CCAO-F · module 3 of 7 · 15% of the exam

Governance, risk, and responsible use

Weight: 15 percent of the exam. Tests whether you can decide what may go into Claude, what may come out without review, and which control actually addresses a given risk.

What the exam expects

This domain is written for the person who uses Claude.ai daily inside an organization, not for the engineer wiring up an API. The scenarios are recognisably ordinary: a client contract pasted into a personal account, a manager automating rejection emails, a consultant under an NDA, an employee who thinks incognito hides a conversation from their employer. Your job is to name the control that actually applies.

Four skills carry most of the marks:

  1. Knowing which data handling rules apply to which plan (consumer versus commercial), and what each privacy control does and does not do.
  2. Recognising high risk use cases where a qualified human must review output before it reaches a person, and where AI involvement must be disclosed.
  3. Separating appropriate delegation (drafting, restructuring, first pass analysis with review) from inappropriate delegation (unreviewed decisions about people, unverifiable claims sent externally).
  4. Locating accountability. The person who publishes or acts on an output owns its accuracy, always.

A recurring exam pattern: the tempting wrong answer applies a real control to the wrong problem. Turning off model improvement is a genuine privacy setting, but it does not satisfy an NDA. Incognito is a genuine feature, but it is not a shield from your employer.

Data handling: consumer plans versus commercial plans

The single most testable distinction in this domain.

Consumer plans (Free, Pro, Max). Since the 2025 consumer terms update, chats and coding sessions may be used to improve Anthropic's models unless the user turns the setting off in Privacy Settings. New users choose at signup; the choice can be changed at any time. Leaving model improvement on also extends how long conversations are retained, to a multi year window. Turning it off stops the primary training use and returns standard conversations to the shorter default retention window.

Commercial plans (Team, Enterprise) and the API. Conversations are not used for model training by default, so there is no per user toggle to set. Narrow exceptions exist: content flagged during safety review, feedback a user explicitly submits (such as a thumbs rating), and voluntary opt in programs.

The safety carve out applies everywhere. Conversations flagged by Anthropic's safety systems may be used to improve detection and enforcement regardless of a user's stated preference. An answer option claiming there are no exceptions under any circumstance is wrong on every plan.

Incognito chats. Excluded from model training and from chat history and memory. This is a personal history control. In a managed organization, incognito chats remain subject to the organization's retention policy and can appear in administrative data exports. Never treat incognito as confidentiality from your employer.

Connectors. A connector operates with the permissions of the account that authorized it, so it inherits your access rather than granting new access. Content retrieved through a connector is not used for training unless it is copied into a chat. The governance question a connector raises is therefore about scope: what can this account already reach, and should all of it be reachable from a chat window?

ControlWhat it actually doesWhat it does not do
Model improvement toggle (Privacy Settings)Stops the primary training use on consumer plans, shortens standard retentionSatisfy an NDA, apply to an organization, act retroactively
Incognito chatKeeps a chat out of history, memory, and trainingHide the chat from an organization's retention or export
Deleting a conversationRemoves it from your account viewErase it instantly everywhere, or undo the fact that you shared it
Enterprise custom retentionSets an organization wide retention period, minimum 30 daysReach below the 30 day floor
Commercial plan (Team, Enterprise)Changes the default so conversations are not used for trainingRemove the safety review exception

Enterprise governance surfaces

Enterprise adds the controls an organization needs to answer an auditor. Expect at least one question that hands you an audit or compliance requirement and asks which capability applies.

  • Identity and access: single sign on, SCIM provisioning, role based access with fine grained permissions.
  • Visibility: usage analytics, audit logs, a Compliance API and an Analytics API for programmatic export into an organization's own monitoring stack.
  • Data control: custom retention with a documented 30 day minimum, administrative control over connectors, and organization level controls over features such as memory.

Two traps live here. First, the 30 day retention floor: if a scenario demands a two week purge policy, the retention setting cannot deliver it. Second, administrative visibility is not live surveillance. Administrators have export, retention, and audit capabilities over workspace content, but an option describing real time keystroke monitoring is fabricated.

High risk use cases and the two obligations

Anthropic's Usage Policy names domains where decisions materially affect a person: legal, medical, financial, employment, housing, insurance, and academic contexts. In these domains two obligations apply together, and the exam almost always removes one of them.

  1. Qualified human review. A professional in that field must review the content or decision before it is disseminated or acted on. The human retains responsibility for accuracy and appropriateness.
  2. Disclosure. End users must be told that AI assisted in producing the advice or recommendation.

Separately, any consumer facing conversational deployment must tell users they are interacting with AI rather than a human, at minimum at the start of the session. A friendly persona name and an avatar are permitted; the absence of disclosure is not.

The classic wrong answer offers disclosure as a substitute for review. A disclaimer on unreviewed discharge instructions does not make them safe, and a note that a memo was AI assisted does not make an incorrect projection correct. Disclosure and review are complements, not alternatives.

Confidential information and appropriate delegation

Before entering anything sensitive, three questions decide the matter, in order:

  1. Is this account governed? Personal accounts used for company work put data outside the organization's contracted terms, retention configuration, and audit trail. That is a policy breach even when the model output is excellent, and "the models are the same on Pro" is a true statement that answers the wrong question.
  2. Does a contract or regulation restrict where this data may be processed? An NDA, a client's approved tools list, a research licence limited to internal use, or a data protection obligation is a constraint on disclosure to third parties. No privacy setting overrides it, and the client or licensor is the party who decides.
  3. Do I need all of this data? Data minimisation is the cheapest control available. Theme analysis on support tickets almost never needs customer names and email addresses. Note that removing names alone rarely anonymises anything, since addresses, policy numbers, and account identifiers remain directly identifying.

For delegation, the reliable test is whether a human retains judgment and can verify the output before it has consequences.

AppropriateInappropriate
First pass summaries the human reads against the sourceFinal decisions about a person sent without review
Restructuring, reformatting, consistency passesSigning off on reasoning the human has not read
Drafting that a qualified reviewer edits and ownsSending unverified factual claims to external or adversarial parties
Brainstorming options for a human to choose amongCovert profiling or emotional inference about identified individuals

Covert monitoring deserves its own note. Inferring an employee's attitude, engagement, or intent to resign from their messages, then acting on it, is not a prompting problem to be improved. It is a request to decline. Anonymising three named colleagues to their own manager is no mitigation, and a confidence score only makes an inappropriate analysis look rigorous.

Bias, verification, and accountability

Bias often enters through the prompt. When a job description comes back skewed against older applicants, look first at the framing the user supplied ("young", "rockstar", "the kind of people we hired in year one"). The correction is to state the actual skills, scope, and outcomes the role requires. Two overcorrections are also wrong: declaring the bias inherent and uncorrectable, and banning AI drafting entirely.

Verification is the user's job. Attributed statistics, citations, and any figure a conclusion rests on must be checked against the primary source before publication. Three failed shortcuts appear repeatedly as distractors: asking the model to confirm its own claims (a confident restatement is not evidence), regenerating and keeping what appears consistently (consistency is not correctness), and adding a disclaimer (disclosure does not repair an error).

Attribution norms come from the governing context. Journals, publishers, universities, and clients each set their own rules, so when a policy exists, read it and follow it rather than deciding unilaterally that your use was too minor to mention. Prevailing publisher norms do not treat AI tools as authors, because authorship carries accountability a tool cannot hold.

Policy design. A blanket ban with no sanctioned alternative reliably produces ungoverned use on personal accounts, which is worse than governed use. A workable policy answers the two questions an employee actually faces: which categories of information may I enter and into which account, and which outputs need human review before they leave the company or affect a person.

How to think through the question

Domain 3 stems are short and the distractors are all defensible sounding, so the discrimination has to come from a procedure rather than from recognising a keyword.

Signal words to catch in the scenario.

  • Named plan ("personal Pro account", "Claude Team", "Enterprise") tells you which data handling rules apply and whether administrative controls exist.
  • A regulated noun (patient, applicant, client, policyholder, student, defendant) means you are in high risk territory: look for the review and disclosure obligations.
  • A contract word (NDA, licence, internal use only, approved tools) means the constraint is contractual, so no product setting resolves it.
  • An automation phrase ("automatically send", "without further review", "directly to the client") almost always marks the flaw, because it is where the human checkpoint was removed.
  • "There is no policy yet" is never permission. It is a signal that the answer involves getting a decision from the accountable owner.

Reasoning procedure.

  1. Identify who is affected by the output and whether it reaches them without a human in between.
  2. Identify the actual constraint: contractual, regulatory, organizational policy, or product data handling. Only one of these is usually the binding one.
  3. Read what the question asks for. "What should they do first" wants the gating check, not the eventual full solution. "What is wrong" wants the flaw, not a list of improvements.
  4. Eliminate options that apply a real control to a different problem. This kills more distractors than any other move.
  5. Eliminate options that overcorrect into a total ban when a reviewed workflow is permitted, and options that treat disclosure as a substitute for review.
  6. Choose the option that keeps a qualified human accountable while preserving the legitimate work.

Worked example. A clinic administrator wants to turn clinical notes into plain language discharge instructions, appending "generated with AI assistance, may contain errors" and sending them straight to patients. Why is this insufficient?

Step 1: the output reaches patients with no human in between. Step 2: the constraint is regulatory and lands in the medical high risk category. Step 3: the question asks why the proposal is insufficient, so I need the missing obligation. Step 4: an option about uploading notes to project knowledge raises a real data handling point but applies it to the wrong problem, since unreviewed medical guidance would still reach patients either way. Step 5: an option saying AI must never touch a clinical workflow overcorrects, because AI assisted drafting with clinician review is legitimate; an option calling the disclaimer too vague treats a governance gap as copywriting. Step 6: the remaining option, that a qualified clinician must review the content before it is sent and disclosure does not substitute for that review, is the answer.

Exam traps

  • Treating the model improvement toggle as a confidentiality control. It governs training use and retention on consumer plans. It has nothing to say about an NDA, a licence, or a regulator, and this is the single most repeated trap in the domain.
  • Believing incognito hides a chat from your employer. It hides it from your history, your memory, and training. A managed organization's retention and export still apply.
  • Assuming Team and Enterprise users must opt out individually. Commercial plans already default to no training use. Carrying the consumer control into the commercial context is a classic misread.
  • Claiming no exceptions exist. Safety flagged content sits outside every opt out. Absolute language in an option is usually a tell.
  • Accepting a disclaimer instead of professional review. In legal, medical, financial, and employment contexts the review is the requirement. Disclosure is the second obligation, not a replacement for the first.
  • Over generalising the AI disclosure rule. The explicit obligation attaches to consumer facing conversational deployments and to high risk advice. For ordinary edited marketing copy, the governing rules are company policy and local law, not a universal labelling requirement.
  • Treating deletion as erasure. Deleting a conversation is a cleanup action for your account, not a remedy for having shared something you should not have shared.
  • Answering a governance question with a capability upgrade. A stronger model does not remove a review obligation, and a higher plan tier does not fix a curation or licensing problem.
  • Solving a policy failure with more prohibition. When a ban has already driven usage onto personal accounts, extending the ban repeats the mistake. A tiered policy with a sanctioned path is the improvement.
  • Letting responsibility drift to the vendor. The person who signs the memo owns the numbers in it. Any option that relocates accountability to the tool is wrong.

Quick reference

  • Consumer plans: training use unless opted out; opting out shortens standard retention. Commercial plans and API: no training use by default.
  • Universal exception: safety flagged conversations may be used for enforcement regardless of settings.
  • Incognito: no training, no history, no memory. Still subject to organizational retention and export.
  • Enterprise: SSO, SCIM, role based access, audit logs, Compliance and Analytics APIs, custom retention with a 30 day minimum, connector and memory administration.
  • Free plan: five Projects maximum. Project sharing is a Team and Enterprise capability.
  • High risk domains (legal, medical, financial, employment, housing, insurance, academic): qualified human review before dissemination, plus disclosure of AI assistance.
  • Consumer facing chat assistants: state at session start that the user is talking to AI.
  • Connectors act with the authorizing account's permissions; connector content is not training data unless copied into a chat.
  • Delegation test: does a human retain judgment and verify before the output has consequences?
  • Accuracy accountability sits with the publisher, not the vendor and not the model.

Ready to test this domain?

Drill mode gives instant feedback: pick a wrong answer and you immediately see why it is wrong.

Start the drill

Not an official source. This is a free, independent study resource from siasola, built by an engineer who sat these exams and wanted better prep material to exist. It is not affiliated with, endorsed by, or sponsored by Anthropic. Claude is a trademark of Anthropic, PBC. Exam facts follow the official exam guides; registration for the real exams happens through the Anthropic Partner Academy and Pearson VUE, not here.