CCAR-P Governance, Safety, and Risk Management Practice Question
An insurance company is preparing an AI risk register for its Claude-based claims triage system. The risk team must document controls that reduce the chance of biased or inconsistent decisions affecting policyholders. (Choose two.)
⚠ Common exam trap
The trap here is equating a larger or more capable model, or longer outputs, with reduced bias, when fairness must be measured and governed through versioned criteria and human recourse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define and version the decision criteria and prompts used for triage, and re-validate them against a representative dataset whenever they change.
Fairness controls require both a defined, versioned decision logic that is re-validated against representative data and a human appeal path that catches harmful outcomes the model produces. Together they create a preventive and a corrective layer. Throughput, token budgets, and model size describe performance or capability, not equity, and cannot substantiate a claim that biased or inconsistent decisions have been controlled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Collect aggregate throughput metrics showing how many claims the system processes per hour during peak periods.
Why it's wrong here
Throughput measures operational efficiency, not fairness. A system can process claims quickly while still producing systematically biased or inconsistent outcomes, so throughput data provides no signal about the risk being managed. Including it as a control would misrepresent coverage in the risk register and could give false assurance to reviewers examining the triage system's equity posture.
- ✓
Define and version the decision criteria and prompts used for triage, and re-validate them against a representative dataset whenever they change.
Why this is correct
This is correct because bias and inconsistency often enter through drifting criteria or undocumented prompt edits. By versioning the decision logic and re-validating against a representative dataset on every change, the team can detect shifts in outcomes across demographic groups and demonstrate that the criteria were intentionally designed and reviewed, which is core evidence for a defensible risk register entry.
- ✗
Raise the model's max_tokens setting so the triage system can produce longer, more detailed justifications for each decision.
Why it's wrong here
Output length has no relationship to fairness or consistency. Longer justifications can be equally biased, and expanding the token budget increases cost and latency without adding any control. Nothing about this setting constrains how decisions are made or verified, so it does not belong in a risk register as a mitigation for biased or inconsistent triage outcomes.
- ✓
Establish a human review and appeal path so affected policyholders can challenge a triage outcome and have a person re-examine the decision.
Why this is correct
This is correct because a documented human review and appeal path provides a corrective control when model output is wrong or unfair. It ensures no adverse decision is final without recourse, which is a standard expectation in regulated insurance contexts. Recording these appeals and their resolutions also generates data the risk team can use to quantify residual bias and refine the register over time.
- ✗
Switch to the largest available Claude model on the assumption that greater capability automatically eliminates biased outputs.
Why it's wrong here
Model scale does not guarantee fairness. A more capable model can still reproduce biases present in its training data or in the prompts it receives, and it may express them more fluently, which can make them harder to detect. Treating a model upgrade as a bias control removes the need for measurement and review, which is precisely the discipline a risk register should enforce.
About these practice questions
One of 262 original CCAR-P practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.