AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q361 In a RACI model for an AI system, the "Accountable" role is BEST assigned to:

Answer: B

Accountability requires a single named owner, distinct from multiple "Responsible" contributors.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q362 "Concept drift" as a risk scenario refers to:

Answer: B

Concept drift is a shift in the real-world input-output relationship that invalidates prior model assumptions.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q363 A build-vs-buy AI decision favoring "buy" still requires the enterprise to:

Answer: B

Outsourcing a capability does not outsource accountability; oversight and due diligence remain.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q364 What should an assessment of an AI vendor's security practices be based on?

Answer: D

Vendor security assessment should be substantive and periodically refreshed, not based solely on self-certification or onboarding-only.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q365 Regarding organizational readiness assessment for AI, the BEST practice is to:

Answer: D

Readiness assessment should cover process, data, and cultural factors, not technical infrastructure alone.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q366 Before integrating a third-party AI model or component, what should be verified?

Answer: B

Provenance/integrity verification should apply broadly, including to open-source components, not be skipped or scoped only to regulated cases.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q367 Risk management's role in AI oversight, as distinct from internal audit's role, is BEST described as:

Answer: D

Risk management proactively integrates AI-related dependencies and threats into BIA and continuity planning, whereas internal audit provides independent, retrospective assurance.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q368 When a regulator requests documentation of an AI system's risk controls, the enterprise's BEST response is to:

Answer: B

Regulatory responses must be accurate and complete, not selectively favorable or incomplete.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q369 A model design document lacking documented assumptions and limitations MOST increases the risk of:

Answer: B

Undocumented limitations increase risk of out-of-scope or inappropriate model use.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q370 When decommissioning an AI model, ensuring downstream systems and processes that depended on its outputs are identified and transitioned is PRIMARILY important to:

Answer: A

Mapping and transitioning dependent systems/processes before retirement prevents unplanned operational disruption; it is a substantive risk-mitigation step, not mere documentation.

‹ Prev
Next ›
Page 37 of 50 · 500 questions