AAIA Practice Questions
Prepare for AAIA with more than an answer.
- Time limit
- 150 minutes
- Questions on the exam
- 90
- Passing score
- 450 (scale 200-800)
- Level
- Advanced
- Valid for
- Continuous with CPE requirements
Domains covered on the exam 3
- AI Governance and Risk33%
- AI Operations46%
- AI Auditing Tools and Techniques21%
- 1
True or False: A well-designed 'human-in-the-loop' (HITL) system for an AI model eliminates the risk of accountability issues because a human makes the final decision.
Show answer details
Correct answer: B
This statement is false. While HITL is a crucial control, it does not eliminate accountability issues. Humans can suffer from 'automation bias,' where they overly trust the AI's recommendation and approve it without proper scrutiny. This can lead to a diffusion of responsibility, where it's unclear whether the AI or the human is accountable for a bad outcome. Therefore, HITL mitigates but does not eliminate accountability risk.
- 2
An audit team is leveraging a process mining tool to analyze the accounts payable process. The tool uses AI to automatically discover process variations and control weaknesses from system event logs. This use of AI primarily enhances which phase of the audit?
Show answer details
Correct answer: A
Process mining directly analyzes vast amounts of data (event logs) to provide objective evidence about how processes actually operate, including deviations from the designed workflow. This allows auditors to test controls on the entire population of transactions and gather strong evidence of control effectiveness or failures. It is a powerful tool for the evidence collection and testing phase.
- 3
An auditor is evaluating the data management practices for a company's AI development. They discover that data scientists frequently use production customer data in their development environments to prototype new models. What is the MOST effective control to mitigate the associated risks?
Show answer details
Correct answer: B
The most effective control is to eliminate the need to use raw production data in non-production environments. By establishing a process to provide data scientists with high-quality, statistically representative data that has been properly anonymized, masked, or synthetically generated, the organization can mitigate privacy and security risks while still enabling effective model development.
- 4
When presenting AI audit findings to the board of directors, which of the following is the MOST important principle for the auditor to follow?
Show answer details
Correct answer: D
The board's primary responsibility is governance and strategic oversight. To be effective, audit findings must be communicated in the language of business risk. The auditor should explain how a technical issue (e.g., model bias) could lead to tangible business consequences (e.g., lawsuits, fines, customer churn, or reputational damage).
- 5
An organization's AI ethics committee has drafted a set of principles, including 'fairness', 'accountability', and 'transparency'. From an audit perspective, what is the MOST significant challenge in evaluating the implementation of these principles?
Show answer details
Correct answer: B
The greatest challenge for an auditor is that ethical principles are abstract. To audit them, they must be translated into specific, testable control objectives. For example, 'fairness' must be defined with specific metrics (e.g., demographic parity, equalized odds), and 'transparency' must be linked to concrete deliverables like model cards or explainability reports. Without this operationalization, the principles are not auditable.
- 6
A financial services firm has implemented an AI model for algorithmic trading. During an audit, it is discovered that the model's decision logic is stored as a configuration file in a code repository with open write access for all developers. Which of the following is the MOST critical risk this practice introduces?
Show answer details
Correct answer: A
The most critical risk is the potential for unauthorized and malicious changes to the trading algorithm's logic. Given the direct financial implications of an algorithmic trading model, an undetected modification could trigger erroneous trades, leading to immediate and substantial financial losses. This represents a direct and high-impact operational risk.
- 7
An auditor is evaluating the fairness of a loan approval AI system. The testing reveals that the model has a disproportionately higher false negative rate for applicants from a specific demographic group, even though protected attributes were excluded from the training data. What is the MOST likely cause of this bias?
Show answer details
Correct answer: B
Even when protected attributes like race or gender are removed, other features (proxies) can be highly correlated with them. For example, ZIP codes, income levels, or certain types of employment can inadvertently act as proxies for demographic groups, allowing the model to learn and perpetuate historical biases present in the data.
- 8
An organization is using a third-party, cloud-based AI service for sentiment analysis of customer feedback. Which of the following audit procedures is MOST crucial for assessing data privacy risks? (Select TWO)
Show answer details
Correct answer: A, D
The data processing agreement (DPA) and terms of service are legally binding documents that outline how the vendor will handle the organization's data, including data ownership, usage rights, security controls, and compliance with privacy regulations like GDPR. This is a primary source of evidence for assessing privacy risk.
A crucial internal control to mitigate third-party privacy risk is to minimize the data shared. Verifying that the organization has a process to scrub PII before sending data to the vendor's service directly reduces the risk of a data breach or misuse of customer PII by the third party.
- 9
During an audit of an AI system's incident response plan, an auditor notes that the plan is identical to the organization's traditional IT incident response plan. What is the MOST significant gap in this approach?
Show answer details
Correct answer: A
AI systems introduce unique failure modes not found in traditional IT systems. These include model drift, performance degradation, generation of harmful or biased outputs, and adversarial attacks. An effective incident response plan must include specific playbooks for identifying, containing (e.g., taking the model offline, reverting to a previous version), and remediating these AI-specific incidents.
- 10
When planning an audit of a newly deployed generative AI chatbot for customer service, what should be the auditor's PRIMARY focus?
Show answer details
Correct answer: A
According to standard audit practices, the first step in planning any audit is to understand the context: what the system is supposed to achieve (business objectives) and what could go wrong (high-level risks). For a generative AI chatbot, risks include reputational damage from inappropriate responses, data leakage, and inaccurate information. This understanding drives the entire audit scope and approach.
