AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q201 In the context of AI model documentation standards, which of the following represents sound AI risk management?

Answer: C

Standardized documentation covering purpose, data, assumptions, and limitations supports consistent risk management.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q202 In the context of design-stage risk identification, which of the following represents sound AI risk management?

Answer: D

Foreseeable risks should be identified at design time, which is cheaper and more effective than post-deployment fixes.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q203 A risk scenario involving third-party AI API outages should be evaluated for impact on:

Answer: B

Third-party dependency risk should be assessed for its effect on business continuity.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q204 When an AI system is used for a dual-use purpose (beneficial and potentially harmful applications), the organization's PRIMARY governance responsibility is to:

Answer: C

Dual-use risk requires proactive assessment and mitigation of misuse potential while still enabling legitimate value, rather than outright avoidance or purely reactive controls.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q205 An AI use case prioritization exercise should MOST rely on:

Answer: A

Prioritization should be risk-informed and value-based, not popularity- or preference-driven.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q206 Under an AI shared responsibility model with a third-party provider, the enterprise deploying the AI solution MOST retains responsibility for:

Answer: D

Shared responsibility models typically leave the deploying enterprise accountable for configuration, use, and governance in its own environment, while the provider is responsible for its own infrastructure.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q207 Regarding legal basis for AI processing of personal data, the BEST practice is to:

Answer: A

A valid, documented legal basis must be established before processing, not assumed or determined after the fact.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q208 A key reason to periodically test AI controls (not just design them once) is that:

Answer: B

Ongoing testing catches control degradation caused by evolving systems/data/usage.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q209 When addressing alignment of AI metrics with business KPIs, an AI risk practitioner should FIRST:

Answer: A

AI metrics should connect to business KPIs and risk indicators, not remain purely technical or reactive.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q210 Change control for AI model updates is important MAINLY because:

Answer: A

Even small changes to AI models can meaningfully change behavior, warranting controlled change management.

‹ Prev
Next ›
Page 21 of 50 · 500 questions