AI Cert Prep
Type to search documentation.

AI Leadership

D3 · Governance and Risk

An AI governance operating model, a risk taxonomy, data handling and residency, vendor and model risk, the enterprise controls in ChatGPT Business and Enterprise, and the difference between governance that enables and governance that is theatre.

This domain carries 18% of the mock — roughly 9 of 50 items. It tests whether you can build governance that enables safe adoption rather than governance that merely performs caution. Leaders who get this wrong either block everything (and drive shadow AI) or wave everything through (and inherit an incident). The material: a governance operating model with clear ownership and decision rights, a risk taxonomy you can apply to any use case, data-handling and residency rules, vendor and model risk, and the concrete enterprise controls available in ChatGPT Business and Enterprise. This connects directly to the credential landscape and to adoption: governance that is all friction is the surest way to kill adoption.

What you need to know

Governance is an operating model, not a document. It names who owns AI risk, who decides what, which policies apply, where use cases are reviewed, and how exceptions are granted. A usable risk taxonomy spans accuracy, privacy, security, IP, regulatory, reputational and workforce risk — each with a different owner and control. Data handling turns on classification and residency: what data may enter a tool, where it is processed, and whether it trains a model. The enterprise editions of ChatGPT ship real controls — SSO, SCIM, EKM, RBAC, compliance logs, data residency in ten regions, and no training on business data by default — that let a leader say “yes, safely” instead of “no”. The recurring judgement is telling enabling governance from governance theatre.

Learning objectives

By the end of this page you should be able to:

  1. Design an AI governance operating model with ownership, decision rights, policy, review boards and exception paths.
  2. Apply a seven-category risk taxonomy to classify and control any AI use case.
  3. Decide data-handling and residency rules from data classification, not habit.
  4. Assess vendor and model risk, including data-training and residency posture.
  5. Map enterprise controls in ChatGPT Business/Enterprise to specific governance requirements.
  6. Distinguish governance that enables safe adoption from governance that is theatre.

3.1 The governance operating model

Governance fails when nobody can say who decides. A working model answers five questions explicitly.

ElementQuestion it answersTypical answer
OwnershipWho is accountable for AI risk overall?A named executive sponsor (often CIO/CDO/CISO jointly)
Decision rightsWho approves a use case at each risk tier?Low: team lead; medium: function + risk; high: review board
PolicyWhat rules bind everyone?Acceptable-use, data-classification, human-review policy
Review boardWhere are non-standard cases judged?A small cross-functional AI review board, meeting on a cadence
Exception pathHow do you say yes to a hard case safely?Time-boxed, conditions attached, logged, revisited
text
AI GOVERNANCE OPERATING MODEL
┌──────────────────────────────────────────────────┐
│ Executive sponsor (owns AI risk) │
└───────────────┬──────────────────────────────────┘
│
┌───────────┴───────────┐
▼ ▼
Policy & standards AI review board
(acceptable use, (cross-functional:
data classes, risk, legal, security,
human review) data, a business voice)
│ │
▼ ▼
Tiered decision rights Exception path
low → team (time-boxed, conditioned,
medium → function+risk logged, reviewed)
high → review board

The tiering is the load-bearing idea: most decisions never reach the board. A governance model that routes every request to a committee is theatre — it produces delay, not safety.

Assessment signal

Stems about “who approves”, “escalation”, “a committee reviews every request”, “an exception” are testing the operating model. Correct answers tier decisions and reserve the board for genuine risk; distractors centralise everything or leave approval undefined.

3.2 The risk taxonomy

You cannot control a risk you cannot name. Seven categories cover almost every AI use case, and each has a distinct owner and control.

RiskWhat it isPrimary controlOwner
AccuracyWrong or fabricated output relied uponHuman review proportional to stakesBusiness owner
PrivacyPersonal data mishandledData classification, minimisation, residencyDPO / privacy
SecurityPrompt injection, data exfiltration, accessRBAC, SSO, monitoring, secure connectorsCISO
IPConfidential input leaks; output IP unclearNo-training terms, input rules, contract reviewLegal
RegulatoryBreach of sector or data lawLegal review, residency, audit logsCompliance
ReputationalPublic harm, biased or off-brand outputReview gates on external content, brand rulesComms / brand
WorkforceFear, deskilling, unfair impactTransparent change plan, enablementHR (D5)

The leadership point: these risks do not share an owner, so a single “AI risk lead” cannot carry them all. Governance assigns each category to the function that already owns that risk class.

3.3 Data handling and residency

Almost every AI incident traces to data — the wrong data entering a tool, or leaving a jurisdiction it should not. Two decisions govern this: classification (what may enter) and residency (where it is processed and stored).

text
Data class May it enter an AI tool?
─────────────────────────────────────────────
Public Yes
Internal Yes, in a governed workspace
Confidential Only in a governed workspace with
no-training terms + access control
Regulated / PII Only with a DPIA/legal sign-off,
residency confirmed, minimised
Secret / restricted No, unless explicitly cleared

The default that changes the whole risk conversation: in ChatGPT Business and Enterprise, business data is not used to train OpenAI’s models by default. That single fact is often the difference between “no” and “yes, in the governed workspace” for confidential data.

3.4 Vendor and model risk

Choosing a provider is a governance decision, not just a procurement one. Assess vendors on the controls that matter to your risk taxonomy.

Vendor questionWhy it matters
Is our data used to train models?Default no-training on business data protects IP and privacy
Where is data processed and stored?Residency drives regulatory compliance
What identity and access controls exist?SSO, SCIM, RBAC gate who can do what
What logging and audit is available?Compliance API logs and audit events enable oversight
What certifications are held?SOC 2 Type 2, ISO 27001/27017/27018/27701 signal maturity
How is encryption handled?TLS 1.2 in transit, AES-256 at rest; EKM for key control

Model risk adds a second layer: models change, deprecate and behave differently. A governed programme pins which models are approved for which risk tier and reviews changes — not every new model is automatically fit for a regulated workflow.

3.5 Enterprise controls in ChatGPT Business/Enterprise

A leader must know which control answers which requirement, because “we can’t use AI, it’s not secure” is usually false — the controls exist, they simply have to be turned on.

ControlWhat it doesGovernance need it meets
SAML SSOCentral sign-in via your IdPAccess control, offboarding
SCIMAutomated user provisioning/deprovisioningJoiner-mover-leaver hygiene
EKMEnterprise-managed encryption keysKey control for regulated data
RBACRole-based permissionsLeast-privilege, separation of duties
Compliance API logs / audit eventsExportable activity recordsOversight, investigations, audit
Data residency (10 regions)Choose processing/storage regionRegulatory and sovereignty needs
No training on business data (default)Inputs not used to train modelsIP and privacy protection
Domain verification, IP allowlistingControl access surfaceReduce account and network risk
SOC 2 Type 2, ISO 27001/17/18/27701Independent assuranceVendor risk sign-off

Note the split: SSO, SCIM, EKM, RBAC and the ten-region residency and default no-training posture are enterprise-grade capabilities; a leader mapping a requirement to a plan should confirm the specific edition rather than assume every control is in every tier.

Assessment signal

Stems naming a requirement — “we must deprovision leavers automatically”, “keep EU data in the EU”, “prove who did what”, “control our own keys” — are asking you to name the control: SCIM, data residency, compliance logs, EKM respectively. Distractors reach for a blanket ban or a custom build.

3.6 Governance that enables vs governance that is theatre

The most examined leadership judgement in this domain is the difference between control that reduces risk and ritual that only signals caution.

Enabling governanceGovernance theatre
Tiered decision rights; most cases decided fastEvery request goes to a monthly committee
Clear acceptable-use policy people can applyA 90-page policy nobody reads
Approved tool list with a safe defaultBlanket ban that drives shadow AI
Exception path that says “yes, with conditions”Exceptions impossible, so people route around
Controls turned on (SSO, RBAC, logs)A signed policy but no technical control
Review focused on genuinely risky casesSign-off ritual on trivial ones

Theatre feels safe and is dangerous: it delays value and increases risk, because a blocked workforce moves to ungoverned personal tools. Enabling governance channels demand into the governed workspace where the controls actually apply.

Decision framework

The G-U-A-R-D use-case review

Route each proposed use case through five checks. It replaces “does the committee like it?” with a repeatable test that most cases pass without a committee at all.

LetterCheckOutcome
Grade the riskWhich taxonomy categories apply, at what tier?Sets the decision right
Use-of-dataWhat data class enters; is residency and no-training satisfied?Blocks unlawful inputs
Accountable humanWho reviews output and owns the decision?Ensures human-in-the-loop where needed
Rights & accessAre SSO/RBAC/SCIM correctly scoped?Least-privilege enforced
Document & revisitIs the decision logged with a review date?Auditability, not permanence

Low-tier cases clear G-U-A-R-D in minutes at the team level; only high-tier cases reach the review board.

Common mistakes

MistakeWhy it happensWhat to do instead
Routing every request to a committeeFeels thorough and safeTier decision rights; reserve the board for high risk
Blanket ban on AI toolsFear of the unknownProvide a governed default; ban drives shadow AI
Treating governance as a documentA policy is easy to produceTurn on technical controls; policy without control is theatre
Assuming enterprise tools are insecureOld intuition about SaaSMap requirements to real controls (SSO, EKM, residency, no-training)
One “AI risk owner” for all riskSimplicity in an org chartAssign each taxonomy category to its natural owner
Ignoring data residencyIt is invisible until auditedConfirm processing region against the data class
No exception pathSimplicity, or cautionProvide a time-boxed, conditioned, logged exception route
Approving a model for all tiers because it is newestNewer feels betterPin approved models per risk tier; review model changes
Confidential data blocked reflexively“AI trains on everything” mythDefault no-training in governed workspaces enables safe use

Scenario challenge

Scenario. You chair the AI review board at a European bank. Adoption is stalling: staff complain that every AI request — even summarising a public regulator circular — must wait for the monthly board, and three teams have quietly started using personal ChatGPT accounts on their phones to get work done. Meanwhile the head of wealth management wants to pilot an assistant that reads client portfolio data (regulated, EU-resident) to draft review notes, and legal is nervous about “AI training on client data”. The CISO asks you to fix both the bottleneck and the shadow-AI problem.

Expert reasoning trace.

  1. Diagnose the bottleneck as theatre. Sending a public-circular summary to a monthly board is pure ritual: it adds delay and, worse, it causes the shadow-AI risk by making the governed path unusable. The fix is tiered decision rights — public and internal-class, low-stakes use cases decided at team level under a clear policy, with only high-risk cases reaching the board.

  2. Address shadow AI by making the governed path faster than the ungoverned one. Personal-account use is the real incident risk: no logging, no residency control, no no-training guarantee. I provide a governed ChatGPT Business/Enterprise workspace with SSO and SCIM (so access follows employment) and communicate that it is both allowed and faster than waiting for the board. Enabling governance channels the demand back inside the controls.

  3. Apply G-U-A-R-D to the wealth-management pilot. Grade: privacy + regulatory + reputational, high tier. Use-of-data: regulated client PII, so residency must be EU (ChatGPT Enterprise’s EU region) and the no-training-on-business-data default must be confirmed in writing — which directly answers legal’s fear. Accountable human: an adviser reviews and owns every drafted note. Rights: RBAC limits the assistant to the advisers who own those clients. Document: logged via the Compliance API, with a review date.

  4. Answer legal precisely, not vaguely. “AI trains on our client data” is false for the governed workspace by default; I cite the no-training default and EU residency rather than debating in the abstract. The pilot proceeds as a high-tier, conditioned exception — human review, EU residency, RBAC, logging — not a blanket yes and not a reflexive no.

  5. Close the loop. The board’s new job is high-risk cases and policy, not rubber-stamping trivia. Adoption recovers because the governed path is now the fast path.

Board-ready outcome: tiered decision rights end the bottleneck; a governed workspace with SSO/SCIM/logging pulls shadow AI back inside the controls; the wealth pilot proceeds under EU residency, default no-training, RBAC and human review as a documented high-tier exception; legal’s concern is answered with the specific control, not a slogan.

Assessment traps

TrapWhy it is temptingThe discriminator
Send every AI request to the review boardIt looks maximally carefulTiering is safer and faster; universal review is theatre that breeds shadow AI
Ban AI outright until “it’s proven safe”Feels like the cautious defaultGoverned workspace + controls is the safe path; bans push data to personal tools
Refuse confidential data because “AI trains on it”A common, outdated beliefBusiness data is not used for training by default in Business/Enterprise
Treat a signed 90-page policy as governanceA document is tangible proofGovernance requires technical controls turned on, not just prose
Give one person all AI risk to ownClean on an org chartEach risk category has its natural owner (DPO, CISO, legal, comms, HR)
Route EU regulated data through a US-only surfaceIt is the newest capabilityResidency must match the data class; confirm the region before routing

Practice questions

Each item states how many responses to select. Commit before revealing.

Q1 · Staff complain that summarising a public document requires monthly-board approval, and some have switched to personal ChatGPT accounts. What is the ROOT problem? (Select one)

A. Staff are simply undisciplined. B. Governance theatre: undifferentiated review creates delay that drives shadow AI. C. The model is not capable enough. D. The policy document is too short.

Answer: B. Routing low-risk work to a committee is theatre that both delays value and pushes users to ungoverned tools. Blaming staff (A) ignores the design fault; model capability (C) and policy length (D) are unrelated to the bottleneck.

Q2 · A firm must automatically remove AI-tool access when an employee leaves. Which enterprise control MOST directly meets this? (Select one)

A. EKM B. SCIM C. Data residency D. Prompt caching

Answer: B. SCIM automates provisioning and deprovisioning so access follows employment. EKM (A) controls encryption keys, residency (C) controls where data lives, and prompt caching (D) is a performance feature.

Q3 · Legal worries that client data entered into ChatGPT will train OpenAI's models. In a governed Business/Enterprise workspace, what is accurate? (Select one)

A. All input trains the model; the concern is valid. B. Business data is not used to train models by default, so the concern is addressed by the default posture plus contract confirmation. C. Training can only be stopped by building a private model. D. Only public data is ever safe to enter.

Answer: B. The default no-training-on-business-data posture directly answers the concern; confirm it in the terms. The blanket-training claim (A) is false; a private model (C) is unnecessary; restricting to public data only (D) is overly conservative.

Q4 · Which categories belong in a working AI risk taxonomy? (Select two)

A. Accuracy of relied-upon output. B. Regulatory breach exposure. C. The colour of the product UI. D. The number of prompt tokens used per day. E. The vendor’s marketing budget.

Answer: A and B. Accuracy and regulatory exposure are core risk categories with distinct owners and controls. UI colour (C), token counts (D) and vendor marketing (E) are not governance risks.

Q5 · A global firm must keep EU customers' regulated data processed within the EU. Which capability makes this possible? (Select one)

A. Faster model reasoning. B. ChatGPT Enterprise data residency, which supports processing in specific regions including the EU. C. A larger context window. D. Prompt caching.

Answer: B. Data residency lets a firm pin processing to a region such as the EU. Reasoning speed (A), context window (C) and caching (D) do not affect where data is processed.

Q6 · A single 'AI risk lead' is asked to own accuracy, privacy, security, IP, regulatory, reputational and workforce risk alone. What is the FLAW? (Select one)

A. None; one owner is simplest. B. These risks have different natural owners (DPO, CISO, legal, comms, HR); concentrating them creates gaps. C. There should be no owner at all. D. Only security matters.

Answer: B. Each risk category maps to the function that already owns that class; concentrating them in one person guarantees blind spots. A single owner (A) is not simplest in practice; no owner (C) is worse; and security alone (D) ignores the rest.

Q7 · A team wants to pilot an assistant on regulated client PII. Applying G-U-A-R-D, which TWO conditions are essential before approval? (Select two)

A. Confirm EU/in-region residency and the default no-training posture for the data class. B. Ensure a named human reviews and owns each output. C. Choose the newest available model regardless of tier. D. Grant every employee access to speed adoption. E. Skip logging to reduce overhead.

Answer: A and B. Regulated PII demands correct residency/no-training and a human-in-the-loop owner. Picking the newest model (C) ignores tiering; universal access (D) violates least-privilege; skipping logging (E) removes auditability.

Q8 · Which is an example of governance that ENABLES rather than theatre? (Select one)

A. A blanket ban on all AI tools until further notice. B. Tiered decision rights with a fast path for low-risk cases and a board only for high-risk ones. C. Sending every request to a monthly committee. D. A 90-page policy with no technical controls enabled.

Answer: B. Tiering decides most cases quickly and reserves scrutiny for genuine risk. A ban (A), universal committee review (C) and an unenforced policy (D) are all forms of theatre.

Q9 · A regulator asks the bank to prove who accessed an AI assistant and what they did over the past year. Which control provides this? (Select one)

A. Compliance API logs and audit events. B. A faster model. C. A larger team. D. Prompt caching.

Answer: A. Exportable compliance logs and audit events provide the who-did-what record a regulator needs. Model speed (B), team size (C) and caching (D) are irrelevant to auditability.

Q10 · A leader must decide whether confidential (not regulated) data may enter a governed AI workspace. What is the MOST appropriate rule? (Select one)

A. Never; confidential data must stay out of all AI tools. B. Yes, in a governed workspace with no-training terms and access control, per the classification gate. C. Yes, in any tool including personal accounts. D. Only after building a private model.

Answer: B. Confidential data is permissible in a governed workspace with no-training terms and access controls. A total ban (A) is over-conservative; personal accounts (C) lack controls; a private model (D) is unnecessary.

Q11 · A team proposes routing EU regulated data through a newly launched managed agent surface that is US-only with no zero-data-retention. What is the correct governance call? (Select one)

A. Approve it; newer surfaces are always better. B. Decline for that data class until an in-region, compliant path exists; the residency requirement is not met. C. Approve if the team promises to be careful. D. Approve and add a note to the risk register.

Answer: B. Residency must match the data class; a US-only, no-ZDR surface cannot carry EU regulated data. Novelty (A), promises (C) and a mere register note (D) do not satisfy the regulatory requirement.

Q12 · What is the PURPOSE of a time-boxed, conditioned exception path in a governance model? (Select one)

A. To make exceptions impossible so nobody asks. B. To let leaders say ‘yes, with conditions and a review date’ to hard cases instead of forcing workarounds. C. To route all decisions to the executive sponsor. D. To avoid logging difficult decisions.

Answer: B. A good exception path enables safe yeses on hard cases, conditioned and revisited. Making exceptions impossible (A) drives workarounds; centralising all decisions (C) is a bottleneck; avoiding logging (D) destroys auditability.

Q13 · A CISO wants the organisation to control its own encryption keys for AI-processed data. Which control addresses this? (Select one)

A. RBAC B. EKM (enterprise key management) C. SSO D. Domain verification

Answer: B. EKM lets the enterprise manage its own encryption keys. RBAC (A) governs role permissions, SSO (C) governs sign-in, and domain verification (D) controls the account surface — none of which is key management.

Q14 · During a use-case review, which factors set the DECISION RIGHT (who approves)? (Select two)

A. The risk tier derived from the applicable taxonomy categories. B. The data class that will enter the tool. C. How enthusiastic the requesting team is. D. Which model version is newest. E. The size of the requesting team’s budget.

Answer: A and B. Risk tier and data class determine the decision right and the review path. Team enthusiasm (C), model recency (D) and budget size (E) do not govern who must approve.

Key takeaways

  • Governance is an operating model — ownership, tiered decision rights, policy, a review board and an exception path — not a document.
  • Use a seven-category risk taxonomy (accuracy, privacy, security, IP, regulatory, reputational, workforce), each assigned to its natural owner.
  • Data handling turns on classification and residency; ChatGPT Enterprise offers residency in ten regions and does not train on business data by default.
  • Assess vendor and model risk on training posture, residency, access controls, logging and certifications; pin approved models per risk tier.
  • Know the enterprise controls — SSO, SCIM, EKM, RBAC, compliance logs, residency — and map each to the requirement it meets.
  • Enabling governance decides most cases fast and channels demand into the governed workspace; theatre blocks everything and breeds shadow AI.
  • Run G-U-A-R-D on each use case: grade risk, check use-of-data, name the accountable human, scope rights, document and revisit.

Last updated Sep 18, 2026