AI Governance, Risk & Compliance Practitioner

24 weeks

24-Week AIGP-aligned practitioner programme: from zero to practitioner across AI foundations, Responsible AI, NIST AI RMF, OECD AI Principles, ISO/IEC 22989, ISO/IEC 42001, ISO/IEC 42005, EU AI Act, UK GDPR, COSO Internal Controls and AI assurance.

Paid programme
Duration
24 weeks
Level
Zero to practitioner
Format
Live or recorded weekly lessons, designed for working professionals at around 5 to 8 hours per week.
Status
Planning
Ask about paid enrolmentTry the free preview

Who it's for

  • Product managers
  • Delivery managers
  • Project managers
  • QA/test leads
  • Business analysts
  • Risk professionals
  • Compliance professionals
  • Internal auditors
  • Data protection/privacy professionals
  • Cyber security professionals
  • AI adoption leads
  • Founders
  • Consultants
  • Career changers moving into AI governance

What this course covers

A practitioner-level programme across five frameworks: NIST AI RMF, ISO/IEC 42001, the EU AI Act, UK GDPR and COSO Internal Controls. Learners build a full AI Governance Evidence Pack using the HireAI capstone case study, working towards one outcome: knowing whether a real AI system should be approved, changed, monitored or blocked.

Free two-week preview

Start with Weeks 1 and 2 before you pay.

Join from Wednesday 23 September 2026, cover AI foundations and responsible AI, and complete the HireAI practical lab. You can decide whether to continue after the preview.

View the free preview

What you'll be able to do by the end

  • Assess an AI system and identify who could be harmed
  • Classify its risk and map the relevant regulatory obligations
  • Design controls and test whether they actually work
  • Collect evidence and assess vendor and supplier risk
  • Prepare for exam-style AI governance scenarios
  • Advise whether the system should be approved, delayed, monitored, restricted, deactivated or blocked

Syllabus

Week 1: AI Foundations for Governance

  • What AI is
  • Traditional software vs AI systems
  • AI > Machine Learning > Deep Learning > Generative AI
  • Supervised learning
  • Unsupervised learning
  • Classic AI vs generative AI
  • Small models vs large models
  • Single-purpose models vs general-purpose models
  • Text models vs multimodal models
  • Proprietary models vs open-source models
  • Foundation models
  • Large Language Models
  • Hallucination
  • RAG
  • AI agents
  • Training vs inference
  • AI lifecycle
  • AI actors and responsibilities: developer, provider, deployer, user, affected person, operator, supplier
  • Why AI governance exists
  • Basic AI risk thinking
  • HireAI case study introduction

Week 2: Responsible AI, Trustworthy AI & Harm

  • Responsible AI
  • Trustworthy AI
  • Types of AI harm
  • Individual harm
  • Group harm
  • Organisational harm
  • Societal harm
  • Bias
  • Fairness
  • Accuracy vs fairness
  • Transparency
  • Explainability
  • Accountability
  • Privacy
  • Safety
  • Reliability
  • Security
  • Human oversight
  • Automation bias
  • Stakeholders and affected people
  • Probability/severity harms matrix
  • Risk mitigation hierarchy: avoid, reduce, transfer/share, accept, monitor
  • When harm should block launch
  • HireAI harm mapping

Week 3: Governance, Risk, Compliance & Assurance Basics

  • What governance means
  • What risk management means
  • What compliance means
  • What assurance means
  • Governance vs management
  • Risk appetite
  • Risk tolerance
  • Risk owners
  • Control owners
  • Inherent risk
  • Residual risk
  • Risk treatment
  • Risk mitigation hierarchy
  • Policies
  • Standards
  • Procedures
  • Evidence
  • Audit trail
  • Three lines of defence
  • Board reporting
  • Why AI GRC is cross-functional: product, technology, risk, privacy, security, legal, compliance, internal audit

Week 4: AI and the Wider Legal Landscape

  • Why AI law is broader than privacy
  • Privacy law
  • Data protection law
  • Intellectual property law
  • Copyright and training data
  • Database rights
  • Trade secrets
  • Contract law
  • Employment law
  • Non-discrimination law
  • Equality law
  • Credit and lending fairness
  • Housing and access to services
  • Insurance fairness
  • Consumer protection law
  • Product liability law
  • Professional negligence
  • Health and safety
  • Sector regulation
  • Public sector duties
  • Procurement law
  • Record keeping
  • Evidence and defensibility
  • Legal risk vs ethical risk vs operational risk

Week 5: NIST AI RMF Overview and OECD AI Principles

  • What NIST is
  • Why NIST AI RMF exists
  • Voluntary frameworks vs legal obligations
  • AI risk management
  • NIST AI RMF Core
  • Govern
  • Map
  • Measure
  • Manage
  • Profiles
  • Playbook
  • Trustworthy AI characteristics
  • OECD AI Principles
  • Inclusive growth, sustainable development and well-being
  • Human-centred values and fairness
  • Transparency and explainability
  • Robustness, security and safety
  • Accountability
  • How OECD, NIST and ISO relate
  • Where NIST fits with ISO 42001, EU AI Act, UK GDPR and COSO

Week 6: NIST GOVERN

  • Purpose of GOVERN
  • AI governance strategy
  • AI governance committee
  • AI policy
  • AI system inventory
  • AI risk appetite
  • AI roles and responsibilities
  • Developer/provider/deployer/user responsibility mapping
  • AI ownership
  • Model ownership
  • Product ownership
  • Data ownership
  • Risk ownership
  • Senior leadership oversight
  • Supplier governance
  • Third-party AI tools
  • AI literacy and training
  • Escalation routes
  • Exceptions and waivers
  • Approval gates
  • Governance reporting

Week 7: NIST MAP

  • Purpose of MAP
  • AI system context
  • Intended use
  • Foreseeable misuse
  • Users
  • Affected people
  • Business objective
  • Deployment environment
  • Data context
  • Social context
  • Legal context
  • Human interaction
  • Level of autonomy
  • Decision impact
  • Benefit-risk trade-off
  • Supplier dependencies
  • External dependencies
  • Risk scenarios
  • Assumptions and constraints
  • Probability/severity risk mapping

Week 8: NIST MEASURE

  • Purpose of MEASURE
  • Testing, evaluation, verification and validation
  • Accuracy testing
  • Reliability testing
  • Robustness testing
  • Bias testing
  • Fairness testing
  • Explainability testing
  • Privacy testing
  • Security testing
  • Data quality testing
  • Human oversight testing
  • Accessibility testing
  • Red teaming
  • Adversarial testing
  • Prompt injection testing
  • Hallucination testing
  • Output validation
  • Benchmarks
  • Acceptance criteria
  • Risk indicators
  • Evidence capture
  • Model cards as testing and release-readiness evidence
  • System cards
  • Known limitations
  • Intended use and prohibited use

Week 9: NIST MANAGE and Risk Treatment

  • Purpose of MANAGE
  • Risk prioritisation
  • Risk treatment options
  • Risk mitigation hierarchy
  • Accept
  • Mitigate/reduce
  • Transfer/share
  • Avoid
  • Monitor
  • Residual risk
  • Risk acceptance
  • Risk escalation
  • Control selection
  • Release gates
  • Model cards as release evidence
  • Human-in-the-loop controls
  • Guardrails
  • Monitoring
  • Incident response
  • Deactivation policy
  • Localisation/geographic restriction policy
  • Kill switches
  • Rollback plan
  • Continuous improvement
  • Model updates
  • Drift
  • Control effectiveness
  • Management reporting

Week 10: GenAI, RAG and LLM Application Risk

  • LLM application architecture
  • Prompting
  • System prompts
  • User prompts
  • RAG basics
  • Retrieval pipeline
  • Embeddings
  • Vector search
  • Source quality
  • Stale information
  • Incorrect retrieval
  • Access-control failure
  • Data leakage
  • Hallucination
  • Toxic outputs
  • Misinformation
  • Overreliance
  • Sensitive data exposure
  • Output validation
  • Grounding
  • Citations and source traceability
  • Proprietary vs open-source model risks
  • Hosted model vs self-hosted model risks
  • Small model vs large model trade-offs
  • Fine-tuning vs RAG

Week 11: Agentic AI, Prompt Injection and AI Security Controls

  • AI agents
  • Tool use
  • Function calling
  • Autonomy levels
  • Multi-step planning
  • Multi-agent systems
  • Agent permissions
  • Tool permissions
  • Prompt injection
  • Indirect prompt injection
  • Jailbreaks
  • Data poisoning
  • Model misuse
  • Agent taking unintended actions
  • Sandboxing
  • Human approval gates
  • Rate limits
  • Kill switches
  • Logging
  • Audit trails
  • Security testing
  • Red teaming
  • Monitoring agent behaviour
  • External communication plan for agent incidents

Week 12: ISO AI Standards: ISO/IEC 22989, ISO/IEC 42001 and ISO/IEC 42005

  • Why ISO standards matter
  • ISO/IEC 22989 AI concepts and terminology
  • Common AI vocabulary
  • AI system terminology
  • AI lifecycle terminology
  • ISO/IEC 42001 AI Management System
  • ISO/IEC 42005 AI system impact assessment
  • Difference between terminology, management system and impact assessment
  • How ISO 22989 supports consistent language
  • How ISO 42001 supports governance system design
  • How ISO 42005 supports impact assessment
  • Relationship to NIST AI RMF
  • Relationship to OECD AI Principles
  • Relationship to EU AI Act and UK GDPR

Week 13: ISO/IEC 42001 Foundations

  • What an AI Management System is
  • Why ISO/IEC 42001 exists
  • Responsible development, provision and use of AI
  • Plan-Do-Check-Act
  • Clauses 4 to 10 overview
  • Annex A overview
  • Relationship to ISO 9001
  • Relationship to ISO 27001
  • Relationship to ISO 27701
  • Certification vs implementation
  • Scope
  • Documented information
  • Continual improvement
  • Internal audit
  • Management review

Week 14: ISO/IEC 42001 Clause 4: Context of the Organisation

  • Understanding the organisation
  • Internal issues
  • External issues
  • Interested parties
  • Needs and expectations
  • Scope of the AIMS
  • AI system boundaries
  • Business context
  • Legal and regulatory context
  • Supplier context
  • Sector context
  • Organisational maturity
  • AIMS processes
  • Documenting scope
  • Exclusions and limitations
  • Affected people as interested parties
  • Regulators as interested parties
  • Suppliers as interested parties

Week 15: ISO/IEC 42001 Clause 5 and Clause 6: Leadership and Planning

  • Leadership commitment
  • AI policy
  • Roles and responsibilities
  • Authorities
  • Accountability
  • Risk-based planning
  • Risks and opportunities
  • AI risk assessment
  • AI risk treatment
  • AI impact assessment
  • AI objectives
  • Planning changes
  • Governance board
  • Senior management responsibilities
  • Resource commitment
  • Policy communication
  • Objectives and measurement
  • Alignment to ISO/IEC 42005 impact assessment
  • Alignment to NIST GOVERN and MAP

Week 16: ISO/IEC 42001 Clauses 7–10 and Annex A Controls

  • Clause 7: Support
  • Resources
  • Competence
  • Awareness
  • Communication
  • Documented information
  • Clause 8: Operation
  • Operational planning
  • AI lifecycle controls
  • AI risk assessment operation
  • AI risk treatment operation
  • AI impact assessment operation
  • Supplier controls
  • Change control
  • Clause 9: Performance evaluation
  • Monitoring
  • Measurement
  • Analysis
  • Evaluation
  • Internal audit
  • Management review
  • Clause 10: Improvement
  • Nonconformity
  • Corrective action
  • Continual improvement
  • Annex A control themes
  • AI policies
  • Internal organisation
  • Resources for AI systems
  • AI impact assessments
  • AI system lifecycle
  • Data for AI systems
  • Information for interested parties
  • Use of AI systems
  • Third-party relationships
  • Customer relationships
  • Control selection
  • Evidence requirements
  • Control maturity
  • Control gaps

Week 17: EU AI Act Foundations and Global AI Law Landscape

  • What the EU AI Act is
  • Why it exists
  • Scope
  • Key definitions
  • AI system
  • Provider
  • Deployer
  • Importer
  • Distributor
  • Authorised representative
  • Product manufacturer
  • General-purpose AI model
  • Risk-based approach
  • Prohibited AI practices
  • High-risk AI systems
  • Limited-risk AI
  • Lower-risk AI
  • Transparency obligations
  • Why UK organisations may still care
  • Global AI law landscape
  • South Korea AI Basic Act
  • US federal AI governance activity
  • US state-level AI laws
  • Canada AI governance direction
  • China AI governance direction
  • International convergence around risk, transparency and accountability
  • Relationship with UK GDPR
  • Relationship with sector regulation

Week 18: EU AI Act High-Risk AI, GPAI, Timeline and Compliance Evidence

  • High-risk AI obligations
  • Updated EU AI Act implementation timeline
  • Annex III high-risk use cases: 2 December 2027
  • Annex I embedded regulated product systems: 2 August 2028
  • Provider obligations
  • Deployer obligations
  • Risk management system
  • Data governance
  • Training data
  • Validation data
  • Testing data
  • Technical documentation
  • Record keeping
  • Logging
  • Transparency and instructions for use
  • Human oversight
  • Accuracy
  • Robustness
  • Cybersecurity
  • Quality management system
  • Conformity assessment
  • EU database registration
  • Post-market monitoring
  • Serious incident reporting
  • Corrective actions
  • GPAI obligations
  • Systemic-risk GPAI
  • Transparency for downstream providers
  • Copyright policy
  • Training data summary
  • Model evaluations
  • Adversarial testing
  • Incident reporting
  • External communication planning
  • Regulatory evidence preservation

Week 19: UK GDPR, DUAA, DPIA and AI Privacy

  • UK GDPR basics
  • Data Protection Act 2018
  • Data (Use and Access) Act 2025
  • Personal data
  • Special category data
  • Criminal offence data
  • Controller
  • Processor
  • Joint controller
  • Lawful basis
  • Consent
  • Legitimate interests
  • Public task
  • Contract
  • Legal obligation
  • Transparency
  • Privacy notices
  • Fairness
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability
  • DPIAs
  • Automated decision-making after DUAA
  • Articles 22A–22D
  • Significant decisions
  • Solely automated processing
  • Meaningful human involvement
  • Special category data restrictions
  • Mandatory safeguards
  • Information to affected people
  • Right to make representations
  • Right to obtain human intervention
  • Right to contest the decision
  • Profiling
  • Decision-support vs solely automated decision-making
  • Recruitment automation
  • Human review vs rubber-stamping
  • Data subject rights
  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to object
  • Privacy by design
  • Security by design
  • Anonymisation
  • Pseudonymisation
  • Synthetic data
  • Data sharing
  • Supplier due diligence
  • Retention
  • Employee monitoring
  • Vulnerable groups
  • AI and privacy notices
  • AI and data subject complaints
  • AI and personal data in model training
  • Plain-language explanations for affected people

Week 20: COSO Internal Control Foundations for AI

  • What COSO is
  • Why internal controls matter
  • Internal control basics
  • Control environment
  • Risk assessment
  • Control activities
  • Information and communication
  • Monitoring activities
  • COSO principles overview
  • Governance culture
  • Accountability
  • Segregation of duties
  • Control ownership
  • Control documentation
  • Control design
  • Evidence quality
  • Management oversight
  • Board reporting
  • How COSO complements NIST and ISO
  • AI control maturity

Week 21: AI Control Testing, Assurance and Audit Readiness

  • Assurance planning
  • First line controls
  • Second line oversight
  • Third line internal audit
  • Control design effectiveness
  • Control operating effectiveness
  • Testing controls
  • Sampling evidence
  • Walkthroughs
  • Inquiry
  • Inspection
  • Reperformance
  • Observation
  • Control deficiencies
  • Significant gaps
  • Remediation
  • Management action plans
  • Audit trail
  • Evidence repository
  • Continuous monitoring
  • Assurance dashboard
  • Control maturity
  • Reporting findings
  • Audit-ready evidence packs
  • External assurance
  • Independent review
  • Model cards as audit evidence
  • Release-readiness review
  • Regulatory evidence preservation

Week 22: Integrated AI Governance Operating Model

  • Integrated AI governance lifecycle
  • AI use-case intake
  • AI system inventory
  • Risk tiering
  • EU AI Act classification
  • UK GDPR screening
  • DPIA trigger
  • AI impact assessment trigger
  • Security review trigger
  • Procurement review
  • Supplier review
  • Vendor/licensing agreement risk review
  • Buy vs build risk comparison
  • Proprietary vs open-source risk comparison
  • Hosted vs self-hosted risk comparison
  • Model review
  • Data review
  • Testing review
  • Legal review
  • Release approval
  • Risk acceptance
  • Post-launch monitoring
  • Incident management
  • External communication plans for incidents
  • Deactivation policy
  • Localisation/geographic restriction policy
  • Periodic review
  • Retirement
  • Evidence repository
  • Governance dashboard
  • Board reporting
  • RACI model
  • Policy architecture
  • Decision gates
  • Exceptions
  • Waivers
  • Continuous improvement
  • Vendor/licensing checks: data use, training on customer data, data retention, confidentiality, intellectual property, output ownership, audit rights, security obligations, subprocessors, incident notification, service availability, model changes, performance claims, indemnity, liability limits, termination rights, export/localisation restrictions, compliance support, evidence provision

Week 23: Sector Case Studies and Practitioner Judgement

  • Financial services AI governance
  • Credit scoring
  • Fraud detection
  • Customer advice
  • Consumer protection
  • Fair lending
  • Model risk management
  • Healthcare AI governance
  • Triage support
  • Clinical decision support
  • Patient data
  • Safety
  • Product liability
  • Medical device boundary
  • Recruitment and HR AI governance
  • CV screening
  • Candidate transparency
  • Bias and employment decisions
  • Non-discrimination law
  • Public sector AI governance
  • Citizen services
  • Equality impact
  • Procurement
  • Accountability
  • Insurance AI governance
  • Claims triage
  • Fraud scoring
  • Pricing support
  • Vulnerable customers
  • Internal copilot governance
  • Enterprise RAG
  • Data leakage
  • Access control
  • Staff misuse
  • IP, privacy and confidentiality risk

Week 24: Mock Exam, Capstone Evidence Pack and Final Viva

  • Final exam structure
  • Question types
  • Multiple-choice questions
  • Scenario questions
  • Short-answer questions
  • Evidence-pack questions
  • Practitioner judgement questions
  • Time management
  • How to read scenario questions
  • How to spot distractors
  • How to separate harm, risk, control and evidence
  • How to identify the relevant actor: provider, deployer, developer, user, affected person, supplier
  • How to map a scenario to OECD AI Principles
  • How to map a scenario to NIST AI RMF
  • How to map a scenario to ISO/IEC 42001
  • How to use ISO/IEC 42005 impact assessment thinking
  • How to classify under EU AI Act
  • How to identify wider legal issues
  • How to identify UK GDPR and DUAA automated decision-making issues
  • How to apply COSO control thinking
  • How to assess vendor risk
  • How to write an approval recommendation
  • Capstone evidence-pack review
  • Viva preparation
  • Final improvement plan
  • Practitioner confidence check

How the course works

  • Live or recorded weekly lessons, designed for working professionals at around 5 to 8 hours per week.
  • 2 to 3 hours of live or recorded lesson each week
  • 1 to 2 hours of reading and notes, plus 1 to 2 hours on a practical artefact each week
  • 30 to 60 minutes of quiz and exam practice each week, 5 checkpoint exams and a full timed final mock exam

Practical work

Across the course you'll produce real, usable work, not just notes. You'll leave with:

  • AI System Description
  • AI Lifecycle Map
  • AI Actor Responsibility Map
  • AI Model Type Assessment
  • Stakeholder Map
  • AI Harm Assessment
  • Probability/Severity Harms Matrix
  • AI System Inventory Entry
  • Basic AI Risk Register
  • AI Control and Evidence Matrix
  • AI Legal Risk Checklist
  • OECD AI Principles Mapping
  • NIST AI RMF Assessment
  • NIST GOVERN Mapping
  • NIST MAP Context Assessment
  • NIST MEASURE Testing Plan
  • NIST MANAGE Risk Treatment Plan
  • Model Card
  • System Card
  • RAG Risk Checklist
  • Agentic AI Control Checklist
  • ISO AI Standards Crosswalk
  • AIMS Scope Statement
  • AIMS Context Register
  • AI Policy Extract
  • AI Objectives
  • ISO 42001 Operating Procedure
  • ISO 42001 Control Mapping
  • ISO 42001 Gap Assessment
  • ISO 42005-Style AI Impact Assessment
  • EU AI Act Classification Checklist
  • Global AI Law Scan
  • High-Risk AI Compliance Matrix
  • EU AI Act Implementation Roadmap
  • UK GDPR / DUAA ADM Safeguards Review
  • UK GDPR DPIA Screening
  • Privacy Risk Assessment
  • Human Oversight Plan
  • AI Testing and Evaluation Plan
  • Supplier AI Due Diligence Checklist
  • Vendor/Licensing Agreement Risk Review
  • Buy vs Build Risk Comparison
  • Deactivation and Localisation Policy
  • AI Incident Report Form
  • External Incident Communication Plan
  • Post-Deployment Monitoring Plan
  • COSO Risk-Control Matrix
  • Control Test Plan
  • Assurance Summary
  • Board Report Template
  • Final Approval Recommendation
  • Final Presentation / Viva Pack

What's included

  • 24 weekly modules with live or recorded lessons, quizzes and scenario-based exam practice
  • 5 checkpoint exams plus a full timed final mock exam
  • 50+ practitioner templates covering the AI governance lifecycle
  • Capstone evidence pack review and a final practitioner viva
  • Templates and worksheets for every module
  • Recordings of every live session
  • Slides from each session
  • Feedback on practical work
  • Certificate of completion

Prerequisites

No prerequisites. Learners do not need to be AI engineers, data scientists, developers, lawyers or auditors.

Who delivers it

Collins Obasuyi, Founder & Principal Consultant

Collins works across product strategy, AI, delivery, quality and education, and teaches from real product and delivery work rather than abstract theory. Sessions are built around practical judgement: making decisions, working through trade-offs and applying methods that hold up outside the classroom.

FAQ

Are sessions recorded?

Yes. Every live session is recorded and shared with participants who can't attend live.

Can my employer pay for this course?

Yes. We're happy to provide an invoice for employer-funded enrolment.

Paid programme

Ready to continue beyond the free preview?

Ask for the next cohort, payment and employer-funded enrolment details. We will reply with the information you need to make a decision.

Request enrolment details

Start a conversation

Have a product or AI decision to make?

Useful first calls usually start with one unclear decision, a deadline and a team that needs a practical next move.

Tell us about it