A lender will embed a third party AI model in loan approvals, live in 90 days by board order. Nobody has set a risk appetite for AI decisions or named an owner. What should the CISO do FIRST? A. Draft an AI acceptable use policy for lenders B. Have the board set risk appetite and name an owner C. Commission due diligence on the model vendor D. Require bias and explainability testing before launch (Explain your answer for more points in the comments!) Come back for the answer tomorrow, or study more now!