Claude Certification Program · v1.0 · Effective July 2026 · All four tracks open

Home › Study guides › CCAR-P › Domain 5

CCAR-P · Domain 5 of 7 · 5 lessons · about 111 min

Domain 5: Governance, Safety & Risk Management

Governing Claude solutions: guardrails, failure modes, human review, GDPR, HIPAA and FedRAMP, and bias, fairness and transparency. 14% of CCAR-P.

14%Of the exam
~9Questions on exam day
5Free lessons
27Practice questions here

This domain is 14% of CCAR-P, about 9 of the 63 questions. It covers what can go wrong with a Claude solution and the controls that keep it within the law, within policy and within what the people affected by it can reasonably expect.

The vocabulary: a guardrail is a control that checks what goes into or comes out of the model, or what an agent is allowed to do. Prompt injection is text in the model's input that tries to override its instructions. Human-in-the-loop means a person approves or reviews some outputs before they take effect. GDPR, HIPAA and FedRAMP are, respectively, the EU data protection regulation, the US health privacy law and the US federal cloud security authorisation programme.

The recurring test: enforce in the system, in proportion to the risk. A rule in the prompt is guidance, not a control; the check that must hold goes in code, permissions or a review step, and the heaviest controls go where the harm would be greatest. Options that rely on the model's good behaviour, or that put every output in front of a human regardless of risk, are usually the distractors.

What the exam guide tests

The official CCAR-P guide lists 5 objectives for this domain. Exam questions are written against them, and so are the lessons: each row says where it is covered.

#ObjectiveLesson
5.1Implement guardrails and safety controls5.1
5.2Identify risks, limitations, and failure modes of LLM systems5.2
5.3Apply human-in-the-loop validation strategies5.3
5.4Ensure compliance with regulations (e.g., GDPR, HIPAA, FedRAMP)5.4
5.5Address ethical AI considerations (bias, fairness, transparency)5.5

Lessons

  1. 5.1 Guardrails in layers: input, model, output and action controlsHow to layer input, model, output and action guardrails, why preventive beats detective, what a failed check should do, and how to test over-blocking.22 min
  2. 5.2 Risks, limitations and failure modes: from threat model to risk registerWhat a language model cannot promise, the failure modes a system adds, which to design around rather than prompt around, and how to keep a risk register.22 min
  3. 5.3 Human-in-the-loop validation: putting review where the risk isWhere a person should approve, spot-check or monitor Claude's output, how to make that review real, and how to build and record approval gates in agents.22 min
  4. 5.4 Compliance by design: GDPR, HIPAA and FedRAMP on ClaudeHow an architect turns GDPR, HIPAA and FedRAMP into design constraints for Claude: data maps, BAAs, retention, residency and authorised environments.22 min
  5. 5.5 Bias, fairness and transparency when Claude helps decide about peopleWhere bias enters a Claude solution, how to test for it with counterfactual pairs and group breakdowns, which mitigations hold, and what people must be told.23 min

Practice question

From the CCAR-P bank, tagged to this domain. Every answer option is explained. Nothing is stored, nothing to sign up for.

27 CCAR-P questions on this domain, free

The domain quiz in the question bank draws 10 random questions from the 27 tagged to Governance, Safety & Risk Management, scores them and explains every option. Repeat it until the weak spots are gone, then sit the 63-question timed simulator.

Open the CCAR-P question bank → Start lesson 5.1 →

The question bank is free. It asks for an account only because the quiz engine has to store answers to score them and show which domains are weak. The questions on this page need nothing.