ISO-IEC-42001-LEAD-AUDITOR · Question #42
ReePharm, a pharmaceutical company, has decided to incorporate its AI risk management into the information security management system (ISMS) to identify and address risks related to the procurement…
The correct answer is A. Yes, integrating AI risk management into other management systems is acceptable. ISO/IEC 42001 Clause 6.1 supports integration of AI-specific risk management into broader management systems, provided that AI-specific risks are addressed appropriately. Integration is allowed to improve efficiency without compromising the focus on AI risks.
Question
ReePharm, a pharmaceutical company, has decided to incorporate its AI risk management into the information security management system (ISMS) to identify and address risks related to the procurement, manufacturing, and distribution of pharmaceutical products. Is this decision appropriate?
Options
- AYes, integrating AI risk management into other management systems is acceptable
- BNo, merging AI risk management directly into the ISMS system creates unnecessary complexity
- CNo, integrating AI risk management into other management systems would not meet ISO/IEC
- DYes, but only if performed after a surveillance audit
How the community answered
(45 responses)- A80% (36)
- B2% (1)
- C11% (5)
- D7% (3)
Explanation
ISO/IEC 42001 Clause 6.1 supports integration of AI-specific risk management into broader management systems, provided that AI-specific risks are addressed appropriately. Integration is allowed to improve efficiency without compromising the focus on AI risks.
Topics
Community Discussion
No community discussion yet for this question.