A fast-growing analytics startup with a deliberately high risk tolerance is building an AI system that scores consumer creditworthiness for lenders across the European Union. Its founders argue that, because the company accepts more risk than a conservative bank would, it may run a lighter governance programme than the objective intensity its competitors choose. A governance adviser is asked what limits how far risk tolerance can shape this organisation's governance. Which principle most accurately states that limit?
- ARisk tolerance may set the governance intensity freely, because each organisation is the sole judge of how much risk its own AI systems should carry.
- BRisk tolerance may shape governance intensity above the baseline, but it cannot reduce controls below the mandatory obligations that external law imposes on a high-risk AI system. Correct
- CRisk tolerance is irrelevant to AI governance design, because every organisation must apply an identical control set regardless of its size, industry, or appetite.
- DRisk tolerance may lower governance only where the organisation buys liability insurance to transfer the financial consequences of any AI harm to an insurer.
Why A is wrong: It is tempting because risk appetite genuinely is an internal board decision that legitimately drives governance intensity. It is wrong because an external mandatory regime such as the EU AI Act for a high-risk credit-scoring system imposes a floor that internal appetite cannot waive.
Why B is correct: It is correct because a credit-scoring AI system is high-risk under the EU AI Act, which fixes a non-negotiable floor of obligations; appetite can add rigour above that floor but never strip the statutory minimum.
Why C is wrong: It is tempting because it sounds rigorous and safe. It is wrong because the objective expressly treats risk tolerance, size, and maturity as legitimate factors that proportionately shape governance above any regulatory baseline.
Why D is wrong: It is tempting because insurance is a recognised risk-transfer treatment in the mitigation toolkit. It is wrong because transferring financial loss does not discharge statutory duties under the EU AI Act, and obligations such as conformity assessment and human oversight remain owed regardless of cover.