CCAO-F · Study Guide

Domain 615%

Quick Reference: Domain 6 — Governance, Risk, and Responsible Use

Data Handling Rules

  1. Check organizational policy before pasting or uploading.
  2. Identify sensitive data: personal, health, financial, credentials, confidential material.
  3. Anonymize or redact before upload, including identifiers in free text.
  4. If policy is silent or unclear, escalate.

Telling Claude not to retain or use data is not a control. Controls act before the data is shared.

Decision Table

If the question says...The answer is likely...
Customer data with names and account numbers needs analysisAnonymize first, then analyze
"Instruct Claude not to retain the data"Not a control. Anonymize before upload
Request to integrate Claude with company systemsEscalate to the team that builds and secures integrations
Policy does not cover the caseAsk the policy owner before proceeding
Claude's output informs hiring or disciplineA person decides and is accountable
Regulated data is involvedFollow policy and regulation; escalate when unsure
Public information summarized for internal useGenerally appropriate, still verify

Traps

TrapCorrect Answer
It can do it, so it is allowedCapability is not permission
Paste now, check policy laterPolicy before paste
Claude is accountable for its outputThe person using the output is accountable
Disclosure never mattersDecide deliberately based on audience, context, and policy
Redact only the obvious columnsCheck free text for identifiers too

If You Remember Nothing Else

  • Anonymize or redact before upload; instructions are not a control.
  • Capability does not equal permission.
  • Escalate system integrations and unclear policy cases.
  • Accountability stays with people.

Lessons in this domain