Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q141 Regarding AI model maintenance schedule, the BEST practice is to:
- A. Avoid retraining to preserve a validated baseline indefinitely
- B. Define a maintenance schedule for retraining or recalibrating models as data and context evolve
- C. Maintain models only when they fail outright
- D. Retrain models on a fixed schedule regardless of observed drift
Answer: B
Maintenance should respond to evolving data/context signals, not rely solely on failure, rigid schedules, or indefinite freezing.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q142 Fourth-party risk in an AI supply chain refers to:
- A. The enterprise's own internal risk
- B. Risk arising from the vendor's own subcontractors/suppliers that the enterprise does not directly contract with
- C. Risk from the enterprise's customers
- D. Risk that does not need assessment since it is indirect
Answer: B
Fourth-party risk flows from the vendor's own supply chain, which still needs assessment despite no direct contract.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q143 Within an enterprise's AI governance structure, the governance committee is PRIMARILY responsible for:
- A. Overseeing the AI governance program and policies and reporting on program metrics
- B. Approving individual end-user access requests to AI tools
- C. Negotiating AI vendor contract pricing
- D. Writing the organization's AI model source code
Answer: A
The governance committee's core role is oversight of the AI governance program and policies, including reporting on related metrics, not day-to-day technical or contractual tasks.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q144 An enterprise evaluating enterprise AI strategy documentation should PRIMARILY ensure that:
- A. Document strategy without reference to risk appetite
- B. Document strategy only after major incidents occur
- C. Document AI strategy with clear links to enterprise risk appetite and business objectives
- D. Leave AI strategy undocumented and informal
Answer: C
AI strategy documentation should explicitly tie to risk appetite and business objectives to guide consistent decisions.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q145 A leading indicator for AI model risk (e.g., rising input data anomalies) is valuable PRIMARILY because it:
- A. Confirms an incident has already occurred
- B. Provides early warning before a risk materializes into an incident
- C. Is only useful for historical reporting
- D. Replaces the need for lagging indicators
Answer: B
Leading indicators provide early warning signals before issues fully materialize.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q146 An enterprise evaluating residual risk re-evaluation after treatment should PRIMARILY ensure that:
- A. Assume residual risk is acceptable once any control is applied
- B. Skip residual risk re-evaluation for time-sensitive projects
- C. Re-evaluate residual risk only during the next annual audit cycle
- D. Re-evaluate residual risk after implementing treatment to confirm it falls within acceptable levels
Answer: D
Residual risk must be explicitly re-evaluated against appetite after treatment, not assumed or deferred to annual cycles.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q147 When addressing AI system design requirements traceability, an AI risk practitioner should FIRST:
- A. Trace requirements only for externally audited systems
- B. Document traceability only after deployment issues arise
- C. Maintain traceability between business requirements and AI system design decisions
- D. Design AI systems without documenting requirement linkage
Answer: C
Design traceability to requirements should be maintained throughout, not skipped or added reactively.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q148 When addressing disaster recovery testing for AI systems, an AI risk practitioner should FIRST:
- A. Assume cloud-hosted AI systems require no DR testing
- B. Include AI systems in disaster recovery testing, including model/data restoration procedures
- C. Exclude AI systems from DR testing because they are 'non-critical' by default
- D. Test DR for AI systems only once at initial implementation
Answer: B
AI systems, including model/data restoration, should be included in regular DR testing, not excluded by default or location assumption.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q149 An enterprise evaluating AI-specific legal review for new deployments should PRIMARILY ensure that:
- A. Require legal review of AI deployments against applicable sector and data protection laws before go-live
- B. Deploy first and seek legal review only if challenged
- C. Limit legal review to marketing-related AI use cases
- D. Assume prior legal review of similar tools covers all new deployments
Answer: A
Legal review before go-live should assess the specific deployment, not rely on assumptions from unrelated prior reviews.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q150 Regarding asset inventory for AI systems, the BEST practice is to:
- A. Maintain inventory only for externally facing AI systems
- B. Update the AI asset inventory only during annual audits
- C. Maintain an inventory of AI models and their associated data assets across the enterprise
- D. Track AI assets informally through individual team spreadsheets
Answer: C
A centralized, current AI asset inventory supports risk oversight across the enterprise, not informal or partial tracking.