CCAO-F exam prep The seven blueprint domains
Domain 6 · Governance, Risk, and Responsible Use
Fifteen percent, and the guide's third published sample lives here — with a rationale that gives away how the whole domain thinks
· Part 2 · The seven blueprint domains · 3 min read
Weight: 15% of the exam. Third heaviest.
This domain does not ask what the law says. It asks what you do next when the data in front of you is sensitive.
The objectives, as the guide states them
"Identify appropriate and inappropriate use cases"
"Apply data sensitivity, regulatory, and privacy considerations"
"Follow organizational AI policies and governance standards"
"Understand the ethical implications of AI usage"
The third official sample item
Section 8 gives the situation: a project manager wants to upload a spreadsheet of customer names and account numbers so Claude can analyse trends, but organisational policy restricts sharing regulated personal data. What is the most appropriate action?
The answer is remove or anonymise the personal identifiers before uploading, consistent with policy, and the rationale reads
"Applying data-sensitivity and privacy safeguards means redacting or anonymizing regulated identifiers before use, so the analysis can proceed without exposing protected data. Uploading as-is (A) violates policy; instructing the model not to retain data (C) does not satisfy the policy control; abandoning the task (D) is unnecessary when anonymization enables it."
Those last three clauses are a pattern you can reuse across the domain.
A go ahead anyway breaks policy
C tell the model not to keep it is not a policy control
D drop the task unnecessary when a way exists
Two traps the guide marks itself
The first — telling the model not to retain data is not a control. A policy control has to happen before the data leaves your hands, not as a request left with the far end. It is the same logic as domain 2's rule that asking the model how confident it is does not count as checking.
The second — refusing the work outright is also wrong. The guide uses the word unnecessary. The exam does not reward maximum caution; it rewards finding the route that gets the work done without breaching anything.
This is where candidates most often go wrong, assuming that on a safety question the safest-sounding option must be right.
Organisational policy outranks your own judgment
The third objective's verb is follow, not evaluate.
Where an item states that a policy exists, that policy is the rule. There is nothing to debate about whether it is sensible. The third sample opens by saying policy restricts it, and the correct answer is the one that complies.
When it lies
"On a safety question, pick the most cautious option." The guide rejects this in its own answer key: abandoning a task that anonymisation would have enabled is marked unnecessary.
"Telling the model not to retain the data is enough." The guide says plainly that this does not satisfy the policy control.
"You need to know GDPR to answer these." The objectives say considerations and organizational policies. The item hands you the policy in the scenario.
References
Official documents
- CCAO-F Exam Guide Section 6 domain 6, Section 8 for the third sample and its rationale
Elsewhere in this course
- Domain 2 applies the same logic to the model's own confidence