Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q101 An AI-specific risk taxonomy is valuable PRIMARILY because it:
- A. Replaces the enterprise risk taxonomy entirely
- B. Provides common categories/language for identifying and comparing AI risks across the enterprise
- C. Is only relevant to the IT department
- D. Eliminates the need for scenario analysis
Answer: B
A shared taxonomy enables consistent identification and comparison of AI risks.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q102 In the context of rollback planning for AI deployments, which of the following represents sound AI risk management?
- A. Create rollback plans only after a failed deployment occurs
- B. Treat rollback planning as optional for low-risk use cases
- C. Prepare rollback plans in case a new AI deployment causes unacceptable issues
- D. Assume new deployments can always be fixed forward without rollback
Answer: C
Rollback plans should be prepared proactively for deployments, not created reactively after failure.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q103 Within an AI governance program, the chief AI officer (CAIO) role is BEST described as:
- A. A role that may be a standalone position or integrated into an existing commensurate role, leading overall AI adoption and reporting to executive management
- B. A mandatory new C-suite position required by law in every enterprise using AI
- C. A purely technical position with no reporting line to executive management
- D. A role limited to managing AI vendor contracts
Answer: A
The CAIO role can be standalone or absorbed into an existing role; what matters is that it leads AI adoption and reports to executive management, not that it is a distinct legally mandated title.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q104 When addressing AI risk reporting to stakeholders, an AI risk practitioner should FIRST:
- A. Tailor AI risk reporting content and frequency to the needs of each stakeholder audience (board, management, operational teams)
- B. Provide identical AI risk reports to all stakeholder groups
- C. Report AI risk only when specifically requested
- D. Limit AI risk reporting to technical teams only
Answer: A
Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q105 With respect to AI training data access controls, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Apply access controls to training and production data consistent with its sensitivity classification
- B. Grant broad data access to all AI project members by default
- C. Apply access controls only to production data, not training data
- D. Rely on project trust rather than formal access controls
Answer: A
Access controls should follow data sensitivity classification across both training and production data, not informal trust.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q106 With respect to AI-specific risk scenario development, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Develop AI-specific risk scenarios covering bias, model failure, and misuse in addition to generic IT risk scenarios
- B. Reuse only generic IT risk scenarios for AI systems
- C. Develop AI risk scenarios only after an incident occurs
- D. Limit scenario development to security risks alone
Answer: A
AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q107 An enterprise evaluating employee AI training program design should PRIMARILY ensure that:
- A. Tailor AI training content to role-specific risk exposure (e.g., developers vs. general staff)
- B. Provide identical generic AI training to every employee regardless of role
- C. Provide AI training only to the data science team
- D. Rely on self-directed learning with no formal program
Answer: A
Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q108 When addressing risk assessment scope for third-party AI components, an AI risk practitioner should FIRST:
- A. Exclude embedded AI features from assessment if they are 'minor' functionality
- B. Include third-party and embedded AI components within the scope of risk assessment
- C. Assess risk only for in-house developed AI components
- D. Assume third-party AI risk is covered by the vendor's own assessment
Answer: B
Risk assessment scope must include third-party and embedded AI, not rely on vendor assessments or exclude 'minor' features.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q109 Maintaining strict separation between training, testing, and validation datasets is important to:
- A. Reduce compute costs
- B. Prevent overstated performance from data leakage
- C. Simplify the model's codebase
- D. Satisfy only internal style conventions
Answer: B
Separation prevents the model from being evaluated on data it has already seen, which would inflate apparent performance.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q110 With respect to risk treatment option selection, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Select AI risk treatment (avoid, mitigate, transfer, accept) based on cost-benefit relative to risk appetite
- B. Always choose mitigation regardless of cost-effectiveness
- C. Always accept AI risk to avoid implementation effort
- D. Transfer all AI risk via insurance without considering mitigation
Answer: A
Treatment choice should be a cost-benefit decision aligned with risk appetite, not a default to one option.