Redwood Community Bank is subject to strict FFIEC and SOX compliance requirements. Their compliance officer wants to evaluate whether the bank's deployed AI agents create any regulatory gaps — specifically, whether agents are operating without proper data retention policies, audit logging, or approved data handling procedures. Which capability in Agent 365 should the administrator use to surface these gaps?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Agent 365 compliance gap evaluation is your agent-specific compliance X-ray — it looks at your deployed agents and flags where they're operating outside your org's compliance boundaries. It's purpose-built for agents, unlike Compliance Manager which works at the org/control level.
Full explanation below image
Full Explanation
Agent 365 includes a compliance gap evaluation feature designed to assess deployed AI agents against defined organizational compliance requirements — including data retention, audit logging, data handling procedures, and approved data access scopes. This gives administrators and compliance officers a structured view of which agents have gaps relative to policy requirements, enabling targeted remediation rather than broad manual assessment.
Option A is incorrect because Microsoft Secure Score improvement actions focus on security configuration hardening (MFA coverage, policy enforcement, threat protection) — they are not designed to evaluate AI agent compliance gaps around data retention, audit logging, or regulatory data handling requirements. Secure Score is a security posture tool, not a compliance gap tool.
Option C is incorrect because manually exporting and cross-referencing the unified audit log against FFIEC control requirements is an extremely labor-intensive process that would require specialized expertise and significant time. It also wouldn't provide the structured agent-by-agent gap analysis that Agent 365 compliance evaluation delivers out of the box.
Option D is incorrect because Microsoft Compliance Manager performs organizational-level self-assessments against regulatory frameworks (GDPR, FFIEC, ISO 27001, etc.) and tracks control implementation status broadly. It does not perform agent-specific evaluations that identify compliance gaps at the individual deployed agent level. It's the right tool for org-wide compliance posture, not for agent-specific gap assessment.
Exam tip: The AB-650 exam tests three Agent 365 governance capabilities: activity monitoring (what are agents doing), data protection (what data can agents access), and compliance gap evaluation (are agents operating within compliance boundaries). Know which tool answers which question.