Skip to main content
Course

AI Assurance & Compliance

Turn AI risk into assurance you can prove.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

9 hours

Estimated time

What you will be able to do

  • Explain how AI risk differs from traditional IT and model risk, and scope an assurance engagement across the full AI lifecycle.
  • Build an AI system inventory and tier each system by risk using EU AI Act categories and your own internal criteria.
  • Stand up an AI governance program with clear structure, policy, ownership, and a working AI risk register.
  • Map a control set to the NIST AI RMF functions and ISO/IEC 42001 requirements, and crosswalk the two into one control framework.
  • Assess third-party and foundation model providers for data, security, and evaluation risk before they reach production.
  • Govern generative AI risks including prompt injection, data leakage, hallucination, and misuse, backed by evaluation evidence.
  • Gather and test control evidence, then report a defensible assurance opinion and remediation plan to technical and executive stakeholders.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Foundations of AI Assurance

    AI systems break the assumptions behind traditional IT and model risk: they learn from data, drift over time, and can behave in ways no one specified. This module is your foundation as an AI auditor. You will see why AI risk is genuinely different, walk the AI lifecycle stage by stage, and catalog the harms you must probe: bias, safety, privacy, security, and opacity. You will then see how the major instruments fit together: the voluntary NIST AI RMF, the certifiable ISO/IEC 42001 management system, and the binding EU AI Act. Their risk tiers give you the logic for an AI system inventory and risk tiering scheme that scopes every assessment that follows.

    2 lessons · 5 quiz questions

  2. 02

    Building the Governance and Control Program

    With scope already set, you stand up the program an auditor assesses against. You will build an ISO/IEC 42001 management system with real governance bodies, an AI policy, clear per-system ownership, and a working AI risk register, then design lifecycle controls and map them to both the NIST AI RMF and ISO/IEC 42001. You leave with a crosswalk that turns two frameworks into one control set you can test, certify, and report against.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Third-Party and Generative AI Risk

    Most AI risk now arrives through someone else's model or API. This module trains you to assess third-party and foundation model providers (their data practices, security, evaluations, and contracts) and then to govern generative AI head on: prompt injection, data leakage, hallucination, and misuse. You finish able to build the evaluation and guardrail evidence that proves a generative system is fit to deploy.

    2 lessons · 5 quiz questions

  4. 04

    Evidence, Testing, and Stakeholder Reporting

    Assurance is only as strong as the evidence behind it. This module teaches you to gather and test proof that AI controls actually operate: model documentation, validation results, monitoring logs, and evaluation runs. You will apply real audit procedures, write findings that survive management challenge, rate them by genuine risk, and report a defensible opinion to both technical and executive stakeholders, backed by an audit trail that holds up under regulatory scrutiny.

    2 lessons · 5 quiz questions · assignment