An organization conducts an AI system risk assessment using a heat map that plots likelihood of harm against severity of harm. An AI model for internal employee scheduling scores 'low likelihood, high severity.' How should this risk be managed?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because a low-likelihood, high-severity risk (sometimes called a 'tail risk' or black swan) cannot simply be accepted without controls; the potential severity justifies control measures even at low probability. For an AI scheduling system, a major failure could leave critical operations unstaffed.
Full explanation below image
Full Explanation
B is correct because a low-likelihood, high-severity risk (sometimes called a 'tail risk' or black swan) cannot simply be accepted without controls; the potential severity justifies control measures even at low probability. For an AI scheduling system, a major failure could leave critical operations unstaffed. Appropriate controls include fallback manual scheduling procedures, automated alerts, and regular model health checks. Accepting without controls (A) is inappropriate for high-severity events. Prioritizing solely on severity (C) ignores relative risk ranking; other high-likelihood risks may warrant more immediate attention. Insurance (D) may be appropriate but does not eliminate the need for operational controls.