Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q361 In a RACI model for an AI system, the "Accountable" role is BEST assigned to:
- A. The data scientist who built the model
- B. A single named business or model owner who answers for outcomes
- C. The end user of the AI output
- D. No one, since accountability is shared equally
Answer: B
Accountability requires a single named owner, distinct from multiple "Responsible" contributors.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q362 "Concept drift" as a risk scenario refers to:
- A. A change in model hosting infrastructure
- B. A change in the underlying relationship between inputs and outcomes that degrades model validity
- C. A change in vendor contract terms
- D. A change in office location
Answer: B
Concept drift is a shift in the real-world input-output relationship that invalidates prior model assumptions.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q363 A build-vs-buy AI decision favoring "buy" still requires the enterprise to:
- A. Assume the vendor fully owns all resulting risk
- B. Perform due diligence and retain oversight of the vendor's AI risk controls
- C. Skip documentation since it is outsourced
- D. Avoid any contractual risk clauses
Answer: B
Outsourcing a capability does not outsource accountability; oversight and due diligence remain.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q364 What should an assessment of an AI vendor's security practices be based on?
- A. Rely solely on a vendor's self-certification of security practices
- B. Assess vendor security only once, at initial onboarding
- C. Limit vendor security assessment to contractual penalty clauses
- D. Conduct security assessments of AI vendors covering data handling, model security, and incident history
Answer: D
Vendor security assessment should be substantive and periodically refreshed, not based solely on self-certification or onboarding-only.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q365 Regarding organizational readiness assessment for AI, the BEST practice is to:
- A. Scale AI adoption uniformly regardless of unit readiness
- B. Assess only technical infrastructure readiness
- C. Skip readiness assessment to move faster
- D. Assess process, data, and cultural readiness before scaling AI adoption
Answer: D
Readiness assessment should cover process, data, and cultural factors, not technical infrastructure alone.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q366 Before integrating a third-party AI model or component, what should be verified?
- A. Verify provenance only for models used in regulated use cases
- B. Verify the provenance and integrity of third-party AI models and components before integration
- C. Integrate third-party models without verifying their origin or integrity
- D. Assume open-source AI components carry no provenance risk
Answer: B
Provenance/integrity verification should apply broadly, including to open-source components, not be skipped or scoped only to regulated cases.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q367 Risk management's role in AI oversight, as distinct from internal audit's role, is BEST described as:
- A. Providing independent assurance after the fact, with no involvement in planning
- B. Managing end-user training on AI tools
- C. Certifying that AI models comply with external regulations
- D. Integrating AI solution dependencies, associated threats, and model risk into the enterprise's business impact analysis and continuity planning
Answer: D
Risk management proactively integrates AI-related dependencies and threats into BIA and continuity planning, whereas internal audit provides independent, retrospective assurance.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q368 When a regulator requests documentation of an AI system's risk controls, the enterprise's BEST response is to:
- A. Provide whatever is readily available, complete or not
- B. Provide accurate, complete documentation reflecting actual controls in place
- C. Delay indefinitely
- D. Provide only favorable excerpts
Answer: B
Regulatory responses must be accurate and complete, not selectively favorable or incomplete.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q369 A model design document lacking documented assumptions and limitations MOST increases the risk of:
- A. Faster deployment with no downside
- B. Users applying the model outside its valid intended scope
- C. Improved explainability
- D. Reduced training cost
Answer: B
Undocumented limitations increase risk of out-of-scope or inappropriate model use.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q370 When decommissioning an AI model, ensuring downstream systems and processes that depended on its outputs are identified and transitioned is PRIMARILY important to:
- A. Prevent unplanned disruption to dependent systems or processes once the model is no longer available
- B. Reduce the original cost of building the model
- C. Avoid the need to notify any stakeholders
- D. Satisfy a purely cosmetic documentation requirement
Answer: A
Mapping and transitioning dependent systems/processes before retirement prevents unplanned operational disruption; it is a substantive risk-mitigation step, not mere documentation.