A risk officer conducts a vendor assessment for a third-party AI fraud detection system. The vendor claims the model has been independently audited. Which follow-up question is MOST important?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because an independent audit claim is only meaningful if the audit was conducted by a qualified, truly independent party, applied recognized standards (such as ISAE 3000, SR 11-7, or NIST AI RMF), and covered the relevant risk dimensions (performance, fairness, security, data governance). Without the audit report, the claim cannot be assessed.
Full explanation below image
Full Explanation
B is correct because an independent audit claim is only meaningful if the audit was conducted by a qualified, truly independent party, applied recognized standards (such as ISAE 3000, SR 11-7, or NIST AI RMF), and covered the relevant risk dimensions (performance, fairness, security, data governance). Without the audit report, the claim cannot be assessed. Programming language (A) is irrelevant to risk assessment. Other users (C) is a market reference, not a risk control. Fraud cases detected (D) is a vendor marketing metric without statistical context.