AIF-C01 / Domain 5 / 14%
Security, Compliance, and Governance for AI Solutions
Privacy, security, compliance, and governance controls for AI workloads.
Official Task Statements
| Task | What to prove |
|---|---|
| AIF-5.1 | Explain methods to secure AI systems. |
| AIF-5.2 | Recognize governance and compliance regulations for AI systems. |
Concepts You Need to Understand
- AI data security, IAM, encryption, governance, compliance, audit, logging, retention, and third-party model risk.
AWS services involved
- IAM
- KMS
- CloudTrail
- CloudWatch Logs
- Organizations
- Artifact
Important configurations
- Least privilege to model endpoints.
- Encryption for prompts, artifacts, and logs.
- Data-retention review.
Exam Decision Patterns
Least operational overhead
Prefer managed and serverless services when they satisfy the requirement. Exceptions appear when the scenario needs host control, unsupported runtimes, specialized network behavior, or exact migration compatibility.
Highly available
Identify the failure boundary. One instance is not HA. Multiple instances in one AZ help capacity but not AZ failure. Multi-AZ handles regional AZ faults. Multi-Region handles regional events but adds complexity and cost.
Durable
Durability is about preserving data. Use replication, versioning, backups, point-in-time recovery, and tested restore plans. A durable backup does not guarantee a low RTO.
Decouple the application
Use SQS for buffering work, SNS for fanout, EventBridge for event routing, and Step Functions for visible workflow state. Add retries, DLQs, and idempotent consumers.
Least privilege
Prefer roles and temporary credentials, scope actions/resources/conditions, watch explicit denies, and remember that resource policies may also be required.
Common Mistakes
- Submitting sensitive data to an unreviewed external model.
- Logging prompts that contain secrets or regulated data.
Example Architecture
Hands-On Activity
Review a prompt-processing design and mark where access logs, encryption, and retention controls belong.
For an AWS-account lab, use one of the linked mini labs and keep cleanup steps visible before you start.
Task-by-Task Study Notes
AIF-5.1 - Explain methods to secure AI systems.
This task statement is asking whether you can turn a scenario into a decision. Start by identifying the workload requirement, the control or service family involved, and the tradeoff AWS is testing in this domain.
- Translate the wording into requirements: security, operations, cost, availability, latency, governance, or data behavior.
- Choose the service or configuration that directly satisfies those requirements with the least unnecessary complexity.
- Reject options that are technically possible but miss the domain goal or increase risk without a requirement.
AIF-5.2 - Recognize governance and compliance regulations for AI systems.
This task statement is asking whether you can turn a scenario into a decision. Start by identifying the workload requirement, the control or service family involved, and the tradeoff AWS is testing in this domain.
- Translate the wording into requirements: security, operations, cost, availability, latency, governance, or data behavior.
- Choose the service or configuration that directly satisfies those requirements with the least unnecessary complexity.
- Reject options that are technically possible but miss the domain goal or increase risk without a requirement.
Review Checklist
Sources and Review Metadata
This independent training application is not affiliated with or endorsed by Amazon Web Services. AWS, Amazon Web Services, and AWS certification names are trademarks of Amazon.com, Inc. or its affiliates.