
ISACAAdvanced in AI Risk
Domain 3Objective 5
AI Supply Chain Risk Management (e.g., Third Party Resources) AAIR Practice Questions (Page 5)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
36questions here
8free pages
10concepts
42%of the exam
Questions 21–25
- 21
A healthcare organization uses a third-party AI diagnostic tool. The vendor's service level agreement (SLA) guarantees 99.9% uptime but does not specify how the vendor handles data breaches or how the organization can verify the vendor's security controls. The organization wants to strengthen its contractual risk controls. Which addition to the contract is most critical?
Select an answer first - 22
A company is considering using a third-party AI model for hiring decisions. The vendor's documentation indicates that the model was trained on data from a specific geographic region. The company operates globally and is concerned about compliance with local employment laws. What is the most important risk to assess?
Select an answer first - 23
Which of the following is an example of an industry standard that may apply to third-party AI resources?
Select an answer first - 24
A government agency is adopting an AI system that uses a third-party model and a cloud infrastructure vendor. The agency must ensure that the AI system is trustworthy and that risks across the entire supply chain are managed. Which framework is most appropriate for the agency to apply?
Select an answer first - 25
Which entity in the AI supply chain is primarily responsible for providing the computational resources needed to train large AI models?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.