AAIR Exam Prep

Free AAIR exam practice questions with answers and explanations, organized by domain and part.

Domain 3: AI Operations/Resilience / Part C - AI Controls Management

Q61 Testing frequency for controls over a high-risk AI system should be:

Answer: B

Control testing frequency should scale with risk level.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q62 When a genuinely new type of AI model is introduced, the FIRST risk management step should be:

Answer: B

New model types require explicit assessment of novel risk before controls can be assumed adequate.

Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment

Q63 Regarding risk assessment stakeholder involvement, the BEST practice is to:

Answer: A

Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.

Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability

Q64 A board-level AI oversight committee's role is MOST focused on:

Answer: B

Board-level oversight is strategic risk-appetite setting and enterprise monitoring, not operational tasks.

Domain 1: AI Governance / Part B - AI Organizational Processes and Alignment

Q65 The MAIN purpose of a cross-functional AI governance committee is to:

Answer: B

Cross-functional alignment ensures AI risk decisions reflect all relevant perspectives.

Domain 3: AI Operations/Resilience / Part B - AI Risk Treatment Strategies

Q66 When addressing residual risk re-evaluation after treatment, an AI risk practitioner should FIRST:

Answer: C

Residual risk must be explicitly re-evaluated against appetite after treatment, not assumed or deferred to annual cycles.

Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training

Q67 With respect to AI acceptable use policy scope, which approach is MOST appropriate for an enterprise managing AI risk?

Answer: A

An AI acceptable use policy should be explicit and enterprise-wide, not informal or narrowly scoped.

Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting

Q68 Continuous monitoring of a production AI model's output distribution is used PRIMARILY to detect:

Answer: B

Output distribution monitoring detects drift/anomalies relative to the validated baseline.

Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations

Q69 Record-keeping for AI regulatory audits should PRIMARILY enable:

Answer: A

Audit-ready records must support reconstructing the decision rationale and process.

Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning

Q70 Ongoing maintenance and retraining cadence for a deployed AI model should be determined by:

Answer: B

Retraining cadence should be risk-informed by actual observed model behavior, not arbitrary.

‹ Prev
Next ›
Page 7 of 50 · 500 questions