An AI oversight committee classifies three activities: (1) establishing enterprise-wide AI policies and accountability structures; (2) ensuring models meet SR 11-7 requirements for independent validation; (3) identifying and mitigating potential harms from model failures. Which answer correctly maps each activity to its discipline?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Think of it this way: in real-world AI governance, activity 1 is governance; activity 2 is compliance; activity 3 is risk management is exactly what teams reach for when they need to handle this scenario. Governance = enterprise AI policies and accountability; compliance = adherence to specific regulations like SR 11-7; risk management = identifying and mitigating potential model harms. On the exam, remember that this falls squarely under the 1.0 AI Governance Overview domain.
Full explanation below image
Full Explanation
Governance = enterprise AI policies and accountability; compliance = adherence to specific regulations like SR 11-7; risk management = identifying and mitigating potential model harms. These are distinct but interrelated disciplines. The correct answer, "Activity 1 is governance; Activity 2 is compliance; Activity 3 is risk management", directly addresses the scenario described because it aligns with the specific governance requirement in question. The incorrect options ("All three are AI risk management because each activity controls potential negative outcomes from AI systems", "Activity 1 is compliance; Activity 2 is governance; Activity 3 is risk management", "Activities 1 and 3 are governance; Activity 2 is risk management because it involves independent model review") may seem plausible but do not satisfy the core requirement. Understanding the distinction between these concepts is critical for IBM watsonx.governance implementations and is frequently tested in the 1.0 AI Governance Overview section of the certification exam.