Claude Certification Blog
CCAR-P governance: the only Claude exam that names a regulation
One objective on the architect professional exam names GDPR, HIPAA and FedRAMP. It is the only place in the entire Claude programme where a specific regulation appears — and it is not asking you to recite one.
CCAR-P governance — formally Governance, Safety and Risk Management — is 14% of that exam, roughly 9 of 63 items, across five objectives. One of them names GDPR, HIPAA and FedRAMP, which makes it the only objective in the whole four-exam programme to name a specific regulatory regime. That is worth knowing precisely, because it is far narrower than it sounds.
Fourteen percent, five objectives
| Objective | Published name | What it asks for |
|---|---|---|
| O26 | Guardrails and safety controls | Where a control sits, and whether it decides |
| O27 | Risks, limitations and failure modes | What the system cannot do, stated in advance |
| O28 | Human-in-the-loop validation | When a person is required, and which work reaches them |
| O29 | Compliance with regulations | Mapping an obligation to a control that satisfies it |
| O30 | Ethical considerations | Bias, fairness and transparency as design properties |
Two of the five are covered elsewhere on this site because they span more than one track: guardrail placement in prompt injection and guardrails, and validation routing in human in the loop. The other three are specific to this exam.
The only named regulations in the programme
Check all four objective lists and one entry names a regime: CCAR-P’s compliance objective, which gives GDPR, HIPAA and FedRAMP as examples. Nothing on the associate, developer or architect foundations blueprints names a statute at all — the associate governance domain, at 15%, covers data, privacy and regulatory policy generically, as covered in governance and responsible use on CCAO-F.
Named as examples, not as syllabus
Three regimes appearing after “e.g.” in one objective is not a reading list. Nothing suggests you need article numbers, safe-harbour conditions or authorisation timelines. What the objective describes is ensuring compliance — an architecture question about controls, not a recall question about text.
Obligation, control, owner, evidence
This is the shape these items reward. An obligation on its own is a fact about the world. A control without an owner is a diagram. A control with an owner but nothing that demonstrates it worked cannot be shown to anyone who asks, which is the situation the objective exists to prevent.
The evidence link is the one most often missing from otherwise strong answers, and it is the one that distinguishes an architecture from an intention. Being able to say what a control did, to a party outside the team, is the difference between complying and believing you comply.
Knowing what the system cannot do
O27 asks for risks, limitations and failure modes. The generic version — models can be wrong, outputs vary — is true and unexaminable. What the objective is after is a design that has accounted for a specific thing this system cannot reliably do, in advance of it going wrong.
So the strong answers name a limitation and then show where it is handled: a category the model confuses, so a check sits at that step; a document format that degrades, so it routes differently; a question type that produces confident wrong answers, so those get sampled. The diagnosis discipline behind that is in troubleshooting on the Claude exams.
Bias, fairness and transparency
O30 names all three, and on no other track do they appear under those names. On this exam they arrive as design questions rather than as values statements: where in the system unequal outcomes would originate, and what explanation is owed to whom.
The second half is the more examinable one, because the audiences differ. A user affected by a decision needs something different from a regulator reviewing the process, which needs something different again from an engineer trying to reproduce a specific output. A design that produces one explanation for all three has usually satisfied none of them — which is the same audience-shaped judgment examined in stakeholder communication.
How it differs from CCAO-F governance
Both exams have a governance domain of similar weight — 15% on the associate track, 14% here — and they are not the same subject. The associate version asks whether a use is appropriate and what policy permits: judgment about a task in front of you. This one asks how a system is built so that the answer holds without you.
That difference shows up in the correct answers. On CCAO-F, stopping and asking is frequently right. On CCAR-P it rarely is, because an architect is being asked to design the thing that decides — the answer is a control, an owner and a record, not an escalation. Anyone moving between the tracks should expect that inversion, along with the rest of the re-weighting in moving from CCAR-F to CCAR-P.
Key takeaways
- Fourteen percent, nine items, five objectives. Guardrails, failure modes, human validation, compliance and ethics.
- The only named regulations in the programme. GDPR, HIPAA and FedRAMP appear as examples in one CCAR-P objective and nowhere else.
- It is not a law exam. No statutory recall is implied; the skill is mapping an obligation to a control that satisfies it.
- Reach the last two links. A control with no owner is a diagram; one with no evidence cannot be shown to anyone.
- Name the limitation, then handle it. Generic weaknesses are unexaminable; a specific one with a check attached is not.
- Design, do not escalate. Where the associate exam rewards stopping to ask, this one rewards building the thing that decides.
Nine items decided by whether you finished the chain
These are among the most winnable items on the paper once you stop answering them as values questions and start answering them as architecture. Timed papers built to the published 63-item allocation are where that switch gets made. Our claude certification study guide covers how to sequence them.
See the CCAR-P blueprintQuestions
Frequently asked
The follow-up questions people search next.
Does any Claude certification exam test GDPR or HIPAA?
One objective on CCAR-P names GDPR, HIPAA and FedRAMP as examples of regulations a solution may have to comply with. It is the only place in the whole programme where a specific regime is named — CCAO-F’s governance domain names none, and neither foundations track names any.
Do I need to memorise regulations for CCAR-P?
No. Naming three regimes as examples is not the same as testing statutory recall. The examinable skill is mapping a stated obligation to a control that satisfies it, with someone accountable and something that demonstrates it worked.
How big is the governance domain on CCAR-P?
Governance, Safety and Risk Management is 14% of the exam — about 9 of 63 items — across five objectives: guardrails and safety controls, risks and failure modes, human-in-the-loop validation, regulatory compliance, and ethical considerations.
What does the failure-modes objective ask for?
Identifying risks, limitations and failure modes of the system before they occur. The examinable version is whether a design accounts for what the system cannot reliably do, rather than whether you can list generic weaknesses of language models.
Is bias and fairness examined anywhere else?
Not under those names. CCAO-F has an ethics objective inside its governance domain, but bias, fairness and transparency are named specifically on CCAR-P, and there they arrive as design questions — where unequal outcomes originate and what explanation is owed to whom.
Keep reading
Related posts
Not affiliated with, or endorsed by, Anthropic or Pearson VUE. Details are summarised from publicly published program information and can change — always confirm against the official exam guide before booking.