After implementing a third-party generative AI tool, an organization learns about new regulations related to how organizations use AI. Which of the following would be the BEST justification for the organization to decide not to comply?
The AAISM framework clarifies that compliance decisions must always be tied to an organization's risk appetite and tolerance. When new regulations emerge, management may choose not to comply if the associated risk remains within the documented and approved risk appetite, provided that accountability is established and governance structures support this decision. Other options such as widespread industry use, third-party audits, or lack of cost assessment do not justify noncompliance under the governance principles. The risk appetite framework is the only recognized justification under AI governance principles.
AAISM Study Guide -- AI Governance and Program Management
ISACA AI Risk Guidance -- Risk Appetite and Compliance Decisions
Adria
10 hours agoTashia
6 days agoLawrence
11 days agoJolene
16 days agoJacinta
21 days agoIvette
26 days agoKarl
1 month agoBrittni
1 month agoNicholle
1 month agoGabriele
2 months agoKaycee
2 months agoEun
2 months agoNickie
2 months agoMichael
3 months agoReta
3 months agoRaelene
3 months agoKristeen
3 months agoCatrice
4 months agoCarman
4 months agoJanine
4 months agoPearly
4 months agoJosephine
4 months agoDannie
4 months agoElliot
5 months agoKris
2 months agoEmogene
2 months ago