Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q301 Exit/transition planning for a critical AI vendor relationship should be established:
- A. Only after the vendor relationship has already failed
- B. Proactively, as part of onboarding, to avoid disruption if a transition becomes necessary
- C. Never, since switching vendors is not realistic
- D. Only if required by the vendor's contract template
Answer: B
Proactive exit planning reduces disruption risk if a transition later becomes necessary.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q302 When addressing documented risk acceptance for AI, an AI risk practitioner should FIRST:
- A. Allow informal verbal acceptance of residual AI risk
- B. Assume risk acceptance if no objection is raised within a project team
- C. Accept residual risk without specifying an accountable approver
- D. Require formal, documented risk acceptance by an appropriate authority when residual AI risk is retained
Answer: D
Residual risk acceptance needs formal documentation by an accountable authority, not informal or implicit assumption.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q303 When addressing vendor AI procurement risk assessment, an AI risk practitioner should FIRST:
- A. Base vendor selection primarily on price
- B. Skip risk assessment for vendors with existing enterprise relationships
- C. Assess vendor risk only after contract signing
- D. Assess AI vendor risk (security, data handling, explainability) as part of procurement due diligence
Answer: D
Procurement due diligence must assess AI-specific vendor risks beforehand, not rely on price or existing relationships.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q304 Protecting vulnerable populations when deploying AI systems that affect them is BEST achieved by:
- A. Deferring all responsibility to the AI vendor's terms of service
- B. Assuming standard fairness testing on the general population is sufficient
- C. Excluding vulnerable populations entirely from the system's user base
- D. Specifically assessing model impact on vulnerable groups and applying additional safeguards where disparate harm is identified
Answer: D
General fairness testing may not surface harms specific to vulnerable groups; targeted assessment and additional safeguards are needed to identify and mitigate disparate impact.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q305 In the context of AI contractual compliance clauses, which of the following represents sound AI risk management?
- A. Include compliance and audit-rights clauses in contracts with AI vendors
- B. Rely on vendor assurances without contractual compliance clauses
- C. Limit vendor contracts to pricing and service-level terms only
- D. Add compliance clauses only after a vendor incident occurs
Answer: A
Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q306 Restricting who can modify a production AI model's parameters is an example of:
- A. A detective control only
- B. An access control (preventive) over model integrity
- C. A risk transfer mechanism
- D. A monitoring/reporting control
Answer: B
Restricting modification access is a preventive access control protecting model integrity.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q307 Documenting training data provenance is MOST important for:
- A. Marketing the dataset's size
- B. Understanding data quality, bias, and legal rights to use the data
- C. Reducing storage requirements
- D. Satisfying only internal curiosity
Answer: B
Provenance documentation underpins data quality, bias, and legal-use assessments.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q308 When disclosing to affected individuals that an automated AI system was involved in a decision about them, the disclosure is MOST effective when it:
- A. Is clear, timely, and specific enough for the individual to understand the AI's role and their available options
- B. Is bundled into unrelated marketing communications
- C. Uses dense technical language to demonstrate rigor
- D. Is provided only on request after the individual files a formal complaint
Answer: A
Effective disclosure must be clear, timely, and specific enough for individuals to understand the AI's role and their options, not buried in jargon, gated behind complaints, or mixed with marketing.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q309 In the context of AI vendor exit and transition planning, which of the following represents sound AI risk management?
- A. Develop exit/transition plans for critical AI vendor relationships to avoid lock-in and continuity risk
- B. Assume vendor relationships will continue indefinitely without a transition plan
- C. Create an exit plan only after a vendor signals they will discontinue service
- D. Treat exit planning as unnecessary for cloud-based AI services
Answer: A
Exit/transition planning should be proactive for critical vendors, not assumed away, reactive, or skipped for cloud services.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q310 A qualitative risk assessment is MOST appropriate when:
- A. Precise loss data and frequency statistics are unavailable
- B. Exact financial loss data is always available
- C. The enterprise wants to avoid any risk discussion
- D. Quantitative models are mandatory by law
Answer: A
Qualitative assessment suits situations lacking reliable quantitative loss/frequency data.