Question 1 of 30
An internal audit department, operating under a charter that emphasizes its role in evaluating governance, risk, and control processes, is informed of a sudden strategic decision by the organization to integrate advanced artificial intelligence (AI) into its primary customer relationship management (CRM) system. This integration is expected to fundamentally alter customer interaction protocols and data handling. Which of the following represents the most appropriate initial response by the internal audit activity to maintain its effectiveness and adherence to its mandate during this significant transition?
Immediately re-evaluate the current audit plan to identify potential impacts of the AI integration on key risk areas and develop a preliminary approach for assessing the new AI-related controls and governance structures.
Continue with the existing, approved audit plan, deferring any assessment of the AI integration until the technology has been fully implemented and stabilized for at least one fiscal year.
Request the IT department to provide a comprehensive post-implementation review of the AI system, focusing solely on technical performance metrics and security vulnerabilities.
Initiate a review of the organization's ethical guidelines regarding AI, without concurrently assessing the operational risks and control effectiveness of the AI system itself.

Preparing for ISO/IEC 27001 Transition Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free