Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q491 Designing clear consent prompts before using AI to personalize a user's experience is valuable PRIMARILY because it:
- A. Removes the need for a privacy policy covering AI use
- B. Automatically satisfies every applicable privacy regulation, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Gives users meaningful awareness and choice over how their data drives personalization, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Is only required for personalization involving financial data, which is a minor but relevant consideration in most situations
Answer: C
Clear consent UX gives users real awareness/choice; it isn't financial-data-only, doesn't automatically satisfy all regulation, or replace a broader privacy policy. Per the AAIR Review Manual: "Then, LLM prompts were used to chunk and analyze the data in the articles to define an 'influence event'-a summa1y of the title, description, and actors in the article that may be relevant to the search query."
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q492 Regarding risk appetite application to AI decisions, the BEST practice is to:
- A. Ignore risk appetite when a use case has strong business sponsorship
- B. Apply the enterprise's defined risk appetite consistently when deciding on AI risk treatment, which is a minor but relevant consideration in most situations
- C. Define risk appetite only after treatment decisions are made, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- D. Apply different undocumented risk appetites across business units, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: B
Risk appetite should be defined upfront and applied consistently, not overridden by sponsorship or defined after the fact. Per the AAIR Review Manual: "Which of the following would be the MOST critical consideration when deciding between in-house or cloud infrastructure for an AI application? A."
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q493 Within an AI governance program, the chief AI officer (CAIO) role is BEST described as:
- A. A role limited to managing AI vendor contracts, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. A mandatory new C-suite position required by law in every enterprise using AI, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. A purely technical position with no reporting line to executive management, which is a minor but relevant consideration in most situations
- D. A role that may be a standalone position or integrated into an existing commensurate role, leading overall AI adoption and reporting to executive management
Answer: D
The CAIO role can be standalone or absorbed into an existing role; what matters is that it leads AI adoption and reports to executive management, not that it is a distinct legally mandated title. Per the AAIR Review Manual: "The chief Al officer {CAIO) is responsible for leading the overall adoption of Al within the organization and reports to executive management."
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q494 "Second line of defense" oversight of AI risk typically refers to:
- A. The AI model itself
- B. External auditors only, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Business units executing daily operations, which is a minor but relevant consideration in most situations
- D. Independent risk/compliance functions reviewing and challenging first-line controls, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
Answer: D
Second line provides independent risk oversight/challenge, distinct from first-line operations. Per the AAIR Review Manual: "The risk management function, often positioned as the second line of defense, plays a critical role in overseeing AI risk management activities, ensuring that first-line functions implement appropriate controls and that third-line audit functions assess effectiveness consistently."
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q495 Scanning container images used to serve an AI model for known vulnerabilities before deployment is important PRIMARILY because it:
- A. Is only relevant for images stored in a public registry
- B. Automatically fixes any vulnerabilities it detects, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. Catches exploitable weaknesses in the serving stack before they reach production, which is a minor but relevant consideration in most situations
- D. Replaces the need to scan the model's training pipeline, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: C
Image scanning catches serving-stack vulnerabilities pre-deployment; it isn't limited to public registries, doesn't auto-fix findings, or replace training-pipeline scanning. Per the AAIR Review Manual: "Vector and embedding weaknesses Vectors and embedding vulnerabilities in retrieval augmented generation (RAG}-based LLM systems, a model adaptation technique that combines pretrained language models with external knowledge sources, expose risk in how data is handled."
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q496 At what point should a plan to revert a new AI deployment be prepared?
- A. Create rollback plans only after a failed deployment occurs, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- B. Treat rollback planning as optional for low-risk use cases, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- C. Assume new deployments can always be fixed forward without rollback
- D. Prepare rollback plans in case a new AI deployment causes unacceptable issues, which is a minor but relevant consideration in most situations
Answer: D
Rollback plans should be prepared proactively for deployments, not created reactively after failure.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q497 Misalignment between an AI initiative's timeline and the enterprise risk assessment cycle MOST often results in:
- A. No practical effect, which is a minor but relevant consideration in most situations
- B. Faster project delivery with no downside, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- C. AI systems being deployed before risks are adequately assessed
- D. Improved risk coverage, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: C
Timeline misalignment can let deployment outpace risk assessment, a control gap. Per the AAIR Review Manual: "Results of the BIA inform control selection for the AI solutions deployed in an enterprise and provide insight into the risk of using AI solutions for business-critical operations."
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q498 When deploying AI-generated content to end users, the enterprise should PRIMARILY ensure:
- A. Accessibility can be skipped for internal-only tools, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. Accessibility is addressed only if a complaint is received
- C. The content and its delivery meet applicable accessibility requirements for all intended users, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Accessibility is solely the responsibility of the content platform, which is a minor but relevant consideration in most situations
Answer: C
Accessibility should be designed in proactively for intended users, not handled reactively, delegated away, or skipped for internal tools. Per the AAIR Review Manual: "This poses a significant challenge, especially when the generated results are used to train models."
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q499 Transferring AI risk via insurance or contractual indemnification is MOST appropriate when:
- A. The enterprise wants to shift financial impact while still managing underlying operational risk, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
- B. It replaces the need for any other controls, which is a minor but relevant consideration in most situations
- C. The risk can be fully eliminated through transfer alone, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. The counterparty has no financial capacity
Answer: A
Risk transfer shifts financial impact but does not eliminate the need to manage operational risk itself. Per the AAIR Review Manual: "• Prioritize/Treat- Once risk exposure is determined, risk management can collaborate with the appropriate stakeholders to rank each scenario based on the likelihood of each risk occurring and the resulting financial impact if the risk were to be realized."
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q500 Accepting a residual AI risk above normal tolerance should PRIMARILY require:
- A. No formal sign-off if the project is already underway, which is a minor but relevant consideration in most situations
- B. Verbal agreement from any available manager
- C. Sign-off from a role with the authority and accountability commensurate with that risk level, an aspect that is often underestimated in real-world settings but can have a significant and lasting impact on both the process and its eventual results
- D. Approval from the vendor providing the AI system, a factor that many practitioners tend to overlook even though it can meaningfully influence the final outcome
Answer: C
Higher residual risk needs sign-off from a correspondingly senior, accountable role; informal or vendor-driven approval is insufficient. Per the AAIR Review Manual: "• Develop and implement an AI risk management framework, including roles and accountability, AI risk policies and procedures, and acceptable risk tolerance levels."