Are you using AI in software development, and are you managing the associated risks?
This question evaluates the organization’s approach to AI use within software development processes. AI use may include code generation, review, testing, or documentation. The focus is on whether usage is defined, governed, and controlled. Key considerations include acceptable use policies, developer education, risk mitigation (e.g., insecure code, IP leakage, model bias), and monitoring of AI tools’ effectiveness and security implications. Mature organizations define and enforce policies, regularly review usage, and integrate AI tooling in a secure and consistent manner and aim to comply with relevant AI regulations.