
ISACAAdvanced in AI Risk
Domain 3Objective 5
AI Supply Chain Risk Management (e.g., Third Party Resources) AAIR Practice Questions (Page 1)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
36questions here
8free pages
10concepts
42%of the exam
Questions 1–5
- 1
A company uses a third-party AI model for real-time fraud detection. The vendor has a history of minor security incidents, but the company has contractual audit rights. The company's risk team wants to implement continuous monitoring, but the operations team is concerned about the overhead. What is the best approach to balance these concerns?
Select an answer first - 2
Which of the following is a key component of an AI supply chain?
Select an answer first - 3
A multinational company uses a third-party AI vendor that processes personal data across multiple jurisdictions, including the EU and countries with less stringent data protection laws. The company must ensure compliance with GDPR and other regulations. What is the most comprehensive approach?
Select an answer first - 4
Which activity is part of ongoing monitoring of third-party AI risks?
Select an answer first - 5
Which framework is specifically designed to help organizations manage AI risks, including those in the AI supply chain?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.