PrepGenAICerts

Governance, Risk, and Responsible Use

15% of exam

Judge when Claude use is appropriate, handle sensitive and regulated data correctly, follow organizational AI policy and escalation paths, and weigh the ethical implications of AI-assisted work.

4

task statements

10

concepts

54

practice questions

Domain Mastery

0%
ts-ccaof-6.1

Distinguish appropriate from inappropriate use cases

Recognizing the outer boundary set by Anthropic's Usage Policy and finding the compliant way to accomplish a task rather than abandoning it or ignoring the rule.

Knowledge of

  • Anthropic's Usage Policy (AUP) as the outer boundary of acceptable use, with heightened requirements for high-risk and agentic scenarios
  • That organizations layer their own AI policies on top of the AUP, and both must be respected
  • What counts as appropriate use: language/knowledge work with human review such as drafting, summarizing, analysis, research, brainstorming, and process support
  • What counts as inappropriate or restricted use: violating the AUP, breaching organizational policy, mishandling regulated data, or placing unverified AI output into high-stakes decisions without human oversight
  • The four delegation criteria used to screen a whole use case (not just a single request): reversibility, consequence of error, need for human creativity/empathy, and accountability
  • That the four criteria interact rather than acting as independent gates, and that naming the load-bearing criterion is what makes a classification defensible
  • The three use-case classifications -- fully appropriate, appropriate with human review, and inappropriate -- and what distinguishes them
  • That 'appropriate with human review' requires a gate defined in WHO/WHAT/WHEN form, and that a restated label ('keep a human in the loop') is not itself a gate

Skills in

  • Recognizing when a request falls outside the AUP or organizational policy rather than assuming it's fine because it wasn't explicitly forbidden
  • Finding the compliant way to accomplish a borderline task (e.g., anonymizing data first) instead of abandoning the task or ignoring the rule
  • Rejecting the 'it's just internal' rationalization for bypassing data and governance rules
  • Identifying the AUP plus organizational policy as the authoritative source for what is appropriate use
  • Screening a whole use case against the four delegation criteria and identifying which one is load-bearing for the specific scenario
  • Classifying a use case as fully appropriate, appropriate with human review, or inappropriate, with a stated rationale tied to the load-bearing criterion
  • Writing a defined human-review gate in WHO/WHAT/WHEN form rather than a vague 'human in the loop' restatement
  • Recognizing when a high-consequence task becomes appropriate specifically because a defined gate restores accountability and reversibility

Concepts

ts-ccaof-6.2

Apply data sensitivity, privacy, and regulatory considerations

Classifying data by sensitivity, minimizing and anonymizing regulated data before sharing it with Claude, and aligning usage with data-protection laws.

Knowledge of

  • The data classification spectrum: public, internal, confidential, and regulated (personal data, financial records, health information)
  • Minimization and anonymization as the practice of removing or masking personal identifiers before sharing data with Claude when policy restricts it
  • That data-protection laws (e.g., GDPR/CCPA-style regimes) constrain what data may be processed and how, and usage must align with them and with contractual obligations
  • Why 'don't retain this' instructions to the model are not a substitute for anonymization or a real policy control
  • Incognito mode as a feature-level privacy control that excludes a standalone chat from Memory and from your visible history, and why it never substitutes for the classification question on regulated data

Skills in

  • Classifying a given dataset or request along the public/internal/confidential/regulated spectrum
  • Removing or masking personal identifiers (names, account numbers, PII) before sharing regulated data with Claude
  • Recognizing when a task can proceed compliantly after minimization rather than being blocked outright
  • Aligning data-handling choices with applicable data-protection regulation and contractual obligations
  • Using Incognito mode appropriately for sensitive or exploratory standalone chats, without treating it as clearance to process regulated data that hasn't been approved for that entry point

Concepts

ts-ccaof-6.3

Follow organizational AI policies and governance

Knowing and following organizational governance layered on the AUP, escalating unclear or novel cases, and treating embedded instructions in external content as untrusted.

Knowledge of

  • That organizations layer their own governance on top of the AUP: approved tools and plans, allowed data types, required review steps, and escalation paths
  • That responsible use means knowing and following those standards, not improvising, and escalating to the right owner when policy is unclear or a case is genuinely novel
  • Prompt injection and manipulated inputs as a security-adjacent governance risk: instructions hidden inside a document or web page that try to redirect the model
  • Why external content (uploaded documents, fetched web pages) must be treated as untrusted, with outputs validated rather than embedded instructions followed
  • Skill trust evaluation as a repeatable governance check -- source, reach, and appropriateness -- before enabling a Skill, and the enable/escalate/decline outcomes that follow from it
  • The least-privilege principle generalized beyond Skills to any feature, connector, or tool: hand over only the access a job actually requires

Skills in

  • Identifying the organization's approved tools, plans, allowed data types, and required review steps for a given task
  • Escalating to the appropriate policy owner when governance is unclear or the use case is novel, instead of guessing or improvising
  • Recognizing hidden or embedded instructions in an uploaded document or fetched page as a prompt-injection attempt rather than a legitimate clarification
  • Treating external content as untrusted and validating outputs before acting on them
  • Evaluating a Skill's source, reach, and appropriateness before enabling it, and choosing to enable, escalate, or decline based on that evaluation
  • Applying least-privilege reasoning to any feature/connector/tool decision, not just Skills

Concepts

ts-ccaof-6.4

Understand the ethical implications of AI use

Weighing bias, transparency, and accountability in AI-assisted work, with the human always owning the outcome.

Knowledge of

  • Bias and fairness: AI output can reflect or amplify bias and requires deliberate review, especially in decisions about people
  • Transparency: being honest about when and how AI was used, per organizational norms
  • Accountability: the human stays responsible for decisions and published output; AI assists, it doesn't absolve
  • The AI Fluency Diligence competency: using AI effectively, ethically, and safely, with the user owning the outcome
  • The need for human oversight where outcomes materially affect people (high-stakes use)

Skills in

  • Reviewing AI output for skewed framing or unfair treatment, especially in decisions about people
  • Disclosing AI use honestly per organizational norms rather than presenting AI-assisted work as purely human-authored without disclosure
  • Taking ownership of AI-assisted decisions and output rather than treating the AI's involvement as an accountability shield
  • Keeping a human in the loop for high-stakes use where outcomes materially affect people
  • Applying the AI Fluency Diligence competency: effective, ethical, and safe use with the human owning the outcome

Concepts

PrepGenAICerts.com is an independent third-party exam-prep platform for the Claude Certified Architect (CCA-F) certification. We are not affiliated with, endorsed by, or acting on behalf of Anthropic PBC.

Note: New premium upgrades are temporarily paused while we resolve an issue with our payment provider. Existing premium members retain full access.