Within the ISACA Advanced in AI Risk framework, life-cycle controls should protect data quality, model design, testing, validation, monitoring, change management, and secure retirement of AI systems. Business processes are most suitable for AI integration when objectives, decisions, and rules are sufficiently defined for the AI tool to operate against clear requirements. Industry popularity, immediate scaling, and staffing reductions do not establish suitability. This makes option D, the process includes clearly defined rules for AI tools to follow, the strongest answer. The other choices describe narrower technical, operational, performance, or administrative considerations and do not address the primary risk-management objective in the scenario as directly. A risk practitioner should select the response that most effectively reduces the stated exposure while preserving appropriate oversight, traceability, and alignment with organizational risk tolerance and business requirements.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit