Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q131 With respect to AI incident classification scheme, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Classify AI incidents by severity and type to drive proportionate response actions
- B. Treat all AI incidents with an identical response regardless of severity
- C. Classify incidents only after the response has already concluded
- D. Limit incident classification to security-related AI incidents
Answer: A
Severity/type-based classification enables proportionate response, rather than uniform, after-the-fact, or security-only classification.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q132 Regarding cross-functional AI committee composition, the BEST practice is to:
- A. Limit AI governance decisions to IT alone
- B. Exclude legal and risk from AI governance committees
- C. Include risk, legal, data, business, and technical stakeholders in AI governance decisions
- D. Limit AI governance decisions to the data science team
Answer: C
Effective AI governance requires cross-functional representation, not a single-function decision group.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q133 With respect to AI incident response team composition, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Rely on the original model developer alone to manage incident response
- B. Include technical, risk, legal, and communications representatives on the AI incident response team
- C. Limit the AI incident response team to technical staff only
- D. Assemble the incident response team only after the incident is publicized
Answer: B
Cross-functional incident response composition is needed, not technical-only, reactive, or single-developer-reliant.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q134 An enterprise evaluating regulatory horizon scanning for AI should PRIMARILY ensure that:
- A. Review AI regulatory developments only once a year
- B. Rely on vendors to notify the enterprise of regulatory changes
- C. Monitor regulation only in the enterprise's headquarters jurisdiction
- D. Maintain an ongoing process to monitor emerging AI regulation relevant to the enterprise
Answer: D
Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q135 When addressing enterprise AI strategy documentation, an AI risk practitioner should FIRST:
- A. Document strategy only after major incidents occur
- B. Document AI strategy with clear links to enterprise risk appetite and business objectives
- C. Leave AI strategy undocumented and informal
- D. Document strategy without reference to risk appetite
Answer: B
AI strategy documentation should explicitly tie to risk appetite and business objectives to guide consistent decisions.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q136 In the context of documentation for regulatory AI audits, which of the following represents sound AI risk management?
- A. Recreate documentation only when a regulator requests it
- B. Maintain documentation informally in individual staff notes
- C. Document only the final model output, not design rationale
- D. Maintain audit-ready documentation of AI design, data sources, and decision logic
Answer: D
Audit-ready AI documentation must be maintained proactively and substantively, not assembled reactively or kept informally.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q137 In the context of AI-specific risk scenario development, which of the following represents sound AI risk management?
- A. Develop AI risk scenarios only after an incident occurs
- B. Limit scenario development to security risks alone
- C. Develop AI-specific risk scenarios covering bias, model failure, and misuse in addition to generic IT risk scenarios
- D. Reuse only generic IT risk scenarios for AI systems
Answer: C
AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q138 With respect to explainability requirements at design stage, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Apply the same explainability level to all AI regardless of risk
- B. Treat explainability as a purely technical afterthought
- C. Define explainability requirements appropriate to the AI system's risk and use context during design
- D. Add explainability features only if regulators demand them later
Answer: C
Explainability requirements should be risk-based and considered during design, not uniform or deferred.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q139 Trend analysis of AI risk KRIs over time is MOST useful for:
- A. Identifying gradual deterioration before it becomes a crisis
- B. Satisfying only a cosmetic reporting requirement
- C. Replacing the need for threshold-based alerts
- D. Eliminating the need for root cause analysis
Answer: A
Trend analysis surfaces gradual deterioration that single-point-in-time metrics might miss.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q140 With respect to control framework mapping for AI, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Map AI controls to a recognized control framework to ensure completeness and avoid gaps
- B. Design AI controls ad hoc without reference to any framework
- C. Map controls to a framework only for externally audited systems
- D. Treat framework mapping as a one-time exercise never revisited
Answer: A
Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.