Claude Certified Associate - Foundations

CCAO-F · Study guide

Governance, Risk & Responsible Use

Mind map

Mind map — governance & responsible use

🗺 Governance

  • Input
    • Client confidential
    • Personal data
    • Regulated content
    • Minimize first
  • Policy
    • Written rule wins
    • Approved tools only
    • Know where published
    • Escalate exceptions
  • Disclosure
    • Disclose when material
    • Human signs output
    • No citing generation
  • Fairness
    • Decisions about people
    • Check the pattern
    • Justify every exclusion
  • Human decision
    • Money health safety
    • Employment credit legal
    • Competent reviewer
  • Record
    • What and who
    • Approval trail
    • Decline in writing
Summary

What governance and responsible use really test

Governance is fifteen percent of the exam, around nine of sixty items, and it is the domain most often lost by candidates who answer from personal ethics instead of from the rule they actually work under. The questions are situational: a colleague wants to paste a client's contract into a prompt, a partner asks whether the deck has to say Claude drafted it, a candidate screening summary is about to go out without anyone competent reading it. Each has a defensible answer that does not require knowing any regulation by name.

The idea that unlocks the domain is that governance lives in the input and the record, not in the model. What you put into a prompt is a disclosure you cannot take back; what comes out is unowned until a human signs it; and the only durable protection is a written policy you checked plus a trail showing what was generated, from what, and who approved it. When an option sounds responsible but rests on your own judgment rather than your organization's written rule, it is the wrong answer. And technically possible is never the same as appropriate, so the exam rewards a clean, reasoned decline.

Cheat sheet

Governance & responsible use — cheat sheet

  • Ask what the material is, not how sensitive it feels. Client confidential, personal data about identifiable people, and regulated or licensed content each carry a rule that does not bend to your comfort level.
  • The rule you work under beats the rule you would have written. Find your organization's AI policy and its approved tool list before improvising, and know where that policy is published.
  • Approved tool, approved data. The same text can be acceptable in a sanctioned enterprise deployment and a breach in a personal account.
  • Minimize before you paste. If the analysis works on anonymized or extracted data, send only that.
  • Consent and purpose travel with personal data. Material a client gave you for one engagement is not automatically available for another.
  • Disclose AI involvement when the client asked, when a contract or regulator requires it, or when a reasonable audience would weigh the work differently knowing.
  • A human owns the output and its errors. Generated work is not a source you can cite or blame; a named person signs it.
  • Where output affects a person's money, health, safety, employment, credit or legal standing, a human makes the decision, not just a review pass.
  • Check output that sorts, ranks or describes people for differences you could not justify to the person on the wrong end.
  • Keep a record: what was generated, from what input, by whom, and who approved it before it left the building.
  • Decline what is technically possible but wrong. Say why plainly and offer the version you can do.
  • Separate a rule from a habit. A rule is written, owned by someone, and binds you whether you agree; anything else is your practice and must not be presented to a client as policy.
Cheat sheet

Governance & responsible use — cheat sheet 2

  • Tempting wrong answer: "it is fine, I will delete the conversation afterward." Deleting later does not undo the disclosure that already happened.
  • Trap: treating name removal as anonymization. Role, region, dates and rare attributes re-identify a person in a small population.
  • Trap: assuming public means usable. Publicly available personal data and licensed third-party material still come with rules.
  • Mistake: asking the model whether your use is compliant. It does not know your policy, your client's contract, or your jurisdiction.
  • Mistake: blanket disclosure. Stamping "AI may have been used" on everything tells a client nothing; disclose specifically where it is material.
  • Trap: the opposite error, hiding involvement that changes how the work should be read. The test is materiality, not whether the model touched the file.
  • Mistake: treating a confident-looking citation or quotation as a verified one. Unchecked attribution becomes a governance failure the moment it reaches a client.
  • Trap: "a human reviewed it" when the human skimmed a summary. Review only counts if a competent person could have changed the outcome.
  • Mistake: judging fairness from one output. Bias is a pattern across cases and is invisible in a single sample.
  • Trap: escalating everything to human sign-off. Blanket review looks safe, becomes rubber-stamping, and buries the cases that actually matter.
  • Mistake: presenting personal caution as company policy. If you cannot point to where it is written, call it your practice.
  • Trap: the request from someone senior. Seniority is not an approval route; an exception comes from whoever owns the policy, and gets recorded.
Mnemonic

Mnemonic — "GUARD"

GUARD — run it before the material goes in, not after the work goes out.

  • G — Gauge the input. Name what you are about to paste: client confidential, personal data, regulated or licensed content, or none of these.
  • U — Use the policy. Your organization's written rule and approved tool list decide. Know where it lives; escalate the new case to whoever owns it.
  • A — Assess the stakes. Who is affected by the output, is the effect on a person material, and must a named human make the decision rather than review it?
  • R — Reveal. Disclose AI involvement where a client, audience or regulator would want to know, and be straight about who authored and owns the result.
  • D — Document. Record what was generated, from what input, by whom, and who approved it.

Any letter can end in no. GUARD is a gate you can stop at, not a checklist you complete.

Practise this domain with original, exam-style questions.

Start practising free