Scenario:
An organization wants to leverage its existing compliance structures to identify AI-specific risks as part of an ongoing data governance audit.
Which of the following compliance-related controls within an organization ismost easily adaptedto identify AI risks?
The correct answer isD -- Privacy impact assessments (PIAs). These aredirectly adaptablefor identifying risks in AI systems, particularly around data usage, bias, and individual impacts.
From the AIGP ILT Guide -- Risk Management Module:
''PIAs and DPIAs are existing tools used in privacy compliance that can be extended to evaluate the risks of AI, including fairness, explainability, and legality.''
AI Governance in Practice Report 2025 further explains:
''Organizations can adapt privacy impact assessments to evaluate the ethical, legal, and technical risks posed by AI systems. They provide a structured and recognized method.''
PIAs are preferable over general security practices (like pen testing) which do not address algorithmic bias or legal compliance directly.
===========
Whitley
4 days agoLevi
9 days agoMariko
14 days agoDelmy
20 days ago