Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q21 With respect to AI risk register maintenance, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Maintain a living AI risk register that is updated as risks, controls, and context change
- B. Maintain the risk register only for regulator-visible systems
- C. Maintain a comprehensive risk register, formally refreshed once a year during the annual risk assessment cycle
- D. Create a risk register once and leave it static
Answer: A
A risk register must be actively, continuously maintained; an annual-only refresh, scope limited to regulator-visible systems, and a static one-time register all fall short of a living register.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q22 Regarding vendor AI procurement risk assessment, the BEST practice is to:
- A. Assess vendor risk only after contract signing
- B. Assess AI vendor risk (security, data handling, explainability) as part of procurement due diligence
- C. Base vendor selection primarily on price
- D. Rely on the vendor's published security certifications as sufficient evidence, without AI-specific due diligence
Answer: B
Procurement due diligence must directly assess AI-specific risk areas; generic certifications alone, post-signing assessment, and price-driven selection don't substitute for that AI-specific review.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q23 Cascading enterprise AI strategy to individual business units is BEST achieved through:
- A. Holding a single enterprise-wide town hall presentation explaining the strategy to all business units
- B. Sending a single enterprise-wide email announcement
- C. Translating strategic objectives into unit-specific policies, KPIs, and accountabilities
- D. Leaving each unit to interpret the strategy independently
Answer: C
Cascading strategy effectively requires translating it into unit-specific, actionable guidance; a one-time presentation or announcement, and unstructured interpretation, don't operationalize it.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q24 When an AI system causes harm to a customer, accountability MOST appropriately resides with:
- A. The AI model itself
- B. The data science team that built the model, since they best understand its technical limitations
- C. No one, since AI decisions are autonomous
- D. The accountable business/model owner who approved its use, regardless of technical cause
Answer: D
Accountability rests with the owner who approved the system's use, not with the builders (technical knowledge isn't the basis for accountability), the model itself, or no one.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q25 In the context of enterprise AI strategy documentation, which of the following represents sound AI risk management?
- A. Document AI strategy with clear links to enterprise risk appetite and business objectives
- B. Leave AI strategy undocumented and informal
- C. Document AI strategy in detail, focused on technology roadmap and tool selection rather than risk appetite
- D. Document strategy only after major incidents occur
Answer: A
Strategy documentation must explicitly link to risk appetite and business objectives; detailed technology-only documentation, no documentation, or reactive post-incident documentation all miss that link.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q26 With respect to documented risk acceptance for AI, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Accept residual risk without specifying an accountable approver
- B. Require formal, documented risk acceptance by an appropriate authority when residual AI risk is retained
- C. Allow informal verbal acceptance of residual AI risk
- D. Record risk acceptance in the project closure report, without sign-off from a designated risk owner
Answer: B
Residual risk acceptance requires formal sign-off by an accountable authority; documentation without a named owner's sign-off, no accountable approver, and informal verbal acceptance all fall short.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q27 With respect to control ownership and accountability, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Assign ownership of each control to the business unit using the system, without naming an individual accountable for monitoring
- B. Rotate control ownership frequently without handover documentation
- C. Assign clear ownership for each AI control, including responsibility for monitoring its operation
- D. Leave control ownership undefined across shared teams
Answer: C
Each control needs a named, accountable owner responsible for monitoring; unit-level ownership without a named individual, frequent rotation without handover, and undefined shared ownership all leave accountability unclear.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q28 Requirements traceability for an AI system helps ensure:
- A. Faster deployment regardless of requirements
- B. The system is delivered on the originally planned schedule
- C. Lower development costs only
- D. The system meets defined business and risk requirements, and gaps are identifiable
Answer: D
Traceability links requirements to implementation so gaps are identifiable; it is not primarily about schedule adherence, speed, or cost.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q29 With respect to training data representativeness, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Validate that training data is representative of the population the model will serve in production
- B. Assume historical data is automatically representative
- C. Validate that training data volume meets a minimum sample-size threshold
- D. Validate representativeness only for the majority class
Answer: A
Representativeness is about matching the production population, not merely having sufficient volume; assuming historical data is representative or checking only the majority class both miss this.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q30 When contracting with an AI vendor, which clause is MOST important for ongoing risk management?
- A. Marketing exclusivity clauses
- B. Audit rights, data handling, and liability allocation provisions
- C. Logo usage rights
- D. Service-level commitments specifying uptime and response times
Answer: B
Audit, data-handling, and liability clauses are the substantive risk-management levers; SLAs matter operationally but are less central to AI-specific risk management than these provisions, and marketing/logo clauses are irrelevant.