CCAO-F - Governance, Risk, and Responsible Use (15% of the exam) - Section 6.3

Follow organizational AI policies and governance standards.

Working within an organisation's AI policy: approved tools and accounts, permitted data, disclosure requirements and approval processes. Candidates should follow policy even when a shortcut looks harmless.

AI use policyapproved toolsdisclosureapproval processes

Practice question for this objective

Free sampleGovernance, Risk, and Responsible Useeasy

A finance assistant at a regional bus operator received information security approval to upload last year's fuel invoices to the company's Claude account to prepare a cost summary for the board. A month later, the fleet manager asks her to use the same invoices, plus drivers' fuel-card records, to identify which drivers refuel most often. Her approval request described only the board cost summary. What should she do?

  • AGo ahead, because the invoices were already approved for use in the company's account.
  • BGo ahead with the invoices only, and leave the fuel-card records out of the analysis.
  • CAsk Claude to check the new request against the policy before uploading the records.
  • DSeek new approval, since the earlier one covered a different purpose and different data. Correct
An approval to use data with Claude covers the purpose and data described in the request, so a new purpose needs fresh approval. Approval processes assess a specific use: what data, for what purpose, with what risk. Analysing individual drivers' behaviour is a different purpose with personal records the original review never considered, so the earlier approval does not extend to it. Asking again lets the reviewers weigh the new risk.

Why A is wrong: Reusing approved material feels safe, but the approval covered a stated purpose. A new purpose that looks at individual drivers was never assessed.

Why B is wrong: Dropping the new records seems to stay inside the approval, but the task itself has changed to analysing individual drivers. The purpose, not just the data, needs approving.

Why C is wrong: Asking Claude feels like a diligence step, but Claude has no authority to grant approval. The information security team decides, and it has not been asked.

Why D is correct: Approval is granted for the use described in the request. The new task adds personal records and a new purpose, so it needs its own approval before any upload.

See more CCAO-F practice questions, answers explained.

Exam traps in Governance, Risk, and Responsible Use

Answers that look right on this material and are not. Each one is a distractor from a different question in the CCAO-F bank for this domain.

  • Connect the drive straight away, since the administrator has already enabled the connector

    Why it is wrong: An available connector can look like permission to use it. Enabling a feature is a technical setting, and the stated policy still requires information security approval before the content is used.

  • Install it, since an extension built on Claude counts as the approved Claude tool.

    Why it is wrong: The shared name makes this tempting, but approval attaches to the specific tool and account the organisation assessed. A third-party extension handles data under its own terms, whatever model sits behind it.

  • Remove the supplier name from the schedule and upload it with the other bid documents

    Why it is wrong: Removing names is the right step for Confidential documents, so it is easy to apply it here too. The policy says Restricted material may not be used in any form, so redaction does not make this upload allowed.

Examworthy is not affiliated with or endorsed by Anthropic. Original, blueprint-aligned practice material only.