Study AIP-C01 governance for lineage, model cards, audit logs, policy evidence, compliance frameworks, and continuous governance controls.
Governance questions on AIP-C01 are about proving control, not only claiming it. AWS usually wants lineage, version history, audit trails, model documentation, and policy evidence that can survive a real internal review or external compliance check.
The current AIP-C01 domain page points to four recurring governance areas:
That means this task is about durable oversight over time, not one-time approval.
| Requirement | Strongest first fit | Why |
|---|---|---|
| Need to document limitations and intended use | Model cards and documented governance metadata | Governance needs explicit artifact trail |
| Need to trace where generated content came from | Source attribution, lineage tracking, and metadata tagging | Traceability is a governance control |
| Need policy-ready audit logs | Decision logs, version history, and access/event records | Evidence must survive review |
| Need consistent oversight across teams | Organizational governance framework with enforced review paths | Governance is bigger than one app |
| Need ongoing readiness for audits | Continuous monitoring for misuse, drift, and policy violations | Audit readiness depends on ongoing control, not snapshots |
Strong governance answers help a reviewer answer:
If the answer does not leave that trail, it is usually weak in a governance scenario.
AWS explicitly includes source tracking because GenAI apps often need to prove:
This is especially important when the app operates in regulated, enterprise, or customer-facing settings.
Some telemetry is operational. Some telemetry becomes governance evidence.
Governance-relevant monitoring often includes:
The exam often rewards the answer that turns monitoring into a reviewable evidence path.
If the scenario spans multiple teams or products, look for answers that standardize:
A per-team spreadsheet or ad hoc review memo is usually weaker than a systematic governance model.
When the requirement is prove the AI system is controlled, think: lineage, versions, approvals, evidence, and continuous governance checks.