Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q391 When handling AI incident response team composition, the enterprise's main priority should be to:
- A. Technical, risk, legal, and communications representatives are included from the outset
- B. Limit the team to technical staff only
- C. A core team of technical and legal staff only, expanding to other functions if the incident becomes public
- D. Rely on the original model developer alone to manage incident response
Answer: A
Effective incident response needs cross-functional composition from the start, not a narrow team expanded only once an incident becomes public, nor a technical- or developer-only team.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q392 Regarding integration of AI risk metrics into enterprise reporting, the enterprise should PRIMARILY:
- A. Report AI risk metrics only within the AI development team
- B. Integrate AI risk metrics into existing enterprise risk reporting rather than maintaining a fully separate report
- C. Combine AI risk metrics into a single unexplained composite score for executives
- D. Maintain a separate AI-specific risk report, reviewed independently of enterprise risk reporting
Answer: B
AI risk metrics should be integrated into enterprise reporting, not kept in a parallel report, confined to the development team, or compressed into an unexplained score.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q393 When addressing key risk indicator thresholds for AI, what is the BEST first step for an enterprise?
- A. Set a single enterprise-wide KRI threshold applied uniformly to all AI systems regardless of risk level
- B. Monitor AI KRIs without any defined escalation threshold
- C. Define threshold levels for AI key risk indicators that trigger defined escalation actions
- D. Review KRI breaches only during scheduled quarterly meetings
Answer: C
KRI thresholds should be risk-appropriate per system and trigger timely escalation; a single uniform threshold, no threshold, and quarterly-only review all fall short.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q394 What is the BEST way for an enterprise to manage data retention policy for AI systems?
- A. Retain all AI-related data indefinitely by default
- B. Apply the enterprise's general records-retention policy unchanged, without AI-specific adaptation
- C. Leave retention decisions to individual data scientists
- D. Apply defined data retention and disposal schedules tailored to data used in AI systems
Answer: D
AI data needs retention/disposal schedules tailored to its specific risks; an unmodified general policy, indefinite retention, and ad hoc individual decisions do not provide this.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q395 The most important consideration for cross-functional AI committee composition is that the enterprise should:
- A. Include risk, legal, data, business, and technical stakeholders in AI governance decisions from the outset
- B. Limit AI governance decisions to the data science team
- C. Include technical and business stakeholders, adding legal and risk representatives only once a regulatory issue arises
- D. Limit AI governance decisions to IT alone
Answer: A
Effective governance committees need full cross-functional representation from the start, not legal/risk added reactively, nor decisions confined to one function.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q396 For AI center of excellence role, sound practice requires that the enterprise PRIMARILY:
- A. Allow each business unit to establish its own AI center of excellence, coordinating informally through personal relationships
- B. Let every business unit define its own AI standards independently
- C. Establish a central function to coordinate standards, risk practices, and knowledge sharing across AI initiatives
- D. Avoid centralizing AI coordination to preserve business unit autonomy
Answer: C
A central coordinating function standardizes practices across the enterprise; informal unit-level coordination, independent standards, and avoiding centralization all leave practices fragmented.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q397 When addressing AI risk register maintenance, what should the enterprise prioritize to manage AI risk effectively?
- A. Maintain a living AI risk register that is updated as risks, controls, and context change
- B. Maintain the risk register only for regulator-visible systems
- C. Maintain a comprehensive risk register, formally refreshed once a year during the annual risk assessment cycle
- D. Create a risk register once and leave it static
Answer: A
A risk register must be actively, continuously maintained; an annual-only refresh, scope limited to regulator-visible systems, and a static one-time register all fall short of a living register.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q398 For documented risk acceptance for AI, which practice best reflects sound AI risk management?
- A. Accept residual risk without specifying an accountable approver
- B. Require formal, documented risk acceptance by an appropriate authority when residual AI risk is retained
- C. Allow informal verbal acceptance of residual AI risk
- D. Record risk acceptance in the project closure report, without sign-off from a designated risk owner
Answer: B
Residual risk acceptance requires formal sign-off by an accountable authority; documentation without a named owner's sign-off, no accountable approver, and informal verbal acceptance all fall short.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q399 How should an enterprise best handle control ownership and accountability as part of its AI risk program?
- A. Assign ownership of each control to the business unit using the system, without naming an individual accountable for monitoring
- B. Rotate control ownership frequently without handover documentation
- C. Assign clear ownership for each AI control, including responsibility for monitoring its operation
- D. Leave control ownership undefined across shared teams
Answer: C
Each control needs a named, accountable owner responsible for monitoring; unit-level ownership without a named individual, frequent rotation without handover, and undefined shared ownership all leave accountability unclear.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q400 Which practice reflects the soundest approach to training data representativeness?
- A. Validate that training data is representative of the population the model will serve in production
- B. Assume historical data is automatically representative
- C. Validate that training data volume meets a minimum sample-size threshold
- D. Validate representativeness only for the majority class
Answer: A
Representativeness is about matching the production population, not merely having sufficient volume; assuming historical data is representative or checking only the majority class both miss this.