6.3 · Lesson 3 of 4
Organizational AI Policy
What you need to know
Your organisation’s AI policy decides what is allowed. Read it before you paste anything, follow it even when it is inconvenient, and escalate when the policy is silent or ambiguous rather than guessing.
Policy before paste
Policies commonly cover approved tools, permitted data types, required review, and disclosure expectations. Check what the organisation permits before sharing any work material with Claude.
Do and don’t lists
Simple team guides help: allowed uses, uses that need approval, never allowed, and who to ask. Keep them short enough to follow. Revisit as tools and regulations evolve. Test the guide on real situations until another person can decide new cases from the guide alone.
Worked example
Draft a one-page team guide from existing policy (or from the data types you handle). Five realistic situations each get a clear answer; unclear cases point to a named contact. A coworker applies the guide to two new cases without your help — that is the skill check.
Exam traps
Paste now, check policy later
Policy before paste — even when it is inconvenient.
Guess that silence means approval
If the policy does not cover your case, ask the owner.
Use personal accounts for work data
Unapproved tools and personal accounts are a classic policy breach when work data is involved.
Leave “who to ask” as vague management
Name a person or channel so the team can escalate consistently.
Practice scenario
Your organisation’s AI policy does not clearly cover uploading a new type of partner data into Claude. A deadline is tomorrow. What should you do?
Build exercise
Draft a One-Page Team AI Use Guide
6.3 · Intermediate · ~35 min · claude.ai
What you will practise
- Why policy comes before pasting data.
- What a useful do/don't list contains.
- How to define who to ask when a case is unclear.
- How to keep a policy short enough to follow.
Build the Domain 6 one-page guide so unclear cases point to a named contact.
Open Domain 6 exercisesPath: /learn/claude-associate/exercises/6-governance-risk-responsible-use
Sources
- CCAO-F Exam Guide v1.0 — Domain 6 task statement 6.3 — Organizational AI Policy
- preporato/claude-certification-guide — do/don’t matrix — rewritten into site voice
- docs/ccao-f-implementation-plan.md — Domain 6 lesson map