AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q471 Exceptions to an AI policy should be:

Answer: A

Exceptions require a controlled approval process with documented risk acceptance, not informal or unilateral decisions. Per the AAIR Review Manual: "Ways to ensure effective risk acceptance include: • Monitoring-Methods to monitor are put in place to track, trend, and determine if changes remain or exceed the defined appetite."

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q472 What is the BEST approach when preparing AI risk reports for the board, management, and operational teams?

Answer: D

Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams. Per the AAIR Review Manual: "This approach facilitates comprehensive risk reporting and prioritization, allowing management to make informed, risk-aware business decisions that consider Al's unique challenges in the context of other enterprise risk, such as cybersecurity, privacy, and operational risk."

Domain 2: AI Lifecycle / Part D - AI Data and Asset Management

Q473 Applying differential privacy techniques when training an AI model is valuable PRIMARILY because it:

Answer: C

Differential privacy bounds individual data influence/inferability; it doesn't improve accuracy, remove access controls, or apply only to image data. Per the AAIR Review Manual: "Oversampling, undersampling, or applying cost-sensitive algorithms in model training are techniques to improve model performance. 2.21 Data Scarcity High-quality data that is relevant and fit for purpose, for which the organization has obtained consent or has license for use, is often hard to acquire."

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q474 Post-incident root cause analysis for an AI failure should PRIMARILY aim to:

Answer: B

Root cause analysis is about preventing recurrence, not blame assignment or speed over substance. Per the AAIR Review Manual: "Incident response for AI aims to identify, mitigate, and prevent such threats while ensuring system reliability, security, and ethical compliance."

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q475 Running tabletop exercises simulating an AI-related incident is valuable PRIMARILY because it:

Answer: A

Tabletop exercises test/improve real readiness ahead of time; they don't replace a documented plan, aren't restricted to firms with prior incidents, or guarantee perfect execution.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q476 Insufficient resource allocation for AI oversight MOST likely results in:

Answer: B

Under-resourced oversight functions fail to scale with growing AI risk. Per the AAIR Review Manual: "Timely escalation facilitates appropriate risk treatment actions, resource allocation, and policy adjustments, reinforcing organizational accountability and oversight."

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q477 When AI initiatives are run as "shadow IT" outside formal governance, the GREATEST risk is:

Answer: C

Shadow AI evades the governance process entirely, removing visibility and control consistency. Per the AAIR Review Manual: "• Establish clear AI governance to ensure oversight and control over AI outputs. 2.s Model Testing and Validation Testing and validation are critical phases in AI model development that provide assurance the model performs as intended, meets business objectives, and adheres to ethical standards."

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q478 Procurement due diligence for a third-party AI solution should PRIMARILY assess:

Answer: C

Due diligence should focus on substantive risk practices, not superficial vendor attributes; pricing is a real procurement factor but secondary to risk. Per the AAIR Review Manual: "Consideration Description Data handling and migration Security and access controls should be applied to datasets, artifacts, and outputs created by the artificial intelligence (Al) solution being decommissioned."

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q479 What characteristic should AI performance metrics have relative to the business?

Answer: C

AI metrics should connect to business KPIs and risk indicators, not remain purely technical or reactive. Per the AAIR Review Manual: "Organizational and governance policies are usually created and applied through a combination of controls, plans of business, strategies, job descriptions, accepted practices of professional discipline, regulations, training, key performance indicators (KPis), and a variety of executive communications."

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q480 Reusing open-source code or pre-trained weights in an AI product requires the enterprise to PRIMARILY verify:

Answer: B

License compliance, including attribution/copyleft obligations, must be verified; functionality, popularity, or being free doesn't address legal risk. Per the AAIR Review Manual: "In the context of AI, where models and codebases often incorporate multiple open-source software libraries, it is critical to conduct thorough license reviews and ensure that all open-source usage aligns with organizational policies and contractual obligations."

‹ Prev
Next ›
Page 48 of 50 · 500 questions