A bank is aiming to comply with ISO/IEC 42005:2025, and is studying how to adopt the standard in light of a new AI customer service system that it would like to implement. In addition to the risk management process the bank already has in place to assess the risks of any potential new systems, which of the following actions is the most effective in adopting the ISO/IEC 42005:2025 standard?
Select an option, then click Submit answer.
Reference / correct answer:
Defining a standalone AI impact assessment procedure to supplement the existing risk management process.
Most accepted answer: C. Defining a standalone AI impact assessment procedure to supplement the existing risk management process.
Community votes: C=1
Selected Answer: C Explanation ISO/IEC 42005:2025 is specifically an AI System Impact Assessment standard that "provides structured guidance for performing AI Impact Assessments" and offers "a systematic methodology for evaluating the potential impacts of AI systems on individuals, groups, and society". The question highlights that the bank already has a general risk management process in place, so the issue is what additional step most effectively adopts this standard. The answer is establishing a dedicated AI impact assessment procedure that works alongside — but is distinct from — the existing process. upvoted 1 times