Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q201 In the context of AI model documentation standards, which of the following represents sound AI risk management?
- A. Document only the model's intended use, omitting limitations
- B. Document models only when externally regulated
- C. Require standardized documentation covering model purpose, data, assumptions, and limitations
- D. Allow documentation format and content to vary freely by team
Answer: C
Standardized documentation covering purpose, data, assumptions, and limitations supports consistent risk management.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q202 In the context of design-stage risk identification, which of the following represents sound AI risk management?
- A. Address risks only once they manifest in production
- B. Limit risk identification to the testing phase
- C. Assign risk identification solely to the compliance team after launch
- D. Identify foreseeable risks (bias, security, misuse) during the AI design stage, not after deployment
Answer: D
Foreseeable risks should be identified at design time, which is cheaper and more effective than post-deployment fixes.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q203 A risk scenario involving third-party AI API outages should be evaluated for impact on:
- A. Vendor stock price only
- B. Business process continuity and dependent downstream services
- C. Marketing campaign timing only
- D. Nothing, since it is outside enterprise control
Answer: B
Third-party dependency risk should be assessed for its effect on business continuity.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q204 When an AI system is used for a dual-use purpose (beneficial and potentially harmful applications), the organization's PRIMARY governance responsibility is to:
- A. Restrict use only after misuse has already occurred
- B. Avoid the technology entirely regardless of its beneficial use cases
- C. Assess and mitigate misuse risk while enabling legitimate use, consistent with the organization's risk appetite and ethical boundaries
- D. Rely solely on the AI vendor to prevent misuse
Answer: C
Dual-use risk requires proactive assessment and mitigation of misuse potential while still enabling legitimate value, rather than outright avoidance or purely reactive controls.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q205 An AI use case prioritization exercise should MOST rely on:
- A. A risk-versus-value matrix
- B. The CIO's personal preference
- C. Vendor marketing material
- D. The number of employees requesting the use case
Answer: A
Prioritization should be risk-informed and value-based, not popularity- or preference-driven.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q206 Under an AI shared responsibility model with a third-party provider, the enterprise deploying the AI solution MOST retains responsibility for:
- A. The provider's internal model training infrastructure security
- B. Nothing, since responsibility fully transfers to the provider upon contract signing
- C. Only incidents that occur during the provider's maintenance windows
- D. How the AI solution is configured, used, and governed within its own environment, even when the underlying model is provided externally
Answer: D
Shared responsibility models typically leave the deploying enterprise accountable for configuration, use, and governance in its own environment, while the provider is responsible for its own infrastructure.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q207 Regarding legal basis for AI processing of personal data, the BEST practice is to:
- A. Establish and document a valid legal basis before using personal data in AI processing
- B. Assume consent is implied by data being already collected
- C. Proceed with processing and determine legal basis if challenged
- D. Use the most convenient legal basis regardless of actual applicability
Answer: A
A valid, documented legal basis must be established before processing, not assumed or determined after the fact.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q208 A key reason to periodically test AI controls (not just design them once) is that:
- A. Controls never change once implemented
- B. Control effectiveness can degrade over time due to changing systems, data, or usage patterns
- C. Testing is only required by external auditors
- D. Testing eliminates the need for monitoring
Answer: B
Ongoing testing catches control degradation caused by evolving systems/data/usage.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q209 When addressing alignment of AI metrics with business KPIs, an AI risk practitioner should FIRST:
- A. Tie AI performance metrics back to relevant business KPIs and risk indicators
- B. Track AI metrics in isolation from business performance
- C. Only track technical accuracy metrics
- D. Avoid defining AI metrics until problems arise
Answer: A
AI metrics should connect to business KPIs and risk indicators, not remain purely technical or reactive.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q210 Change control for AI model updates is important MAINLY because:
- A. Even minor changes can alter model behavior and introduce new risk
- B. Updates never affect model behavior
- C. It is only relevant for major version changes
- D. It replaces the need for post-update monitoring
Answer: A
Even small changes to AI models can meaningfully change behavior, warranting controlled change management.