A CISO asks the AI risk team to assess the risks of using a third-party AI vendor for employee performance evaluation. Which due diligence element is MOST critical from an AI risk perspective?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because third-party AI vendor risk management requires the ability to independently assess the AI system's accuracy, bias, validation status, and control environment. Without audit rights and access to performance documentation, the organization cannot fulfill its own obligations as the deployer of the AI system.
Full explanation below image
Full Explanation
B is correct because third-party AI vendor risk management requires the ability to independently assess the AI system's accuracy, bias, validation status, and control environment. Without audit rights and access to performance documentation, the organization cannot fulfill its own obligations as the deployer of the AI system. Financial stability (A) is relevant to vendor risk but is not AI-specific. Data center location (C) is a data residency concern. Benchmark performance claims (D) are marketing materials and do not substitute for independent validation.