AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q301 Exit/transition planning for a critical AI vendor relationship should be established:

Answer: B

Proactive exit planning reduces disruption risk if a transition later becomes necessary.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q302 When addressing documented risk acceptance for AI, an AI risk practitioner should FIRST:

Answer: D

Residual risk acceptance needs formal documentation by an accountable authority, not informal or implicit assumption.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q303 When addressing vendor AI procurement risk assessment, an AI risk practitioner should FIRST:

Answer: D

Procurement due diligence must assess AI-specific vendor risks beforehand, not rely on price or existing relationships.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q304 Protecting vulnerable populations when deploying AI systems that affect them is BEST achieved by:

Answer: D

General fairness testing may not surface harms specific to vulnerable groups; targeted assessment and additional safeguards are needed to identify and mitigate disparate impact.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q305 In the context of AI contractual compliance clauses, which of the following represents sound AI risk management?

Answer: A

Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q306 Restricting who can modify a production AI model's parameters is an example of:

Answer: B

Restricting modification access is a preventive access control protecting model integrity.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q307 Documenting training data provenance is MOST important for:

Answer: B

Provenance documentation underpins data quality, bias, and legal-use assessments.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q308 When disclosing to affected individuals that an automated AI system was involved in a decision about them, the disclosure is MOST effective when it:

Answer: A

Effective disclosure must be clear, timely, and specific enough for individuals to understand the AI's role and their options, not buried in jargon, gated behind complaints, or mixed with marketing.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q309 In the context of AI vendor exit and transition planning, which of the following represents sound AI risk management?

Answer: A

Exit/transition planning should be proactive for critical vendors, not assumed away, reactive, or skipped for cloud services.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q310 A qualitative risk assessment is MOST appropriate when:

Answer: A

Qualitative assessment suits situations lacking reliable quantitative loss/frequency data.

‹ Prev
Next ›
Page 31 of 50 · 500 questions