A government policy analyst is developing an AI risk register entry for a new automated tax fraud screening system. Which field is most uniquely important for AI risk governance that would not appear in a standard IT asset register?
- A.System owner and system administrator names
- B.Vendor name and contract expiration date
- C.Training data description and known biases - documenting what data the model was trained on, the time period it covers, known demographic or contextual biases, and whether the training data remains representative of the current population being screened
- D.IP address and network segment assignment
Why C is correct