A Chief Risk Officer is implementing an AI governance structure. She proposes that AI risk oversight be embedded within the existing Three Lines of Defense model. How should AI risk oversight MOST appropriately map to this model?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the Three Lines of Defense maps naturally to AI governance: first-line business units own and manage their AI systems day-to-day; the second-line risk function establishes AI risk frameworks, policies, and independent oversight; and internal audit (third line) independently assesses the effectiveness of AI controls. Centralizing in the second line (A) removes day-to-day accountability from business units.
Full explanation below image
Full Explanation
B is correct because the Three Lines of Defense maps naturally to AI governance: first-line business units own and manage their AI systems day-to-day; the second-line risk function establishes AI risk frameworks, policies, and independent oversight; and internal audit (third line) independently assesses the effectiveness of AI controls. Centralizing in the second line (A) removes day-to-day accountability from business units. Continuous monitoring by internal audit (C) would compromise audit independence. A separate fourth line (D) is not a recognized governance structure and would create confusion about accountability.