組織の顧客サービス チャットボットにおける AI の使用状況を監査する場合、情報システム監査人は主に次の点に重点を置く必要があります。
正解:A
Comprehensive and Detailed Step-by-Step Explanation: Theprimary concernwhen auditing an AI-powered chatbot is ensuring thesafeguarding of personal datato comply with privacy regulations such asGDPR, CCPA, and ISO 27701. AI chatbots process customer inquiries, often handling sensitive personal data. * Safeguarding of Personal Data (Correct Answer - A) * Ensures compliance with data protection laws. * Reduces the risk of unauthorized access or data leakage. * Example:An AI chatbot collecting customer financial information must follow encryption and access control policies. * Compliance with Industry Standards (Incorrect - B) * Important, but protecting customer data takes priority over general compliance. * Speed and Accuracy of Chatbot Responses (Incorrect - C) * A performance metric, but not a primary audit focus. * AI's Ability to Handle Multiple Queries (Incorrect - D) * Efficiency metric, but does not address security risks. References: * ISACA CISA Review Manual * ISO 27701 (Privacy Information Management System) * GDPR & CCPA Compliance Guidelines