Free AAIR sample questions with answers
These follow ISACA’s style: scenario-led, from the risk professional’s perspective, with a qualifier that decides the answer. The mix reflects the weighting, so most come from governance and programme management.
Question 1. An enterprise is preparing to adopt AI across several business units. No AI systems have yet been catalogued. Which should the risk practitioner recommend FIRST?
- A. Select an AI risk framework and adopt it enterprise-wide
- B. Establish an inventory of AI systems and their intended use cases
- C. Write an AI acceptable use policy and circulate it
- D. Deploy monitoring tooling across all AI workloads
Show answer
Answer: B
Risk cannot be assessed or treated for systems nobody has identified, so establishing an inventory of AI systems and their use cases comes before assessment, policy or controls. Selecting a framework, writing policy or deploying monitoring before knowing what exists produces work that does not fit the estate.
Question 2. A model supplied by a third-party provider underpins a regulated process. Which supply chain risk is MOST significant?
- A. The provider may increase pricing at renewal
- B. The provider’s support response times may lengthen
- C. The provider may update the model, changing behaviour without notice and invalidating prior validation
- D. The provider’s API documentation may become outdated
Show answer
Answer: C
A provider can update a hosted model and change production behaviour without notice, invalidating prior validation evidence in a regulated process. Pricing changes are commercial, support response times are operational, and interface documentation is a delivery concern — none of them alters the behaviour you have attested to.
Question 3. An AI system's risk was assessed as acceptable at deployment. Eighteen months later no reassessment has occurred and nothing about the system has changed. Which is the BEST conclusion?
- A. The assessment may no longer be valid, because drift changes the risk profile without any system change
- B. The assessment remains valid, since nothing about the system changed
- C. Reassessment is only required following an incident
- D. Reassessment is satisfied by annually recertifying user access
Show answer
Answer: A
Drift means an AI system’s risk profile changes as real-world data diverges from training data, so an assessment can become invalid with no change to the system, making periodic reassessment necessary. Treating the original assessment as still valid ignores drift, and neither reassessment on incident nor annual recertification of users addresses the mechanism.
Question 4. Management proposes to accept a documented AI risk that falls within the enterprise's stated appetite, with a named owner and a scheduled review. What should the risk practitioner do?
- A. Override the decision and require mitigating controls
- B. Escalate to the board as an unresolved risk
- C. Require controls regardless, since AI risk should always be reduced
- D. Confirm the acceptance is properly authorised, documented and has a review date
Show answer
Answer: D
Acceptance within appetite, documented, owned and scheduled for review, is a valid treatment decision, and the practitioner’s role is to confirm it was properly made and recorded. Overriding it substitutes the practitioner’s appetite for the enterprise’s, escalation implies an unresolved issue, and requiring controls regardless disregards the appetite framework.
Question 5. A generative AI service is decommissioned. Which consideration is MOST likely to be overlooked?
- A. Cancelling the vendor licence agreement
- B. Disposition of the model artefact, training data, and records of decisions the system already made
- C. Reassigning the support team to other work
- D. Removing the service from the operations dashboard
Show answer
Answer: B
Retiring the service does not resolve the model artefact, the training data or the record of decisions already made, all of which may carry retention, privacy or defensibility obligations. Cancelling the licence, reassigning staff and removing dashboard entries are routine and rarely missed.
How did you do?
Notice how few of these require technical knowledge of AI. Question 5 is the only one touching the lifecycle domain, which matches the weighting — that domain is 21% while governance and programme management together are 79%.
If you picked defensible-but-not-best answers, that is the most common failure mode on ISACA exams and it is trainable. See the study plan.