Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q51 An enterprise evaluating procedure documentation for AI model changes should PRIMARILY ensure that:
- A. Skip documentation for minor model updates
- B. Maintain documented procedures for requesting, approving, and recording AI model changes
- C. Allow informal verbal approval for AI model changes
- D. Document procedures only for production failures
Answer: B
Documented change procedures should apply consistently, including to seemingly minor AI model updates.
Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery
Q52 When addressing business impact analysis for AI-dependent processes, an AI risk practitioner should FIRST:
- A. Conduct business impact analysis for critical processes that depend on AI systems
- B. Assume AI-dependent processes have the same impact profile as manual processes
- C. Perform BIA only for processes classified as mission-critical by IT alone
- D. Update BIA only after an AI-related outage occurs
Answer: A
BIA should specifically assess AI-dependent processes and be kept current, not assumed equivalent to manual processes or updated only post-outage.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q53 Regarding AI risk metric selection, the BEST practice is to:
- A. Define metrics once and never revisit their relevance
- B. Select AI risk metrics that are measurable, relevant to key risks, and actionable for decision-makers
- C. Select metrics based only on what is easiest to collect
- D. Track only technical accuracy metrics as the sole risk indicator
Answer: B
Risk metrics should be relevant and actionable, not chosen purely for ease of collection or left static over time.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q54 With respect to organizational alignment of AI initiatives, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Ensure AI initiatives are aligned to defined business objectives and governance structures
- B. Allow business units to pursue AI initiatives independently of governance
- C. Align AI initiatives only to IT's technical roadmap
- D. Align AI initiatives only after audit findings require it
Answer: A
AI initiatives should align to business objectives within governance structures, not run independently of oversight.
Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management
Q55 Regarding AI supply chain risk mapping, the BEST practice is to:
- A. Map the supply chain only once at initial vendor onboarding
- B. Map the full AI supply chain, including sub-vendors and third-party data/model providers, not just direct vendors
- C. Assess risk only for the primary contracted vendor
- D. Assume sub-vendor risk is immaterial if not contractually visible
Answer: B
Full supply chain mapping, including sub-vendors, is needed and should be kept current, not limited to direct vendors or a one-time exercise.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q56 When addressing risk transfer via contracts/insurance for AI, an AI risk practitioner should FIRST:
- A. Evaluate contractual risk transfer (e.g., indemnification, insurance) as a complement to, not replacement for, internal controls
- B. Rely entirely on vendor indemnification instead of internal controls
- C. Avoid risk transfer mechanisms entirely as unnecessary overhead
- D. Transfer risk only after an incident has already occurred
Answer: A
Risk transfer should complement internal controls, not substitute for them or be arranged only reactively.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q57 Acceptance of residual AI risk should be authorized by:
- A. Any employee, informally
- B. A risk owner with the appropriate authority level given the risk's magnitude
- C. The AI vendor
- D. No one; residual risk cannot be accepted
Answer: B
Risk acceptance requires authority commensurate with the risk's magnitude, per governance structure.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q58 When addressing cost-benefit analysis of AI controls, an AI risk practitioner should FIRST:
- A. Select controls without considering impact on system usability
- B. Perform cost-benefit analysis when selecting controls to treat AI risk
- C. Select controls based on vendor recommendation alone
- D. Implement the most expensive available control by default
Answer: B
Control selection should weigh cost and benefit, not default to vendor recommendation, maximum cost, or ignore usability.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q59 An enterprise evaluating AI contractual compliance clauses should PRIMARILY ensure that:
- A. Limit vendor contracts to pricing and service-level terms only
- B. Add compliance clauses only after a vendor incident occurs
- C. Include compliance and audit-rights clauses in contracts with AI vendors
- D. Rely on vendor assurances without contractual compliance clauses
Answer: C
Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q60 In the context of AI policy enforcement mechanism, which of the following represents sound AI risk management?
- A. Pair AI policies with monitoring and enforcement mechanisms to ensure compliance
- B. Publish AI policies without any compliance monitoring
- C. Rely entirely on employee self-reporting of violations
- D. Enforce AI policy only during annual audits
Answer: A
Policies need active monitoring/enforcement, not reliance on self-reporting or infrequent audit-only checks.