A model risk team calculates that a loan approval model has an inherent risk score of 85 but a residual risk score of 42 after compensating controls are documented. In the context of watsonx.governance risk assessments, what do these two scores represent?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Think of it this way: in real-world AI governance, inherent risk is the risk before mitigating controls are applied; residual risk is the risk that remains after documented controls reduce the exposure is exactly what teams reach for when they need to handle this scenario. In watsonx. On the exam, remember that this falls squarely under the 2.0 AI Lifecycle Governance domain.
Full explanation below image
Full Explanation
In watsonx.governance model risk assessments, inherent risk quantifies the raw level of risk associated with a model before any mitigating controls or safeguards are considered, reflecting the model's potential impact and complexity in isolation. Residual risk quantifies the remaining risk after documented controls — such as validation procedures, monitoring thresholds, and usage restrictions — have been applied and assessed. The gap between the two scores indicates how effectively the control environment manages the model's raw risk, which informs governance decisions about approval conditions and ongoing monitoring requirements. The correct answer, "Inherent risk is the risk before mitigating controls are applied; residual risk is the risk that remains after documented controls reduce the exposure", directly addresses the scenario described because it aligns with the specific governance requirement in question. The incorrect options ("Inherent risk is the model's in-sample training error rate; residual risk is its out-of-sample production error rate", "Inherent risk reflects data drift severity; residual risk reflects concept drift severity over the monitoring period", "Inherent risk is assessed by the model developer; residual risk is independently assessed by the model validation team") may seem plausible but do not satisfy the core requirement. Understanding the distinction between these concepts is critical for IBM watsonx.governance implementations and is frequently tested in the 2.0 AI Lifecycle Governance section of the certification exam.