
- C. Benchmark AI model performance against defined acceptance criteria before production release
- D. Release models once they outperform a prior inferior baseline only slightly
Answer: C
Formal benchmarking against acceptance criteria should precede release, not rely on marginal improvement or developer confidence alone.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q96 Independent model validation (separate from the model development team) is valuable PRIMARILY because it:
- A. Slows delivery with no benefit
- B. Reduces conflict of interest and provides objective challenge to development assumptions
- C. Is required only for regulatory filings
- D. Replaces the need for any testing by developers
Answer: B
Independent validation provides unbiased challenge, reducing developer conflict-of-interest risk.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q97 When addressing AI contractual compliance clauses, an AI risk practitioner should FIRST:
- A. Add compliance clauses only after a vendor incident occurs
- B. Include compliance and audit-rights clauses in contracts with AI vendors
- C. Rely on vendor assurances without contractual compliance clauses
- D. Limit vendor contracts to pricing and service-level terms only
Answer: B
Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q98 When addressing AI-specific legal review for new deployments, an AI risk practitioner should FIRST:
- A. Deploy first and seek legal review only if challenged
- B. Limit legal review to marketing-related AI use cases
- C. Assume prior legal review of similar tools covers all new deployments
- D. Require legal review of AI deployments against applicable sector and data protection laws before go-live
Answer: D
Legal review before go-live should assess the specific deployment, not rely on assumptions from unrelated prior reviews.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q99 Backtesting an AI model against historical outcomes is MOST useful for:
- A. Confirming the model performs reasonably on data outside its original training/validation set
- B. Replacing the need for live monitoring
- C. Satisfying marketing claims
- D. Reducing data storage needs
Answer: A
Backtesting checks real-world generalization, though it does not replace ongoing monitoring.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q100 With respect to treatment plan monitoring and follow-up, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Monitor treatment plans only if the risk recurs
- B. Assign treatment follow-up responsibility ambiguously across teams
- C. Track AI risk treatment plans to completion and verify effectiveness after implementation
- D. Consider a risk treated once a plan is merely approved
Answer: C
Treatment plans require tracked completion and verified effectiveness, not approval alone or unclear ownership.