AAIA Sample Questions

AAIA Sample Questions & Answers

AI operations, from data management to solution development lifecycles and change management, dominates, ahead of AI governance and risk considerations, and the design, sampling and evidence-collection techniques used when auditing and testing AI systems.

Launch the full AAIA simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    AI Auditing Tools and Techniques · Audit Testing and Sampling Methodologies

    True or False: In the context of AI auditing, statistical sampling is always preferable to judgmental sampling because it eliminates all forms of bias.

    Show answer & explanation

    Correct answer: B

    This statement is false. While statistical sampling allows for quantifiable measurement of sampling risk, it does not eliminate all bias. Furthermore, in AI auditing, judgmental (or risk-based) sampling is often necessary to target high-risk areas, such as testing the model's behavior on known edge cases or transactions involving sensitive data, which might be missed by a purely random statistical sample.

  2. Question 2Advanced

    AI Operations · Supervision of AI Solutions (e.g., outputs, impacts, and decisions)

    A manufacturing company uses an AI model to predict machinery failure. The model is highly accurate but is a complex 'black box' ensemble of deep learning networks, making its predictions difficult to interpret. This lack of explainability poses the GREATEST challenge to which of the following operational processes?

    Show answer & explanation

    Correct answer: B

    If the model predicts a failure but cannot explain why (e.g., which sensor reading or combination of factors led to the prediction), it is extremely difficult for maintenance engineers to perform targeted diagnostics and root cause analysis. They know the machine is likely to fail, but they don't know which component is the problem. This lack of insight hinders proactive repair and learning from potential failures.

  3. Question 3Advanced

    AI Governance and Risk · AI Governance and Program Management

    An e-commerce company is developing an AI-powered dynamic pricing engine. The AI governance committee is establishing key risk indicators (KRIs) for the system. Which of the following would be the MOST effective KRI for monitoring potential non-compliance with anti-price discrimination regulations?

    Show answer & explanation

    Correct answer: D

    A key risk indicator must be a measurable metric that provides an early warning of increasing risk. Measuring the statistical variance in pricing across defined demographic segments (e.g., based on geography, inferred income, etc.) directly targets the risk of price discrimination. A rising variance would trigger an investigation, making it the most effective KRI for this specific risk.

  4. Question 4Intermediate

    AI Governance and Risk · Leading Practices, Ethics, Regulations, and Standards for AI

    A hospital is implementing an AI system to triage emergency room patients based on initial symptom data. According to the EU AI Act, this system would likely be classified as 'high-risk'. What is the PRIMARY implication of this classification for the audit scope?

    Show answer & explanation

    Correct answer: C

    The 'high-risk' classification under the EU AI Act mandates a comprehensive set of obligations. The audit scope must therefore be significantly expanded to include conformity assessments against these legal requirements, which cover the entire lifecycle of the AI system, including the quality of training data, technical documentation, transparency for users, human oversight mechanisms, and a robust risk management system.

  5. Question 5Intermediate

    AI Operations · AI Solution Development Methodologies and Lifecycle

    An auditor is reviewing the MLOps pipeline for a critical AI model. The process is depicted below. The auditor's primary concern is ensuring model integrity and reproducibility. Which stage in this pipeline is MOST critical for achieving this objective?

    flowchart LR A[Data Ingestion] --> B{Feature Engineering} B --> C[Model Training] C --> D(Model Evaluation) D --> E{Model Registry} E --> F[Deployment]
    Show answer & explanation

    Correct answer: D

    The Model Registry is the central component for ensuring integrity and reproducibility. It should version and store not just the trained model artifact, but also the code used for training, the version of the data it was trained on, its evaluation metrics, and its dependencies. This allows an auditor or data scientist to precisely recreate the model and its training environment, which is the essence of reproducibility.

  6. Question 6Intermediate

    AI Operations · Change Management specific to AI

    Case Study

    Global Logistics Inc. (GLI) has deployed an AI-powered route optimization system for its fleet of delivery trucks. The system analyzes real-time traffic, weather, and delivery schedules to generate the most efficient routes. The primary business objective is to reduce fuel costs and delivery times. The system was developed in-house and has been operational for six months.

    During a preliminary audit review, it was noted that the data science team frequently updates the model's algorithm and parameters directly in the production environment to respond to changing road conditions. There is no formal change management process for these updates. Logs show that on several occasions, route suggestions became highly inefficient for several hours following an update, leading to driver complaints and increased fuel consumption.

    The audit team is tasked with evaluating the operational readiness and control environment of this AI system. The key stakeholders are concerned about the system's reliability and the potential for financial losses due to flawed updates.

    Question

    Given the situation at GLI, which audit recommendation is the MOST critical to address the immediate operational risk?

    Show answer & explanation

    Correct answer: A

    The core issue is the uncontrolled and untested changes being pushed directly to production. This creates significant operational risk, as evidenced by the system's periodic failures. Implementing a formal change management process with a pre-production testing (staging) environment is the most critical control to ensure that updates are vetted for performance and stability before they can impact live operations and cause financial loss.

  7. Question 7Beginner

    AI Auditing Tools and Techniques · Audit Testing and Sampling Methodologies

    An auditor uses a data analytics tool to re-perform a calculation done by an AI-based financial forecasting model. The auditor's tool produces a slightly different result. This audit procedure is an example of:

    Show answer & explanation

    Correct answer: B

    Substantive testing is designed to detect material misstatements in financial data. By independently recalculating the forecast (an analytical procedure), the auditor is gathering evidence about the validity and accuracy of the financial numbers produced by the AI model. This is a classic example of a substantive test.

  8. Question 8Intermediate

    AI Governance and Risk · AI Governance and Program Management

    What is the primary purpose of creating an 'AI Bill of Materials' or 'Model Card' as part of an organization's AI governance framework?

    Show answer & explanation

    Correct answer: C

    The primary purpose of a Model Card or AI Bill of Materials is to provide clear, standardized documentation about an AI model's purpose, performance, limitations, and ethical considerations. This includes details about the training data, evaluation metrics, intended use cases, and potential biases. This practice directly supports the principles of transparency and accountability in AI governance.

  9. Question 9IntermediateSelect 3

    AI Governance and Risk · Privacy and Data Governance Programs

    A university uses an AI system to screen student applications. To comply with privacy regulations, the university's data governance program must ensure which of the following regarding the student data used for model training? (Select THREE)

    Show answer & explanation

    Correct answers: A, B, D

    Under regulations like GDPR, using personal data for a new purpose (like training an AI model) requires a valid legal basis, often specific and informed consent from the data subjects (the students).

    The principle of data minimization requires that only data essential for the specific, stated purpose should be collected and processed. The university should not use extraneous student data to train the model.

    Good data governance requires maintaining data lineage—a record of the data's origin, transformations, and usage. This is crucial for auditing the model's training process, ensuring data integrity, and investigating issues like bias.

  10. Question 10Advanced

    AI Operations · Threats and Vulnerabilities specific to AI

    Which of the following describes a 'model inversion' attack against an AI system?

    Show answer & explanation

    Correct answer: C

    A model inversion attack specifically aims to reverse-engineer the training data. By having access to the model and its outputs (e.g., class labels or confidence scores), an attacker can infer sensitive features or even reconstruct representative samples of the data used to train it. This is a severe privacy breach, especially for models trained on PII or medical images.

Ready for the real thing?

The full AAIA simulator has every exam-style question, timed mode, and instant scoring.

Go to the AAIA simulator →