A project lead is turning a proof of concept into a governed production workflow. The team is focused on risk classification. Which recommendation is most appropriate?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Think of risk classification like building codes—a small storage shed has different rules than a hospital. Impact, regulatory requirements, data sensitivity, how automated the decisions are, and who's affected all matter. Using all these factors together gives you the real risk picture, not shortcuts that miss the tough cases!
Full explanation below image
Full Explanation
The correct answer is b. Comprehensive risk classification requires evaluating multiple dimensions: business impact (revenue loss, reputational harm), regulatory exposure (GDPR, industry standards), data characteristics (personally identifiable information, sensitive attributes), automation level (how autonomous the AI decision is), and user population scope (internal vs. external, privileged vs. vulnerable groups). These factors combined determine the actual governance controls needed. Option a (team size) is irrelevant to AI risk. Option c (all internal tools are low risk) is dangerously false—internal tools handling protected data or making critical decisions are often high-risk. Option d (vendor popularity) has no correlation to governance requirements. IBM watsonx.governance demands multi-dimensional risk assessment.