A risk practitioner assesses a new AI system and determines that the risk is within the organization's risk tolerance. Which of the following is the BEST recommendation to ensure system controls remain effective over time?
Even when an AI system is initially assessed as within risk tolerance, its risk profile evolves as the system encounters new data, the operational environment changes, and model performance drifts. Controls that were effective at deployment may become insufficient as these changes accumulate.
Why C is Correct: The ISACA AAIR operational monitoring guidance identifies continuous monitoring for data and performance drift as the most important mechanism for maintaining control effectiveness over time. Drift detection provides early warning when the AI system begins behaving differently from its validated state---enabling timely control adjustments before risk tolerance is breached. This is particularly critical because AI systems can degrade gradually in ways not visible without active monitoring.
Why A is Wrong: Framework alignment establishes the control baseline but does not actively verify that controls remain effective as the system evolves. Frameworks provide structure; monitoring provides assurance.
Why B is Wrong: Security and risk awareness training is an important human capability development activity but does not detect technical changes in AI system behavior. Training does not substitute for technical monitoring.
Why D is Wrong: Periodic compliance reviews occur at scheduled intervals and may miss drift that develops between review cycles. Continuous monitoring provides real-time detection that periodic reviews cannot match.
Floyd
1 day agoTyra
6 days agoGertude
11 days agoLamonica
17 days agoRose
22 days agoKandis
27 days agoCyril
1 month agoMaile
1 month agoKindra
1 month ago