Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q111 With respect to AI fairness across demographic groups, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Test AI outcomes for disparate impact across relevant demographic groups before and after deployment
- B. Assume fairness if overall accuracy is high
- C. Test for fairness only if a complaint is received
- D. Limit fairness testing to the development dataset only
Answer: A
Fairness testing should proactively assess subgroup outcomes, not rely on aggregate accuracy or reactive complaints.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q112 With respect to AI incident communication to affected stakeholders, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Communicate AI incident impact to affected internal and external stakeholders in a timely, accurate manner
- B. Delay all stakeholder communication until the investigation is fully closed
- C. Limit incident communication to internal stakeholders only
- D. Communicate only positive aspects of the incident response
Answer: A
Timely, accurate communication to all appropriately affected stakeholders is expected, not delayed, internal-only, or selectively positive.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q113 Patch and dependency management for AI systems (e.g., ML libraries) is important PRIMARILY to:
- A. Avoid any downtime regardless of risk
- B. Address known vulnerabilities that could compromise the system
- C. Satisfy a vendor marketing requirement
- D. Eliminate the need for access controls
Answer: B
Timely patching addresses known vulnerabilities in the AI system's dependencies.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q114 A/B testing an AI model against its predecessor in a controlled rollout is PRIMARILY used to:
- A. Reduce infrastructure cost
- B. Compare real-world performance/impact before full-scale deployment
- C. Eliminate the need for monitoring post-launch
- D. Satisfy a marketing requirement
Answer: B
Controlled A/B comparison validates real-world performance before full rollout.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q115 Reliance on a single AI vendor for multiple critical functions MOST increases:
- A. Diversification of risk
- B. Concentration risk, since a single vendor failure can affect multiple functions
- C. Enterprise flexibility
- D. Vendor competition
Answer: B
Single-vendor reliance across critical functions creates concentration risk.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q116 When addressing data quality management for AI inputs, an AI risk practitioner should FIRST:
- A. Rely on end users to report data quality issues
- B. Implement ongoing data quality checks for inputs feeding AI models
- C. Assume data quality is adequate if the source system is trusted
- D. Check data quality only at initial model training
Answer: B
Ongoing data quality checks are needed for AI inputs, not a one-time assumption or reactive reporting.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q117 A cross-functional AI review board is MOST effective when it includes:
- A. Only data scientists
- B. Representation from risk, legal, business, and technical functions
- C. Only external consultants
- D. Only the CEO
Answer: B
Cross-functional representation ensures all relevant risk dimensions are considered.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q118 Regarding trend analysis of AI risk indicators, the BEST practice is to:
- A. Analyze trends in AI risk indicators over time to detect gradual degradation, not just point-in-time snapshots
- B. Evaluate AI risk indicators using only the most recent single data point
- C. Analyze trends only after a significant incident has occurred
- D. Limit trend analysis to indicators that are already favorable
Answer: A
Trend analysis over time catches gradual degradation that single snapshots or incident-triggered reviews would miss.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q119 Algorithmic accountability in AI governance is BEST defined as:
- A. A purely technical metric computed during model training
- B. The requirement that an algorithm's source code be fully public
- C. Ensuring there are identifiable, responsible parties who can answer for an AI system's decisions and outcomes
- D. A guarantee that no AI decision can ever be appealed
Answer: C
Algorithmic accountability means clear ownership and answerability for an AI system's outcomes, not public code disclosure or a technical training metric.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q120 With respect to likelihood and impact estimation for AI risk, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Estimate impact only in financial terms, ignoring reputational or legal impact
- B. Estimate likelihood and impact of AI risk scenarios using available data and expert judgment
- C. Estimate risk levels based on intuition alone without supporting rationale
- D. Assume all AI risks have equal likelihood and impact
Answer: B
Risk estimation should use available evidence and judgment across multiple impact types, not uniform assumptions or financial-only framing.