An AI governance architect is aligning the organization's risk management process to a framework organized into four core functions: Govern, Map, Measure, and Manage. Which watsonx.governance Compliance Accelerator supports this four-function structure?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Think of it this way: in real-world AI governance, nist ai rmf which organizes ai risk management into the govern, map, measure, and manage core functions is exactly what teams reach for when they need to handle this scenario. The NIST AI Risk Management Framework (AI RMF) organizes AI risk management activities into four core functions: Govern establishes organizational accountability and culture for AI risk; Map identifies and categorizes AI risks in context; Measure assesses and tracks AI risks using metrics and benchmarks; and Manage implements risk treatments and tracks their effectiveness over time. On the exam, remember that this falls squarely under the 2.0 AI Lifecycle Governance domain.
Full explanation below image
Full Explanation
The NIST AI Risk Management Framework (AI RMF) organizes AI risk management activities into four core functions: Govern establishes organizational accountability and culture for AI risk; Map identifies and categorizes AI risks in context; Measure assesses and tracks AI risks using metrics and benchmarks; and Manage implements risk treatments and tracks their effectiveness over time. The NIST AI RMF Compliance Accelerator in watsonx.governance maps governance activities and questionnaires to these four functions, helping organizations systematically demonstrate alignment with this voluntary US government framework for trustworthy AI. The correct answer, "NIST AI RMF which organizes AI risk management into the Govern, Map, Measure, and Manage core functions", directly addresses the scenario described because it aligns with the specific governance requirement in question. The incorrect options ("EU AI Act which categorizes AI systems into prohibited, high-risk, limited-risk, and minimal-risk tiers based on intended use", "SR 11-7 which addresses model development, validation, and implementation for US financial institution model risk management", "ISO 42001 which provides an AI management system standard organized around a Plan, Do, Check, Act management system cycle") may seem plausible but do not satisfy the core requirement. Understanding the distinction between these concepts is critical for IBM watsonx.governance implementations and is frequently tested in the 2.0 AI Lifecycle Governance section of the certification exam.