Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q231 An AI maturity assessment is MOST useful for:
- A. Benchmarking current governance capability against a target state to prioritize improvement
- B. Determining employee bonuses
- C. Replacing the need for a risk register
- D. Satisfying a one-time audit request only
Answer: A
Maturity assessments gauge current vs. target capability, driving a prioritized roadmap.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q232 A control's operating effectiveness refers to:
- A. Whether the control concept would work in theory
- B. Whether the control is actually functioning as designed in practice over time
- C. The documentation quality of the control
- D. The control's cost relative to budget
Answer: B
Operating effectiveness is about real-world, ongoing performance of the control.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q233 A "risk-based" AI regulatory approach (e.g., EU AI Act tiering) requires the enterprise to PRIMARILY:
- A. Apply identical controls to every AI system regardless of use case
- B. Classify systems by risk tier and apply proportionate obligations accordingly
- C. Ignore low-risk systems entirely
- D. Apply controls only to systems already causing incidents
Answer: B
Risk-based regulation requires tiered classification and proportionate control application.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q234 Ongoing vendor risk monitoring (not just pre-contract due diligence) is important PRIMARILY because:
- A. Vendor risk posture is static once assessed
- B. Vendor risk posture can change over time (e.g., breaches, ownership changes, control degradation)
- C. It is required only at contract renewal
- D. It replaces the need for contractual protections
Answer: B
Vendor risk can evolve, so monitoring must continue beyond the initial assessment.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q235 Comparing candidate AI frameworks, an enterprise should weigh "ease of integration with existing GRC tooling" because it:
- A. Guarantees regulatory compliance
- B. Affects the practical cost/speed of embedding AI risk into existing governance processes
- C. Is irrelevant to governance outcomes
- D. Replaces the need for board oversight
Answer: B
Integration ease is a practical adoption factor, not a compliance guarantee.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q236 Regarding build vs buy AI strategy, the BEST practice is to:
- A. Always buy to minimize effort
- B. Decide based on vendor relationship history only
- C. Assess risk, control, and total cost of ownership differences between building and buying AI
- D. Always build in-house for control reasons alone
Answer: C
Build-vs-buy decisions require weighing risk, control, and cost, not defaulting to one option automatically.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q237 In the context of AI incident classification scheme, which of the following represents sound AI risk management?
- A. Classify incidents only after the response has already concluded
- B. Limit incident classification to security-related AI incidents
- C. Classify AI incidents by severity and type to drive proportionate response actions
- D. Treat all AI incidents with an identical response regardless of severity
Answer: C
Severity/type-based classification enables proportionate response, rather than uniform, after-the-fact, or security-only classification.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q238 Scheduled maintenance/retraining of an AI model is driven PRIMARILY by:
- A. Calendar convenience only
- B. Observed or expected model drift and changing data/business conditions
- C. Vendor contract renewal dates exclusively
- D. Marketing campaign schedules
Answer: B
Retraining cadence should track actual drift/conditions, not arbitrary calendar convenience.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q239 The distinction between "human-in-the-loop" and "human-on-the-loop" oversight models is BEST described as:
- A. Human-in-the-loop requires human approval before an AI decision takes effect, while human-on-the-loop allows the AI to act autonomously with human monitoring and intervention capability
- B. Human-in-the-loop is only used for low-risk, low-impact decisions
- C. Human-on-the-loop means no human involvement at all
- D. There is no meaningful difference between the two terms
Answer: A
Human-in-the-loop gates each decision on human approval, whereas human-on-the-loop permits autonomous AI action with a human able to monitor and intervene; the choice should match the decision's stakes.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q240 Regarding AI risk register maintenance, the BEST practice is to:
- A. Create a risk register once and leave it static
- B. Maintain the risk register only for regulator-visible systems
- C. Update the risk register only during annual reviews
- D. Maintain a living AI risk register that is updated as risks, controls, and context change
Answer: D
The AI risk register should be actively maintained and updated, not static, partial, or infrequently reviewed.