Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q171 In the context of risk treatment option selection, which of the following represents sound AI risk management?
- A. Always accept AI risk to avoid implementation effort
- B. Transfer all AI risk via insurance without considering mitigation
- C. Select AI risk treatment (avoid, mitigate, transfer, accept) based on cost-benefit relative to risk appetite
- D. Always choose mitigation regardless of cost-effectiveness
Answer: C
Treatment choice should be a cost-benefit decision aligned with risk appetite, not a default to one option.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q172 Post-incident root cause analysis for an AI failure should PRIMARILY aim to:
- A. Assign individual blame as the main outcome
- B. Identify the true underlying cause(s) to prevent recurrence
- C. Close the incident ticket as quickly as possible with minimal analysis
- D. Avoid documenting findings
Answer: B
Root cause analysis is about preventing recurrence, not blame assignment or speed over substance.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q173 When addressing cross-border AI strategy alignment, an AI risk practitioner should FIRST:
- A. Apply one region's rules globally without review
- B. Let each region choose frameworks independently with no coordination
- C. Defer all strategy decisions to IT
- D. Reconcile AI strategy with varying regional regulatory and risk expectations
Answer: D
Cross-border AI strategy must reconcile differing regional requirements, not default to one region or fragment entirely.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q174 Risk scenario ownership should be assigned to:
- A. Whoever is available at the time
- B. The role best positioned to understand, monitor, and respond to that specific risk
- C. The AI vendor by default
- D. No one, since scenarios are theoretical
Answer: B
Ownership should align with who can actually monitor and respond to the specific risk.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q175 An AI asset inventory should, at minimum, capture:
- A. Only the purchase price of each system
- B. System owner, purpose, data used, and risk classification
- C. Only the vendor's logo and marketing materials
- D. Nothing beyond the system name
Answer: B
Meaningful asset inventories need owner/purpose/data/risk classification to support governance.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q176 In the context of procedure documentation for AI model changes, which of the following represents sound AI risk management?
- A. Allow informal verbal approval for AI model changes
- B. Document procedures only for production failures
- C. Skip documentation for minor model updates
- D. Maintain documented procedures for requesting, approving, and recording AI model changes
Answer: D
Documented change procedures should apply consistently, including to seemingly minor AI model updates.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q177 When addressing emerging AI risk identification, an AI risk practitioner should FIRST:
- A. Establish a process to continuously identify new and emerging AI risks as technology and use evolve
- B. Identify AI risks only once during initial project approval
- C. Rely solely on external audit to surface new AI risks
- D. Limit risk identification to risks already seen at peer companies
Answer: A
Continuous, enterprise-driven identification is needed for emerging AI risk, not one-time, audit-only, or peer-limited approaches.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q178 Board-level approval of the enterprise AI strategy is important PRIMARILY because:
- A. It is a regulatory formality with no substantive value
- B. The board is accountable for overseeing enterprise risk, including AI risk
- C. It delays implementation, reducing risk exposure
- D. It transfers liability to the board alone
Answer: B
Board accountability for enterprise risk extends to AI; approval reflects substantive oversight, not formality.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q179 An AI risk scenario describing "model drift causing incorrect loan approvals" should PRIMARILY be assessed for:
- A. Likelihood and business impact to prioritize treatment
- B. Only the cost of retraining
- C. Marketing reputation alone
- D. Whether competitors have the same model
Answer: A
Risk scenarios are prioritized by likelihood and impact, the core risk assessment inputs.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q180 Regarding risk treatment option selection, the BEST practice is to:
- A. Transfer all AI risk via insurance without considering mitigation
- B. Select AI risk treatment (avoid, mitigate, transfer, accept) based on cost-benefit relative to risk appetite
- C. Always choose mitigation regardless of cost-effectiveness
- D. Always accept AI risk to avoid implementation effort
Answer: B
Treatment choice should be a cost-benefit decision aligned with risk appetite, not a default to one option.