An AI audit program is being developed for a large bank. Which sequence of activities represents the CORRECT logical order for conducting an AI model audit?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a structured AI audit follows: scope definition (establish what is being audited and why), risk tier assessment (calibrate depth of testing), documentation and validation record review (establish baseline), performance testing (validate claims against evidence), control evaluation (assess governance and operational controls), and reporting. Starting with performance testing (A) or reporting (C) without scope and documentation review is inefficient and may miss key risks.
Full explanation below image
Full Explanation
B is correct because a structured AI audit follows: scope definition (establish what is being audited and why), risk tier assessment (calibrate depth of testing), documentation and validation record review (establish baseline), performance testing (validate claims against evidence), control evaluation (assess governance and operational controls), and reporting. Starting with performance testing (A) or reporting (C) without scope and documentation review is inefficient and may miss key risks. D has an incorrect sequence where control assessment precedes scope definition.