Question 1
Which of the following is a risk practitioner's BEST recommendation to establish accountability for AI system outputs and decisions?
Accountability in AI governance requires that specific individuals or roles be clearly designated as responsible for AI system outputs, decisions, and associated risks. Without formal documentation of ownership, accountability gaps emerge.
Why D is Correct: The ISACA AAIR framework emphasizes that accountability must be explicit and documented, with named individuals assigned to own AI outcomes. Formal role assignments create a traceable chain of responsibility that supports auditability, regulatory compliance, and effective escalation when issues arise. Named ownership prevents diffusion of responsibility.
Why A is Wrong: A centralized task force creates collective responsibility, which can dilute individual accountability. Governance bodies support oversight but do not replace individual role ownership for specific outputs.
Why B is Wrong: Continuous monitoring and KPIs are valuable operational controls but represent monitoring mechanisms, not accountability structures. Monitoring detects issues but does not assign responsibility for them.
Why C is Wrong: Resource allocation reviews address investment efficiency rather than accountability for AI decisions and outputs. This is a management activity, not an accountability framework.