Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q281 When selecting fairness metrics for an AI model, the enterprise should FIRST:
- A. Pick the metric that produces the best-looking result
- B. Determine which fairness definition is appropriate for the specific use case and context
- C. Use every available fairness metric simultaneously without analysis
- D. Defer entirely to the vendor's default metric
Answer: B
Fairness metric selection must be context-appropriate; no single metric fits all use cases.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q282 Transferring AI risk via insurance or contractual indemnification is MOST appropriate when:
- A. The risk can be fully eliminated through transfer alone
- B. The enterprise wants to shift financial impact while still managing underlying operational risk
- C. It replaces the need for any other controls
- D. The counterparty has no financial capacity
Answer: B
Risk transfer shifts financial impact but does not eliminate the need to manage operational risk itself.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q283 A Business Impact Analysis (BIA) for an AI system should PRIMARILY determine:
- A. The system's purchase cost
- B. Criticality and maximum tolerable downtime/impact if the system is unavailable
- C. The system's marketing value
- D. The vendor's headquarters location
Answer: B
BIA determines criticality and tolerable downtime/impact, driving continuity planning priorities.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q284 Liability for harm caused by an AI system is typically determined by:
- A. Which party had control, knowledge, and ability to prevent the harm, per applicable law and contract
- B. Whichever party is smallest and least able to pay
- C. The AI vendor alone, in every case
- D. No one, since AI decisions are not attributable
Answer: A
Liability allocation depends on control, knowledge, and contractual/legal framework, not a fixed default party.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q285 When addressing control framework mapping for AI, an AI risk practitioner should FIRST:
- A. Map controls to a framework only for externally audited systems
- B. Treat framework mapping as a one-time exercise never revisited
- C. Map AI controls to a recognized control framework to ensure completeness and avoid gaps
- D. Design AI controls ad hoc without reference to any framework
Answer: C
Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q286 When no single owner can be identified for a deployed AI system, the MOST appropriate action is:
- A. Leave it unowned since it is already running
- B. Assign interim ownership and formalize accountability before continued use
- C. Shut down all AI systems enterprise-wide
- D. Delegate ownership to the vendor by default
Answer: B
Ownership gaps must be closed promptly; unowned systems are an accountability and control gap.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q287 "Second line of defense" oversight of AI risk typically refers to:
- A. Business units executing daily operations
- B. Independent risk/compliance functions reviewing and challenging first-line controls
- C. External auditors only
- D. The AI model itself
Answer: B
Second line provides independent risk oversight/challenge, distinct from first-line operations.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q288 Regarding AI model documentation standards, the BEST practice is to:
- A. Document only the model's intended use, omitting limitations
- B. Document models only when externally regulated
- C. Require standardized documentation covering model purpose, data, assumptions, and limitations
- D. Allow documentation format and content to vary freely by team
Answer: C
Standardized documentation covering purpose, data, assumptions, and limitations supports consistent risk management.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q289 AI policies should be reviewed:
- A. Only once, when first published
- B. Periodically and when significant changes in AI use, regulation, or risk occur
- C. Only after a regulatory fine
- D. Every ten years
Answer: B
Periodic and trigger-based review keeps policies current with evolving AI risk and regulation.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q290 When addressing AI vendor security assessment, an AI risk practitioner should FIRST:
- A. Conduct security assessments of AI vendors covering data handling, model security, and incident history
- B. Rely solely on a vendor's self-certification of security practices
- C. Assess vendor security only once, at initial onboarding
- D. Limit vendor security assessment to contractual penalty clauses
Answer: A
Vendor security assessment should be substantive and periodically refreshed, not based solely on self-certification or onboarding-only.