A financial institution is subject to both the EU AI Act and the Basel AI Risk Principles. A high-risk AI model used in credit risk management must comply with both frameworks. Which control would MOST effectively address requirements under both frameworks simultaneously?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the overlapping requirements of the EU AI Act for high-risk AI (documentation, conformity assessment, human oversight, transparency) and Basel/SR 11-7 principles for model risk (independent validation, explainability, monitoring, governance) converge on a common set of practices: comprehensive documentation, independent validation that includes explainability assessment, ongoing performance monitoring, and human oversight for consequential decisions. These controls satisfy both frameworks' core requirements efficiently.
Full explanation below image
Full Explanation
B is correct because the overlapping requirements of the EU AI Act for high-risk AI (documentation, conformity assessment, human oversight, transparency) and Basel/SR 11-7 principles for model risk (independent validation, explainability, monitoring, governance) converge on a common set of practices: comprehensive documentation, independent validation that includes explainability assessment, ongoing performance monitoring, and human oversight for consequential decisions. These controls satisfy both frameworks' core requirements efficiently. Publishing training data (A) is not required and may violate confidentiality. EU registration alone (C) satisfies only one framework's administrative requirement. Advisory-only limitation (D) may be overly restrictive and still doesn't address validation requirements.