Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q221 Automated AI risk reporting, compared to manual reporting, is MOST valuable because it:
- A. Is required by law in all jurisdictions
- B. Eliminates the need for any human review of risk data
- C. Provides timelier, more consistent visibility into risk metrics, supporting faster escalation when thresholds are breached
- D. Removes the need to define key risk indicators (KRIs) in advance
Answer: C
Automated reporting improves timeliness and consistency of risk visibility, supporting faster escalation; it still requires human review and predefined KRIs, and is not a universal legal mandate.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q222 Regarding AI vendor security assessment, the BEST practice is to:
- A. Assess vendor security only once, at initial onboarding
- B. Limit vendor security assessment to contractual penalty clauses
- C. Conduct security assessments of AI vendors covering data handling, model security, and incident history
- D. Rely solely on a vendor's self-certification of security practices
Answer: C
Vendor security assessment should be substantive and periodically refreshed, not based solely on self-certification or onboarding-only.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q223 The four standard risk treatment options applicable to AI risk are:
- A. Avoid, mitigate, transfer, accept
- B. Ignore, escalate, delay, deny
- C. Automate, outsource, insure, disclose
- D. Report, retrain, redeploy, retire
Answer: A
These are the standard enterprise risk treatment categories, applicable to AI risk as well.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q224 Regarding post-incident lessons-learned integration, the BEST practice is to:
- A. Feed AI incident lessons learned back into risk assessments, controls, and training
- B. Close AI incidents without updating related risk assessments or controls
- C. Share lessons learned only informally among the immediate response team
- D. Document lessons learned but take no corrective action
Answer: A
Lessons learned should formally update assessments, controls, and training, not stay informal or undocumented without action.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q225 A control requiring human review before an AI-generated loan decision takes effect is an example of:
- A. A detective control
- B. A preventive control
- C. A corrective control
- D. A control with no risk-reduction effect
Answer: B
Reviewing/approving before the decision takes effect prevents harm before it occurs, making it preventive.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q226 Version control for AI models in production is PRIMARILY important because it:
- A. Is only relevant for open-source models
- B. Replaces the need for a documented rollback plan
- C. Is handled automatically by cloud providers with no organizational responsibility
- D. Enables tracing which model version produced a given decision and supports reverting to a known-good version if issues arise
Answer: D
Model version control provides traceability of decisions to specific model versions and underpins the ability to revert reliably, complementing rather than replacing rollback planning.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q227 When assessing likelihood and impact of an AI risk scenario, the enterprise should PRIMARILY use:
- A. Pure intuition, with no documented basis
- B. A consistent, defined methodology applied across the risk register
- C. Only the AI vendor's self-assessment
- D. A method chosen anew for every assessment
Answer: B
Consistent methodology ensures comparability of risk assessments across the enterprise.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q228 Regarding data lineage documentation during development, the BEST practice is to:
- A. Assume data lineage is unnecessary if data was purchased
- B. Document data lineage only for personally identifiable data
- C. Document data lineage only after a data quality incident
- D. Document the lineage of training and input data from source to model use
Answer: D
Full data lineage documentation supports traceability and risk management regardless of data source or incident history.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q229 A generative AI use case that produces customer-facing content introduces risk MOST related to:
- A. Hardware depreciation
- B. Output accuracy, bias, and reputational harm
- C. Office space planning
- D. Employee parking allocation
Answer: B
Customer-facing generative outputs carry accuracy/bias/reputational exposure, not facilities concerns.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q230 When selecting a risk treatment option, cost-effectiveness should be evaluated by comparing:
- A. Only the cost of controls, ignoring risk reduction achieved
- B. The cost of the treatment against the risk reduction it achieves relative to risk appetite
- C. Only the likelihood of the risk occurring
- D. Only vendor pricing
Answer: B
Cost-effectiveness weighs treatment cost against the actual risk reduction achieved.