Domain 5 · 14% of the exam
Governance, Safety & Risk Management
Implement guardrails, surface risks, apply HITL, meet compliance, and address ethical AI concerns.
Objectives
- 5.1
Implement guardrails and safety controls
Layer prompt guidance with deterministic input/output filters, policy checks, and hard blocks on irreversible tool paths — prompts alone never satisfy “must always” safety language.
- 5.2
Identify risks, limitations, and failure modes of LLM systems
Enumerate hallucination, drift, tool misuse, outages, and policy gaps with user impact, mitigations, and residual risk owners — never “the model will handle it.”
- 5.3
Apply human-in-the-loop validation strategies
Route high-risk or ambiguous work to humans with measurable escalation triggers and a structured handoff — facts, suggestion, uncertainty, and required decision.
- 5.4
Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP)
Map data classes, regions, and flows to the named regulatory regime; minimize sensitive data in prompts and logs; document control ownership and evidence.
- 5.5
Address ethical AI considerations (bias, fairness, transparency)
Treat bias, fairness, and transparency as design requirements: measure disparate outcomes, disclose AI involvement when required, and provide recourse — not slogans.