AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q51 An enterprise evaluating procedure documentation for AI model changes should PRIMARILY ensure that:

Answer: B

Documented change procedures should apply consistently, including to seemingly minor AI model updates.

Domain 3: AI Operations/Resilience / Part F - AI Incident Response, BIA, Business Continuity, and Disaster Recovery

Q52 When addressing business impact analysis for AI-dependent processes, an AI risk practitioner should FIRST:

Answer: A

BIA should specifically assess AI-dependent processes and be kept current, not assumed equivalent to manual processes or updated only post-outage.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q53 Regarding AI risk metric selection, the BEST practice is to:

Answer: B

Risk metrics should be relevant and actionable, not chosen purely for ease of collection or left static over time.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q54 With respect to organizational alignment of AI initiatives, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

AI initiatives should align to business objectives within governance structures, not run independently of oversight.

Domain 3: AI Operations/Resilience / Part E - AI Supply Chain Risk Management

Q55 Regarding AI supply chain risk mapping, the BEST practice is to:

Answer: B

Full supply chain mapping, including sub-vendors, is needed and should be kept current, not limited to direct vendors or a one-time exercise.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q56 When addressing risk transfer via contracts/insurance for AI, an AI risk practitioner should FIRST:

Answer: A

Risk transfer should complement internal controls, not substitute for them or be arranged only reactively.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q57 Acceptance of residual AI risk should be authorized by:

Answer: B

Risk acceptance requires authority commensurate with the risk's magnitude, per governance structure.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q58 When addressing cost-benefit analysis of AI controls, an AI risk practitioner should FIRST:

Answer: B

Control selection should weigh cost and benefit, not default to vendor recommendation, maximum cost, or ignore usability.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q59 An enterprise evaluating AI contractual compliance clauses should PRIMARILY ensure that:

Answer: C

Contracts with AI vendors should proactively include compliance and audit-rights clauses, not rely on verbal assurance or reactive amendment.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q60 In the context of AI policy enforcement mechanism, which of the following represents sound AI risk management?

Answer: A

Policies need active monitoring/enforcement, not reliance on self-reporting or infrequent audit-only checks.

‹ Prev
Next ›
Page 6 of 50 · 500 questions