AI Governance Foundations
From AI risk to audit-ready assurance, one framework at a time.
Tuition
$349
Beginner
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
8 hours
Estimated time
What you will be able to do
- Explain in plain language why AI systems create risks that traditional software controls do not catch.
- Walk through the four functions of the NIST AI Risk Management Framework (Govern, Map, Measure, and Manage) and what each one produces.
- Classify an AI use case into the correct EU AI Act risk tier and list the obligations that tier triggers.
- Describe how ISO/IEC 42001 structures an AI management system and where it overlaps with ISO 27001.
- Translate the principles of fairness, transparency, and accountability into specific, testable controls.
- Gather the evidence an AI assurance review needs and spot the most common governance gaps.
- Draft a short, structured AI assurance findings write-up that a manager or auditor can act on.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Why AI Needs Governance
AI is not ordinary software. It learns from data, behaves probabilistically, and can fail in ways nobody intended. This module builds the shared mental model and vocabulary you need before touching any framework. You will learn what makes AI genuinely risky (bias, opacity, and drift), study the real incidents that made governance non-negotiable, and map the stakeholders, the AI lifecycle, and the core terms that every later module builds on.
2 lessons · 5 quiz questions
- 02
The NIST AI Risk Management Framework
The NIST AI RMF is the voluntary framework most organizations reach for first, and it gives you a repeatable operating model for AI risk. This module works through its four functions (Govern, Map, Measure, and Manage) and the seven trustworthiness characteristics they protect, then shows how a profile turns the framework into a concrete plan for one specific system.
2 lessons · 5 quiz questions · assignment
- 03
The Rules: EU AI Act and ISO/IEC 42001
Voluntary frameworks are only half the picture. Laws and certifiable standards are what create real, enforceable obligations. This module unpacks the EU AI Act risk tiers, from unacceptable down to minimal, and the duties each tier carries. It then shows how ISO/IEC 42001 turns AI governance into a certifiable management system you can audit against.
2 lessons · 5 quiz questions
- 04
Responsible AI as an Assurance Practice
Principles like fairness, transparency, and accountability only matter when someone can prove they hold. This module turns those principles into controls you can test and evidence you can collect, then walks you through a basic AI assurance review from scope to written findings, which is the core of the AI auditor role.
2 lessons · 5 quiz questions · assignment