AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q421 What is the most effective way to manage AI fairness across demographic groups within an AI risk program?

Answer: A

Fairness testing should proactively assess subgroup outcomes, not rely on aggregate accuracy or reactive complaints.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q422 What is the BEST way for an enterprise to manage AI incident communication to affected stakeholders?

Answer: A

Timely, accurate communication to all appropriately affected stakeholders is expected, not delayed, internal-only, or selectively positive.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q423 When addressing likelihood and impact estimation for AI risk, what should the enterprise prioritize to manage AI risk effectively?

Answer: B

Risk estimation should use available evidence and judgment across multiple impact types, not uniform assumptions or financial-only framing.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q424 For AI incident classification scheme, which practice best reflects sound AI risk management?

Answer: A

Severity/type-based classification enables proportionate response, rather than uniform, after-the-fact, or security-only classification.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q425 How should an enterprise best handle AI incident response team composition as part of its AI risk program?

Answer: B

Cross-functional incident response composition is needed, not technical-only, reactive, or single-developer-reliant.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q426 Regarding regulatory horizon scanning for AI, the enterprise should PRIMARILY:

Answer: D

Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring.

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q427 Which practice reflects the soundest approach to explainability requirements at design stage?

Answer: C

Explainability requirements should be risk-based and considered during design, not uniform or deferred.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q428 What is the most effective way to manage control framework mapping for AI within an AI risk program?

Answer: A

Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q429 When addressing enterprise AI strategy documentation, what is the BEST first step for an enterprise?

Answer: C

AI strategy documentation should explicitly tie to risk appetite and business objectives to guide consistent decisions.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q430 The most important consideration for residual risk re-evaluation after treatment is that the enterprise should:

Answer: D

Residual risk must be explicitly re-evaluated against appetite after treatment, not assumed or deferred to annual cycles.

‹ Prev
Next ›
Page 43 of 50 · 500 questions