Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q471 Exceptions to an AI policy should be:
- A. Approved through a defined process with documented risk acceptance
- B. Granted automatically upon request, which is a minor but relevant consideration in most situations
- C. Never permitted under any circumstance, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Decided solely by the requesting business unit, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: A
Exceptions require a controlled approval process with documented risk acceptance, not informal or unilateral decisions. Per the AAIR Review Manual: "Ways to ensure effective risk acceptance include: • Monitoring-Methods to monitor are put in place to track, trend, and determine if changes remain or exceed the defined appetite."
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q472 What is the BEST approach when preparing AI risk reports for the board, management, and operational teams?
- A. Report AI risk only when specifically requested
- B. Provide identical AI risk reports to all stakeholder groups, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Limit AI risk reporting to technical teams only, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Tailor AI risk reporting content and frequency to the needs of each stakeholder audience (board, management, operational teams), which is a minor but relevant consideration in most situations
Answer: D
Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams. Per the AAIR Review Manual: "This approach facilitates comprehensive risk reporting and prioritization, allowing management to make informed, risk-aware business decisions that consider Al's unique challenges in the context of other enterprise risk, such as cybersecurity, privacy, and operational risk."
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q473 Applying differential privacy techniques when training an AI model is valuable PRIMARILY because it:
- A. Removes the need for any data access controls, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Automatically improves the model's overall accuracy, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Limits how much any single individual's data can influence or be inferred from the trained model, which is a minor but relevant consideration in most situations
- D. Is only relevant for models trained on image data
Answer: C
Differential privacy bounds individual data influence/inferability; it doesn't improve accuracy, remove access controls, or apply only to image data. Per the AAIR Review Manual: "Oversampling, undersampling, or applying cost-sensitive algorithms in model training are techniques to improve model performance. 2.21 Data Scarcity High-quality data that is relevant and fit for purpose, for which the organization has obtained consent or has license for use, is often hard to acquire."
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q474 Post-incident root cause analysis for an AI failure should PRIMARILY aim to:
- A. Assign individual blame as the main outcome
- B. Identify the true underlying cause(s) to prevent recurrence, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Close the incident ticket as quickly as possible with minimal analysis, which is a minor but relevant consideration in most situations
- D. Avoid documenting findings, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: B
Root cause analysis is about preventing recurrence, not blame assignment or speed over substance. Per the AAIR Review Manual: "Incident response for AI aims to identify, mitigate, and prevent such threats while ensuring system reliability, security, and ethical compliance."
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q475 Running tabletop exercises simulating an AI-related incident is valuable PRIMARILY because it:
- A. Tests and improves the enterprise's actual readiness and coordination before a real incident occurs, which is a minor but relevant consideration in most situations
- B. Is only useful for enterprises that have already had a real incident, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Replaces the need for a documented incident response plan
- D. Guarantees that a real incident will be handled perfectly, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: A
Tabletop exercises test/improve real readiness ahead of time; they don't replace a documented plan, aren't restricted to firms with prior incidents, or guarantee perfect execution.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q476 Insufficient resource allocation for AI oversight MOST likely results in:
- A. Short-term cost savings that are offset by increased risk exposure over time, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Governance processes that cannot keep pace with AI risk growth, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Reduced need for policies, which is a minor but relevant consideration in most situations
- D. Lower regulatory scrutiny
Answer: B
Under-resourced oversight functions fail to scale with growing AI risk. Per the AAIR Review Manual: "Timely escalation facilitates appropriate risk treatment actions, resource allocation, and policy adjustments, reinforcing organizational accountability and oversight."
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q477 When AI initiatives are run as "shadow IT" outside formal governance, the GREATEST risk is:
- A. Improved documentation
- B. Reduced total AI spend, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Lack of visibility, oversight, and consistent control application, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Faster innovation with no tradeoff, which is a minor but relevant consideration in most situations
Answer: C
Shadow AI evades the governance process entirely, removing visibility and control consistency. Per the AAIR Review Manual: "• Establish clear AI governance to ensure oversight and control over AI outputs. 2.s Model Testing and Validation Testing and validation are critical phases in AI model development that provide assurance the model performs as intended, meets business objectives, and adheres to ethical standards."
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q478 Procurement due diligence for a third-party AI solution should PRIMARILY assess:
- A. The vendor's office size, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. The vendor's pricing relative to competitors, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. The vendor's data handling, security, and model risk practices, which is a minor but relevant consideration in most situations
- D. The vendor's social media presence
Answer: C
Due diligence should focus on substantive risk practices, not superficial vendor attributes; pricing is a real procurement factor but secondary to risk. Per the AAIR Review Manual: "Consideration Description Data handling and migration Security and access controls should be applied to datasets, artifacts, and outputs created by the artificial intelligence (Al) solution being decommissioned."
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q479 What characteristic should AI performance metrics have relative to the business?
- A. Avoid defining AI metrics until problems arise, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Only track technical accuracy metrics, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Tie AI performance metrics back to relevant business KPIs and risk indicators, which is a minor but relevant consideration in most situations
- D. Track AI metrics in isolation from business performance
Answer: C
AI metrics should connect to business KPIs and risk indicators, not remain purely technical or reactive. Per the AAIR Review Manual: "Organizational and governance policies are usually created and applied through a combination of controls, plans of business, strategies, job descriptions, accepted practices of professional discipline, regulations, training, key performance indicators (KPis), and a variety of executive communications."
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q480 Reusing open-source code or pre-trained weights in an AI product requires the enterprise to PRIMARILY verify:
- A. That no cost is charged for using the component, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Compliance with the applicable license terms, including any attribution or copyleft obligations, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. That the component is popular on code-sharing platforms, which is a minor but relevant consideration in most situations
- D. That the code compiles without errors
Answer: B
License compliance, including attribution/copyleft obligations, must be verified; functionality, popularity, or being free doesn't address legal risk. Per the AAIR Review Manual: "In the context of AI, where models and codebases often incorporate multiple open-source software libraries, it is critical to conduct thorough license reviews and ensure that all open-source usage aligns with organizational policies and contractual obligations."