AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q21 With respect to AI risk register maintenance, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

A risk register must be actively, continuously maintained; an annual-only refresh, scope limited to regulator-visible systems, and a static one-time register all fall short of a living register.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q22 Regarding vendor AI procurement risk assessment, the BEST practice is to:

Answer: B

Procurement due diligence must directly assess AI-specific risk areas; generic certifications alone, post-signing assessment, and price-driven selection don't substitute for that AI-specific review.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q23 Cascading enterprise AI strategy to individual business units is BEST achieved through:

Answer: C

Cascading strategy effectively requires translating it into unit-specific, actionable guidance; a one-time presentation or announcement, and unstructured interpretation, don't operationalize it.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q24 When an AI system causes harm to a customer, accountability MOST appropriately resides with:

Answer: D

Accountability rests with the owner who approved the system's use, not with the builders (technical knowledge isn't the basis for accountability), the model itself, or no one.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q25 In the context of enterprise AI strategy documentation, which of the following represents sound AI risk management?

Answer: A

Strategy documentation must explicitly link to risk appetite and business objectives; detailed technology-only documentation, no documentation, or reactive post-incident documentation all miss that link.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q26 With respect to documented risk acceptance for AI, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: B

Residual risk acceptance requires formal sign-off by an accountable authority; documentation without a named owner's sign-off, no accountable approver, and informal verbal acceptance all fall short.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q27 With respect to control ownership and accountability, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: C

Each control needs a named, accountable owner responsible for monitoring; unit-level ownership without a named individual, frequent rotation without handover, and undefined shared ownership all leave accountability unclear.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q28 Requirements traceability for an AI system helps ensure:

Answer: D

Traceability links requirements to implementation so gaps are identifiable; it is not primarily about schedule adherence, speed, or cost.

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q29 With respect to training data representativeness, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

Representativeness is about matching the production population, not merely having sufficient volume; assuming historical data is representative or checking only the majority class both miss this.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q30 When contracting with an AI vendor, which clause is MOST important for ongoing risk management?

Answer: B

Audit, data-handling, and liability clauses are the substantive risk-management levers; SLAs matter operationally but are less central to AI-specific risk management than these provisions, and marketing/logo clauses are irrelevant.

‹ Prev
Next ›
Page 3 of 50 · 500 questions