Courseiva

CCAR-P Governance, Safety, and Risk Management Practice Question

A hospital network is drafting its AI risk register for a Claude-based discharge-summary assistant. The governance lead wants entries that describe residual risk after existing controls are applied, and that can be assigned an owner and a review cadence. Which TWO characteristics must each risk register entry have to meet this standard? (Choose two.)

⚠ Common exam trap

The trap here is padding risk entries with supporting evidence and business-case data, which feels thorough but leaves the register without the ownership and residual-exposure statements that make it actionable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A residual risk rating that reflects the effect of the controls already in place.

An operational risk register entry must state the exposure that remains after controls and must have someone accountable for watching it on a schedule. Residual rating captures what is actually at stake post-mitigation, while owner and review interval ensure the entry is revisited and acted upon as the assistant and its clinical context change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A verbatim copy of the vendor's model card and system prompt.

    Why it's wrong here

    Model cards and prompts are useful supporting evidence, but they are inputs to risk analysis, not register entries. Pasting them verbatim produces documentation without an owner, rating, or review date, so the entry cannot be tracked, escalated, or closed, and it will not satisfy the governance lead's requirement for actionable residual-risk records.

  • ✗

    A list of every employee who has ever accessed the assistant.

    Why it's wrong here

    Access rosters belong to identity and access management records, not to a risk register line item. Attaching exhaustive user lists to each risk bloats the register with data that changes constantly and provides no statement of exposure, ownership, or treatment, so it does not help the network manage the discharge-summary risk.

  • ✓

    A residual risk rating that reflects the effect of the controls already in place.

    Why this is correct

    The governance lead explicitly asked for residual risk, meaning the exposure remaining after existing mitigations. Recording only inherent risk overstates exposure and misdirects investment; recording only that a control exists hides whether it is effective. A residual rating ties the register to the actual decision the network faces about accepting or further reducing exposure.

  • ✗

    A projected cost saving attributed to deploying the assistant.

    Why it's wrong here

    Expected financial benefit is a business-case input, not a risk attribute. Mixing savings estimates into risk entries conflates upside with downside and can bias ratings toward understating harm. The register needs a residual exposure statement with an owner and review cycle, which a savings figure does not supply.

  • ✓

    A named accountable owner and a defined review interval.

    Why this is correct

    Risk entries without an owner and a review cadence decay into static documents. Naming an accountable owner establishes who must act when the risk materializes or the tolerance changes, and a defined review interval forces periodic reassessment as the model, prompts, and clinical workflows evolve. Together they make the register an operational instrument rather than an archive.

About these practice questions

One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Anthropic exam blueprint

This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.