Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q11 An enterprise evaluating key risk indicator thresholds for AI should PRIMARILY ensure that:
- A. Set a single enterprise-wide KRI threshold applied uniformly to all AI systems regardless of risk level
- B. Monitor AI KRIs without any defined escalation threshold
- C. Define threshold levels for AI key risk indicators that trigger defined escalation actions
- D. Review KRI breaches only during scheduled quarterly meetings
Answer: C
KRI thresholds should be risk-appropriate per system and trigger timely escalation; a single uniform threshold, no threshold, and quarterly-only review all fall short.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q12 With respect to data retention policy for AI systems, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Retain all AI-related data indefinitely by default
- B. Apply the enterprise's general records-retention policy unchanged, without AI-specific adaptation
- C. Leave retention decisions to individual data scientists
- D. Apply defined data retention and disposal schedules tailored to data used in AI systems
Answer: D
AI data needs retention/disposal schedules tailored to its specific risks; an unmodified general policy, indefinite retention, and ad hoc individual decisions do not provide this.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q13 An enterprise evaluating cross-functional AI committee composition should PRIMARILY ensure that:
- A. Include risk, legal, data, business, and technical stakeholders in AI governance decisions from the outset
- B. Limit AI governance decisions to the data science team
- C. Include technical and business stakeholders, adding legal and risk representatives only once a regulatory issue arises
- D. Limit AI governance decisions to IT alone
Answer: A
Effective governance committees need full cross-functional representation from the start, not legal/risk added reactively, nor decisions confined to one function.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q14 When addressing new-hire AI onboarding training, an AI risk practitioner should FIRST:
- A. Limit onboarding AI training to technical staff only
- B. Include dedicated AI risk and acceptable-use training in new-hire onboarding
- C. Make AI training optional for new hires
- D. Provide standard information-security onboarding training and assume it adequately covers AI-specific risks
Answer: B
AI risk awareness needs dedicated onboarding content; generic security training alone, technical-only scope, and optional participation all leave gaps.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q15 An enterprise evaluating AI center of excellence role should PRIMARILY ensure that:
- A. Allow each business unit to establish its own AI center of excellence, coordinating informally through personal relationships
- B. Let every business unit define its own AI standards independently
- C. Establish a central function to coordinate standards, risk practices, and knowledge sharing across AI initiatives
- D. Avoid centralizing AI coordination to preserve business unit autonomy
Answer: C
A central coordinating function standardizes practices across the enterprise; informal unit-level coordination, independent standards, and avoiding centralization all leave practices fragmented.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q16 Lessons learned from an AI incident should PRIMARILY be used to:
- A. File the report away with no further action
- B. Produce a detailed report for senior management, without a formal requirement to update controls or training
- C. Assign blame publicly to the individuals involved
- D. Update controls, policies, and training to reduce the likelihood and impact of recurrence
Answer: D
Lessons learned should feed back into controls, policy, and training; reporting without a mandate to act, filing away, and public blame-assignment all fail to close the loop.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q17 A RACI matrix for AI risk governance is MOST useful for:
- A. Clarifying who is Responsible, Accountable, Consulted, and Informed for AI risk decisions
- B. Deciding software licensing costs for AI tools
- C. Documenting the reporting hierarchy and job titles involved in AI governance
- D. Automating model training workflows
Answer: A
RACI clarifies decision roles (R/A/C/I), which is distinct from an org chart of titles/hierarchy, and unrelated to licensing costs or automation.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q18 Regarding business continuity planning for AI outages, the BEST practice is to:
- A. Assume existing generic IT continuity plans fully cover AI failure scenarios
- B. Include AI system failure/outage scenarios explicitly within business continuity plans
- C. Limit continuity planning to data center failure scenarios
- D. Extend the existing data-center failover plan to also cover AI systems hosted there
Answer: B
Continuity plans need AI-specific failure scenarios (e.g., model degradation, not just infrastructure loss); extending only a data-center failover plan, assuming generic coverage, or limiting scope to infrastructure all miss AI-specific failure modes.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q19 Design-stage threat modeling for an AI system should PRIMARILY identify:
- A. General IT infrastructure vulnerabilities, such as unpatched servers hosting the model
- B. Marketing positioning risks
- C. Potential adversarial, data, and misuse risks specific to the system's design
- D. Office location risks
Answer: C
Design-stage threat modeling targets risks inherent to the AI system's design (adversarial, data, misuse), not generic infrastructure vulnerabilities, which are covered by standard IT security processes.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q20 When AI regulations conflict across jurisdictions where the enterprise operates, legal counsel should be engaged to:
- A. Pick whichever regulation is easiest to ignore
- B. Select whichever jurisdiction's requirements are least costly to implement
- C. Avoid documenting the conflict
- D. Determine applicable obligations and the most defensible compliance approach
Answer: D
Legal counsel should determine actual applicability and recommend a defensible path; choosing by cost alone, ignoring rules, or avoiding documentation are not substitutes for that analysis.