During a design review, an architect asks which choice best matches the IBM guidance. Which approach best demonstrates risk classification in a IBM Certified watsonx Governance Lifecycle Advisor environment?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Risk classification is like sorting patients in an emergency room — you triage by severity of impact, not by who showed up first or which hospital the ambulance came from. IBM expects you to evaluate real risk drivers: business impact, applicable regulations, data sensitivity, automation level, and the population being affected. Team size tells you nothing about whether a model is making high-stakes lending decisions. Get the classification right, and your governance controls automatically scale to match the actual risk!
Full explanation below image
Full Explanation
The correct answer is B. Classify use cases by impact, regulation, data sensitivity, automation level, and user population. IBM watsonx.governance's approach to risk classification under domain 5.0 requires a multi-dimensional assessment that reflects the true risk profile of each AI use case. Impact measures how significantly errors affect business outcomes or people's lives; regulatory scope determines which legal frameworks apply; data sensitivity captures privacy and confidentiality risk; automation level reflects how much human oversight exists; and user population identifies whether vulnerable groups are affected. Option A is incorrect because team size is entirely unrelated to the risk a model poses — a two-person team can deploy a high-stakes lending model, while a large team may run a low-risk internal search tool. Option C is incorrect because blanket low-risk classification for internal tools bypasses the need to evaluate factors like sensitive employee data or automated HR decisions that could have significant impact. Option D is incorrect because vendor popularity is a marketing attribute, not a governance signal — a popular model vendor does not reduce a use case's regulatory, ethical, or operational risk. IBM's Define and Govern AI Use Case Inventory objective requires classification frameworks that drive proportionate governance responses.