Map each named risk to a specific control: versioned model IDs for change control, centralized gateways and policy for shadow AI, a safety committee for oversight, and grounding plus human review for factual accuracy. The key skill is justifying why a chosen control directly mitigates the stated risk.
Start practicing
Governance, Safety, and Risk Management — choose a session length
Free · No account required
Domain overview
This domain covers enterprise governance, safety, and risk management for Claude deployments: model versioning, usage policy enforcement, AI review bodies, and controls for high-stakes outputs. Questions are scenario-based, asking you to select governance controls that directly mitigate named risks such as silent model changes, shadow AI, and hallucination in regulated workflows.
Exam objectives
Pinning dated model IDs like claude-3-5-sonnet-20240620 versus floating aliases in production
Using Amazon Bedrock, Vertex AI, or the Anthropic Console to centralize and monitor Claude access
Anthropic usage policies, acceptable use, and trust/safety review processes for enterprise deployments
Grounding and verification controls such as citations, RAG, and human-in-the-loop review for high-stakes outputs
Assuming a generic alias like claude-3-5-sonnet is stable, when it can silently point to a newer snapshot and change behavior.
Treating a safety committee as an approval bottleneck rather than an ongoing risk-oversight and policy body.
Relying on model self-confidence or prompt wording alone to prevent hallucinations instead of retrieval grounding and human review.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A global financial institution must ensure that all prompt data and model responses for their Claude 3.5 Sonnet implementation remain within the European Union to comply with strict GDPR data residency requirements. Which architecture strategy best fulfills this governance mandate?
2An architect is defining the Shared Responsibility Model for a company deploying Claude via the Messages API. Which THREE tasks are the sole responsibility of the customer (the 'User') rather than Anthropic?
3Refer to the exhibit. An architect reviews this API request log. Despite the 'Ignore all previous safety instructions' directive, Claude refuses to provide instructions for bypassing the firewall. Which safety mechanism is primarily responsible for this refusal?
4A security architect is configuring the Anthropic Console for a large enterprise. Which TWO features should be implemented to enforce centralized governance and reduce the risk of unauthorized account access?
5An organization is deploying Claude to provide automated coding assistance. To manage the risk of generating insecure code or violating open-source licenses, which governance step is most effective?
6When conducting a risk assessment for a new Claude-based customer support bot, which TWO factors should be prioritized as 'High Risk' according to Anthropic's safety guidelines?
7Refer to the exhibit. The user is attempting to trick the model into revealing sensitive information by claiming a high-clearance role. This is an example of which security threat, and how does the 'system' prompt help mitigate it?
8An architect needs to implement a 'Red Teaming' process for a new Claude deployment. What is the primary objective of this activity in the context of AI governance and safety?
9When deploying Claude in a production environment, an architect notices that the model occasionally generates responses that are slightly biased. What is the most appropriate governance-first approach to address this?
10A company is using Claude to process customer feedback. They want to ensure that if a customer mentions self-harm or illegal activities, the system immediately flags this for a human moderator. Which tool is best suited for this specific governance task?
11Which governance risk is most directly mitigated by using 'Versioned' model identifiers (e.g., 'claude-3-5-sonnet-20240620') instead of the generic 'claude-3-5-sonnet' alias in production?
12An organization requires strict adherence to data residency requirements for PII processed by Claude. Which strategy best ensures that customer prompts and completions remain within a specific geographic boundary while utilizing Anthropic's API?
13An enterprise is deploying Claude for high-stakes financial analysis. Which TWO governance controls should be implemented to mitigate the risk of model hallucinations and ensure factual accuracy?
14Refer to the exhibit. An audit of an Anthropic API configuration reveals the policy shown. What is the primary governance concern with this implementation?
15Which governance model best minimizes the risk of 'shadow AI' usage within a large corporation?
16A healthcare provider is using Claude to summarize patient clinical notes. Which governance control is most critical to prevent potential HIPAA violations?
17Which approach best aligns with the principle of 'least privilege' when providing API access to internal teams?
18An enterprise wants to deploy an AI-powered customer service agent. What is the most important governance consideration when integrating with internal customer databases?
19Which THREE strategies are effective for managing bias in AI-driven decision-making systems?
20What is the primary role of a 'Model Card' in the context of enterprise AI governance?
21When designing an LLM application, what is the best strategy for managing 'system instructions' (system prompts) to prevent unauthorized alteration?
22Refer to the exhibit. An organization uses this configuration to prevent the model from continuing the conversation as the user. What is the governance benefit of this configuration?
23When integrating Anthropic's API with a CI/CD pipeline for automated testing, which security practice is mandatory to avoid credential leakage?
24An organization is deploying Claude for a customer support chatbot. They need to ensure that PII is not processed or stored by the model. Which approach best aligns with Anthropic’s safety governance standards?
25Refer to the exhibit. An application developer is testing a model endpoint. Which security control should be prioritized to prevent the specific risk demonstrated in the exhibit?
26A company is integrating Claude into a high-stakes automated decision-making system. Which TWO practices should be implemented to align with Anthropic’s Responsible AI principles?
27An organization is conducting a risk assessment for an AI application. They are concerned about 'model drift' over time. Which governance action is most appropriate to manage this risk?
28What is the primary role of an AI Safety Committee in an enterprise architecture?
29A firm is building a financial advisor chatbot. Which safety measure is most critical for preventing the model from providing unauthorized investment advice?
30Which document is essential for an organization to maintain when preparing for an AI audit?
31Refer to the exhibit. The model's response to the user's request is a safety violation. How should the architecture be updated to improve safety?
32An organization is evaluating the safety of an LLM-based agent. What is the 'Red Teaming' process in this context?
33What is the primary risk associated with 'Prompt Injection' attacks in enterprise AI?
34Which governance practice is most effective for managing 'Third-Party Model Risk'?
35When implementing AI safety policies, which THREE components should be included to ensure effective operationalization?
36An organization discovers that their AI application is producing biased outputs on certain demographic groups. What is the correct governance step to take first?
37An organization is deploying a customer-facing chatbot using Claude 3.5 Sonnet and needs to ensure the model adheres to ethical guidelines without relying solely on manual moderation. Which core Anthropic safety framework is primarily responsible for the model's ability to self-correct based on a predefined set of principles during its training phase?
38A security architect is performing red-teaming on a new Claude-powered application. They are specifically testing for 'jailbreaking' attempts where a user tries to bypass safety filters by using roleplay or adversarial framing. Which TWO strategies are most effective for mitigating this specific risk at the architectural level?
39Refer to the exhibit. Which component in this API request represents the primary governance layer for preventing model bypass of organizational policies?
40Under the shared responsibility model for AI safety, which task is the primary responsibility of the customer when using Anthropic's APIs?
41An enterprise wants to minimize the risk of PII (Personally Identifiable Information) being processed by Claude while maintaining low latency. Which architectural approach provides the best balance of safety and performance?
42A large enterprise is setting up its governance framework for Anthropic API usage. Which THREE features provided by the Anthropic Console are essential for maintaining auditability and administrative control?
43A fintech company wants to use Claude to generate personalized financial advice for retail customers. The compliance team mandates that all AI-generated advice must be traceable to a specific model version and configuration for audit purposes. Which governance control best satisfies this requirement?
44A startup is using Claude to generate marketing copy. The legal team is concerned about potential copyright infringement if the model reproduces copyrighted text. Which governance measure should the startup implement to best mitigate this risk?
45A multinational corporation is using Claude to process employee feedback surveys. The data includes sensitive personal opinions. The governance team must ensure that the AI system complies with the EU's General Data Protection Regulation (GDPR). Which control is most critical to address the 'right to explanation' requirement for automated decision-making?
46A multinational bank runs a Claude-powered assistant that drafts internal credit memos. Auditors require the bank to prove that every generated memo can be traced to the exact human who requested it, the data sources the model retrieved, and the decision it influenced. Which governance capability should the architect implement first to satisfy this requirement?
47A retail company is building a governance program for a customer-facing Claude agent that can issue refunds and update order records. The risk committee wants controls that limit the blast radius of a compromised or misbehaving agent. (Choose two.)
48A software company is using Claude to generate code snippets for internal projects. The security team is concerned that the model might inadvertently suggest code with known vulnerabilities. Which governance control should be implemented to best mitigate this risk?
49A fintech startup wants to use Claude to generate marketing copy that references competitor products by name and makes performance comparisons. Legal counsel asks the architect which governance step is most appropriate before this capability goes live.
50A fintech company's risk committee is operationalizing a governance program for Claude-powered customer support agents. They must demonstrate to regulators that model behavior changes are tracked, attributable, and reversible. Which TWO practices best satisfy this requirement? (Choose two.)
51A financial services firm runs a Claude-powered loan pre-screening agent that reads applicant emails and drafts a preliminary recommendation. The firm's risk committee insists that no automated decision may be finalized without a documented human review step. Which control most directly satisfies this requirement while preserving the agent's throughput?
52An enterprise architect is designing a Claude deployment where a single prompt may contain data belonging to customers in the EU, Brazil, and California. The legal team requires that each data subject's rights be honored independently and that processing purposes be documented per jurisdiction. Which architectural approach best supports this requirement?
53A multinational bank deploys Claude to draft internal policy summaries for staff in the EU and Singapore. Legal requires that personal data embedded in employee questions never leave its region of origin, but the bank wants a single application codebase. Which architecture most directly enforces the residency requirement?
54A financial services firm runs Claude-powered document review for loan applications. The CISO asks the platform team to produce evidence that every model change affecting production was reviewed and approved before deployment. Which governance mechanism most directly satisfies this requirement?
55A multinational insurer wants to quantify how often its Claude-based claims assistant produces outputs that violate its internal tone and fairness policy before it expands the pilot to three new countries. The compliance team needs a repeatable, statistically defensible measurement rather than anecdotal review. Which approach best meets this need?
56An insurer uses a Claude-based agent that can call internal tools to look up policy details. During review, the safety team finds that a document uploaded by a claimant contains text instructing the agent to email the full policy database to an external address. The agent has an email tool available. Which control most directly prevents this class of failure?
57A media company uses Claude to moderate user-generated comments at high volume. The risk team wants a control that detects when the moderation model's behavior drifts, for example becoming unusually permissive or aggressive, before it affects the community at scale. Which control best fits this need?
58A bank is deploying a Claude agent that can call internal tools to move funds between accounts. Risk leadership wants a control that limits the blast radius if the agent is manipulated into performing unauthorized transfers. Which control best addresses this requirement?
59A hospital network is drafting its AI risk register for a Claude-based discharge-summary assistant. The governance lead wants entries that describe residual risk after existing controls are applied, and that can be assigned an owner and a review cadence. Which TWO characteristics must each risk register entry have to meet this standard? (Choose two.)
60A media company wants a lightweight, recurring review of its Claude-powered content moderation assistant. The team has no dedicated compliance staff and wants the cheapest process that still produces defensible evidence of oversight. Which approach fits best?
61An insurance company is preparing an AI risk register for its Claude-based claims triage system. The risk team must document controls that reduce the chance of biased or inconsistent decisions affecting policyholders. (Choose two.)
62A media company uses Claude through the Anthropic API to draft articles. Legal counsel asks the platform team to demonstrate that every published draft can be traced to the exact model behavior that produced it, even after Anthropic deprecates older models. The team currently calls the alias claude-sonnet-4-5. Which change best satisfies counsel's requirement?
63A public-sector agency must demonstrate to an external auditor that its Claude-based citizen inquiry assistant was operated in line with its approved safety policy throughout the prior fiscal year. The agency has no centralized record of which policy text was in force, when it changed, or who approved each change. Which governance practice should the agency institute first?
64A government agency wants assurance that its Claude deployment will not be used to generate content that violates Anthropic's usage policies. Which action most directly supports ongoing policy compliance?
65A financial services firm runs a Claude-powered agent that can call internal tools to move funds between accounts. Risk management wants a control that prevents the agent from executing a transfer above a threshold without human sign-off, and that remains effective even if the model is manipulated through injected content in a retrieved document. Which control best meets this requirement?
66A software company's internal AI review board is defining escalation criteria for its Claude-powered support assistant. The board wants a rule that reliably routes the highest-consequence cases to human specialists rather than relying on the model's own confidence statements. Which escalation design best achieves this?
67A multinational retailer operates Claude in three regions and must prove that customer data from each region never leaves that region, even during model upgrades. Which architectural approach best satisfies this requirement?
68A retail company's legal team discovers that several engineering squads have been calling the Anthropic API with personal API keys obtained on individual credit cards, outside the corporate agreement. Leadership wants a governance model that both eliminates this practice and preserves the ability to audit all Claude usage centrally. Which governance model best achieves this?
69A software vendor is preparing for a customer security review of its Claude-powered support assistant. The customer asks how the vendor prevents the assistant from leaking one tenant's data into another tenant's conversation. Which architectural control most directly addresses this concern?
Map each named risk to a specific control: versioned model IDs for change control, centralized gateways and policy for shadow AI, a safety committee for oversight, and grounding plus human review for factual accuracy. The key skill is justifying why a chosen control directly mitigates the stated risk.
The Courseiva CCAR-P question bank contains 69 questions in the Governance, Safety, and Risk Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Governance, Safety, and Risk Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included