QuestionQ91

AI Governance and Risk

Which of the following is MOST important for an IS auditor to consider when identifying AI risk in a know-your-customer (KYC) application at a banking organization?

Explanation

AI risk is assessed in terms of the likelihood and magnitude of adverse consequences. In a banking KYC application, the most material consideration is the potential business disruption and financial impact arising from erroneous, unavailable, or compromised AI-supported KYC processing. An incident-response plan is a mitigating control, while peer benchmarking and intellectual-property concerns do not most directly establish the application’s business risk exposure.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!