CCAO-F · Study Guide

← Build Exercises

Domain 6

Governance, Risk, and Responsible Use

4 build exercises to practise the concepts in this domain.

6.1Beginner25 minutes

6.1 — Classify Requests as Appropriate, Conditional, or Escalate

What you will learn

  • Why being able to do something is not permission to do it.
  • Which uses are fine, which need conditions, and which need escalation.
  • When a request needs a developer or architect because it involves integrations.
  • How to explain your classification to a colleague.
Open lesson 6.1
6.2Intermediate35 minutes

6.2 — Anonymize Sensitive Data Before You Analyze It

What you will learn

  • Why you remove or mask identifiers before upload.
  • Why telling Claude not to retain data is not a privacy control.
  • What counts as sensitive: personal, health, financial, and confidential business data.
  • How to keep the analysis useful after masking.
Open lesson 6.2
6.3Intermediate35 minutes

6.3 — Draft a One-Page Team AI Use Guide

What you will learn

  • Why policy comes before pasting data.
  • What a useful do/don't list contains.
  • How to define who to ask when a case is unclear.
  • How to keep a policy short enough to follow.
Open lesson 6.3
6.4Advanced40 minutes

6.4 — Review a Workflow for Ethical Risks

What you will learn

  • When to disclose that AI helped produce something.
  • Why accountability stays with the person, not the tool.
  • Why people decisions such as hiring or discipline need extra care.
  • How bias in inputs can show up in outputs.
Open lesson 6.4