A project lead is turning a proof of concept into a governed production workflow. The team is focused on regulatory alignment. Which recommendation is most appropriate?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Regulatory alignment is like international shipping—you can't use one checklist for every country! Map your governance activities to actual laws, industry standards, and company policies that apply to your context. Know the rules, design controls to fit them, prove compliance. Alignment wins audits!
Full explanation below image
Full Explanation
The correct answer is D. Mapping governance activities to relevant laws (GDPR, AI Act, sector regulations), industry standards (ISO, NIST), and organizational policies ensures the governance framework is aligned with actual requirements and evidence supports compliance claims. Option A is risky; regulatory requirements vary by geography and industry—a one-size-fits-all approach invites non-compliance. Option B is backwards; building evidence during deployment is too late—controls and evidence capture must start early in the lifecycle to demonstrate compliance. Option C is self-defeating; documentation is the proof that governance happened; removing it destroys evidence and invites regulatory penalties. IBM watsonx.governance requires explicit mapping of controls to regulatory requirements so the organization can confidently claim compliance and provide evidence on demand.