AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q271 When addressing documentation for regulatory AI audits, an AI risk practitioner should FIRST:

Answer: A

Audit-ready AI documentation must be maintained proactively and substantively, not assembled reactively or kept informally.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q272 Regarding framework integration with ERM, the BEST practice is to:

Answer: A

AI risk frameworks should integrate with, not duplicate or replace, existing enterprise risk management.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q273 Regarding control design for AI-specific risks, the BEST practice is to:

Answer: B

AI risk requires purpose-built controls (bias, drift, explainability) beyond generic IT or security-only controls.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q274 Setting a Key Risk Indicator (KRI) threshold too conservatively (too sensitive) for AI model drift MOST risks:

Answer: B

Overly sensitive thresholds generate excess false positives, risking alert fatigue.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q275 When addressing prioritizing AI risk scenarios for treatment, an AI risk practitioner should FIRST:

Answer: C

Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q276 When an enterprise operates in multiple jurisdictions, its AI framework selection should MOST consider:

Answer: B

A framework must flex to the most stringent applicable requirement, not the lowest common denominator.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q277 Integrating AI risk reporting into existing enterprise risk management (ERM) reporting cycles is valuable because it:

Answer: B

Consolidated reporting avoids AI risk being treated in isolation from overall enterprise risk.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q278 Identifying AI risk scenarios should draw on:

Answer: B

Comprehensive scenario identification draws on multiple, enterprise-specific information sources.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q279 Classifying an AI incident's severity should PRIMARILY consider:

Answer: B

Severity classification should reflect real/potential impact, not procedural or arbitrary factors.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q280 Role-based AI training (e.g., different content for developers vs. business users) is MOST effective because it:

Answer: B

Tailored training addresses each role's actual risk exposure and responsibilities.

‹ Prev
Next ›
Page 28 of 50 · 500 questions