Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q71 An enterprise evaluating prioritizing AI risk scenarios for treatment should PRIMARILY ensure that:
- A. Treat all identified AI risks with equal priority and resources
- B. Prioritize risk treatment based solely on ease of implementation
- C. Prioritize only risks that have already caused incidents
- D. Prioritize AI risk scenarios for treatment based on combined likelihood and impact, aligned with risk appetite
Answer: D
Prioritization should reflect likelihood, impact, and risk appetite, not equal treatment, ease alone, or past incidents only.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q72 An enterprise evaluating AI training data access controls should PRIMARILY ensure that:
- A. Apply access controls to training and production data consistent with its sensitivity classification
- B. Grant broad data access to all AI project members by default
- C. Apply access controls only to production data, not training data
- D. Rely on project trust rather than formal access controls
Answer: A
Access controls should follow data sensitivity classification across both training and production data, not informal trust.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q73 Regarding employee AI training program design, the BEST practice is to:
- A. Provide AI training only to the data science team
- B. Rely on self-directed learning with no formal program
- C. Tailor AI training content to role-specific risk exposure (e.g., developers vs. general staff)
- D. Provide identical generic AI training to every employee regardless of role
Answer: C
Role-tailored AI training addresses differing risk exposure better than one-size-fits-all or team-limited training.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q74 Segregation of duties in AI model deployment (e.g., developer cannot self-approve production release) is intended to:
- A. Slow down releases with no benefit
- B. Reduce the risk of unauthorized or unreviewed changes reaching production
- C. Increase vendor costs
- D. Replace the need for testing
Answer: B
Segregation of duties prevents unilateral, unreviewed changes from reaching production.
Domain 2: AI Lifecycle / Part D - AI Data and Asset Management
Q75 In the context of AI training data access controls, which of the following represents sound AI risk management?
- A. Apply access controls to training and production data consistent with its sensitivity classification
- B. Grant broad data access to all AI project members by default
- C. Apply access controls only to production data, not training data
- D. Rely on project trust rather than formal access controls
Answer: A
Access controls should follow data sensitivity classification across both training and production data, not informal trust.
Domain 3: AI Operations/Resilience / Part C - AI Controls Management
Q76 An enterprise evaluating control framework mapping for AI should PRIMARILY ensure that:
- A. Design AI controls ad hoc without reference to any framework
- B. Map controls to a framework only for externally audited systems
- C. Treat framework mapping as a one-time exercise never revisited
- D. Map AI controls to a recognized control framework to ensure completeness and avoid gaps
Answer: D
Mapping to a recognized framework, kept current, supports completeness; ad hoc or one-time-only mapping risks gaps.
Domain 2: AI Lifecycle / Part A - AI Design, Development/Procurement, and Documentation
Q77 In the context of explainability requirements at design stage, which of the following represents sound AI risk management?
- A. Define explainability requirements appropriate to the AI system's risk and use context during design
- B. Add explainability features only if regulators demand them later
- C. Apply the same explainability level to all AI regardless of risk
- D. Treat explainability as a purely technical afterthought
Answer: A
Explainability requirements should be risk-based and considered during design, not uniform or deferred.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q78 Configuration drift in a production AI system (undocumented changes diverging from approved baseline) is a risk PRIMARILY because it:
- A. Improves system performance automatically
- B. Can introduce unapproved, unreviewed changes to system behavior and controls
- C. Has no effect on risk posture
- D. Is required for normal operations
Answer: B
Unreviewed configuration drift can silently alter behavior/controls outside the approved baseline.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q79 With respect to phased AI rollout approach, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Deploy AI system-wide immediately after passing lab validation
- B. Skip pilot phases to reduce project timeline
- C. Pilot only with internal users regardless of intended end-user population
- D. Use a phased or pilot rollout to monitor real-world AI performance before full-scale deployment
Answer: D
Phased rollout against the intended population allows real-world risk monitoring before full-scale deployment.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q80 With respect to procedure documentation for AI model changes, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Skip documentation for minor model updates
- B. Maintain documented procedures for requesting, approving, and recording AI model changes
- C. Allow informal verbal approval for AI model changes
- D. Document procedures only for production failures
Answer: B
Documented change procedures should apply consistently, including to seemingly minor AI model updates.