QuestionQ145

AI Risk Management

An organization intends to use an external vendor’s AI service for customer-retention analytics. Management is concerned about reliance on a third party and the possibility of unauthorized access to customer data. Which of the following is the BEST approach to mitigate this risk?

Explanation

Vendor contracts should establish explicit data-protection obligations, including security, access, confidentiality, incident-handling, and compliance requirements. Regular monitoring verifies that the external provider continues to meet those obligations and supports ongoing third-party risk management.

Community Discussion

No comments yet. Be the first to start the discussion!