Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q61 Testing frequency for controls over a high-risk AI system should be:
- A. Lower than for low-risk systems
- B. Commensurate with the system's risk level, generally more frequent for higher risk
- C. The same fixed frequency for all systems regardless of risk
- D. Determined solely by the vendor
Answer: B
Control testing frequency should scale with risk level.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q62 When a genuinely new type of AI model is introduced, the FIRST risk management step should be:
- A. Deploy immediately and monitor afterward
- B. Assess emerging/novel risks the new model type may introduce before deployment
- C. Assume existing controls are automatically sufficient
- D. Skip assessment since the model is "new" and therefore unregulated
Answer: B
New model types require explicit assessment of novel risk before controls can be assumed adequate.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q63 Regarding risk assessment stakeholder involvement, the BEST practice is to:
- A. Involve business, technical, and risk stakeholders jointly in AI risk assessment
- B. Conduct AI risk assessment using only the technical team's input
- C. Conduct AI risk assessment using only business stakeholder input
- D. Outsource all risk assessment judgment entirely to external consultants
Answer: A
Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q64 A board-level AI oversight committee's role is MOST focused on:
- A. Writing model code
- B. Setting risk appetite and monitoring enterprise-wide AI risk exposure
- C. Approving individual data scientist hires
- D. Running day-to-day model validation tests
Answer: B
Board-level oversight is strategic risk-appetite setting and enterprise monitoring, not operational tasks.
Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment
Q65 The MAIN purpose of a cross-functional AI governance committee is to:
- A. Approve IT budgets only
- B. Align AI risk decisions across legal, risk, business, and technology stakeholders
- C. Replace the board's oversight role
- D. Manage day-to-day model coding
Answer: B
Cross-functional alignment ensures AI risk decisions reflect all relevant perspectives.
Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies
Q66 When addressing residual risk re-evaluation after treatment, an AI risk practitioner should FIRST:
- A. Skip residual risk re-evaluation for time-sensitive projects
- B. Re-evaluate residual risk only during the next annual audit cycle
- C. Re-evaluate residual risk after implementing treatment to confirm it falls within acceptable levels
- D. Assume residual risk is acceptable once any control is applied
Answer: C
Residual risk must be explicitly re-evaluated against appetite after treatment, not assumed or deferred to annual cycles.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q67 With respect to AI acceptable use policy scope, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Define an AI acceptable use policy covering permitted tools, data handling, and prohibited uses
- B. Leave AI acceptable use undefined and rely on informal norms
- C. Limit the policy to only prohibit a single named tool
- D. Apply the acceptable use policy only to the IT department
Answer: A
An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q68 Continuous monitoring of a production AI model's output distribution is used PRIMARILY to detect:
- A. Vendor billing discrepancies
- B. Drift or anomalies indicating the model's behavior has changed from its validated baseline
- C. Office network congestion
- D. Marketing campaign performance
Answer: B
Output distribution monitoring detects drift/anomalies relative to the validated baseline.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q69 Record-keeping for AI regulatory audits should PRIMARILY enable:
- A. Reconstructing how and why an AI decision was made
- B. Reducing storage costs
- C. Avoiding the need for model documentation
- D. Satisfying marketing claims only
Answer: A
Audit-ready records must support reconstructing the decision rationale and process.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q70 Ongoing maintenance and retraining cadence for a deployed AI model should be determined by:
- A. A fixed schedule regardless of model behavior
- B. Observed drift, performance degradation, and changes in the operating environment
- C. Vendor convenience only
- D. Marketing release cycles
Answer: B
Retraining cadence should be risk-informed by actual observed model behavior, not arbitrary.