Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q41 In the context of trend analysis of AI risk indicators, which of the following represents sound AI risk management?
- A. Analyze trends in AI risk indicators over time to detect gradual degradation, not just point-in-time snapshots
- B. Limit trend analysis to indicators that are already favorable
- C. Benchmark each indicator only against industry-average values published annually, without tracking the enterprise's own trend over time
- D. Analyze trends only after a significant incident has occurred
Answer: A
Genuine trend analysis tracks the enterprise's own indicators over time; external benchmarking alone, cherry-picking favorable indicators, or incident-triggered-only review all fail to track ongoing internal trend.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q42 With respect to cross-border AI strategy alignment, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Defer all strategy decisions to IT
- B. Reconcile AI strategy with varying regional regulatory and risk expectations
- C. Let each region choose frameworks independently with no coordination
- D. Adopt the strictest regional regulatory standard and apply it uniformly everywhere, without further analysis
Answer: B
Cross-border strategy should reconcile differing regional requirements through analysis; defaulting to the strictest standard everywhere without analysis, deferring to IT, or fragmenting entirely with no coordination all bypass that reconciliation.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q43 Regarding escalation path for AI risk issues, the BEST practice is to:
- A. Require model owners to report issues to IT service management, which triages severity before any risk governance body is involved
- B. Let model owners decide independently whether to escalate issues
- C. Define a clear escalation path from model owners to senior risk governance bodies
- D. Escalate only after regulatory inquiry
Answer: C
A direct, defined escalation path to risk governance bodies ensures timely visibility; routing through IT service management first adds an unnecessary, non-risk-focused gate, and ad hoc or regulator-triggered-only escalation both delay visibility.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q44 With respect to alignment of AI metrics with business KPIs, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Only track technical accuracy metrics
- B. Display technical accuracy metrics alongside business KPIs on the same dashboard, without defining how they relate
- C. Avoid defining AI metrics until problems arise
- D. Tie AI performance metrics back to relevant business KPIs and risk indicators
Answer: D
Metrics must be explicitly tied to business KPIs and risk indicators; placing them on the same dashboard without a defined linkage, tracking accuracy only, or waiting for problems to define metrics all fall short of real alignment.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q45 Explainability is MOST critical for AI systems that:
- A. Make or materially influence high-stakes decisions affecting individuals (credit, hiring, healthcare)
- B. Generate internal marketing copy
- C. Process large volumes of transactions quickly, regardless of the stakes for affected individuals
- D. Recommend office supplies
Answer: A
Explainability need is driven by the stakes of decisions for individuals, not by transaction volume or speed; high-volume/low-stakes systems don't carry the same explainability urgency as high-stakes individual decisions.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q46 Risk acceptance for an AI risk scenario requires:
- A. No formal process, since acceptance is informal by nature
- B. Documented approval by an authorized owner, with periodic review
- C. Approval from the AI vendor only
- D. A one-time sign-off by the project sponsor at go-live, with no requirement for subsequent review
Answer: B
Risk acceptance needs documented approval plus periodic review as conditions change; a one-time sign-off with no review, informal acceptance, and vendor-only approval all lack ongoing accountability.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q47 Version control for AI models and training data is important PRIMARILY because it:
- A. Primarily prevents unauthorized users from accessing the model's codebase
- B. Is only useful for marketing records
- C. Enables traceability and reproducibility of model behavior over time
- D. Eliminates the need for testing new versions
Answer: C
Version control's core value is traceability/reproducibility of model behavior changes; access restriction is a separate concern (access control), and it doesn't replace marketing records or testing.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q48 When requirements gathering for an AI project omits risk and compliance stakeholders, the MOST likely consequence is:
- A. Faster delivery with no tradeoff
- B. The project proceeds on schedule, but with a higher likelihood of post-launch customer complaints
- C. Improved model accuracy
- D. Controls and compliance needs being retrofitted late, at higher cost and risk
Answer: D
Omitting risk/compliance stakeholders typically forces late, costly retrofitting of controls; a vague increase in complaints understates the specific cost/risk consequence, and there is no accuracy benefit or tradeoff-free speed gain.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q49 Regarding data quality management for AI inputs, the BEST practice is to:
- A. Implement ongoing data quality checks for inputs feeding AI models
- B. Rely on end users to report data quality issues
- C. Validate data quality thoroughly at initial training, then re-check only when a new model version is released
- D. Assume data quality is adequate if the source system is trusted
Answer: A
Data quality for live AI inputs needs ongoing checks, not just checks at training/version-release points; relying on end users or trusting the source system without verification are both reactive/unverified approaches.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q50 An incident communication plan for an AI-related incident should ensure:
- A. Communication occurs only if media coverage begins
- B. Timely, accurate communication to affected stakeholders based on severity and impact
- C. No communication until the incident is fully resolved
- D. Communication is drafted immediately but released only after full legal review, regardless of urgency
Answer: B
Communication timing should be proportionate to severity/impact; mandatory full legal review regardless of urgency can delay timely communication, and media-triggered-only or resolution-only communication are both too reactive/delayed.