CCAO-F · Study Guide

Domain 615%

Glossary: Governance, Risk, and Responsible Use

Quick-lookup definitions for the 15% exam domain. Each entry includes a concise definition and exam context. Follow the lesson links to dive deeper.

Appropriate Use

Using Claude in ways that are permitted and sensible for the task and the data involved. Capability alone does not make a use acceptable.

Exam context: Capability is not permission. Requests to integrate Claude with other systems are escalated to the team that handles integrations.

See also: 6.1 Appropriate vs Inappropriate Use

Escalation

Sending an unclear or high-risk question to the right owner, such as security, legal, or the team that builds integrations, instead of deciding alone.

See also: 6.1 Appropriate vs Inappropriate Use

Sensitive Data

Information whose exposure could harm people or the business: personal, health, and financial data, credentials, and confidential business material.

See also: 6.2 Data Sensitivity, Privacy, Regulation

Anonymization

Removing or masking identifiers before data is shared, often replacing them with stable codes so analysis stays useful. It is a real control because the sensitive data never leaves your hands.

Exam context: Anonymize before upload. Telling Claude not to retain or use the data is not a control.

See also: 6.2 Data Sensitivity, Privacy, Regulation

Redaction

Removing specific sensitive details from a document before sharing it. Check free-text fields, since identifiers often hide in comments.

See also: 6.2 Data Sensitivity, Privacy, Regulation

Regulated Data

Data covered by laws or rules, such as privacy or sector regulations, that restrict how it may be handled. Using it with an AI tool requires a policy check first.

Exam context: When regulation applies and policy is unclear, stop and ask before pasting.

See also: 6.2 Data Sensitivity, Privacy, Regulation

Organizational AI Policy

Your organization's rules for what AI tools may be used for and with which data. Policy comes first; check it before you paste anything sensitive.

Exam context: Policy before paste. If the policy is silent or ambiguous, escalate rather than assume it is allowed.

See also: 6.3 Organizational AI Policy

Accountability

The principle that the person or team using Claude's output remains responsible for it. The tool does not carry responsibility.

Exam context: In people decisions, Claude may inform but a person decides and is accountable.

See also: 6.4 Ethical Implications

Disclosure

Being open, where it matters, that AI assisted in producing content. The right level depends on audience, context, and policy.

See also: 6.4 Ethical Implications

Human Oversight

Keeping a person in the loop for decisions that affect people, especially hiring, discipline, health, finance, and legal outcomes.

See also: 6.4 Ethical Implications