Free AAIR exam practice questions with answers and explanations, organized by domain and part.
Domain 1: AI Governance / Part F - AI Trustworthiness, Ethical, and Societal Implications
Q81 Societal-level risk from widescale AI deployment (e.g., labor displacement) should be considered PRIMARILY by:
- A. Technical teams alone, as a coding concern
- B. Enterprise leadership as part of broader strategic and ethical risk assessment
- C. No one, since it is outside enterprise control
- D. External regulators exclusively
Answer: B
Broad societal impacts belong in leadership's strategic/ethical risk view, not purely technical scope.
Domain 2: AI Lifecycle / Part C - AI Implementation, Maintenance, and Decommissioning
Q82 A phased or canary deployment of an AI system is valuable PRIMARILY because it:
- A. Guarantees zero defects
- B. Limits exposure by validating real-world performance on a limited scale before full rollout
- C. Is required only for cost reasons
- D. Eliminates the need for monitoring after full rollout
Answer: B
Phased rollout limits blast radius while confirming real-world performance.
Domain 1: AI Governance / Part E - AI Regulatory Compliance and Legal Considerations
Q83 An enterprise evaluating sector-specific AI regulatory requirements should PRIMARILY ensure that:
- A. Rely solely on peer company practices instead of applicable law
- B. Identify and apply sector-specific AI requirements (e.g., financial services, healthcare) in addition to general regulations
- C. Apply only general-purpose AI regulations to all sectors
- D. Assume sector regulators do not address AI specifically
Answer: B
Sector-specific requirements layer on top of general AI regulation and must be separately identified and applied.
Domain 3: AI Operations/Resilience / Part D - AI Risk Metrics, Monitoring, and Reporting
Q84 In the context of AI risk reporting to stakeholders, which of the following represents sound AI risk management?
- A. Provide identical AI risk reports to all stakeholder groups
- B. Report AI risk only when specifically requested
- C. Limit AI risk reporting to technical teams only
- D. Tailor AI risk reporting content and frequency to the needs of each stakeholder audience (board, management, operational teams)
Answer: D
Reporting should be tailored to audience needs, not uniform, on-demand only, or restricted to technical teams.
Domain 2: AI Lifecycle / Part B - AI Model Training, Testing, and Validation
Q85 Regarding documentation of validation results, the BEST practice is to:
- A. Document only successful validation outcomes
- B. Share validation findings verbally without written record
- C. Document validation after go-live if issues surface
- D. Document validation results, including known limitations and failure conditions, before go-live
Answer: D
Validation documentation, including limitations and failure modes, should be complete and recorded before go-live.
Domain 1: AI Governance / Part C - AI Ownership, Oversight, and Accountability
Q86 Applying the three lines of defense model to AI, the SECOND line is typically responsible for:
- A. Building and operating the AI model
- B. Independent risk and compliance oversight of AI controls
- C. Providing independent assurance via audit
- D. Approving the enterprise budget
Answer: B
The second line (risk/compliance) provides independent oversight distinct from the first line (operations) and third line (audit).
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q87 With respect to risk assessment stakeholder involvement, which approach is MOST appropriate for an enterprise managing AI risk?
- A. Conduct AI risk assessment using only the technical team's input
- B. Conduct AI risk assessment using only business stakeholder input
- C. Outsource all risk assessment judgment entirely to external consultants
- D. Involve business, technical, and risk stakeholders jointly in AI risk assessment
Answer: D
Joint stakeholder involvement produces more complete risk assessment than single-function or fully outsourced judgment.
Domain 1: AI Governance / Part D - AI Policies, Procedures, and Organizational Training
Q88 AI training content should be MOST tailored by:
- A. Employee tenure only
- B. Role, since developers, business users, and executives face different AI risks
- C. Geographic location only
- D. A single generic module for all staff
Answer: B
Role-based training addresses the distinct risk exposures of different functions.
Domain 3: AI Operations/Resilience / Part A - AI Risk Scenario Identification and Assessment
Q89 In the context of emerging AI risk identification, which of the following represents sound AI risk management?
- A. Identify AI risks only once during initial project approval
- B. Rely solely on external audit to surface new AI risks
- C. Limit risk identification to risks already seen at peer companies
- D. Establish a process to continuously identify new and emerging AI risks as technology and use evolve
Answer: D
Continuous, enterprise-driven identification is needed for emerging AI risk, not one-time, audit-only, or peer-limited approaches.
Domain 1: AI Governance / Part A - AI Models, Frameworks, Strategies, and Use Cases
Q90 When two AI frameworks conflict in control recommendations, the enterprise should:
- A. Default to the oldest framework
- B. Reconcile differences based on the enterprise's own risk appetite and regulatory obligations
- C. Adopt neither
- D. Let each business unit choose independently with no coordination
Answer: B
Conflicts are resolved by anchoring to the enterprise's own risk appetite and obligations, not arbitrary defaults.