Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q151 Escalation thresholds for AI model issues should be defined PRIMARILY based on:
- A. Arbitrary round numbers with no analysis
- B. Materiality of potential business, customer, or compliance impact
- C. The data scientist's personal judgment alone
- D. Vendor marketing commitments
Answer: B
Thresholds should reflect actual materiality of impact, ensuring proportionate escalation.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q152 Enterprises should disclose AI use to end users PRIMARILY to:
- A. Comply with marketing best practice only
- B. Support informed consent and trust, and meet transparency expectations/regulation
- C. Avoid the need for explainability
- D. Reduce the need for human oversight
Answer: B
Transparency about AI use supports informed consent, trust, and regulatory expectations.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q153 A concentration risk in AI supply chain arises when:
- A. An enterprise uses multiple independent AI vendors
- B. The enterprise's AI capability depends heavily on a single vendor or foundation model provider
- C. Vendors are located in different countries
- D. Contracts are renewed annually
Answer: B
Heavy reliance on a single vendor/provider creates concentration risk and single-point-of-failure exposure.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q154 Assessing a third-party AI vendor's risk should PRIMARILY evaluate:
- A. The vendor's logo and branding
- B. The vendor's security, data handling, model risk, and resilience practices
- C. The vendor's social media following
- D. The vendor's office amenities
Answer: B
Vendor risk assessment should focus on substantive security/resilience practices.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q155 In the context of post-incident lessons-learned integration, which of the following represents sound AI risk management?
- A. Document lessons learned but take no corrective action
- B. Feed AI incident lessons learned back into risk assessments, controls, and training
- C. Close AI incidents without updating related risk assessments or controls
- D. Share lessons learned only informally among the immediate response team
Answer: B
Lessons learned should formally update assessments, controls, and training, not stay informal or undocumented without action.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q156 When addressing AI policy review cadence, an AI risk practitioner should FIRST:
- A. Review AI policies only once at initial publication
- B. Review AI policies only when an incident forces a change
- C. Review AI policies annually regardless of major changes in between
- D. Review and update AI policies on a defined periodic cycle and after significant regulatory or technology changes
Answer: D
AI policies need periodic review plus trigger-based updates for significant regulatory or technology shifts, not a one-time or purely incident-driven cycle.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q157 A documented procedure for human override of an AI decision is MOST important for:
- A. Slowing down operations unnecessarily
- B. Ensuring a human can intervene when AI output is incorrect or harmful
- C. Replacing the need for model testing
- D. Satisfying marketing claims about "human-centered AI"
Answer: B
Override procedures are a key control against erroneous or harmful automated decisions.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q158 When addressing independent validation of model results, an AI risk practitioner should FIRST:
- A. Have model validation performed by a function independent from model development
- B. Allow the development team to self-validate without independent review
- C. Use independent validation only for regulator-mandated models
- D. Skip independent validation for internally facing tools
Answer: A
Independent validation reduces conflict-of-interest risk and should not be limited to regulated or self-validated cases.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q159 A defined trigger for AI model retraining (e.g., performance degradation beyond a threshold) is preferable to a purely calendar-based retraining schedule PRIMARILY because it:
- A. Is required by all regulatory frameworks
- B. Is cheaper to implement in all cases
- C. Responds to actual model drift or degradation rather than retraining unnecessarily or too late
- D. Removes the need for ongoing performance monitoring
Answer: C
Trigger-based retraining responds to observed drift/degradation, avoiding both wasted effort from premature retraining and risk from waiting too long under a fixed calendar schedule.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q160 Regarding AI policy review cadence, the BEST practice is to:
- A. Review AI policies annually regardless of major changes in between
- B. Review and update AI policies on a defined periodic cycle and after significant regulatory or technology changes
- C. Review AI policies only once at initial publication
- D. Review AI policies only when an incident forces a change
Answer: B
AI policies need periodic review plus trigger-based updates for significant regulatory or technology shifts, not a one-time or purely incident-driven cycle.