nerdexam
Isaca

AAISM · Question #211

After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI. Which of the following would be the BEST justification for the…

The correct answer is C. The risk is within the organization's risk appetite. The AAISM framework clarifies that compliance decisions must always be tied to an organization's risk appetite and tolerance. When new regulations emerge, management may choose not to comply if the associated risk remains within the documented and approved risk appetite…

AI Security Risk Management

Question

After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI. Which of the following would be the BEST justification for the organization to decide not to comply?

Options

  • AThe AI tool is widely used within the industry
  • BThe AI tool is regularly audited
  • CThe risk is within the organization's risk appetite
  • DThe cost of noncompliance was not determined

How the community answered

(41 responses)
  • A
    2% (1)
  • B
    15% (6)
  • C
    78% (32)
  • D
    5% (2)

Explanation

The AAISM framework clarifies that compliance decisions must always be tied to an organization's risk appetite and tolerance. When new regulations emerge, management may choose not to comply if the associated risk remains within the documented and approved risk appetite, provided that accountability is established and governance structures support this decision. Other options such as widespread industry use, third-party audits, or lack of cost assessment do not justify noncompliance under the governance principles. The risk appetite framework is the only recognized justification under AI governance principles.

Topics

#Risk appetite#Regulatory compliance#Risk acceptance#AI risk management

Community Discussion

No community discussion yet for this question.

Full AAISM Practice