Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q421 What is the most effective way to manage AI fairness across demographic groups within an AI risk program?
- A. Test AI outcomes for disparate impact across relevant demographic groups before and after deployment
- B. Assume fairness if overall accuracy is high
- C. Test for fairness only if a complaint is received
- D. Limit fairness testing to the development dataset only
Answer: A
Fairness testing should proactively assess subgroup outcomes, not rely on aggregate accuracy or reactive complaints.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q422 What is the BEST way for an enterprise to manage AI incident communication to affected stakeholders?
- A. Communicate AI incident impact to affected internal and external stakeholders in a timely, accurate manner
- B. Delay all stakeholder communication until the investigation is fully closed
- C. Limit incident communication to internal stakeholders only
- D. Communicate only positive aspects of the incident response
Answer: A
Timely, accurate communication to all appropriately affected stakeholders is expected, not delayed, internal-only, or selectively positive.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q423 When addressing likelihood and impact estimation for AI risk, what should the enterprise prioritize to manage AI risk effectively?
- A. Estimate impact only in financial terms, ignoring reputational or legal impact
- B. Estimate likelihood and impact of AI risk scenarios using available data and expert judgment
- C. Estimate risk levels based on intuition alone without supporting rationale
- D. Assume all AI risks have equal likelihood and impact
Answer: B
Risk estimation should use available evidence and judgment across multiple impact types, not uniform assumptions or financial-only framing.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q424 For AI incident classification scheme, which practice best reflects sound AI risk management?
- A. Classify AI incidents by severity and type to drive proportionate response actions
- B. Treat all AI incidents with an identical response regardless of severity
- C. Classify incidents only after the response has already concluded
- D. Limit incident classification to security-related AI incidents
Answer: A
Severity/type-based classification enables proportionate response, rather than uniform, after-the-fact, or security-only classification.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q425 How should an enterprise best handle AI incident response team composition as part of its AI risk program?
- A. Rely on the original model developer alone to manage incident response
- B. Include technical, risk, legal, and communications representatives on the AI incident response team
- C. Limit the AI incident response team to technical staff only
- D. Assemble the incident response team only after the incident is publicized
Answer: B
Cross-functional incident response composition is needed, not technical-only, reactive, or single-developer-reliant.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q426 Regarding regulatory horizon scanning for AI, the enterprise should PRIMARILY:
- A. Review AI regulatory developments only once a year
- B. Rely on vendors to notify the enterprise of regulatory changes
- C. Monitor regulation only in the enterprise's headquarters jurisdiction
- D. Maintain an ongoing process to monitor emerging AI regulation relevant to the enterprise
Answer: D
Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q427 Which practice reflects the soundest approach to explainability requirements at design stage?
- A. Apply the same explainability level to all AI regardless of risk
- B. Treat explainability as a purely technical afterthought
- C. Define explainability requirements appropriate to the AI system's risk and use context during design
- D. Add explainability features only if regulators demand them later
Answer: C
Explainability requirements should be risk-based and considered during design, not uniform or deferred.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q428 What is the most effective way to manage control framework mapping for AI within an AI risk program?
- A. Map AI controls to a recognized control framework to ensure completeness and avoid gaps
- B. Design AI controls ad hoc without reference to any framework
- C. Map controls to a framework only for externally audited systems
- D. Treat framework mapping as a one-time exercise never revisited
Answer: A
Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q429 When addressing enterprise AI strategy documentation, what is the BEST first step for an enterprise?
- A. Document strategy without reference to risk appetite
- B. Document strategy only after major incidents occur
- C. Document AI strategy with clear links to enterprise risk appetite and business objectives
- D. Leave AI strategy undocumented and informal
Answer: C
AI strategy documentation should explicitly tie to risk appetite and business objectives to guide consistent decisions.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q430 The most important consideration for residual risk re-evaluation after treatment is that the enterprise should:
- A. Assume residual risk is acceptable once any control is applied
- B. Skip residual risk re-evaluation for time-sensitive projects
- C. Re-evaluate residual risk only during the next annual audit cycle
- D. Re-evaluate residual risk after implementing treatment to confirm it falls within acceptable levels
Answer: D
Residual risk must be explicitly re-evaluated against appetite after treatment, not assumed or deferred to annual cycles.