A county CIO office has designed a low, medium, and high risk classification framework for AI use cases to determine which ones require governance board review. A department head argues every AI system, regardless of tier, should go through the same full review process to be safe. How should the CIO office respond?
Select an answer to reveal the explanation.
Short Explanation
Think about airport security: everyone gets some level of screening, but a routine domestic commuter and a passenger flagged for additional questions don't go through an identical process, resources get focused where risk is highest. A county's AI systems work the same way, tying review intensity to a risk tier means the governance board spends its scrutiny where it actually matters instead of spreading it evenly thin.
Full Explanation
Tying governance review intensity to a use case's assessed risk tier lets the governance board concentrate its scrutiny on systems most likely to cause serious harm, like an eligibility-determination tool, while moving lower-risk systems, like an internal scheduling aid, through a lighter process, which is a more effective use of limited review capacity than treating every system identically. Eliminating the risk-tier framework in favor of uniform full review for everything sounds cautious but actually dilutes attention, since board members reviewing routine low-risk tools with the same depth as high-risk ones have less bandwidth left for the systems that most need careful scrutiny. Applying full review only to externally procured systems while exempting internally built ones assumes risk correlates with where a system was built rather than with what it does, which is the wrong axis entirely, an internally built tool making consequential decisions about residents carries the same risk regardless of who coded it. Keeping the tiered framework on paper while informally requiring full review for everything anyway creates a governance framework that doesn't match actual practice, undermining the documented process's credibility and creating confusion about what departments can actually expect. A scope caveat: risk tiers should be periodically reassessed, since a system's actual risk profile can shift as its use case or scale changes after initial classification. A concrete check: audit a sample of recently classified use cases to confirm their assigned tier matches the review depth they actually received.