Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q261 Regarding AI center of excellence role, the BEST practice is to:
- A. Avoid centralizing AI coordination to preserve business unit autonomy
- B. Establish a central function to coordinate standards, risk practices, and knowledge sharing across AI initiatives
- C. Let every business unit define its own AI standards
- D. Assign AI coordination to a single developer informally
Answer: B
A coordinating function (e.g., CoE) standardizes practices and risk management across decentralized AI efforts.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q262 A right-to-audit clause in an AI vendor contract is valuable PRIMARILY because it:
- A. Guarantees the vendor will never have control failures
- B. Enables the enterprise to independently verify the vendor's control effectiveness
- C. Replaces the need for ongoing monitoring
- D. Is a purely symbolic legal formality
Answer: B
Audit rights enable independent verification, a substantive risk-management lever.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q263 Informed consent for individuals subject to AI-driven decisions is MOST meaningfully achieved when:
- A. Consent is implied simply by using the organization's service
- B. Consent is only required for AI systems used in healthcare
- C. Individuals are given clear, understandable disclosure about the AI's role in the decision and a genuine opportunity to question or contest it
- D. A generic privacy policy is published on the organization's website
Answer: C
Meaningful informed consent requires clear disclosure of the AI's role and a real avenue to question or contest outcomes, not a generic policy or implied consent through mere usage.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q264 Regarding AI-specific risk scenario development, the BEST practice is to:
- A. Limit scenario development to security risks alone
- B. Develop AI-specific risk scenarios covering bias, model failure, and misuse in addition to generic IT risk scenarios
- C. Reuse only generic IT risk scenarios for AI systems
- D. Develop AI risk scenarios only after an incident occurs
Answer: B
AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q265 The principle of explainability in AI trustworthiness is MOST concerned with:
- A. Ensuring the model is open-source
- B. Reducing the computational cost of running the model
- C. Guaranteeing a model's outputs are always 100% accurate
- D. Ensuring a model's internal workings or decision rationale can be understood by relevant stakeholders
Answer: D
Explainability is about making a model's decision logic understandable to affected stakeholders; it does not guarantee accuracy, reduce cost, or require open-source licensing.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q266 Upon decommissioning an AI model, the MOST critical consideration is:
- A. Reusing the hardware immediately
- B. Retaining data/documentation per legal and regulatory retention requirements
- C. Deleting all records immediately regardless of obligations
- D. Notifying only the original vendor
Answer: B
Decommissioning must respect legal/regulatory retention obligations, not default to deletion or reuse.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q267 When a KRI threshold is breached, the escalation process should ensure:
- A. The breach is noted but no action is required
- B. Timely notification to the appropriate risk owner for assessment and response
- C. The KRI is simply redefined to avoid future breaches
- D. Escalation occurs only at year-end
Answer: B
Threshold breaches require timely escalation and response, not redefinition to avoid the alert.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q268 Holdout/test data used to validate an AI model must be:
- A. Identical to the training data for consistency
- B. Independent of the training data to provide an unbiased performance estimate
- C. Smaller than the production dataset, with no other requirement
- D. Chosen after the model is deployed
Answer: B
Independent holdout data prevents inflated/biased performance estimates.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q269 A well-designed key risk indicator (KRI) for an AI system should be:
- A. Vague and qualitative only
- B. Measurable, relevant to a specific risk, and tied to a defined threshold
- C. Changed frequently with no consistent definition
- D. Reported only during audits
Answer: B
Effective KRIs are measurable, risk-relevant, and threshold-based.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q270 In the context of control effectiveness evaluation, which of the following represents sound AI risk management?
- A. Evaluate AI control effectiveness using evidence, not just confirmation that the control exists
- B. Treat a control as effective if it is merely documented in policy
- C. Evaluate control effectiveness only during external audits
- D. Assume control effectiveness if no incidents have occurred yet
Answer: A
Effectiveness evaluation needs evidence-based testing, not mere existence, external-only review, or absence-of-incident assumption.