Free AAIR practice test: 20 questions

Updated September 20, 2026

Twenty questions across the three AAIR domains, weighted roughly as the real exam is. AAIR is about managing an AI risk programme, so the right answer usually concerns process and accountability rather than technique.

AI Risk Governance and Framework Integration

Question 1. An organisation already runs an enterprise risk management framework. How should AI risk be handled?

  • A. Build a separate AI risk framework with its own reporting line
  • B. Integrate AI risk into the existing enterprise risk framework, extending taxonomy and criteria
  • C. Delegate it entirely to the data science team
  • D. Defer until regulation is final
Show answer

Answer: B

Integrating AI risk into the existing framework avoids a parallel process that competes for attention and reports separately. A standalone silo weakens both.

Question 2. Who should own an AI risk in the risk register?

  • A. The model development team
  • B. The internal audit function
  • C. The accountable business owner of the process the AI supports
  • D. The cloud provider
Show answer

Answer: C

Risk ownership sits with the business accountable for the outcome, not with the technical team that built the system or the function that monitors it.

Question 3. An AI risk is assessed as exceeding appetite. What are the legitimate options?

  • A. Proceed and monitor informally
  • B. Reduce the assessed rating until it fits appetite
  • C. Remove it from the register
  • D. Treat, transfer, avoid, or formally accept at the appropriate authority level
Show answer

Answer: D

Treat, transfer, avoid, or formally accept with documented authority are the standard responses. Proceeding without a decision is not one of them.

Question 4. Which AI-specific risk is least likely to be captured by a traditional IT risk taxonomy?

  • A. Emergent model behaviour that was never specified or tested for
  • B. Service availability
  • C. Vendor concentration
  • D. Unauthorised access to data
Show answer

Answer: A

Emergent behaviour that was never specified has no equivalent in conventional IT risk, where systems do what they were coded to do. Availability, vendor and access risks map across readily.

Question 5. A regulator publishes AI obligations that partly overlap existing privacy requirements. What is the efficient response?

  • A. Build a separate control set for each regulation
  • B. Map the new obligations to existing controls and address only genuine gaps
  • C. Wait for enforcement action before responding
  • D. Apply the strictest requirement to every system regardless of risk
Show answer

Answer: B

Mapping obligations to existing controls identifies genuine gaps and avoids duplicating work. Building a separate control set for each regulation creates redundancy and drift.

Question 6. Which factor should most influence the depth of assessment applied to an AI system?

  • A. The cost of the system
  • B. How novel the technology is
  • C. The potential impact on people and the degree of autonomy
  • D. Which team built it
Show answer

Answer: C

Risk-based effort scales assessment to potential impact and autonomy, concentrating scrutiny where consequences are greatest. Cost and novelty are poor proxies.

Question 7. The board asks for assurance that AI risk is within appetite. What should the report contain?

  • A. Current exposure against defined thresholds, trend, and exceptions with owners
  • B. The number of AI projects underway
  • C. The number of models in production
  • D. The AI team’s headcount
Show answer

Answer: A

Exposure against defined thresholds, with trend and exceptions, answers the question directly. Counts of projects and models describe activity, not risk.

AI Life Cycle Risk Management

Question 8. At which point should AI risk assessment first occur?

  • A. After deployment, once behaviour is observable
  • B. Immediately before go-live
  • C. At the first incident
  • D. At concept or design stage, before significant investment
Show answer

Answer: D

Assessing at concept or design, before significant investment, allows risk to shape the design. Assessing only before go-live means expensive rework or pressure to approve.

Question 9. A model is retrained on newer data. What should the risk process require?

  • A. Nothing, as the code has not changed
  • B. Re-validation and re-approval proportionate to the system’s risk rating
  • C. A note in the release log only
  • D. Approval by the data scientist who retrained it
Show answer

Answer: B

Retraining changes behaviour, so re-validation and re-approval proportionate to risk are required before release. Treating it as a routine change ignores that.

Question 10. Which decommissioning risk is specific to AI systems?

  • A. Software licences must be cancelled
  • B. Hardware must be disposed of securely
  • C. Downstream dependencies on its outputs, and retention duties over training data and past decisions
  • D. Staff must be reassigned
Show answer

Answer: C

Downstream processes and other models may consume its outputs, and retention obligations may apply to training data and decisions. Licence and hardware concerns are generic.

Question 11. A pilot AI system quietly became business-critical without formal approval. What is the primary risk management failure?

  • A. No control gate between pilot and production status
  • B. The pilot ran too long
  • C. The team used the wrong framework
  • D. Costs were not tracked
Show answer

Answer: A

No gate existed between pilot and production, so a system escaped the controls its actual risk demands. Documentation and monitoring gaps follow from that.

AI Risk Program Management

Question 12. What is the most reliable indicator that an AI risk programme is operating rather than merely designed?

  • A. An approved programme charter
  • B. Evidence of systems modified, delayed or rejected as a result of assessments
  • C. A published policy on the intranet
  • D. An annual awareness email
Show answer

Answer: B

Evidence of decisions the programme changed, such as systems modified, delayed or rejected, shows real influence. Existence of artefacts shows design only.

Question 13. Business units are bypassing the AI risk process because it is slow. What is the appropriate response?

  • A. Issue a reminder that the process is mandatory
  • B. Remove the process
  • C. Introduce risk-tiered assessment so low-risk systems clear quickly
  • D. Extend the process to cover more systems
Show answer

Answer: C

Tiering the process so low-risk systems pass quickly removes the incentive to bypass it while preserving scrutiny where it matters. Enforcement alone does not address the cause.

Question 14. Which metric best reflects AI risk programme effectiveness?

  • A. Number of assessments completed
  • B. Training completion percentage
  • C. Number of AI systems deployed
  • D. Percentage of the AI inventory assessed, and time to remediate open high risks
Show answer

Answer: D

Coverage of the inventory combined with time to remediate open risks measures both reach and follow-through. Counts of assessments and training completions measure activity only.

Question 15. An AI incident occurs. What should the programme ensure happens beyond technical fix?

  • A. Root cause analysis with updates to controls, the risk register and affected systems
  • B. Restoration of service and closure of the ticket
  • C. Reassignment of the responsible engineer
  • D. A public statement
Show answer

Answer: A

Root cause analysis feeding back into controls and the risk register prevents recurrence across other systems. Restoring service alone leaves the cause in place.

Question 16. Third-party AI components are used across many systems. What programme control addresses concentration risk?

  • A. An annual vendor satisfaction survey
  • B. Mapping dependency concentration and defining contingency and exit arrangements
  • C. Requiring vendors to hold a certification
  • D. Negotiating a discount
Show answer

Answer: B

Identifying dependency concentration and defining contingency reduces the impact of a single provider failing or changing terms. Vendor satisfaction surveys do not.

Question 17. Which stakeholder group is most often missing from AI risk governance, and most needed?

  • A. Procurement
  • B. External auditors
  • C. Affected users and the front-line staff who act on the outputs
  • D. The marketing department
Show answer

Answer: C

The people affected by decisions, and the front-line staff who must act on model output, surface failure modes that technical and legal reviewers miss.

Question 18. A risk owner disputes an assessed rating. What should the programme do?

  • A. Adjust the rating to end the dispute
  • B. Remove the risk from the register
  • C. Refer it to the data science team
  • D. Apply a documented escalation and adjudication path with evidence
Show answer

Answer: D

A documented escalation path resolves disputes with evidence and appropriate authority, preserving both challenge and accountability. Silent adjustment undermines the register’s integrity.

Question 19. What should trigger reassessment of an AI system outside the normal cycle?

  • A. Material change in purpose, data, model version or applicable regulation
  • B. The annual budget cycle
  • C. A change of project manager
  • D. A new office location
Show answer

Answer: A

Material change in use, data, model or regulation alters the risk profile and warrants immediate reassessment. Budget cycles and staff changes do not by themselves.

Question 20. Which is the clearest sign that AI risk reporting is not useful to decision-makers?

  • A. Reports are produced monthly
  • B. No decision has ever changed as a result of the reporting
  • C. Reports include technical detail
  • D. Reports are circulated by email
Show answer

Answer: B

If reports never change a decision, they are documentation rather than governance. Length and frequency matter only insofar as they affect that.

How did you do?

Sixteen or more correct suggests you are close. Below fourteen, the domain guides in this section are the fastest route back — AAIR rewards programme thinking: who decides, on what evidence, and what changes as a result.