AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q401 What is the most effective way to manage trend analysis of AI risk indicators within an AI risk program?

Answer: C

Trend analysis over time catches gradual degradation; a fixed, never-updated baseline, a single data point, or incident-triggered-only analysis all miss ongoing drift.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q402 To properly manage likelihood and impact estimation for AI risk, an enterprise should PRIMARILY:

Answer: A

Estimation should combine available data with expert judgment, especially where data is sparse; excluding judgment, relying on intuition alone, or assuming uniform risk all weaken the estimate.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q403 What is the BEST way for an enterprise to manage cross-border AI strategy alignment?

Answer: B

Cross-border strategy should reconcile differing regional requirements through analysis; defaulting to the strictest standard everywhere without analysis, deferring to IT, or fragmenting entirely with no coordination all bypass that reconciliation.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q404 When addressing alignment of AI metrics with business KPIs, what should the enterprise prioritize to manage AI risk effectively?

Answer: D

Metrics must be explicitly tied to business KPIs and risk indicators; placing them on the same dashboard without a defined linkage, tracking accuracy only, or waiting for problems to define metrics all fall short of real alignment.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q405 When handling procedure documentation for AI model changes, the enterprise's main priority should be to:

Answer: B

Documented change procedures should apply consistently, including to seemingly minor AI model updates.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q406 For organizational alignment of AI initiatives, which practice best reflects sound AI risk management?

Answer: A

AI initiatives should align to business objectives within governance structures, not run independently of oversight.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q407 Regarding AI contractual compliance clauses, the enterprise should PRIMARILY:

Answer: C

Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q408 How should an enterprise best handle AI acceptable use policy scope as part of its AI risk program?

Answer: A

An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q409 When addressing prioritizing AI risk scenarios for treatment, what is the BEST first step for an enterprise?

Answer: D

Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q410 The most important consideration for AI training data access controls is that the enterprise should:

Answer: A

Access controls should follow data sensitivity classification across both training and production data, not informal trust.

‹ Prev
Next ›
Page 41 of 50 · 500 questions