Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q251 When an enterprise cannot fully explain a third-party AI model's internal logic because it is proprietary, the enterprise's BEST course of action is to:
- A. Avoid any accountability since the logic is not accessible
- B. Decommission all third-party AI models immediately
- C. Seek alternative assurance (e.g., independent testing, documentation, audit rights) to compensate for the lack of internal visibility
- D. Assume the vendor's claims about the model are accurate without verification
Answer: C
When internal visibility into proprietary logic is limited, compensating controls such as independent testing, documentation review, or audit rights help maintain accountability.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q252 A change management approval process for updating a production AI model is MOST important because it:
- A. Can be bypassed for minor configuration changes without review
- B. Is only needed for changes initiated by external vendors
- C. Primarily exists to satisfy marketing requirements
- D. Ensures changes are reviewed and authorized before deployment, reducing the risk of unintended impact
Answer: D
Formal change management ensures proposed model changes are reviewed, tested, and authorized, reducing the risk that an update introduces unintended performance or risk impacts.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q253 When an AI model's output directly informs a regulated business decision (e.g., credit approval), accountability for that decision rests PRIMARILY with:
- A. The AI vendor exclusively
- B. The business owner responsible for the decision, informed by model risk controls
- C. The data scientist who built the model
- D. No one, since the decision is automated
Answer: B
Automation does not remove business accountability for regulated decisions.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q254 When addressing organizational alignment of AI initiatives, an AI risk practitioner should FIRST:
- A. Align AI initiatives only to IT's technical roadmap
- B. Align AI initiatives only after audit findings require it
- C. Ensure AI initiatives are aligned to defined business objectives and governance structures
- D. Allow business units to pursue AI initiatives independently of governance
Answer: C
AI initiatives should align to business objectives within governance structures, not run independently of oversight.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q255 Providing affected individuals with a clear channel to contest or appeal an AI-driven decision is BEST justified as:
- A. A core transparency and accountability practice that allows errors or unfair outcomes to be identified and corrected
- B. A substitute for explaining how the decision was reached
- C. Relevant only in jurisdictions with specific AI legislation
- D. An optional courtesy with no bearing on trustworthiness
Answer: A
A contest/appeal channel is a core accountability mechanism that surfaces and corrects errors or unfairness; it complements, rather than substitutes for, explaining the decision itself.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q256 An effective escalation path for AI risk issues should ensure that:
- A. Only the CEO is informed, regardless of severity
- B. Issues are routed to the appropriate risk owner based on severity and impact
- C. All issues are resolved by the original developer only
- D. Escalation only occurs after regulatory inquiry
Answer: B
Escalation paths should route issues by severity/impact, not centralize everything or wait for external triggers.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q257 Contractual AI vendor clauses should address liability allocation PRIMARILY to:
- A. Ensure the vendor bears zero responsibility
- B. Clearly define responsibility for AI-related harms, errors, or compliance failures
- C. Avoid specifying any responsibility, to simplify the contract
- D. Shift all liability to end customers
Answer: B
Clear liability allocation reduces disputes and clarifies accountability for AI-related harm.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q258 Risk avoidance as an AI risk treatment means:
- A. Implementing additional monitoring controls
- B. Choosing not to proceed with the AI use case due to unacceptable risk
- C. Accepting the risk as-is
- D. Purchasing insurance against the risk
Answer: B
Avoidance means not pursuing the activity because the risk is unacceptable.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q259 When addressing control ownership and accountability, an AI risk practitioner should FIRST:
- A. Leave control ownership undefined across shared teams
- B. Assign control ownership only for controls tied to regulatory requirements
- C. Rotate control ownership frequently without handover documentation
- D. Assign clear ownership for each AI control, including responsibility for monitoring its operation
Answer: D
Each control needs a clear, accountable owner responsible for ongoing operation, not undefined or poorly transitioned ownership.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q260 A cost-benefit analysis of an AI control should weigh:
- A. Only the control's implementation cost
- B. Implementation/operating cost against the risk reduction and potential loss avoided
- C. Only the vendor's price list
- D. Only qualitative stakeholder opinion
Answer: B
Cost-benefit analysis balances control cost against quantified/qualified risk reduction.