Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q241 A control's design effectiveness refers to:
- A. Whether the control is operating as intended in practice
- B. Whether the control, if operated as designed, would adequately address the risk
- C. The cost of implementing the control
- D. The popularity of the control among peers
Answer: B
Design effectiveness is about whether the control's design would address the risk if executed properly.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q242 Regarding emerging AI risk identification, the BEST practice is to:
- A. Rely solely on external audit to surface new AI risks
- B. Limit risk identification to risks already seen at peer companies
- C. Establish a process to continuously identify new and emerging AI risks as technology and use evolve
- D. Identify AI risks only once during initial project approval
Answer: C
Continuous, enterprise-driven identification is needed for emerging AI risk, not one-time, audit-only, or peer-limited approaches.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q243 When addressing likelihood and impact estimation for AI risk, an AI risk practitioner should FIRST:
- A. Estimate risk levels based on intuition alone without supporting rationale
- B. Assume all AI risks have equal likelihood and impact
- C. Estimate impact only in financial terms, ignoring reputational or legal impact
- D. Estimate likelihood and impact of AI risk scenarios using available data and expert judgment
Answer: D
Risk estimation should use available evidence and judgment across multiple impact types, not uniform assumptions or financial-only framing.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q244 In the context of ethical use boundaries for AI, which of the following represents sound AI risk management?
- A. Define ethical boundaries only after public criticism arises
- B. Delegate ethical boundary decisions entirely to individual engineers
- C. Define clear ethical boundaries for AI use cases, including prohibited applications
- D. Allow any AI use case that is technically feasible
Answer: C
Ethical boundaries should be defined proactively and formally, not left to feasibility alone or individual discretion.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q245 When multiple control gaps are identified for an AI system, remediation should be prioritized by:
- A. Alphabetical order
- B. The severity of risk each gap exposes the enterprise to
- C. Which gap is cheapest to fix, regardless of risk
- D. Random selection
Answer: B
Remediation priority should track risk severity, not cost or arbitrary order alone.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q246 In the context of integration of AI risk metrics into enterprise reporting, which of the following represents sound AI risk management?
- A. Integrate AI risk metrics into existing enterprise risk reporting rather than maintaining a fully separate report
- B. Maintain AI risk metrics completely isolated from enterprise risk reporting
- C. Report AI risk metrics only within the AI development team
- D. Combine AI risk metrics into one unexplained composite score for executives
Answer: A
AI risk metrics should feed into integrated enterprise reporting, not remain isolated, team-limited, or overly compressed.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q247 Regarding concentration risk in AI supply chains, the BEST practice is to:
- A. Assume concentration risk is not a concern if the vendor is reputable
- B. Address concentration risk only after a vendor outage occurs
- C. Ignore concentration risk for non-customer-facing AI functions
- D. Evaluate concentration risk when multiple critical AI functions depend on a single vendor or model provider
Answer: D
Concentration risk should be proactively evaluated regardless of vendor reputation or whether functions are customer-facing.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q248 When AI initiatives are run as "shadow IT" outside formal governance, the GREATEST risk is:
- A. Faster innovation with no tradeoff
- B. Lack of visibility, oversight, and consistent control application
- C. Improved documentation
- D. Reduced total AI spend
Answer: B
Shadow AI evades the governance process entirely, removing visibility and control consistency.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q249 Exceptions to an AI policy should be:
- A. Granted automatically upon request
- B. Approved through a defined process with documented risk acceptance
- C. Never permitted under any circumstance
- D. Decided solely by the requesting business unit
Answer: B
Exceptions require a controlled approval process with documented risk acceptance, not informal or unilateral decisions.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q250 When addressing AI strategy use-case feasibility review, an AI risk practitioner should FIRST:
- A. Skip feasibility review for small-scale pilots
- B. Approve use cases once a vendor demo looks promising
- C. Conduct a feasibility review covering data availability, risk, and resourcing before approving a use case
- D. Approve use cases based only on executive sponsorship
Answer: C
Feasibility review of data, risk, and resourcing should precede use-case approval regardless of sponsorship or pilot size.