AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q481 When addressing regulatory horizon scanning for AI, what is the BEST first step for an AI risk practitioner?

Answer: C

Ongoing horizon scanning across relevant jurisdictions is needed, not infrequent, vendor-dependent, or single-jurisdiction monitoring. Per the AAIR Review Manual: "When adopting new technology, risk managers need to ensure the enterprise has a process for addressing the growing feelings of uncertainty or dissatisfaction that changes to current roles will have on employees."

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q482 Before decommissioning an AI system, the enterprise should PRIMARILY ensure:

Answer: C

Decommissioning requires addressing dependencies and retention obligations, not abrupt deletion. Per the AAIR Review Manual: "• P rivacy and security- Risk management should report on the effectiveness of privacy and security controls, especially related to potential data leakage. 3.16.1 Al Risk Escalations Effective escalation processes are critical to ensure that AI risk findings are addressed in a timely way."

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q483 A model performing poorly on both training and validation data is a key indicator that the enterprise should investigate for:

Answer: A

Poor performance on both training and validation data points to underfitting, not a successful run, a risk-appetite issue, or a retention violation. Per the AAIR Review Manual: "Types include:45 • Rule-based sentiment analysis ML sentiment analysis • Underfitting The ML model under development is too simplistic to identify the patterns in the data used for training."

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q484 After implementing a risk treatment for an AI risk, the enterprise should PRIMARILY report:

Answer: B

Reporting should cover the resulting residual risk and appetite alignment, not just implementation cost, staffing, or a bare completion statement. Per the AAIR Review Manual: "The enterprise will also need to review what level of risk it is willing to accept related to the use of AI, as it may differ from existing risk tolerance and appetite levels."

Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications

Q485 A societal impact assessment for a new AI deployment should consider:

Answer: B

Societal impact assessments look beyond financial return to broader stakeholder effects. Per the AAIR Review Manual: "Organizations should track accountability for data handling decisions and consider the downstream impacts on individuals, groups, and communities affected by Al system retirement."

Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation

Q486 Independent model validation (separate from the model development team) is valuable PRIMARILY because it:

Answer: A

Independent validation provides unbiased challenge, reducing developer conflict-of-interest risk. Per the AAIR Review Manual: "Organizations should implement policies that separate AI system development from testing and evaluation functions to enable independent oversight and course correction."

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q487 Addressing employee resistance to an AI-driven process change is BEST supported by:

Answer: C

Clear rationale plus training/support addresses resistance constructively; mandates without explanation, assumed self-resolution, or indefinite delay are not effective approaches. Per the AAIR Review Manual: "Employee engagement, training, and change management are vital to maximizing productivity gains and ensuring that AI solutions are effectively integrated into business processes. 1.4 Al Business Strategies Strategies for adopting AI can be based on a perceived need to provide guidance to applicable stakeholders."

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q488 When evaluating a vendor's AI solution, which criterion is MOST relevant to risk management?

Answer: A

Risk-relevant criteria are substantive (validation, security, monitoring), not reputational. Per the AAIR Review Manual: "AI risk identification, assessment, mitigation, and monitoring across the AI life cycle requires identified owners, including delineation of responsibilities among AI developers, deployers, risk practitioners, and senior management."

Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases

Q489 When an enterprise operates in multiple jurisdictions, its AI framework selection should MOST consider:

Answer: A

A framework must flex to the most stringent applicable requirement, not the lowest common denominator. Per the AAIR Review Manual: "This aljgnment ensures that AI controls support enterprise risk appetite and tolerance levels and comply with applicable legal, regulatory, and ethical standards."

Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation

Q490 Design-stage threat modeling for an AI system should PRIMARILY identify:

Answer: A

Design-stage threat modeling targets risks inherent to the AI system's design (adversarial, data, misuse), not generic infrastructure vulnerabilities, which are covered by standard IT security processes. Per the AAIR Review Manual: "These simulations can incorporate AI-specific threat considerations, such as adversarial ML attacks, data poisoning, and prompt injection attacks, which traditional threat modeling methods may not fully address."

‹ Prev
Next ›
Page 49 of 50 · 500 questions