H Handrail Lesson 2-min video · optional 9-min read
Module 5 · Your assessed level (0–2) + certificate

Your Safe-Use Habits and Certificate

This module doesn't teach anything new. It takes everything from the earlier lessons and boils it down to five habits you can actually remember on a busy Tuesday, checks your judgment with a short mixed-scenario confidence check set to your firm's real level, and — if you're ready — issues your AI Safe-Use Certificate (Aware tier): a named, dated, publicly verifiable record that you completed this training.

A ~2-minute walk-through. Prefer to read? The full lesson is below. Captions are on.
Listen instead (audio only) — good for a commute or patchy signal
In one line

Nobody retains nine separate lessons' worth of detail under pressure. What people actually carry into the moment a scam email lands, or a client asks them to run something through an AI tool, is a short list of instincts — the kind you can recall in three seconds without opening a manual. This module exists to compress everything you've learned into five habits small and durable enough to survive contact with a real Tuesday morning, confirm with a quick check that they've actually stuck, and hand you something concrete to show for it: a certificate with a unique ID that a client, an insurer, or an auditor can verify themselves, in seconds, without having to trust your word for it.

The short version — what to remember
  • Everything in this course reduces to five habits: verify before you act, protect your data before you paste it, check AI output before you trust it, keep your own skills, and know when to escalate — all underneath one rule, AI advises, human decides.
  • The confidence check uses mixed scenarios drawn from across the whole course, scaled to your firm's actual placed level (0, 1, or 2 for this cohort), and doesn't tell you in advance which habit each scenario is testing.
  • Level 3–4 content (autonomous agents) is deliberately locked and labeled 'not relevant to your firm yet' for Level 0–2 learners — it unlocks automatically if your firm's assessed level ever grows into that territory.
  • Passing issues the AI Safe-Use Certificate — Aware tier, with a unique ID and a public verification URL anyone can check independently, without needing an account or access to your firm's records.
  • The certificate is personal and expires after 12 months; the firm-wide view — who's certified, who's due for renewal, overall firm level — lives in the exportable compliance report under Admin → Reports.
A real (anonymized) example

A 9-person accounting practice used its AI Safe-Use Certificates during a professional indemnity insurance renewal. The insurer's questionnaire asked, for the first time that year, whether staff had received 'documented AI-usage training with independently verifiable completion records.' Rather than writing a paragraph explaining an internal spreadsheet, the practice manager sent the insurer the firm's exportable compliance report (showing all 9 staff certified at Aware tier, current level 1) plus two certificate verification links the insurer's underwriter checked directly, in under a minute, with no login required. The renewal went through without a follow-up call. The practice manager's comment afterwards: 'It wasn't the training itself that saved time — it was that someone else could check it without having to trust me.'

Reflect

A few open questions — nothing to trip on

These are to think through, not a test — there's no score and no wrong answer. Jot a line if it helps, then open the note to see what a careful answer usually considers. Nothing is saved or shown to your admin.

Question 1 of 4

You get an AI-drafted email ready to send to a client. According to the five habits, what should you do before sending it?

See what a careful answer considers

A careful answer usually lands on: Read it and check the facts, names, and figures yourself before sending, since the AI can sound confident whether or not it's correct. Habit 3 — check the output, don't just trust the tone — applies to every AI-drafted output going to a client, not only financial ones. A confident sentence is not the same as a correct one.

Question 2 of 4

Your firm was placed at Level 1 in the first lesson. What will the confidence check scenarios focus on?

See what a careful answer considers

A careful answer usually lands on: Messages and calls aimed at the firm, plus individual everyday AI use like drafting or summarising — with the Level 3–4 agent content locked out. Scenarios are scaled to your firm's actual assessed level. Level 1 adds individual AI use on top of the outside-facing risks from Level 0, while Level 3–4 (autonomous agents) stays locked and labeled 'not relevant to your firm yet' until your level changes.

Question 3 of 4

A client's insurer asks for proof that your staff completed AI-safety training and wants to check it without contacting you. What lets them do that?

See what a careful answer considers

A careful answer usually lands on: The certificate's unique ID and public verification URL, which anyone can check without an account or access to your firm's internal records. The public verification URL is built precisely so a third party — insurer, client, auditor — can confirm a certificate independently in seconds, without an account and without needing to trust the firm's word for it.

Question 4 of 4

As the person managing training for your whole firm, where do you go to see who's certified, who's due for renewal, and the firm's overall AI-use level?

See what a careful answer considers

A careful answer usually lands on: The exportable compliance report under Admin → Reports. Individual certificates cover one person; the exportable compliance report is the firm-wide rollup built for whoever manages training, designed to export cleanly for insurers, clients, or auditors.

Read the full written lesson (~9 min)

The five habits — everything else was building toward these

Every lesson in this course, however different the topic, was really teaching one of five habits. Here they are in plain language, in the order you'd actually use them:

  • 1. Verify before you act. If a message asks you to pay, share, approve, or change something — and it feels urgent, unusual, or slightly off — confirm who you're really dealing with through a channel you already know and trust (a saved phone number, a known contact), not through the contact details the message itself gives you.
  • 2. Protect your data before you paste it. Before typing anything into an AI tool, pause and ask: would I be comfortable if this exact text were posted publicly? If it contains a client's details, financial information, health information, or anything confidential, don't paste it in — or strip out the identifying details first.
  • 3. Check the output, don't just trust the tone. AI tools write confidently whether they're right or wrong. Before you send, file, or act on anything an AI produced, check the facts, names, and numbers in it yourself — a confident sentence is not the same thing as a correct one.
  • 4. Keep your skills — don't let the tool do your thinking for you. Use AI to draft, summarise, and speed things up, but keep doing the parts of your job that build your judgment. A tool that always writes the client email for you is fine; a person who's forgotten how to write one without it is a risk to the firm.
  • 5. Know when to escalate. If something feels wrong and you're not sure — a message, a request, an AI suggestion, an unexplained action a system took on its own — say so to the right person early. Escalating something that turns out to be nothing costs a few minutes. Not escalating something real costs far more.

Notice the shape of these: four of them are about being careful with the world coming at you and the AI tools you use yourself, and the fifth is the safety net underneath all of them — because nobody gets every judgment call right, and the habit of asking for a second opinion is what catches the ones you don't.

The one rule underneath all five

If you remember nothing else from this entire course, remember this: AI advises, a human decides. Whether it's a chatbot drafting a reply, a tool suggesting an action, or a system that could act on its own — a person stays responsible for what actually happens. That single sentence is what the five habits above are built to protect. Verifying, protecting data, checking output, keeping your own skills, and escalating are all just this one rule applied to five different everyday situations.

This is also the honest answer to the fear this course was built to reduce. The goal was never to make you distrust every tool or freeze at every email. It was to give you a small, repeatable way to stay in charge of decisions that are still yours to make — so that using AI well and staying safe end up being the same habit, not two competing ones.

The confidence check: mixed scenarios at your level

Before your certificate is issued, you'll work through a short set of mixed scenarios — around eight, each just a few sentences — drawn from across everything this course covered, not from any single lesson. Unlike the per-lesson quizzes, these deliberately don't announce which habit they're testing; part of the skill is recognising, in a normal-sounding situation, which of the five habits actually applies.

The scenarios are pulled from the level your firm was placed at in the very first lesson — Level 0, 1, or 2 for this MVP cohort:

  • At Level 0, scenarios centre on messages and calls arriving at your firm — a supplier email with a changed bank detail, a caller who sounds exactly like someone you know — since that's where a firm with no AI tools of its own actually carries risk.
  • At Level 1, scenarios add individual, everyday use — someone drafting a client email with a chat tool, or pasting in a document to summarise it, with a data-protection or output-checking decision folded in.
  • At Level 2, scenarios reflect AI as routine, day-to-day practice across the team — including moments where an AI suggestion needs checking before it goes out, or a colleague's shortcut is one a careful firm should question.

You need roughly two-thirds of the mixed set right to proceed to the certificate. If you're below that, you'll see exactly which of the five habits your misses cluster around, with a direct link back to the relevant lesson — not a vague "try again." There's no limit on attempts and no cooling-off period; you can revisit the material and retake the check whenever you're ready.

What's locked, and why

You may notice this course goes up to Level 4 — autonomous AI agents acting without a person clicking approve each time. If your firm was placed at Level 0, 1, or 2, that Level 3–4 material is deliberately locked in your view, shown greyed out with the label "Not relevant to your firm yet."

This isn't a paywall or a tease — it's a pedagogical choice. Teaching a 10-person firm with no built-in AI features how to govern an autonomous agent it doesn't have is exactly the kind of content that makes cautious, non-technical learners feel this course wasn't built for them. If your firm's real-world usage grows into that territory — an autonomous booking assistant, a system that emails clients on its own — the Level 3–4 modules unlock automatically the next time your firm's level is reassessed, and you'll be notified rather than needing to go looking for them.

For now: everything you were tested on, and everything your certificate reflects, is scoped to what your firm actually does today. That's deliberate. A certificate that claims mastery of risks you don't yet face would be less credible, not more.

Your certificate: the AI Safe-Use Certificate — Aware tier

Passing the confidence check issues your AI Safe-Use Certificate — Aware tier. "Aware" is a deliberately honest name: it certifies that you know the five habits, can apply them in mixed everyday scenarios at your firm's actual level, and understand the AI-advises-human-decides rule — not that you're an AI expert, and not that your firm has zero risk. It's the tier built for exactly the audience this course was written for: careful, non-technical people who now have a working, tested set of habits.

Every certificate carries:

  • Your name and your firm's name
  • The date it was issued and the course version it was issued under
  • The AI-use level it was assessed against (0, 1, or 2)
  • A unique certificate ID (for example, ASU-AWARE-2026-4F7K-2R9)
  • A public verification URL — anyone can visit it, enter or follow the link with the certificate ID, and see a simple confirmation: holder name, firm, tier, issue date, and current validity. No login, no account, no access to your firm's internal records — just a yes/no anyone can check in a few seconds.

That public verification link is the point. A certificate that only your firm can see is just a badge; one a client, an insurer, or an auditor can independently confirm is evidence. This is deliberately built to be the kind of thing you can attach to an insurance renewal, cite in a client proposal, or hand to a regulator asking about AI-literacy training — and have it hold up because it's checkable, not just claimed.

Like the rest of this course, the certificate is valid for 12 months. AI tools, scams, and the risks around both change enough in a year that a certificate with no expiry would stop meaning very much. Renewal is a shorter version of this same mixed-scenario check, refreshed with anything new since you last took it.

For your firm as a whole: the compliance report

Your personal certificate covers you. If you're the person responsible for the whole firm's training — an owner, office manager, or compliance lead — there's a separate, firm-wide view built for that job: the admin dashboard's exportable compliance report.

That report rolls up, across everyone at your firm: who has completed which modules, who holds a current certificate and at what tier, whose certificate is approaching its 12-month renewal, and where the firm's overall AI-use level sits based on the original placement checklist. It's built to export as a clean PDF or spreadsheet — the same kind of document you'd attach to an insurance renewal, a client due-diligence request, or a board update, without needing to explain the platform itself to whoever's reading it.

If you don't already have admin access and you think you should, ask whoever set up your firm's account to add you — the compliance report lives under Admin → Reports once you're in.

This lesson is written and reviewed by named humans. Content current as of 21 July 2026. See the Trust Center for our review process and AI-assistance disclosure.