AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q141 Regarding AI model maintenance schedule, the BEST practice is to:

Answer: B

Maintenance should respond to evolving data/context signals, not rely solely on failure, rigid schedules, or indefinite freezing.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q142 Fourth-party risk in an AI supply chain refers to:

Answer: B

Fourth-party risk flows from the vendor's own supply chain, which still needs assessment despite no direct contract.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q143 Within an enterprise's AI governance structure, the governance committee is PRIMARILY responsible for:

Answer: A

The governance committee's core role is oversight of the AI governance program and policies, including reporting on related metrics, not day-to-day technical or contractual tasks.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q144 An enterprise evaluating enterprise AI strategy documentation should PRIMARILY ensure that:

Answer: C

AI strategy documentation should explicitly tie to risk appetite and business objectives to guide consistent decisions.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q145 A leading indicator for AI model risk (e.g., rising input data anomalies) is valuable PRIMARILY because it:

Answer: B

Leading indicators provide early warning signals before issues fully materialize.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q146 An enterprise evaluating residual risk re-evaluation after treatment should PRIMARILY ensure that:

Answer: D

Residual risk must be explicitly re-evaluated against appetite after treatment, not assumed or deferred to annual cycles.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q147 When addressing AI system design requirements traceability, an AI risk practitioner should FIRST:

Answer: C

Design traceability to requirements should be maintained throughout, not skipped or added reactively.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q148 When addressing disaster recovery testing for AI systems, an AI risk practitioner should FIRST:

Answer: B

AI systems, including model/data restoration, should be included in regular DR testing, not excluded by default or location assumption.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q149 An enterprise evaluating AI-specific legal review for new deployments should PRIMARILY ensure that:

Answer: A

Legal review before go-live should assess the specific deployment, not rely on assumptions from unrelated prior reviews.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q150 Regarding asset inventory for AI systems, the BEST practice is to:

Answer: C

A centralized, current AI asset inventory supports risk oversight across the enterprise, not informal or partial tracking.

‹ Prev
Next ›
Page 15 of 50 · 500 questions