Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q431 For AI-specific legal review for new deployments, sound practice requires that the enterprise PRIMARILY:
- A. Require legal review of AI deployments against applicable sector and data protection laws before go-live
- B. Deploy first and seek legal review only if challenged
- C. Limit legal review to marketing-related AI use cases
- D. Assume prior legal review of similar tools covers all new deployments
Answer: A
Legal review before go-live should assess the specific deployment, not rely on assumptions from unrelated prior reviews.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q432 What is the BEST way for an enterprise to manage AI model ownership assignment?
- A. Leave AI models without a designated owner
- B. Assign ownership only to the original developer who may later leave
- C. Rotate ownership randomly to spread accountability
- D. Assign a clearly accountable business owner for each AI model throughout its lifecycle
Answer: D
Each AI model needs a clearly accountable owner for its full lifecycle, not an undefined or rotating assignment.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q433 To properly manage testing for adversarial robustness, an enterprise should PRIMARILY:
- A. Defer robustness testing until after a security incident
- B. Test AI models for robustness against adversarial or unexpected inputs prior to deployment
- C. Assume robustness because the model performs well on clean test data
- D. Test adversarial robustness only for external-facing models
Answer: B
Adversarial robustness testing is a distinct check beyond standard accuracy evaluation and should be done proactively.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q434 When addressing AI strategy use-case feasibility review, what should the enterprise prioritize to manage AI risk effectively?
- A. Conduct a feasibility review covering data availability, risk, and resourcing before approving a use case
- B. Approve use cases based only on executive sponsorship
- C. Skip feasibility review for small-scale pilots
- D. Approve use cases once a vendor demo looks promising
Answer: A
Feasibility review of data, risk, and resourcing should precede use-case approval regardless of sponsorship or pilot size.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q435 When handling cross-border AI strategy alignment, the enterprise's main priority should be to:
- A. Reconcile AI strategy with varying regional regulatory and risk expectations
- B. Apply one region's rules globally without review
- C. Let each region choose frameworks independently with no coordination
- D. Defer all strategy decisions to IT
Answer: A
Cross-border AI strategy must reconcile differing regional requirements, not default to one region or fragment entirely.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q436 Regarding process alignment for AI change management, the enterprise should PRIMARILY:
- A. Apply change management only to AI changes that fail initially
- B. Integrate AI initiatives into existing change management processes
- C. Treat AI changes as exempt from standard change management
- D. Use ad hoc approval for AI changes outside formal processes
Answer: B
AI changes should flow through existing, not exempted or ad hoc, change management processes.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q437 For prioritizing AI risk scenarios for treatment, which practice best reflects sound AI risk management?
- A. Prioritize AI risk scenarios for treatment based on combined likelihood and impact, aligned with risk appetite
- B. Treat all identified AI risks with equal priority and resources
- C. Prioritize risk treatment based solely on ease of implementation
- D. Prioritize only risks that have already caused incidents
Answer: A
Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q438 How should an enterprise best handle AI-specific legal review for new deployments as part of its AI risk program?
- A. Assume prior legal review of similar tools covers all new deployments
- B. Require legal review of AI deployments against applicable sector and data protection laws before go-live
- C. Deploy first and seek legal review only if challenged
- D. Limit legal review to marketing-related AI use cases
Answer: B
Legal review before go-live should assess the specific deployment, not rely on assumptions from unrelated prior reviews.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q439 When addressing model performance benchmarking, what is the BEST first step for an enterprise?
- A. Benchmark AI model performance against defined acceptance criteria before production release
- B. Release models once they outperform a prior inferior baseline only slightly
- C. Release models based on developer confidence alone
- D. Skip benchmarking for minor model updates
Answer: A
Formal benchmarking against acceptance criteria should precede release, not rely on marginal improvement or developer confidence alone.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q440 Which practice reflects the soundest approach to independent validation of model results?
- A. Use independent validation only for regulator-mandated models
- B. Skip independent validation for internally facing tools
- C. Have model validation performed by a function independent from model development
- D. Allow the development team to self-validate without independent review
Answer: C
Independent validation reduces conflict-of-interest risk and should not be limited to regulated or self-validated cases.