AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q151 Escalation thresholds for AI model issues should be defined PRIMARILY based on:

Answer: B

Thresholds should reflect actual materiality of impact, ensuring proportionate escalation.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q152 Enterprises should disclose AI use to end users PRIMARILY to:

Answer: B

Transparency about AI use supports informed consent, trust, and regulatory expectations.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q153 A concentration risk in AI supply chain arises when:

Answer: B

Heavy reliance on a single vendor/provider creates concentration risk and single-point-of-failure exposure.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q154 Assessing a third-party AI vendor's risk should PRIMARILY evaluate:

Answer: B

Vendor risk assessment should focus on substantive security/resilience practices.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q155 In the context of post-incident lessons-learned integration, which of the following represents sound AI risk management?

Answer: B

Lessons learned should formally update assessments, controls, and training, not stay informal or undocumented without action.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q156 When addressing AI policy review cadence, an AI risk practitioner should FIRST:

Answer: D

AI policies need periodic review plus trigger-based updates for significant regulatory or technology shifts, not a one-time or purely incident-driven cycle.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q157 A documented procedure for human override of an AI decision is MOST important for:

Answer: B

Override procedures are a key control against erroneous or harmful automated decisions.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q158 When addressing independent validation of model results, an AI risk practitioner should FIRST:

Answer: A

Independent validation reduces conflict-of-interest risk and should not be limited to regulated or self-validated cases.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q159 A defined trigger for AI model retraining (e.g., performance degradation beyond a threshold) is preferable to a purely calendar-based retraining schedule PRIMARILY because it:

Answer: C

Trigger-based retraining responds to observed drift/degradation, avoiding both wasted effort from premature retraining and risk from waiting too long under a fixed calendar schedule.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q160 Regarding AI policy review cadence, the BEST practice is to:

Answer: B

AI policies need periodic review plus trigger-based updates for significant regulatory or technology shifts, not a one-time or purely incident-driven cycle.

‹ Prev
Next ›
Page 16 of 50 · 500 questions