Within the ISACA Advanced in AI Risk framework, program management connects risk identification, control selection, treatment, monitoring, resilience, third-party oversight, and reporting to enterprise risk objectives. AI-specific contract clauses should clearly allocate liability and responsibilities for breaches affecting models, data, and services. Baseline frameworks and anonymization duties may be included, but enforceable accountability is the key reason for risk-based contracting. This makes option A, Assignment of liability for breaches impacting models and training data, the strongest answer. The other choices describe narrower technical, operational, performance, or administrative considerations and do not address the primary risk-management objective in the scenario as directly. A risk practitioner should select the response that most effectively reduces the stated exposure while preserving appropriate oversight, traceability, and alignment with organizational risk tolerance and business requirements.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit