Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q411 For control framework mapping for AI, sound practice requires that the enterprise PRIMARILY:
- A. Design AI controls ad hoc without reference to any framework
- B. Map controls to a framework only for externally audited systems
- C. Treat framework mapping as a one-time exercise never revisited
- D. Map AI controls to a recognized control framework to ensure completeness and avoid gaps
Answer: D
Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q412 Which practice reflects the soundest approach to phased AI rollout approach?
- A. Deploy AI system-wide immediately after passing lab validation
- B. Skip pilot phases to reduce project timeline
- C. Pilot only with internal users regardless of intended end-user population
- D. Use a phased or pilot rollout to monitor real-world AI performance before full-scale deployment
Answer: D
Phased rollout against the intended population allows real-world risk monitoring before full-scale deployment.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q413 What is the most effective way to manage procedure documentation for AI model changes within an AI risk program?
- A. Skip documentation for minor model updates
- B. Maintain documented procedures for requesting, approving, and recording AI model changes
- C. Allow informal verbal approval for AI model changes
- D. Document procedures only for production failures
Answer: B
Documented change procedures should apply consistently, including to seemingly minor AI model updates.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q414 To properly manage sector-specific AI regulatory requirements, an enterprise should PRIMARILY:
- A. Rely solely on peer company practices instead of applicable law
- B. Identify and apply sector-specific AI requirements (e.g., financial services, healthcare) in addition to general regulations
- C. Apply only general-purpose AI regulations to all sectors
- D. Assume sector regulators do not address AI specifically
Answer: B
Sector-specific requirements layer on top of general AI regulation and must be separately identified and applied.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q415 What is the BEST way for an enterprise to manage risk assessment stakeholder involvement?
- A. Conduct AI risk assessment using only the technical team's input
- B. Conduct AI risk assessment using only business stakeholder input
- C. Outsource all risk assessment judgment entirely to external consultants
- D. Involve business, technical, and risk stakeholders jointly in AI risk assessment
Answer: D
Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q416 When addressing treatment plan monitoring and follow-up, what should the enterprise prioritize to manage AI risk effectively?
- A. Monitor treatment plans only if the risk recurs
- B. Assign treatment follow-up responsibility ambiguously across teams
- C. Track AI risk treatment plans to completion and verify effectiveness after implementation
- D. Consider a risk treated once a plan is merely approved
Answer: C
Treatment plans require tracked completion and verified effectiveness, not approval alone or unclear ownership.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q417 For AI training data access controls, which practice best reflects sound AI risk management?
- A. Apply access controls to training and production data consistent with its sensitivity classification
- B. Grant broad data access to all AI project members by default
- C. Apply access controls only to production data, not training data
- D. Rely on project trust rather than formal access controls
Answer: A
Access controls should follow data sensitivity classification across both training and production data, not informal trust.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q418 How should an enterprise best handle AI-specific risk scenario development as part of its AI risk program?
- A. Develop AI-specific risk scenarios covering bias, model failure, and misuse in addition to generic IT risk scenarios
- B. Reuse only generic IT risk scenarios for AI systems
- C. Develop AI risk scenarios only after an incident occurs
- D. Limit scenario development to security risks alone
Answer: A
AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q419 When handling employee AI training program design, the enterprise's main priority should be to:
- A. Tailor AI training content to role-specific risk exposure (e.g., developers vs. general staff)
- B. Provide identical generic AI training to every employee regardless of role
- C. Provide AI training only to the data science team
- D. Rely on self-directed learning with no formal program
Answer: A
Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q420 Which practice reflects the soundest approach to risk treatment option selection?
- A. Select AI risk treatment (avoid, mitigate, transfer, accept) based on cost-benefit relative to risk appetite
- B. Always choose mitigation regardless of cost-effectiveness
- C. Always accept AI risk to avoid implementation effort
- D. Transfer all AI risk via insurance without considering mitigation
Answer: A
Treatment choice should be a cost-benefit decision aligned with risk appetite, not a default to one option.