
ISACAAdvanced in AI Risk
Domain 3Objective 5
AI Supply Chain Risk Management (e.g., Third Party Resources) AAIR Practice Questions (Page 3)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
36questions here
8free pages
10concepts
42%of the exam
Questions 11–15
- 11
An online retailer relies on a third-party AI recommendation engine and a cloud provider for hosting. A critical failure in the AI engine causes the website to recommend irrelevant products, leading to a drop in sales. The retailer has no plan for such an event. What should the retailer do first to prepare for future incidents?
Select an answer first - 12
A financial institution is evaluating a third-party AI model for credit scoring. The vendor claims the model is 'bias-free' and provides only a high-level summary of its training data. The institution's compliance team requires evidence that the model does not discriminate against protected groups. Which action best addresses this requirement during due diligence?
Select an answer first - 13
A European company uses a US-based AI vendor that processes personal data of EU citizens. The company must ensure compliance with GDPR when using the vendor's services. What is the most important contractual measure to include?
Select an answer first - 14
What is a key component of managing ongoing third-party AI risks?
Select an answer first - 15
Which contractual element is used to define expected performance levels for an AI service?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.