Supplier incidents may remain undiscovered or unreported: What specific risk remains?
Internal policy coverage does not close the supplier gap: incidents may remain unknown or unreported, delaying response to exposed financial documents.
The question
A financial-document processor extends its internal security policy to cover prompts, outputs, and retention. A cloud supplier still has no contractual incident-notification duty, and the company lacks evidence about the supplier’s monitoring. What specific risk remains?
Preparing for AIGP? Take the free 5-min readiness quiz →
- The company should prohibit all cloud processing until a new security framework is adopted.A broad prohibition is not required by the facts and avoids specifying controls for supplier visibility, notification, and response.
- Employees may require refresher training on the revised internal policy.Training supports implementation, but it does not resolve the supplier’s missing notification duty or unknown monitoring capability.
- The revised policy should require employees to approve every document-processing prompt manually.Manual prompt approval does not provide supplier incident visibility and may address a different risk than external monitoring and notification.
- Supplier incidents may remain undiscovered or unreported, delaying response to document exposure. ✓Without supplier notification and monitoring evidence, the company may lack timely awareness of incidents involving sensitive financial documents.
The trap
Map each mitigation to its owner; an internal control does not automatically govern a supplier’s detection or notification duties. How to remember it
Internal policy coverage does not close the supplier gap: incidents may remain unknown or unreported, delaying response to exposed financial documents.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding the Foundations of AI Governance questions
- Require prompt change notice with impact evidence before: Which contractual mitigation best addresses the →
- The policy may remain unsuitable after material model: What risk remains? →
- The business owner supplies use and data details: Which handoff is correct? →
- All 337 Understanding the Foundations of AI Governance questions →
Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance ·
Every answer, right and wrong, comes with its own explanation.