After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI. Which of the following would be the BEST justification for the organization to decide not to comply?
The AAISM framework clarifies that compliance decisions must always be tied to an organization's risk appetite and tolerance. When new regulations emerge, management may choose not to comply if the associated risk remains within the documented and approved risk appetite, provided that accountability is established and governance structures support this decision. Other options such as widespread industry use, third-party audits, or lack of cost assessment do not justify noncompliance under the governance principles. The risk appetite framework is the only recognized justification under AI governance principles.
AAISM Study Guide -- AI Governance and Program Management
ISACA AI Risk Guidance -- Risk Appetite and Compliance Decisions
Alonso
22 days agoCarman
27 days agoAdria
2 months agoTashia
2 months agoLawrence
2 months agoJolene
2 months agoJacinta
2 months agoIvette
2 months agoKarl
3 months agoBrittni
3 months agoNicholle
3 months agoGabriele
3 months agoKaycee
3 months agoEun
3 months agoNickie
4 months agoMichael
4 months agoReta
4 months agoRaelene
5 months agoKristeen
5 months agoCatrice
5 months agoCarman
5 months agoJanine
5 months agoPearly
6 months agoJosephine
6 months agoDannie
6 months agoElliot
6 months agoErnest
11 days agoLavina
17 days agoKris
4 months agoEmogene
4 months ago