Supplier incidents may remain undiscovered or unreported | AIGP
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

Supplier incidents may remain undiscovered or unreported: What specific risk remains?

AIGP Understanding the Foundations of AI Governance Hard

Internal policy coverage does not close the supplier gap: incidents may remain unknown or unreported, delaying response to exposed financial documents.

The question

A financial-document processor extends its internal security policy to cover prompts, outputs, and retention. A cloud supplier still has no contractual incident-notification duty, and the company lacks evidence about the supplier’s monitoring. What specific risk remains?

Preparing for AIGP? Take the free 5-min readiness quiz →

  1. The company should prohibit all cloud processing until a new security framework is adopted.
    A broad prohibition is not required by the facts and avoids specifying controls for supplier visibility, notification, and response.
  2. Employees may require refresher training on the revised internal policy.
    Training supports implementation, but it does not resolve the supplier’s missing notification duty or unknown monitoring capability.
  3. The revised policy should require employees to approve every document-processing prompt manually.
    Manual prompt approval does not provide supplier incident visibility and may address a different risk than external monitoring and notification.
  4. Supplier incidents may remain undiscovered or unreported, delaying response to document exposure.
    Without supplier notification and monitoring evidence, the company may lack timely awareness of incidents involving sensitive financial documents.
The trap
Map each mitigation to its owner; an internal control does not automatically govern a supplier’s detection or notification duties.

How to remember it

Internal policy coverage does not close the supplier gap: incidents may remain unknown or unreported, delaying response to exposed financial documents.

How many of these would you get right?

One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.

Test your AIGP readiness — free

More Understanding the Foundations of AI Governance questions

Part of the Certsqill AIGP question bank · Understanding the Foundations of AI Governance · Every answer, right and wrong, comes with its own explanation.