Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q211 When addressing holdout and cross-validation practices, an AI risk practitioner should FIRST:
- A. Evaluate performance only on the training dataset
- B. Skip validation when time pressure is high
- C. Validate only on a small, convenient sample
- D. Use holdout or cross-validation techniques to assess model generalization before deployment
Answer: D
Robust generalization assessment via holdout/cross-validation is needed, not training-only or convenience-sample evaluation.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q212 Independent model validation (separate from the development team) is important PRIMARILY to:
- A. Slow down deployment for its own sake
- B. Provide objective assurance that the model performs as intended without developer bias
- C. Replace the need for documentation
- D. Satisfy a purely cosmetic governance requirement
Answer: B
Independence reduces the risk of developer bias influencing the validation outcome.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q213 HR's role in supporting AI governance is MOST accurately described as:
- A. Supporting employee end users of AI solutions through job classification and related job training
- B. Approving the technical architecture of AI models
- C. Setting the enterprise's AI risk appetite
- D. Conducting the independent audit of AI risk
Answer: A
HR's contribution is centered on job classification and training support for employee end users, not technical architecture, audit, or risk appetite decisions.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q214 Record-keeping obligations for high-risk AI systems typically require retaining:
- A. Nothing, since AI decisions are self-explanatory
- B. Logs sufficient to demonstrate traceability, decisions, and compliance over the system's lifecycle
- C. Only the initial design document
- D. Only marketing materials
Answer: B
Traceable logs/records across the lifecycle support audit and regulatory demonstration.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q215 Regarding segregation of duties in AI operations, the BEST practice is to:
- A. Apply segregation of duties between AI model development, validation, and deployment approval
- B. Allow the same individual to develop, validate, and approve deployment of a model
- C. Apply segregation of duties only for financial-reporting-related AI
- D. Rely on informal trust instead of segregation of duties
Answer: A
Segregation of duties across development, validation, and approval reduces risk and should not be collapsed into one role or informal trust.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q216 Automated monitoring tools for AI controls are valuable PRIMARILY because they:
- A. Eliminate the need for any human oversight
- B. Can detect control failures or anomalies faster and more consistently than manual review alone
- C. Guarantee zero false positives
- D. Replace the need for independent validation
Answer: B
Automation improves speed/consistency of detection but does not eliminate the need for human oversight.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q217 An AI-specific incident response plan should differ from a generic IT plan PRIMARILY by including:
- A. Identical generic steps with no AI-specific considerations
- B. Specific procedures for model-related issues (e.g., harmful outputs, data poisoning, drift-driven errors)
- C. No reference to the AI system at all
- D. Steps relevant only to hardware failures
Answer: B
AI incident response must address AI-specific failure modes beyond generic IT issues.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q218 Integrating AI risk checkpoints into the software development lifecycle (SDLC) is valuable MAINLY because it:
- A. Slows down all development uniformly
- B. Catches AI-specific risks (bias, data quality) before deployment rather than after
- C. Replaces the need for post-deployment monitoring
- D. Is required only for regulated industries
Answer: B
Embedding checkpoints early catches AI risks before they reach production.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q219 AI risk reporting to the board should PRIMARILY focus on:
- A. Granular technical model code details
- B. Material risk exposure, trends, and decisions requiring board attention
- C. Every minor technical incident regardless of materiality
- D. Vendor sales pitches
Answer: B
Board reporting should be material and decision-relevant, not granular technical detail.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q220 Defining acceptance criteria BEFORE AI model development begins is important PRIMARILY because it:
- A. Guarantees the model will be perfect
- B. Establishes clear, objective targets against which success/risk can later be measured
- C. Is only relevant for procurement, not in-house builds
- D. Eliminates the need for testing
Answer: B
Upfront acceptance criteria give objective, measurable targets for later evaluation.