Advanced in AI Audit (AAIA) Free Sample Questions

20 free sample questions262 in the full practice test

Try simulator

AAIA Sample Questions

  1. Question 1

    A financial services firm has implemented an AI model for algorithmic trading. During an audit, it is discovered that the model's decision logic is stored as a configuration file in a code repository with open write access for all developers. Which of the following is the MOST critical risk this practice introduces?

    Answer and explanation

    Correct answer: A

    The most critical risk is the potential for unauthorized and malicious changes to the trading algorithm's logic. Given the direct financial implications of an algorithmic trading model, an undetected modification could trigger erroneous trades, leading to immediate and substantial financial losses. This represents a direct and high-impact operational risk.

  2. Question 2

    An auditor is evaluating the fairness of a loan approval AI system. The testing reveals that the model has a disproportionately higher false negative rate for applicants from a specific demographic group, even though protected attributes were excluded from the training data. What is the MOST likely cause of this bias?

    Answer and explanation

    Correct answer: B

    Even when protected attributes like race or gender are removed, other features (proxies) can be highly correlated with them. For example, ZIP codes, income levels, or certain types of employment can inadvertently act as proxies for demographic groups, allowing the model to learn and perpetuate historical biases present in the data.

  3. Question 3

    Multiple answers

    An organization is using a third-party, cloud-based AI service for sentiment analysis of customer feedback. Which of the following audit procedures is MOST crucial for assessing data privacy risks? (Select TWO)

    Answer and explanation

    Correct answers: A, D

    The data processing agreement (DPA) and terms of service are legally binding documents that outline how the vendor will handle the organization's data, including data ownership, usage rights, security controls, and compliance with privacy regulations like GDPR. This is a primary source of evidence for assessing privacy risk.

    A crucial internal control to mitigate third-party privacy risk is to minimize the data shared. Verifying that the organization has a process to scrub PII before sending data to the vendor's service directly reduces the risk of a data breach or misuse of customer PII by the third party.

  4. Question 4

    During an audit of an AI system's incident response plan, an auditor notes that the plan is identical to the organization's traditional IT incident response plan. What is the MOST significant gap in this approach?

    Answer and explanation

    Correct answer: A

    AI systems introduce unique failure modes not found in traditional IT systems. These include model drift, performance degradation, generation of harmful or biased outputs, and adversarial attacks. An effective incident response plan must include specific playbooks for identifying, containing (e.g., taking the model offline, reverting to a previous version), and remediating these AI-specific incidents.

  5. Question 5

    When planning an audit of a newly deployed generative AI chatbot for customer service, what should be the auditor's PRIMARY focus?

    Answer and explanation

    Correct answer: A

    According to standard audit practices, the first step in planning any audit is to understand the context: what the system is supposed to achieve (business objectives) and what could go wrong (high-level risks). For a generative AI chatbot, risks include reputational damage from inappropriate responses, data leakage, and inaccurate information. This understanding drives the entire audit scope and approach.

  6. Question 6

    True or False: In the context of AI auditing, statistical sampling is always preferable to judgmental sampling because it eliminates all forms of bias.

    Answer and explanation

    Correct answer: B

    This statement is false. While statistical sampling allows for quantifiable measurement of sampling risk, it does not eliminate all bias. Furthermore, in AI auditing, judgmental (or risk-based) sampling is often necessary to target high-risk areas, such as testing the model's behavior on known edge cases or transactions involving sensitive data, which might be missed by a purely random statistical sample.

  7. Question 7

    A manufacturing company uses an AI model to predict machinery failure. The model is highly accurate but is a complex 'black box' ensemble of deep learning networks, making its predictions difficult to interpret. This lack of explainability poses the GREATEST challenge to which of the following operational processes?

    Answer and explanation

    Correct answer: B

    If the model predicts a failure but cannot explain why (e.g., which sensor reading or combination of factors led to the prediction), it is extremely difficult for maintenance engineers to perform targeted diagnostics and root cause analysis. They know the machine is likely to fail, but they don't know which component is the problem. This lack of insight hinders proactive repair and learning from potential failures.

  8. Question 8

    An e-commerce company is developing an AI-powered dynamic pricing engine. The AI governance committee is establishing key risk indicators (KRIs) for the system. Which of the following would be the MOST effective KRI for monitoring potential non-compliance with anti-price discrimination regulations?

    Answer and explanation

    Correct answer: D

    A key risk indicator must be a measurable metric that provides an early warning of increasing risk. Measuring the statistical variance in pricing across defined demographic segments (e.g., based on geography, inferred income, etc.) directly targets the risk of price discrimination. A rising variance would trigger an investigation, making it the most effective KRI for this specific risk.

  9. Question 9

    A hospital is implementing an AI system to triage emergency room patients based on initial symptom data. According to the EU AI Act, this system would likely be classified as 'high-risk'. What is the PRIMARY implication of this classification for the audit scope?

    Answer and explanation

    Correct answer: C

    The 'high-risk' classification under the EU AI Act mandates a comprehensive set of obligations. The audit scope must therefore be significantly expanded to include conformity assessments against these legal requirements, which cover the entire lifecycle of the AI system, including the quality of training data, technical documentation, transparency for users, human oversight mechanisms, and a robust risk management system.

  10. Question 10

    An auditor is reviewing the MLOps pipeline for a critical AI model. The process is depicted below. The auditor's primary concern is ensuring model integrity and reproducibility. Which stage in this pipeline is MOST critical for achieving this objective?

    flowchart LR A[Data Ingestion] --> B{Feature Engineering} B --> C[Model Training] C --> D(Model Evaluation) D --> E{Model Registry} E --> F[Deployment]
    Answer and explanation

    Correct answer: D

    The Model Registry is the central component for ensuring integrity and reproducibility. It should version and store not just the trained model artifact, but also the code used for training, the version of the data it was trained on, its evaluation metrics, and its dependencies. This allows an auditor or data scientist to precisely recreate the model and its training environment, which is the essence of reproducibility.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 262 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon