QuestionQ12

AI Risk Governance and Framework Integration

An organization intends to deploy a generative AI system that processes sensitive personal data in multiple countries with differing privacy laws. Which option is the BEST course of action for managing legal and regulatory exposure?

Explanation

Legal and regulatory risk is best managed through jurisdiction-specific organizational controls aligned with applicable statutory requirements, together with retained audit evidence demonstrating compliance. For example, the GDPR accountability principle requires controllers to be responsible for, and able to demonstrate, compliance, supported by appropriate technical and organizational measures.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!