✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: AI Risk Governance and Framework Integration
A financial services company is deploying a credit scoring AI system that processes applications from customers across multiple European countries. The Chief Risk Officer wants to ensure the AI governance framework addresses both EU AI Act requirements and financial regulatory obligations. Which approach BEST establrates a comprehensive governance structure?
Financial AI systems under the EU AI Act are typically classified as high-risk, requiring integrated governance that addresses both AI-specific risks and sector-specific regulations. A tiered approach with dual oversight ensures both technical AI risks and financial regulatory requirements (like fair lending, transparency) are addressed in an integrated manner, avoiding gaps that separate governance tracks create.
Question 2 of 12 · Domain 2: AI Life Cycle Risk Management
A healthcare AI company is deploying a diagnostic imaging model that was trained on data from 15 hospitals in North America. During pre-deployment validation, the model shows 94% accuracy on the training dataset but only 78% accuracy on a test dataset from hospitals in Southeast Asia. What is the MOST appropriate first step to address this issue before deployment?
The performance drop indicates distribution shift and potential demographic bias in the training data. AAIR principles require ensuring training data is representative of deployment populations. Collecting data from target regions addresses the root cause of the bias before deployment.
Question 3 of 12 · Domain 3: AI Risk Program Management
A financial services company is deploying an AI-powered loan approval system that will process applications across multiple jurisdictions with different regulatory requirements. The AI Risk Manager needs to establish a framework for ongoing monitoring of the system's fairness metrics across protected classes. Which approach BEST balances regulatory compliance with operational efficiency?
Continuous automated monitoring with the 4/5ths rule (0.8-1.25 range) aligns with regulatory guidance like the EEOC's Uniform Guidelines on Employee Selection Procedures and allows for timely intervention. Monthly cross-functional reviews ensure business context is applied to metrics while maintaining operational efficiency.
Question 4 of 12 · Domain 1: AI Risk Governance and Framework Integration
An organization has implemented an AI system for resume screening that was recently flagged by internal audit as potentially exhibiting bias against certain demographic groups. The AI governance board needs to determine the appropriate risk classification under their framework. The system processes 500 applications per week, makes initial filtering recommendations that HR reviews before final decisions, and has shown a 12% disparity rate in pass-through rates. How should this system be classified?
Under frameworks like the EU AI Act, AI systems used for employment, worker management, and access to self-employment are explicitly classified as high-risk systems (Annex III). This classification is based on the application domain (employment) and potential for significant impact on individuals' rights and opportunities, not on whether humans are in the loop or the measured disparity rate.
Question 5 of 12 · Domain 2: AI Life Cycle Risk Management
A financial services company is deploying a credit scoring AI model that was trained on historical loan data from 2015-2020. During pre-deployment validation, the data science team discovers that the model's performance has degraded by 15% on recent 2025-2026 application data, particularly for applicants in emerging gig economy professions. Which risk management approach BEST addresses this issue?
This addresses model drift (concept drift specifically) through continuous monitoring and retraining—a core AI lifecycle risk management practice. The performance degradation indicates the model's assumptions no longer match current data distributions, requiring both monitoring infrastructure and training data updates to maintain model validity over time.
Question 6 of 12 · Domain 3: AI Risk Program Management
An AI governance committee is establishing risk tolerance levels for a healthcare diagnostic AI system. The system will provide decision support to radiologists for detecting early-stage lung cancer. Which risk appetite statement BEST reflects appropriate governance for this high-stakes application?
Healthcare diagnostic AI should meet or exceed human expert performance while maintaining human oversight for critical decisions. Requiring human-in-the-loop for positive findings balances sensitivity with specificity and aligns with medical device AI regulatory expectations for clinical decision support systems.
Question 7 of 12 · Domain 1: AI Risk Governance and Framework Integration
A healthcare AI startup is selecting a primary AI risk management framework for their diagnostic imaging AI system that will be marketed in the US, EU, and Asia-Pacific regions. The system uses deep learning to identify potential cancerous lesions and is classified as a medical device. Which framework selection strategy provides the MOST comprehensive coverage for their multi-jurisdictional deployment?
Medical AI devices must first comply with medical device regulations (ISO 13485 is the international standard), then layer AI-specific risk management (NIST AI RMF provides comprehensive AI risk coverage). This approach addresses the primary regulatory classification (medical device) while adding AI-specific controls, with jurisdiction-specific requirements (FDA, EU MDR, TGA) mapped as overlays maintaining a coherent core framework.
Question 8 of 12 · Domain 2: AI Life Cycle Risk Management
An AI governance team is establishing a model registry for their organization's 40+ production AI models. The registry must track model lineage, version history, performance metrics, and approval status. Which component is MOST critical to include for effective AI lifecycle risk management?
Data provenance is fundamental to AI lifecycle risk management because it enables reproducibility, bias detection, drift analysis, and regulatory compliance. Understanding what data was used to train a model is essential for investigating issues, retraining models correctly, and meeting audit requirements under AI regulations.
Question 9 of 12 · Domain 3: AI Risk Program Management
A multinational corporation is implementing an AI risk management program across 15 countries. The Chief AI Risk Officer needs to establish a governance structure that addresses varying regulatory requirements while maintaining consistent core standards. Which governance model BEST achieves this objective?
A federated governance model establishes consistent core risk management practices (assessment frameworks, governance processes, incident protocols) while allowing necessary flexibility for regional regulatory variations like GDPR in EU, AI Act requirements, or sector-specific rules. This balances standardization with compliance.
Question 10 of 12 · Domain 1: AI Risk Governance and Framework Integration
A company's AI governance framework requires risk assessments at multiple stages of the AI lifecycle. During a model update that improves accuracy from 94% to 96%, the ML team wants to deploy without a full re-assessment since 'the model only got better.' The existing governance policy states: 'Material changes to AI systems require risk re-assessment.' Which action BEST aligns with robust AI risk governance principles?
Aggregate accuracy improvements can mask important changes in model behavior: decision boundaries may shift affecting different subpopulations differently, the model may achieve higher accuracy by being more confident in wrong predictions in edge cases, or fairness metrics may degrade even as overall accuracy improves. Material model changes require full re-assessment to evaluate these multidimensional risk factors, not just accuracy.
Question 11 of 12 · Domain 2: AI Life Cycle Risk Management
A healthcare AI system used for predicting patient readmission risk is being updated from version 2.1 to version 3.0. Version 3.0 uses a transformer-based architecture instead of the previous gradient boosting model, improving accuracy from 82% to 89% on the test set. Before deploying version 3.0 to replace version 2.1 in production, which validation step is MOST important from a lifecycle risk management perspective?
When changing model architectures (especially to more complex models like transformers), adversarial testing and edge case analysis are critical because different architectures can fail in different ways despite better aggregate metrics. Higher accuracy doesn't guarantee the model won't make catastrophic errors in specific clinical scenarios—a key risk in healthcare applications.
Question 12 of 12 · Domain 3: AI Risk Program Management
An organization's AI system caused a significant privacy breach affecting 50,000 customers due to a training data contamination issue. The AI Risk Manager is developing the incident response report. According to AI risk management best practices, which element is MOST critical to include in the root cause analysis?
Effective incident response focuses on identifying control failures (where did data governance break down), root causes (why did controls fail), and corrective actions (how to prevent recurrence). This approach addresses the systemic issue rather than just the technical symptom.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
$109.99$34.99 with code FREETEST33 — valid through August 23.
The exam fee is approximately $575 and varies by region — confirm current pricing with the certification vendor before you book.
What topics are on the exam?
It covers 3 domains: AI Risk Governance and Framework Integration (37%), AI Life Cycle Risk Management (21%), AI Risk Program Management (42%). The full course has a dedicated chapter, lab and practice-test coverage for each.
Is this practice test really free?
Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.
How do I get the discount?
Use code FREETEST33 at checkout for $34.99 (list $109.99) through August 23 — the enroll button applies it automatically.
Will this prepare me for the real exam?
The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.