Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q271 When addressing documentation for regulatory AI audits, an AI risk practitioner should FIRST:
- A. Maintain audit-ready documentation of AI design, data sources, and decision logic
- B. Recreate documentation only when a regulator requests it
- C. Maintain documentation informally in individual staff notes
- D. Document only the final model output, not design rationale
Answer: A
Audit-ready AI documentation must be maintained proactively and substantively, not assembled reactively or kept informally.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q272 Regarding framework integration with ERM, the BEST practice is to:
- A. Integrate the AI risk framework into the existing enterprise risk management structure
- B. Operate the AI risk framework fully separate from ERM
- C. Replace ERM entirely with a standalone AI framework
- D. Ignore ERM when AI risk is involved
Answer: A
AI risk frameworks should integrate with, not duplicate or replace, existing enterprise risk management.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q273 Regarding control design for AI-specific risks, the BEST practice is to:
- A. Limit AI controls to data security measures alone
- B. Design controls specifically addressing AI risks such as bias, drift, and explainability gaps, not only generic IT controls
- C. Rely only on generic IT general controls for AI risk
- D. Design AI-specific controls only after a compliance finding
Answer: B
AI risk requires purpose-built controls (bias, drift, explainability) beyond generic IT or security-only controls.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q274 Setting a Key Risk Indicator (KRI) threshold too conservatively (too sensitive) for AI model drift MOST risks:
- A. Missing real drift events
- B. Excessive false-positive alerts, causing alert fatigue and reduced responsiveness
- C. Guaranteeing perfect detection with no downside
- D. Eliminating the need for any monitoring
Answer: B
Overly sensitive thresholds generate excess false positives, risking alert fatigue.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q275 When addressing prioritizing AI risk scenarios for treatment, an AI risk practitioner should FIRST:
- A. Prioritize risk treatment based solely on ease of implementation
- B. Prioritize only risks that have already caused incidents
- C. Prioritize AI risk scenarios for treatment based on combined likelihood and impact, aligned with risk appetite
- D. Treat all identified AI risks with equal priority and resources
Answer: C
Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q276 When an enterprise operates in multiple jurisdictions, its AI framework selection should MOST consider:
- A. Only the jurisdiction with the lowest regulatory burden
- B. The ability to adapt/scale controls to the most stringent applicable regulatory environment
- C. Picking a single framework regardless of jurisdictional differences
- D. Ignoring jurisdictional differences until an incident occurs
Answer: B
A framework must flex to the most stringent applicable requirement, not the lowest common denominator.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q277 Integrating AI risk reporting into existing enterprise risk management (ERM) reporting cycles is valuable because it:
- A. Creates a parallel, disconnected risk silo
- B. Gives leadership a consolidated view of AI risk alongside other enterprise risks
- C. Removes the need for AI-specific metrics
- D. Is required only for public companies
Answer: B
Consolidated reporting avoids AI risk being treated in isolation from overall enterprise risk.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q278 Identifying AI risk scenarios should draw on:
- A. Only the development team's opinion
- B. Multiple sources: incident history, threat intelligence, regulatory guidance, and business context
- C. Only vendor marketing claims
- D. A single generic industry checklist with no customization
Answer: B
Comprehensive scenario identification draws on multiple, enterprise-specific information sources.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q279 Classifying an AI incident's severity should PRIMARILY consider:
- A. The time of day the incident occurred
- B. The actual or potential impact on customers, operations, and the enterprise
- C. Which team reported the incident
- D. The incident's alphabetical category name
Answer: B
Severity classification should reflect real/potential impact, not procedural or arbitrary factors.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q280 Role-based AI training (e.g., different content for developers vs. business users) is MOST effective because it:
- A. Reduces total training cost regardless of relevance
- B. Targets the specific risks and responsibilities relevant to each role
- C. Is required only for executives
- D. Eliminates the need for policy documents
Answer: B
Tailored training addresses each role's actual risk exposure and responsibilities.