CCAR-P Governance, Safety, and Risk Management Practice Question
Which document is essential for an organization to maintain when preparing for an AI audit?
⚠ Common exam trap
Candidates often confuse the AI Risk Register with technical logs or performance dashboards. They fail to realize that auditors need a high-level governance document, not just raw system data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An up-to-date AI Risk Register.
An AI audit requires proof of governance, testing, and safety measures. An AI Risk Register, which documents identified risks, their potential impact, and the mitigation strategies in place, is essential. It provides auditors with a clear history of how the organization identifies, assesses, and manages its AI-related risks, demonstrating a mature approach to safety and compliance that satisfies both internal and external oversight requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A list of all model parameters and hyperparameters.
Why it's wrong here
While documenting model parameters is useful for technical reproducibility, it is not the primary focus of an AI audit. Auditors are more interested in the governance processes, risk management strategies, and safety controls, rather than the specific hyperparameter settings used for a particular model version.
- ✓
An up-to-date AI Risk Register.
Why this is correct
An AI Risk Register is a critical document for any compliance or safety audit. It tracks potential risks, their severity, and the controls implemented to mitigate them. It serves as evidence that the organization is actively managing its AI safety profile and following best practices in governance.
- ✗
The raw training data files for the LLM.
Why it's wrong here
The raw training data is rarely provided to auditors due to intellectual property concerns and privacy regulations. Instead, auditors look for evidence of data governance, such as policies on data sourcing, handling, and filtering. The register and governance policies are far more relevant to an audit than raw data.
- ✗
A transcript of every single user interaction.
Why it's wrong here
Storing every user interaction is a privacy nightmare and is not required for an audit. Instead, organizations should provide samples and the methodology used to audit those interactions for safety. Blanket storage of all user data is unnecessary and potentially violates data protection regulations like GDPR or CCPA.
About these practice questions
This CCAR-P question is part of Courseiva's 262-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Anthropic exam blueprint
This CCAR-P practice question is part of Courseiva's free Anthropic certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCAR-P exam.