Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q291 Vendor lock-in risk in AI supply chain management is BEST mitigated by:
- A. Favoring portable formats, documented interfaces, and contractual exit/transition provisions that preserve the ability to switch providers
- B. Avoiding any documentation of data formats to keep flexibility informal
- C. Accepting lock-in as unavoidable and unmanageable
- D. Relying on a single vendor to simplify contract management
Answer: A
Portability, documented interfaces, and contractual exit provisions preserve an enterprise's ability to switch providers, directly mitigating lock-in risk; single-vendor reliance increases it.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q292 When addressing documentation of validation results, an AI risk practitioner should FIRST:
- A. Document validation after go-live if issues surface
- B. Document validation results, including known limitations and failure conditions, before go-live
- C. Document only successful validation outcomes
- D. Share validation findings verbally without written record
Answer: B
Validation documentation, including limitations and failure modes, should be complete and recorded before go-live.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q293 Regarding holdout and cross-validation practices, the BEST practice is to:
- A. Validate only on a small, convenient sample
- B. Use holdout or cross-validation techniques to assess model generalization before deployment
- C. Evaluate performance only on the training dataset
- D. Skip validation when time pressure is high
Answer: B
Robust generalization assessment via holdout/cross-validation is needed, not training-only or convenience-sample evaluation.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q294 Regarding AI use-case prioritization, the BEST practice is to:
- A. Prioritize solely by implementation speed
- B. Prioritize by whichever team requests first
- C. Prioritize by lowest cost regardless of value
- D. Prioritize use cases by combined business value and risk exposure
Answer: D
Use-case prioritization should balance value against risk exposure, not speed, order of request, or cost alone.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q295 A human-in-the-loop control is MOST effective when:
- A. The human's review is a formality with no real authority to change the outcome
- B. The human has genuine authority, time, and information to meaningfully review the AI output
- C. The human reviews outputs only once per year
- D. The human has less expertise than the AI system
Answer: B
Meaningful human-in-the-loop controls require real authority and sufficient information/time to act.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q296 When addressing key risk indicator thresholds for AI, an AI risk practitioner should FIRST:
- A. Monitor AI KRIs without any defined escalation threshold
- B. Set identical KRI thresholds for all AI systems regardless of risk level
- C. Review KRI breaches only during scheduled quarterly meetings
- D. Define threshold levels for AI key risk indicators that trigger defined escalation actions
Answer: D
KRIs need defined, risk-appropriate thresholds with timely escalation, not undefined, uniform, or delayed review.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q297 Establishing clear ethical use boundaries for AI within an enterprise is BEST supported by:
- A. Relying solely on the AI vendor's terms of service
- B. Addressing ethical boundaries only after a public incident occurs
- C. Documented policies defining acceptable and prohibited AI use cases, reviewed by a diverse group of stakeholders
- D. Leaving ethical judgment entirely to individual employees on a case-by-case basis
Answer: C
Documented, stakeholder-reviewed policies establish consistent ethical boundaries proactively, rather than relying on ad hoc individual judgment, vendor terms alone, or reactive incident response.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q298 Regarding control testing frequency for AI systems, the BEST practice is to:
- A. Test controls only when requested by internal audit
- B. Test controls once at implementation and not again
- C. Test AI controls at a frequency proportionate to the risk level of the system they protect
- D. Test all AI controls on an identical fixed schedule regardless of risk
Answer: C
Control testing frequency should be risk-proportionate, not uniform, audit-triggered only, or one-time.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q299 Transparency to end users about AI involvement in a decision is important PRIMARILY to:
- A. Satisfy marketing preferences
- B. Support informed trust and enable users to seek recourse if needed
- C. Increase system latency intentionally
- D. Reduce the need for any further documentation
Answer: B
Transparency underpins informed trust and the ability to contest/appeal decisions.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q300 When addressing data retention policy for AI systems, an AI risk practitioner should FIRST:
- A. Retain all AI-related data indefinitely by default
- B. Apply retention schedules only to structured data, not unstructured
- C. Leave retention decisions to individual data scientists
- D. Apply defined data retention and disposal schedules to data used in AI systems
Answer: D
Formal retention/disposal schedules should govern AI data by policy, not default indefinite retention or informal decisions.