A Chief Risk Officer is concerned that AI models are being deployed without adequate documentation of their limitations. Which policy control MOST directly addresses this concern?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because requiring model cards or model documentation sheets with known limitations, failure modes, and out-of-scope use cases directly ensures that model limitations are documented and communicated before deployment. This creates a structured artifact that can be reviewed by risk, compliance, and operations teams.
Full explanation below image
Full Explanation
B is correct because requiring model cards or model documentation sheets with known limitations, failure modes, and out-of-scope use cases directly ensures that model limitations are documented and communicated before deployment. This creates a structured artifact that can be reviewed by risk, compliance, and operations teams. Accuracy thresholds (A) measure performance but do not address documentation of limitations. Limiting model count (C) is a portfolio management control. Ethics training (D) builds developer capability but does not ensure that any specific documentation is produced for each model.