Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q31 With respect to trend analysis of AI risk indicators, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Compare each AI risk indicator against a fixed baseline set at initial validation, without ever updating the baseline
- B. Evaluate AI risk indicators using only the most recent single data point
- C. Analyze trends in AI risk indicators over time to detect gradual degradation, not just point-in-time snapshots
- D. Analyze trends only after a significant incident has occurred
Answer: C
Trend analysis over time catches gradual degradation; a fixed, never-updated baseline, a single data point, or incident-triggered-only analysis all miss ongoing drift.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q32 Choosing between a principles-based framework (e.g., broad AI RMF) and a certifiable management-system standard (e.g., ISO/IEC 42001) should be driven MOST by:
- A. Which framework is cheaper to adopt
- B. Which framework has broader adoption among regulators in the enterprise's industry
- C. Which framework is newer
- D. The enterprise's need for flexibility versus external certification/assurance
Answer: D
The choice should hinge on the enterprise's own need for flexibility versus certifiable assurance; regulator adoption trends are relevant context but not the primary driver, and cost or recency are secondary.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q33 When addressing control effectiveness evaluation, an AI risk practitioner should FIRST:
- A. Evaluate AI control effectiveness using evidence, not just confirmation that the control exists
- B. Assume control effectiveness if no incidents have occurred yet
- C. Treat a control as effective if it has operated without a reported exception for the past 12 months
- D. Treat a control as effective if it is merely documented in policy
Answer: A
Effectiveness requires actual evidence-based testing; absence of reported exceptions, absence of incidents, and mere policy documentation are not equivalent to tested evidence.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q34 When addressing AI vendor exit and transition planning, an AI risk practitioner should FIRST:
- A. Treat exit planning as unnecessary for cloud-based AI services
- B. Develop exit/transition plans for critical AI vendor relationships to avoid lock-in and continuity risk
- C. Create an exit plan only after a vendor signals they will discontinue service
- D. Negotiate a right to extend the current contract on short notice if the vendor later signals discontinuation
Answer: B
Exit/transition planning should be proactive for critical vendors; a reactive contract-extension right, assuming it's unnecessary for cloud services, and waiting for a discontinuation signal are all reactive or incomplete.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q35 Adversarial testing of an AI model is used to evaluate:
- A. The model's accuracy on a held-out validation dataset
- B. Marketing effectiveness
- C. The model's robustness against intentionally crafted inputs designed to cause errors
- D. Office network speed
Answer: C
Adversarial testing specifically probes robustness against deliberately crafted problematic inputs, which is distinct from standard held-out validation accuracy testing.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q36 Aggregating AI risk metrics across business units is valuable PRIMARILY to:
- A. Hide unit-level issues within enterprise averages
- B. Allow executives to rank business units against each other on a single composite scorecard
- C. Replace unit-level monitoring entirely
- D. Provide enterprise-wide visibility into overall AI risk exposure
Answer: D
Aggregation's value is enterprise-wide visibility while unit-level detail is retained; using it mainly to rank units on one score, hiding issues in averages, or replacing unit monitoring all misuse or lose that detail.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q37 An enterprise evaluating likelihood and impact estimation for AI risk should PRIMARILY ensure that:
- A. Estimate likelihood and impact of AI risk scenarios using available data and expert judgment
- B. Estimate risk levels based on intuition alone without supporting rationale
- C. Base likelihood and impact purely on quantitative historical loss data, excluding expert judgment where data is sparse
- D. Assume all AI risks have equal likelihood and impact
Answer: A
Estimation should combine available data with expert judgment, especially where data is sparse; excluding judgment, relying on intuition alone, or assuming uniform risk all weaken the estimate.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q38 When addressing societal impact assessment for high-risk AI, an AI risk practitioner should FIRST:
- A. Perform impact assessment only after deployment
- B. Conduct a societal impact assessment for AI systems with significant potential societal effects
- C. Skip societal impact assessment for internally used AI
- D. Conduct a standard privacy impact assessment and treat it as equivalent to a societal impact assessment
Answer: B
A dedicated societal impact assessment is needed for high-impact systems; a privacy impact assessment covers narrower ground and isn't equivalent, and post-deployment-only or internal-use exemptions both miss pre-deployment review.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q39 Regarding AI maturity model selection, the BEST practice is to:
- A. Adopt the framework used by the largest competitor in the same industry
- B. Select a framework based solely on vendor marketing
- C. Align framework choice to the enterprise's actual AI maturity level and risk appetite
- D. Adopt the most complex framework available regardless of maturity
Answer: C
Framework choice should fit the enterprise's own maturity and risk appetite; copying a competitor, following marketing, or choosing complexity for its own sake all ignore organizational fit.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q40 A data retention and disposal policy for AI training data should balance:
- A. Only cost minimization
- B. Balance IT storage capacity planning against anticipated future model retraining needs
- C. Only the preference of the data science team
- D. Legal/regulatory retention obligations against privacy and minimization principles
Answer: D
Retention policy should balance legal obligations against privacy/minimization principles; storage-capacity planning is an operational concern, not the governance balance at issue, and cost- or team-preference-only framing ignores both sides.