Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q451 A validation report showing strong aggregate accuracy but poor performance on a minority subgroup indicates:
- A. A data storage problem only, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. A potential fairness/bias issue requiring further investigation before deployment
- C. The model is fully validated with no concerns, which is a minor but relevant consideration in most situations
- D. No action needed since aggregate accuracy is high, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: B
Subgroup performance gaps despite good aggregate accuracy signal a fairness risk needing follow-up. Per the AAIR Review Manual: "Regular audits of AI performance for bias and accuracy should be conducted to maintain fairness."
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q452 When addressing AI incident response team composition, what is the BEST first step for an AI risk practitioner?
- A. Limit the AI incident response team to technical staff only, which is a minor but relevant consideration in most situations
- B. Assemble the incident response team only after the incident is publicized
- C. Include technical, risk, legal, and communications representatives on the AI incident response team, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Rely on the original model developer alone to manage incident response, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: C
Cross-functional incident response composition is needed, not technical-only, reactive, or single-developer-reliant. Per the AAIR Review Manual: "Integrate AI-related risk considerations into the change management process. 22.Incorporate AI-related risk considerations into incident response, BIAs, the BCP, and DRP. 23."
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q453 Risk transfer for AI risk (e.g., insurance, vendor indemnification) is MOST appropriate when:
- A. The risk is negligible
- B. The risk can be fully eliminated by transfer alone, which is a minor but relevant consideration in most situations
- C. The enterprise chooses to shift financial impact while still managing operational exposure, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. No other treatment option exists, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: C
Transfer shifts financial impact but does not eliminate the need to manage operational risk. Per the AAIR Review Manual: "• Prioritize/Treat- Once risk exposure is determined, risk management can collaborate with the appropriate stakeholders to rank each scenario based on the likelihood of each risk occurring and the resulting financial impact if the risk were to be realized."
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q454 Risk management's role in AI oversight, as distinct from internal audit's role, is BEST described as:
- A. Integrating AI solution dependencies, associated threats, and model risk into the enterprise's business impact analysis and continuity planning
- B. Providing independent assurance after the fact, with no involvement in planning, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Certifying that AI models comply with external regulations, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Managing end-user training on AI tools, which is a minor but relevant consideration in most situations
Answer: A
Risk management proactively integrates AI-related dependencies and threats into BIA and continuity planning, whereas internal audit provides independent, retrospective assurance. Per the AAIR Review Manual: "Risk management is responsible for integrating Al solution dependencies, associated threats, and model risk into the enterprise's business impact analysis (BIA) and continuity planning."
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q455 When addressing likelihood and impact estimation for AI risk, what is the BEST first step for an AI risk practitioner?
- A. Estimate likelihood and impact of AI risk scenarios using available data and expert judgment, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Assume all AI risks have equal likelihood and impact, which is a minor but relevant consideration in most situations
- C. Estimate risk levels based on intuition alone without supporting rationale
- D. Estimate impact only in financial terms, ignoring reputational or legal impact, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: A
Risk estimation should use available evidence and judgment across multiple impact types, not uniform assumptions or financial-only framing. Per the AAIR Review Manual: "The combination of AI automation and expert judgment creates a robust approach to managing AI-related risk effectively. 3.3 Development of Al Risk Scenarios Constructing detailed AI risk scenarios is a critical step in understanding and managing the complex and evolving risk associated with AI systems."
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q456 Automated monitoring tools for AI controls are valuable PRIMARILY because they:
- A. Eliminate the need for any human oversight
- B. Replace the need for independent validation, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Guarantee zero false positives, which is a minor but relevant consideration in most situations
- D. Can detect control failures or anomalies faster and more consistently than manual review alone, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: D
Automation improves speed/consistency of detection but does not eliminate the need for human oversight. Per the AAIR Review Manual: "This supports continuous auditing and monitoring, with automated identification of anomalies or control failures."
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q457 When addressing risk transfer via contracts/insurance for AI, what is the BEST first step for an AI risk practitioner?
- A. Rely entirely on vendor indemnification instead of internal controls, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Evaluate contractual risk transfer (e.g., indemnification, insurance) as a complement to, not replacement for, internal controls, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Avoid risk transfer mechanisms entirely as unnecessary overhead, which is a minor but relevant consideration in most situations
- D. Transfer risk only after an incident has already occurred
Answer: B
Risk transfer should complement internal controls, not substitute for them or be arranged only reactively. Per the AAIR Review Manual: "During the collect and process data phase, they would evaluate the risk associated with data poisoning and establish robust controls to maintain data integrity."
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q458 Encrypting AI model weights at rest is valuable PRIMARILY because it:
- A. Automatically improves the model's inference accuracy, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Protects proprietary model intellectual property and reduces exposure if storage is compromised
- C. Removes the need for access controls on the storage location, which is a minor but relevant consideration in most situations
- D. Is only necessary for models deployed outside the enterprise's primary cloud region, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: B
At-rest encryption protects IP and limits exposure if storage is compromised; it doesn't affect accuracy, isn't region-specific, or remove the need for access controls. Per the AAIR Review Manual: "Model Theft The development of an Al model is a significant investment for many organizations, sometimes costing millions of dollars; therefore, enterprises aim to protect this form of intellectual property (IP) or proprietary information."
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q459 When building a risk scenario library for AI, what is MOST important?
- A. Reuse only generic IT risk scenarios for AI systems, which is a minor but relevant consideration in most situations
- B. Develop AI-specific risk scenarios covering bias, model failure, and misuse in addition to generic IT risk scenarios
- C. Limit scenario development to security risks alone, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Develop AI risk scenarios only after an incident occurs, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: B
AI risk scenarios should be tailored beyond generic IT risk and security-only scenarios, developed proactively. Per the AAIR Review Manual: "Once identified, specific risk scenarios can be analyzed based on what matters most to the identified stakeholders."
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q460 Algorithmic accountability in AI governance is BEST defined as:
- A. The requirement that an algorithm's source code be fully public, which is a minor but relevant consideration in most situations
- B. Ensuring there are identifiable, responsible parties who can answer for an AI system's decisions and outcomes
- C. A guarantee that no AI decision can ever be appealed, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. A purely technical metric computed during model training, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: B
Algorithmic accountability means clear ownership and answerability for an AI system's outcomes, not public code disclosure or a technical training metric. Per the AAIR Review Manual: "For example, in a compliance-driven culture, governance efforts might initially focus on clarifying policies and ensuring regulatory adherence, while in an ownership culture, governance can emphasize empowerment and accountability for AI risk decisions."