Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q191 An AI steering committee is MOST usefully described as:
- A. A technical team solely responsible for writing AI model code
- B. A subcommittee of the board with no operational involvement
- C. A cross-functional group providing insight into AI strategy, opportunities, and concerns across organizational units
- D. An external auditor engaged to certify AI model accuracy
Answer: C
The AI steering committee is cross-functional, spanning disciplines, and is sometimes integrated into existing IT or innovation committees to advise on AI strategy impacts.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q192 When addressing AI center of excellence role, an AI risk practitioner should FIRST:
- A. Let every business unit define its own AI standards
- B. Assign AI coordination to a single developer informally
- C. Avoid centralizing AI coordination to preserve business unit autonomy
- D. Establish a central function to coordinate standards, risk practices, and knowledge sharing across AI initiatives
Answer: D
A coordinating function (e.g., CoE) standardizes practices and risk management across decentralized AI efforts.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q193 The responsibility of the enterprise's governing body for AI oversight is BEST characterized as:
- A. Delegable to a third-party AI vendor once a service contract is signed
- B. Required only when an AI incident has already occurred
- C. Limited to financial objectives only, excluding ethics and culture
- D. Non-delegable, extending beyond financial objectives to the culture, values, and ethics of the enterprise
Answer: D
The governing body's accountability for organizational activities, including AI adoption and its consequences, cannot be delegated and extends beyond financial goals to culture, values, and ethics.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q194 In the context of AI risk metric selection, which of the following represents sound AI risk management?
- A. Track only technical accuracy metrics as the sole risk indicator
- B. Define metrics once and never revisit their relevance
- C. Select AI risk metrics that are measurable, relevant to key risks, and actionable for decision-makers
- D. Select metrics based only on what is easiest to collect
Answer: C
Risk metrics should be relevant and actionable, not chosen purely for ease of collection or left static over time.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q195 Procurement due diligence for a third-party AI solution should PRIMARILY assess:
- A. The vendor's office size
- B. The vendor's data handling, security, and model risk practices
- C. The vendor's social media presence
- D. The length of the vendor's sales pitch
Answer: B
Due diligence should focus on substantive risk practices, not superficial vendor attributes.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q196 A societal impact assessment for a new AI deployment should consider:
- A. Only the enterprise's direct financial return
- B. Broader effects on stakeholders, communities, and vulnerable groups
- C. Only IT infrastructure costs
- D. Only the competitive landscape
Answer: B
Societal impact assessments look beyond financial return to broader stakeholder effects.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q197 When synthetic data is used for model training, validation should additionally confirm:
- A. The synthetic data's statistical properties and that it does not introduce new bias or unrealistic patterns
- B. That synthetic data is always superior to real data
- C. That no further validation is needed
- D. Only the file format of the synthetic dataset
Answer: A
Synthetic data carries its own risk of unrealistic patterns or bias that validation must specifically check.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q198 Product management's role in AI governance, as distinct from development and operations, is BEST described as:
- A. Bridging the gap between technical staff and end users to ensure AI solution usability
- B. Writing the model's training code
- C. Approving the enterprise's overall risk appetite
- D. Performing the independent audit of the AI program
Answer: A
Product management connects technical teams and end users to ensure usability, distinct from development/operations (building and running the solution) or audit/governing-body functions.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q199 Preventive controls for AI risk are intended PRIMARILY to:
- A. Detect issues after they occur
- B. Stop an undesired event from occurring in the first place
- C. Recover systems after failure
- D. Document incidents after the fact
Answer: B
Preventive controls act before the undesired event occurs.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q200 When rolling out a new AI system, change management is MOST critical for:
- A. Reducing software licensing costs
- B. Ensuring affected staff understand new processes and residual risks
- C. Avoiding vendor contract renegotiation
- D. Shortening the testing phase
Answer: B
Change management addresses human/process impacts, which is where unmanaged AI risk often surfaces.