AAISM · Question #67
A large financial services organization is integrating a third-party AI solution into its critical fraud detection system. Which of the following is the BEST way for the organization to reduce risk…
The correct answer is C. Establishing contractual agreements requiring vendors to provide evidence of secure development. AAISM emphasizes supplier assurance through contractual obligations as the foundational control for AI supply chain risk. Contracts should require verifiable evidence of secure development practices (e.g., secure SDLC, model and data provenance documentation, SBOM/MBOM where…
Question
A large financial services organization is integrating a third-party AI solution into its critical fraud detection system. Which of the following is the BEST way for the organization to reduce risk associated with AI vendor and supply chain dependencies?
Options
- AConducting annual vulnerability assessments of the fraud detection system after integration
- BFocusing on performance testing to ensure the solution meets operational requirements
- CEstablishing contractual agreements requiring vendors to provide evidence of secure development
- DImplementing isolated virtual environments to validate the integration of the fraud detection
How the community answered
(27 responses)- A4% (1)
- B4% (1)
- C85% (23)
- D7% (2)
Explanation
AAISM emphasizes supplier assurance through contractual obligations as the foundational control for AI supply chain risk. Contracts should require verifiable evidence of secure development practices (e.g., secure SDLC, model and data provenance documentation, SBOM/MBOM where applicable, vulnerability disclosure, patch SLAs, audit rights, incident notification, and regulatory compliance assertions). This creates enforceable, continuous assurance beyond point-in-time tests.
Topics
Community Discussion
No community discussion yet for this question.