CLLMSP · Domain 7
LLM Security Governance & Compliance
About 10% of the exam
The AI risk framework functions
- Govern
- culture, roles and accountability throughout
- Map
- context, use and potential harms
- Measure
- test, evaluate and track performance
- Manage
- prioritize, treat and monitor risk
- Cross-cutting
- govern informs the other three
- Profiles
- the framework tailored per use
- Voluntary
- guidance, not a certifiable standard
The framework tells you which questions to answer, the management standard tells you how to run the system, and the law tells you what happens if you do not
Telling the documents apart
- ISO/IEC 42001
- certifiable AI management system
- ISO/IEC 23894
- AI risk management guidance
- ISO/IEC 27001
- information security management system
- NIST AI RMF
- voluntary framework, four functions
- NIST AI 100-2
- evasion, poisoning, privacy, abuse
- MITRE ATLAS
- tactics and techniques against ML
- EU AI Act
- binding law with risk tiers
- Model card
- intended use, limits, evaluations
- System card
- deployment context and safeguards described
Risk tiers under the AI Act
- Unacceptable
- prohibited, no compliance route exists
- High risk
- conformity duties before market entry
- Limited risk
- transparency duties toward users
- Minimal risk
- no specific obligations imposed
- Employment use
- listed among high-risk cases
- Synthetic media
- marked machine-readably and disclosed
General purpose model duties
- Technical documentation for downstream deployers
- A published training content summary
- Copyright policy covering training data
- Systemic risk presumed above compute thresholds
- Extra evaluation and incident reporting then
- Duties follow capability, not company size
Who owes what
- Provider
- develops and places on market
- Deployer
- uses the system under authority
- Importer
- brings a foreign system in
- Fine-tuner
- can become a provider
- Silence
- unclear duties delay required reports
- Contract
- should allocate roles explicitly
The policy set
- Acceptable use for every AI tool
- Cover free tools touching company data
- An approved model and vendor list
- Data classification rules for prompts
- Human review thresholds by impact
- Unmonitored policy drifts from practice
Roles and accountability
- One accountable executive per system
- The risk owner accepts residual findings
- Control ownership transfers on departure
- A review board with real authority
- The charter must match actual practice
- Independence separates audit from build
Inside a risk assessment
- Intended use and affected people
- Data sensitivity and provenance
- Autonomy level and reachable tools
- Threat scenarios and plausible harms
- Mitigations mapped to each harm
- Residual risk accepted by name
Documentation that counts
- Model card states the intended use
- Known limits and failure modes
- Evaluation results with the methodology
- Assurance evidence, not vendor marketing
- Version and date on everything
- Written before deployment, not after
Change control for prompts and models
- Classify change
- Assess risk
- Evaluate
- Approve
- Deploy
- Monitor
- Review
- Risk-classify changes rather than reviewing all
- High-impact changes get named approval
- Low-impact changes sampled after release
- Security patches weighed against regression risk
- Keep rollback ready through the change
- Prompt edits are production changes
Third parties and procurement
- Diligence questions answered before signature
- Refusal to answer is itself risk
- Certifications scoped narrowly can mislead
- Right to audit or equivalent report
- Incident notification timelines written down
- Exit terms covering data return
- Reassess on renewal, not never
A certificate describes a scope somebody else chose, so read the statement of applicability and the report dates before you accept the badge
Reporting an AI incident
Deciding
- Test the facts against legal thresholds
- Harm or data exposure triggers duty
- Ambiguity resolves toward accurate disclosure
- Candor gaps compound into enforcement
Doing
- Preserve evidence independently of the team
- Impartial review, not comfortable self-assessment
- Notify with facts, correct later
- Track the clock from awareness
Glossary
- Conformity assessment
- checking duties before market entry
- Statement of applicability
- which controls the scope covers
- Residual risk
- what remains after treatment
- Assurance evidence
- documented results against defined criteria
- Model card
- intended use, limits, evaluations
- GPAI
- general purpose model, many uses
- Systemic risk
- very capable model, wider consequences
- Deployer
- organization using the system operationally
Quick rules
- Framework guides, standard certifies, law binds
- Know provider from deployer duties
- Risk-classify before you review
- Evidence beats assertion every time
- Policies without monitoring drift quietly
- Name the accountable executive
Reference strip: frameworks, law, roles, process, evidence
Frameworks
- Govern, map, measure and manage
- The management standard is certifiable
- Risk guidance is not certifiable
- Attack taxonomies inform the threat model
Law
- Four tiers from prohibited to minimal
- Employment and biometrics sit high
- Synthetic media must be marked
- Model duties scale with capability
Roles
- Provider builds, deployer operates
- Fine-tuning can make you provider
- One accountable executive per system
- Contracts allocate duties explicitly
Process
- Classify, assess, evaluate, approve, monitor
- Sample the low-impact changes
- Rollback available through every deployment
- Reassess vendors at renewal
Evidence
- Model cards with dated evaluations
- Audit reports scoped to you
- Residual risk accepted in writing
- Override and violation rates tracked
Quick exam traps
- Trap: A voluntary risk framework can be certified against like a management standard
- Trap: An internal team review can be presented to a regulator as an audit
- Trap: Reviewing every prompt change is the only defensible governance posture
- Trap: A free consumer chatbot falls outside the acceptable use policy
- Trap: A vendor certificate covers whatever service you happen to buy
- Trap: Fine-tuning a purchased model leaves every duty with the original provider
- Trap: A written policy is evidence that the control actually operates
cybercertprep.com · original revision sheet written from the public body of knowledge