Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q331 Procedures supporting an AI policy should PRIMARILY:
- A. Restate the policy in different words
- B. Provide actionable, specific steps for implementing the policy's requirements
- C. Be left to each employee's interpretation
- D. Apply only to new hires
Answer: B
Procedures operationalize policy into specific, actionable steps.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q332 In the context of risk appetite application to AI decisions, which of the following represents sound AI risk management?
- A. Define risk appetite only after treatment decisions are made
- B. Apply the enterprise's defined risk appetite consistently when deciding on AI risk treatment
- C. Apply different undocumented risk appetites across business units
- D. Ignore risk appetite when a use case has strong business sponsorship
Answer: B
Risk appetite should be defined upfront and applied consistently, not overridden by sponsorship or defined after the fact.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q333 In the context of risk transfer via contracts/insurance for AI, which of the following represents sound AI risk management?
- A. Rely entirely on vendor indemnification instead of internal controls
- B. Avoid risk transfer mechanisms entirely as unnecessary overhead
- C. Transfer risk only after an incident has already occurred
- D. Evaluate contractual risk transfer (e.g., indemnification, insurance) as a complement to, not replacement for, internal controls
Answer: D
Risk transfer should complement internal controls, not substitute for them or be arranged only reactively.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q334 AI governance processes should be aligned with the enterprise's risk appetite PRIMARILY to:
- A. Ensure consistent risk-based decision-making across AI initiatives
- B. Reduce the number of committees required
- C. Avoid involving the risk function
- D. Eliminate the need for policies
Answer: A
Risk appetite alignment keeps AI decisions consistent with enterprise-wide risk tolerance.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q335 Regarding documentation for regulatory AI audits, the BEST practice is to:
- A. Maintain documentation informally in individual staff notes
- B. Document only the final model output, not design rationale
- C. Maintain audit-ready documentation of AI design, data sources, and decision logic
- D. Recreate documentation only when a regulator requests it
Answer: C
Audit-ready AI documentation must be maintained proactively and substantively, not assembled reactively or kept informally.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q336 Ownership of AI-generated output is MOST likely to be addressed through:
- A. Assuming default public domain status
- B. Contractual terms and applicable IP law specific to the jurisdiction and use case
- C. The AI vendor's terms of service only, in all cases
- D. Ignoring the issue since AI output cannot be owned
Answer: B
IP ownership of AI output depends on contract terms and jurisdiction-specific law, not a universal default.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q337 A validation report showing strong aggregate accuracy but poor performance on a minority subgroup indicates:
- A. The model is fully validated with no concerns
- B. A potential fairness/bias issue requiring further investigation before deployment
- C. A data storage problem only
- D. No action needed since aggregate accuracy is high
Answer: B
Subgroup performance gaps despite good aggregate accuracy signal a fairness risk needing follow-up.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q338 In the context of cost-benefit analysis of AI controls, which of the following represents sound AI risk management?
- A. Perform cost-benefit analysis when selecting controls to treat AI risk
- B. Select controls based on vendor recommendation alone
- C. Implement the most expensive available control by default
- D. Select controls without considering impact on system usability
Answer: A
Control selection should weigh cost and benefit, not default to vendor recommendation, maximum cost, or ignore usability.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q339 The governing body's determination of whether an intended AI use aligns with the organization's risk appetite is MOST important because:
- A. It is only relevant for regulated industries
- B. Risk appetite is fixed and never needs reassessment
- C. AI-related risk can change quickly, and a proactive governance system allows the organization to respond, including modifying or aborting plans if needed
- D. It removes the organization's legal accountability for the AI solution
Answer: C
Because AI risk can shift rapidly, ongoing alignment checks against risk appetite enable timely responses, including plan modification or termination; they do not remove legal accountability.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q340 Use of open-source AI components introduces risk PRIMARILY related to:
- A. Guaranteed vendor support
- B. Unclear provenance, maintenance, and security vulnerabilities in the component
- C. Elimination of all licensing considerations
- D. Automatic compliance with enterprise policy
Answer: B
Open-source components can carry provenance, maintenance, and vulnerability risks requiring assessment.