Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q401 What is the most effective way to manage trend analysis of AI risk indicators within an AI risk program?
- A. Compare each AI risk indicator against a fixed baseline set at initial validation, without ever updating the baseline
- B. Evaluate AI risk indicators using only the most recent single data point
- C. Analyze trends in AI risk indicators over time to detect gradual degradation, not just point-in-time snapshots
- D. Analyze trends only after a significant incident has occurred
Answer: C
Trend analysis over time catches gradual degradation; a fixed, never-updated baseline, a single data point, or incident-triggered-only analysis all miss ongoing drift.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q402 To properly manage likelihood and impact estimation for AI risk, an enterprise should PRIMARILY:
- A. Estimate likelihood and impact of AI risk scenarios using available data and expert judgment
- B. Estimate risk levels based on intuition alone without supporting rationale
- C. Base likelihood and impact purely on quantitative historical loss data, excluding expert judgment where data is sparse
- D. Assume all AI risks have equal likelihood and impact
Answer: A
Estimation should combine available data with expert judgment, especially where data is sparse; excluding judgment, relying on intuition alone, or assuming uniform risk all weaken the estimate.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q403 What is the BEST way for an enterprise to manage cross-border AI strategy alignment?
- A. Defer all strategy decisions to IT
- B. Reconcile AI strategy with varying regional regulatory and risk expectations
- C. Let each region choose frameworks independently with no coordination
- D. Adopt the strictest regional regulatory standard and apply it uniformly everywhere, without further analysis
Answer: B
Cross-border strategy should reconcile differing regional requirements through analysis; defaulting to the strictest standard everywhere without analysis, deferring to IT, or fragmenting entirely with no coordination all bypass that reconciliation.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q404 When addressing alignment of AI metrics with business KPIs, what should the enterprise prioritize to manage AI risk effectively?
- A. Only track technical accuracy metrics
- B. Display technical accuracy metrics alongside business KPIs on the same dashboard, without defining how they relate
- C. Avoid defining AI metrics until problems arise
- D. Tie AI performance metrics back to relevant business KPIs and risk indicators
Answer: D
Metrics must be explicitly tied to business KPIs and risk indicators; placing them on the same dashboard without a defined linkage, tracking accuracy only, or waiting for problems to define metrics all fall short of real alignment.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q405 When handling procedure documentation for AI model changes, the enterprise's main priority should be to:
- A. Skip documentation for minor model updates
- B. Maintain documented procedures for requesting, approving, and recording AI model changes
- C. Allow informal verbal approval for AI model changes
- D. Document procedures only for production failures
Answer: B
Documented change procedures should apply consistently, including to seemingly minor AI model updates.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q406 For organizational alignment of AI initiatives, which practice best reflects sound AI risk management?
- A. Ensure AI initiatives are aligned to defined business objectives and governance structures
- B. Allow business units to pursue AI initiatives independently of governance
- C. Align AI initiatives only to IT's technical roadmap
- D. Align AI initiatives only after audit findings require it
Answer: A
AI initiatives should align to business objectives within governance structures, not run independently of oversight.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q407 Regarding AI contractual compliance clauses, the enterprise should PRIMARILY:
- A. Limit vendor contracts to pricing and service-level terms only
- B. Add compliance clauses only after a vendor incident occurs
- C. Include compliance and audit-rights clauses in contracts with AI vendors
- D. Rely on vendor assurances without contractual compliance clauses
Answer: C
Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q408 How should an enterprise best handle AI acceptable use policy scope as part of its AI risk program?
- A. Define an AI acceptable use policy covering permitted tools, data handling, and prohibited uses
- B. Leave AI acceptable use undefined and rely on informal norms
- C. Limit the policy to only prohibit a single named tool
- D. Apply the acceptable use policy only to the IT department
Answer: A
An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q409 When addressing prioritizing AI risk scenarios for treatment, what is the BEST first step for an enterprise?
- A. Treat all identified AI risks with equal priority and resources
- B. Prioritize risk treatment based solely on ease of implementation
- C. Prioritize only risks that have already caused incidents
- D. Prioritize AI risk scenarios for treatment based on combined likelihood and impact, aligned with risk appetite
Answer: D
Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q410 The most important consideration for AI training data access controls is that the enterprise should:
- A. Apply access controls to training and production data consistent with its sensitivity classification
- B. Grant broad data access to all AI project members by default
- C. Apply access controls only to production data, not training data
- D. Rely on project trust rather than formal access controls
Answer: A
Access controls should follow data sensitivity classification across both training and production data, not informal trust.