nerdexam
PECB

ISO-IEC-42001-LEAD-AUDITOR · Question #42

ReePharm, a pharmaceutical company, has decided to incorporate its AI risk management into the information security management system (ISMS) to identify and address risks related to the procurement…

The correct answer is A. Yes, integrating AI risk management into other management systems is acceptable. ISO/IEC 42001 Clause 6.1 supports integration of AI-specific risk management into broader management systems, provided that AI-specific risks are addressed appropriately. Integration is allowed to improve efficiency without compromising the focus on AI risks.

AIMS Risk Management

Question

ReePharm, a pharmaceutical company, has decided to incorporate its AI risk management into the information security management system (ISMS) to identify and address risks related to the procurement, manufacturing, and distribution of pharmaceutical products. Is this decision appropriate?

Options

  • AYes, integrating AI risk management into other management systems is acceptable
  • BNo, merging AI risk management directly into the ISMS system creates unnecessary complexity
  • CNo, integrating AI risk management into other management systems would not meet ISO/IEC
  • DYes, but only if performed after a surveillance audit

How the community answered

(45 responses)
  • A
    80% (36)
  • B
    2% (1)
  • C
    11% (5)
  • D
    7% (3)

Explanation

ISO/IEC 42001 Clause 6.1 supports integration of AI-specific risk management into broader management systems, provided that AI-specific risks are addressed appropriately. Integration is allowed to improve efficiency without compromising the focus on AI risks.

Topics

#AI risk integration#ISMS integration#management system integration#ISO/IEC 42001

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-42001-LEAD-AUDITOR Practice