Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q461 When addressing disaster recovery testing for AI systems, what is the BEST first step for an AI risk practitioner?
- A. Include AI systems in disaster recovery testing, including model/data restoration procedures, which is a minor but relevant consideration in most situations
- B. Assume cloud-hosted AI systems require no DR testing
- C. Exclude AI systems from DR testing because they are 'non-critical' by default, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Test DR for AI systems only once at initial implementation, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: A
AI systems, including model/data restoration, should be included in regular DR testing, not excluded by default or location assumption. Per the AAIR Review Manual: "Governance and accountability Effective data disposition requires governance structures that oversee the decommissioning process, including policies addressing ancillary data such as model predictions, explanations, intermediate feature representations, and credentials."
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q462 For a high-risk AI system subject to regulatory reporting, the enterprise's MOST important obligation is to:
- A. Report only if a complaint is received, which is a minor but relevant consideration in most situations
- B. Delegate all reporting to the AI vendor without oversight, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Maintain accurate records and report as required by the applicable regulatory regime
- D. Avoid documentation to reduce audit exposure, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: C
Regulatory reporting obligations require proactive, accurate record-keeping, not reactive or delegated compliance. Per the AAIR Review Manual: "By proactively managing the retirement of AI solutions, organizations can optimize their technology investments, reduce exposure to obsolete or unsupported systems, and maintain compliance with applicable legal and regulatory obligations."
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q463 Regarding asset inventory for AI systems, the BEST practice is to:
- A. Update the AI asset inventory only during annual audits, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Maintain inventory only for externally facing AI systems, which is a minor but relevant consideration in most situations
- C. Track AI assets informally through individual team spreadsheets, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Maintain an inventory of AI models and their associated data assets across the enterprise
Answer: D
A centralized, current AI asset inventory supports risk oversight across the enterprise, not informal or partial tracking. Per the AAIR Review Manual: "Maintaining a full Al model inventory ensures completeness and accuracy in Al asset management.52 Unlike traditional IT assets, Al solutions are complex systems composed of multiple models, datasets, algorithms, and workflows, often with decentralized ownership and varying development life cycles."
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q464 Reliance on a single AI vendor for multiple critical functions MOST increases:
- A. Vendor competition, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Diversification of risk, which is a minor but relevant consideration in most situations
- C. Enterprise flexibility
- D. Concentration risk, since a single vendor failure can affect multiple functions, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: D
Single-vendor reliance across critical functions creates concentration risk. Per the AAIR Review Manual: "• C oncentr ation risk-Organizations should also assess concentration risk, where heavy reliance on a limited number of AI vendors creates systemic exposure if a provider fails."
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q465 A risk scenario involving third-party AI API outages should be evaluated for impact on:
- A. Business process continuity and dependent downstream services, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Nothing, since it is outside enterprise control, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Vendor stock price only, which is a minor but relevant consideration in most situations
- D. Marketing campaign timing only
Answer: A
Third-party dependency risk should be assessed for its effect on business continuity. Per the AAIR Review Manual: "Risk management is responsible for integrating Al solution dependencies, associated threats, and model risk into the enterprise's business impact analysis (BIA) and continuity planning."
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q466 Recovery Time Objective (RTO) for a critical AI system should be set based on:
- A. Arbitrary preference with no analysis, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. The shortest possible time regardless of cost, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. The vendor's convenience
- D. The maximum downtime the business can tolerate before unacceptable impact occurs, which is a minor but relevant consideration in most situations
Answer: D
RTO should reflect actual tolerable downtime derived from business impact, not arbitrary choice. Per the AAIR Review Manual: "Part F: Al Incident Response, BIA, Business Continuity, and Disaster Recovery As AI systems become increasingly integrated into critical infrastructures, business operations, and everyday applications, the need for a structured approach to incident response bas become more crucial."
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q467 A business impact analysis (BIA) for a process dependent on AI should assess:
- A. The criticality of the AI-dependent process and the impact of its disruption, which is a minor but relevant consideration in most situations
- B. Only the AI model's training data size, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Only the number of lines of code in the model, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Only the AI vendor's revenue
Answer: A
BIA focuses on process criticality and disruption impact, not technical model attributes. Per the AAIR Review Manual: "Its goals are to mitigate risk, enhance transparency, and build trust in AI systems. 3.5.4 Privacy Impact Assessment A privacy impact assessment (PIA) is an analysis of how personal information is collected, used, shared, and maintained for a specified scope of consideration."
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q468 Implementing a quality assurance process for human-labeled training data is valuable PRIMARILY because it:
- A. Automatically increases the size of the training dataset
- B. Is only necessary when labels are produced by external contractors, which is a minor but relevant consideration in most situations
- C. Catches labeling errors and inconsistencies before they are baked into the trained model, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Removes the need to measure inter-rater reliability, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: C
QA catches labeling errors before they propagate into the model; it isn't limited to contractor-produced labels, doesn't grow dataset size, or remove the need for reliability measurement. Per the AAIR Review Manual: "An improvement in this score since implementing the AI agents indicates that customers are pleased with the quality of the response they receive from not only human agents but also the AI triage and response process."
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q469 When addressing societal impact assessment for high-risk AI, what is the BEST first step for an AI risk practitioner?
- A. Skip societal impact assessment for internally used AI, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Conduct a standard privacy impact assessment and treat it as equivalent to a societal impact assessment
- C. Perform impact assessment only after deployment, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Conduct a societal impact assessment for AI systems with significant potential societal effects, which is a minor but relevant consideration in most situations
Answer: D
A dedicated societal impact assessment is needed for high-impact systems; a privacy impact assessment covers narrower ground and isn't equivalent, and post-deployment-only or internal-use exemptions both miss pre-deployment review. Per the AAIR Review Manual: "Its goals are to mitigate risk, enhance transparency, and build trust in AI systems. 3.5.4 Privacy Impact Assessment A privacy impact assessment (PIA) is an analysis of how personal information is collected, used, shared, and maintained for a specified scope of consideration."
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q470 Which is the BEST indicator that AI policy adoption is effective?
- A. Observed employee behavior and control compliance consistent with the policy's intent, which is a minor but relevant consideration in most situations
- B. Frequency of policy reissuance, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Number of training emails sent
- D. Number of pages in the policy document, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: A
Effectiveness is measured by actual behavior/compliance, not document volume or reissue frequency. Per the AAIR Review Manual: "This enables effective communication about risk to senior leadership and other relevant stakeholders. 153 Compliance-driven enterprises can map FAIR-AIR outputs to jurisdictional regulatory frameworks like the EU AI Act."