Your SOC analyst uses an AI assistant to summarize phishing email alerts. Management asks how you can prove, months later, what influenced the final triage decision. Which AI governance practice best supports accountability?
Select an answer to reveal the explanation.
Short Explanation
Think of AI triage like a junior analyst with a very fast memory but no badge. You need to know what it saw, which model version answered, and whether you overrode it. If you only record confidence scores, you're trusting the answer instead of proving the chain of custody.
Full Explanation
Accountability for AI-assisted security decisions depends on a durable audit trail that ties the recommendation to its inputs and the human decision. Logging the prompt, model version, data sources, and analyst overrides lets the SOC reconstruct why the AI produced a specific output and whether the analyst accepted, modified, or rejected it. This supports review, dispute resolution, model drift detection, and governance. Requiring confidence scores and plain-language rationale can improve transparency, but it does not prove what data was supplied, which model version generated the recommendation, or how the analyst acted on it. Retaining raw telemetry for replay is useful for investigations and reproducibility, yet it does not by itself link AI prompts, model changes, and analyst overrides to a final triage decision. Restricting AI-assisted triage to high-confidence alerts may reduce noise, but it is a control on usage, not an audit mechanism that preserves evidence of AI influence. Exam caveat: AI governance questions often test auditability rather than model accuracy or explainability. Operational check: sample ten AI-assisted alerts and confirm you can identify the prompt, model version, referenced data sources, and analyst override record.