CCAO-F Prep0/30
Lesson 6.3 · D6 Governance, Risk & Responsible Use · 5 min

Follow organisational AI governance policy

Policy applies under time pressure and regardless of who asks; concerns go through the proper channel.

What the exam tests

Choosing the right response when a manager, deadline or convenience pushes against policy.

Key ideas

Approved tools only
If the approved workspace is down or slow, report it; don't switch to a personal or unapproved tool.
Required reviews and disclosures
Follow approval steps and disclosure requirements in policy, contracts and regulation, even for “low-risk” flash sales or urgent work.
Seniority doesn't override
A manager's request doesn't authorise breaching policy or ethics. Decline and escalate.
Report incidents
Confidential data in an unapproved tool, exposed API keys or secrets, or misuse: report through the incident or security process so it can be assessed. Don't hide it or fix it quietly.
Improve policy properly
If a control is slowing work, raise it through governance rather than working around it.

Common traps

  • “Just this once” exceptions.
  • Asking Claude to approve in place of the named approver.
  • Deleting evidence to protect a colleague.
Remember

Follow the policy, then raise the problem through the right channel.

Practise D6 questions