
ISACAAdvanced in AI Risk
Domain 3Objective 5
AI Supply Chain Risk Management (e.g., Third Party Resources) AAIR Practice Questions (Page 4)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
36questions here
8free pages
10concepts
42%of the exam
Questions 16–20
- 16
A company is using multiple third-party AI components, including data providers, model developers, and infrastructure vendors. The company wants to establish a consistent approach to managing risks across all these components. Which action is most aligned with the NIST AI RMF?
Select an answer first - 17
When using third-party AI resources, which of the following is a compliance consideration?
Select an answer first - 18
When assessing a third-party AI vendor, which of the following is a potential compliance gap to evaluate?
Select an answer first - 19
A company is adopting an AI system that uses a third-party model and a data provider. The company is subject to ISO/IEC 42001 and must demonstrate compliance. The vendor's security practices are not fully aligned with the standard. What is the most effective approach?
Select an answer first - 20
Which of the following is a risk that can arise from using third-party AI resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.