Escalate acceptance to the designated risk authority: What is the decisive response?
Material customer-data risk with unresolved security evidence requires the policy-designated committee, not project-manager acceptance.
The question
A software vendor’s tool processes customer data. Testing leaves unresolved security uncertainty, and organizational policy requires the enterprise risk committee to accept material customer-data residual risk. The project manager proposes accepting deployment to meet a launch target. What is the decisive response?
Preparing for AIGP? Take the free 5-min readiness quiz →
- Deploy with monitoring while the project manager records the uncertainty.Monitoring can manage some risks, but deployment would bypass the specified acceptance authority for material customer-data risk.
- Seek user consent before allowing customer-data processing.Consent may not resolve organizational risk authority or security uncertainty; the scenario requires committee acceptance for this risk category.
- Ask the vendor to provide a revised security brochure.More vendor information may help, but it does not substitute for the designated authority’s required residual-risk decision.
- Escalate acceptance to the designated risk authority. ✓The project manager lacks authority under the stated policy, and unresolved security uncertainty makes committee review necessary before acceptance.
The trap
Separate mitigation evidence from authorization: the person managing delivery may not hold residual-risk acceptance authority. How to remember it
Material customer-data risk with unresolved security evidence requires the policy-designated committee, not project-manager acceptance.
How many of these would you get right?
One of 1581 AIGP questions on Certsqill. Take a free five-minute check and see your score per domain — not one number, but which section to open tonight.
Test your AIGP readiness — freeMore Understanding How to Govern AI Development questions
- Users may influence coworker evaluations with incomplete: Which concrete misuse risk remains? →
- The missing transformation and version history prevents: Which distinction is decisive for governance? →
- Evaluate across shifts: Which evaluation requirement is decisive? →
- All 426 Understanding How to Govern AI Development questions →
Part of the Certsqill AIGP question bank · Understanding How to Govern AI Development ·
Every answer, right and wrong, comes with its own explanation.