Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q321 A Data Protection Impact Assessment (DPIA) is typically required when an AI system:
- A. Uses no personal data whatsoever
- B. Involves processing of personal data likely to result in high risk to individuals
- C. Is used only internally by IT
- D. Has fewer than 100 users
Answer: B
DPIAs are triggered by high-risk personal data processing, not internal use or user count alone.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q322 A model owner's responsibilities should explicitly include:
- A. Writing marketing copy about the model
- B. Monitoring model performance/drift and escalating issues within defined thresholds
- C. Approving unrelated IT purchases
- D. Managing the vendor's internal staffing
Answer: B
Ongoing performance monitoring and escalation are core model-owner duties.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q323 Executive managers' responsibility regarding AI strategy is BEST described as:
- A. Delegating all AI-related accountability to the AI development team
- B. Only becoming involved after an AI-related incident occurs
- C. Limiting involvement to budget approval
- D. Setting the tone at the top, signing off on AI strategy, and being ultimately responsible for AI's effects on the organization and its stakeholders
Answer: D
Executive managers set organizational tone, approve AI strategy, and bear ultimate responsibility for AI's effects, not merely budget sign-off or after-the-fact incident response.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q324 Regarding treatment plan monitoring and follow-up, the BEST practice is to:
- A. Consider a risk treated once a plan is merely approved
- B. Monitor treatment plans only if the risk recurs
- C. Assign treatment follow-up responsibility ambiguously across teams
- D. Track AI risk treatment plans to completion and verify effectiveness after implementation
Answer: D
Treatment plans require tracked completion and verified effectiveness, not approval alone or unclear ownership.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q325 Regarding dashboard design for AI risk monitoring, the BEST practice is to:
- A. Present AI risk dashboards as large raw data tables without context
- B. Update AI risk dashboards only during annual reviews
- C. Limit dashboards to a single aggregate risk score with no detail
- D. Design AI risk dashboards to highlight exceptions and trends, not just raw data points
Answer: D
Effective dashboards surface exceptions/trends with appropriate context, not raw-only, stale, or over-aggregated views.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q326 When a technical mitigation for an identified AI risk is not currently feasible, the enterprise should:
- A. Deploy without any treatment
- B. Implement compensating controls and document the rationale and residual risk
- C. Cancel the entire AI program
- D. Wait indefinitely with no interim action
Answer: B
Compensating controls with documented rationale are the appropriate interim treatment.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q327 When an AI model is retired (decommissioned), the organization's data retention obligations for the model's training and output data are PRIMARILY governed by:
- A. Applicable legal, regulatory, and contractual retention requirements, independent of the model's own retirement
- B. The preference of the team that built the model
- C. The AI vendor's default cloud storage settings
- D. No requirements, since the model is no longer in use
Answer: A
Data retention is driven by legal, regulatory, and contractual obligations that persist regardless of whether the model itself has been decommissioned.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q328 In the context of extraterritorial AI regulation applicability, which of the following represents sound AI risk management?
- A. Ignore extraterritorial reach until a regulator intervenes
- B. Apply only the most lenient jurisdiction's rules globally
- C. Assess whether AI regulations apply extraterritorially based on where affected individuals are located
- D. Assume regulations only apply where the company is headquartered
Answer: C
Extraterritorial applicability often depends on the location of affected individuals, not just company headquarters.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q329 In the context of disaster recovery testing for AI systems, which of the following represents sound AI risk management?
- A. Include AI systems in disaster recovery testing, including model/data restoration procedures
- B. Exclude AI systems from DR testing because they are 'non-critical' by default
- C. Test DR for AI systems only once at initial implementation
- D. Assume cloud-hosted AI systems require no DR testing
Answer: A
AI systems, including model/data restoration, should be included in regular DR testing, not excluded by default or location assumption.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q330 When addressing training data representativeness, an AI risk practitioner should FIRST:
- A. Validate representativeness only for the majority class
- B. Skip representativeness checks for time-constrained projects
- C. Validate that training data is representative of the population the model will serve in production
- D. Assume historical data is automatically representative
Answer: C
Representativeness must be validated against the actual production population, not assumed or checked only for majority outcomes.