AIF-C01 notes
Security, compliance, and governance

Approaches for Implementing Governance Strategies

Five governance approaches

The story: A hospital introducing a new robot surgeon:

  • Writes clear rules for when the robot can be used, who supervises it, and how its work is checked, and updates them each year.
  • Holds regular reviews: monthly for risky procedures, less often for routine ones, with doctors, lawyers, and patient representatives.
  • Reviews both the technical side (is it accurate and reliable?) and the ethical side (is it fair and legal?), tests before each new use, and sets clear rules for when a human surgeon takes over.
  • Publishes what the robot can and can't do, and gives patients a way to give feedback.
  • Trains staff on fairness and safe use, gets departments working together, and keeps certifications current.

In AI/AWS terms:

  • Policies: clear policies on the organization's approach to generative AI, covering data management, training, output validation, safety, human oversight, IP, bias, and privacy. Review them regularly.
  • Review cadence: regular technical, legal, and responsible AI reviews, for example monthly, quarterly, or twice a year depending on risk, with diverse stakeholders.
  • Review strategies: technical reviews (performance, data quality, robustness) and non-technical reviews (policy, ethics, regulation), testing before deployment, and clear rules for when to intervene.
  • Transparency standards: publish information about models, training data, and key decisions. Document capabilities, limitations, and intended use. Give stakeholders a feedback channel.
  • Team training: bias mitigation and responsible AI training, cross-functional collaboration, ongoing certification.

For the exam: The five governance approaches are policies, review cadence, review strategies, transparency standards, and team training.

Monitoring an AI system

The story: Separate from those policies, the hospital's technicians watch the robot's daily readings: how accurate and fast it is, how hot its motors run, whether it treats some patient groups differently, and whether it stays within the rules.

In AI/AWS terms: These are operational practices, separate from the governance approaches above:

  • Performance metrics: accuracy, precision, recall, F1, latency
  • Infrastructure: CPU, GPU, memory, network, storage, logs
  • Bias and fairness, especially in healthcare, finance, and HR
  • Compliance and responsible AI

For the exam: Monitoring metrics are operational practices, not one of the five governance approaches.

Generative AI Security Scoping Matrix

The story: Five ways to get a meal, from least to most responsibility:

  1. Eat at a public food court.
  2. Your company contracts a catering service that delivers to the office.
  3. Buy a ready-made meal kit and cook it at home.
  4. Buy the meal kit but change the recipe with your own ingredients.
  5. Grow your own vegetables and cook from scratch.

The more you do yourself, the more you're responsible for food safety.

In AI/AWS terms: The Generative AI Security Scoping Matrix classifies an application into one of five scopes, from least to most ownership:

MealScopeYou...Example
Food court1. Consumer appUse a public generative AI serviceA public chatbot
Office catering2. Enterprise appUse a third-party business app with generative AI built in, under a business agreementA scheduling app that drafts agendas
Meal kit3. Pre-trained modelsBuild your app on an existing FMAn app calling a model in Amazon Bedrock
Adjusted meal kit4. Fine-tuned modelsFine-tune an existing FM with your dataA model tuned on your support tickets
Grow your own5. Self-trained modelsTrain a model from scratch on your dataYour own FM

For each scope, the matrix covers four security disciplines: governance and compliance, legal and privacy, risk management, and controls and resilience.

  • Controls are security measures that reduce risk, such as controlling who can use which FMs and who can reach inference endpoints.
  • Resilience means staying available and meeting SLAs, for example by checking each service is available in your Region.

For the exam: Scope 3 = using an FM like Bedrock as is. Scope 4 = fine-tuning. Scope 5 = training from scratch. The four disciplines: governance and compliance, legal and privacy, risk management, controls and resilience.

On this page