Your company's HR department deploys a resume-screening AI tool without consulting security or legal. A rejected applicant files a discrimination complaint claiming the tool filtered out candidates based on age.
Who should the CISO escalate to FIRST?
A. The AI vendor to request bias testing documentation
B. Legal counsel to assess regulatory exposure from the unauthorized deployment
C. The HR director to immediately disable the tool
D. Internal audit to begin a full algorithmic fairness review