
ISACAAdvanced in AI Risk
Domain 3Objective 5
AI Supply Chain Risk Management (e.g., Third Party Resources) AAIR Practice Questions (Page 6)
Part of the AI Risk Program Management domain, which accounts for 42% of the AAIR exam.
36questions here
8free pages
10concepts
42%of the exam
Questions 26–30
- 26
What does data provenance refer to in the context of AI supply chains?
Select an answer first - 27
A manufacturing company uses a third-party AI model for predictive maintenance. The vendor has been reliable, but the company wants to ensure that any future issues are detected early. The contract includes audit rights and a data protection clause. What should the company implement to manage ongoing third-party risk?
Select an answer first - 28
A retail company uses a third-party AI model for demand forecasting. The model's training data includes customer purchase history, but the company cannot determine where the data originated or whether it was legally obtained. The company is subject to data protection regulations. What is the most effective way to address this risk?
Select an answer first - 29
What is the primary purpose of an incident response plan for AI supply chain failures?
Select an answer first - 30
Which contractual provision allows an organization to verify a vendor's compliance with security and privacy requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “AAIR” is a trademark of its owner, used for identification only.