
Section 2: Identify AI types, apply NIST AI RMF and EU AI Act, evaluate AI use cases, and align AI business strategies with organizational objectives.
Examine the risk and governance implications across ANI, AGI, and ASI, then explore generative AI fundamentals and model types like LLMs, GANs, and diffusion models.
Explore multi-agent systems in ai risk management and governance of agent interactions; examine predictive models, their scores or probabilities, and risks like bias, drift, and explainability.
Analyze unsupervised learning on unlabeled data, featuring clustering and dimensionality reduction, with use in customer segmentation and security detection, and examine reinforcement learning risks, reward hacking, and governance controls.
Neural networks underlie deep learning, with input, hidden, and output layers and tunable weights; understand CNNs, RNNs, and transformers, plus opacity, adversarial risk, and explainability tools SHAP and LIME.
Consolidates ai types, agentic ai, predictive models, and machine learning, highlighting key risks and governance controls, including oversight, bias, drift, and explainability, mapped to compliance frameworks.
Explore explainability and transparency as legal and governance requirements, examine high-risk AI under the EU AI Act and NIST framework, and map lifecycle risks from design to retirement.
Explore the NIST AI risk management framework (AIRMF), a voluntary lifecycle guide published January 2023 that improves AI trustworthiness through Govern, Map, Measure, and Manage, with profiles shaping implementation.
Explore how GPAI models under the EU AI Act face transparency and documentation obligations, while systemic risk GPI models trigger stricter duties like adversarial testing and incident reporting.
Explore fairness and accountability in AI governance, and examine safety, privacy, human oversight, and robustness across NIST and EU AI Act frameworks for high-risk applications.
Risk scenarios reveal hidden threads in AI use cases and drive go/no-go decisions through the NIST measure function, while AI-ROI weighs data, governance, costs, and tangible and intangible benefits.
Evaluate AI benefits holistically via value impact assessment, aligned with strategic goals and documented objectives under ISO IEC 42001, and integrate risk management with ROI analysis to guide investment decisions.
Define AI opportunities and distinguish operational from strategic value, showing how automation and new offerings drive efficiency, revenue, and risk reduction. Align opportunities with NIST MAP and ISO 42001 governance.
Define AI vision and AI mission as distinct, leadership-driven directions, mapped to ISO/IEC 42001 and COBIT EDM01, with real-world healthcare and financial services examples and focus on value alignment.
Explore how National Institute of Standards and Technology risk management framework and European Union artificial intelligence act address value alignment with human rights, governance, misalignment risks, and build-versus-buy decisions.
Master due diligence and contract protections for AI vendors, covering ethics, governance, transparency, data ownership, vendor concentration, opaque models, EU AI Act, ISO IEC 42001, and AI model inventory.
Maintain an AI model inventory capturing name, version, deployment date, governance status, training data source, and risk tier, aligned with NIST and ISO frameworks for governance.
AI governance is a framework of policies guiding responsible AI use, aligning with organizational values via accountability, transparency, and ethical oversight, including NIST AIRMF and the EU AI Act.
Identify how the NIST AIRMF's four functions—govern, map, measure, manage—build AI risk programs, guided by two frames and seven trustworthy characteristics, with profiles for customization.
Explore how COSO ERM integrates AI risk into enterprise-wide risk management, aligning risk appetite with strategy, and map the three lines of defense, governance roles, and policy requirements for AAIR certification.
Explore AI governance foundations: risk appetite set by the board and risk tolerance within governance frameworks, plus COBED EDM02 alignment, shadow AI risks, ISO 42001, and Plan-Do-Check-Act for continuous monitoring.
Consolidate AI governance fundamentals by aligning accountability, transparency, and ethical oversight with key frameworks like NIST AIRMF, ISO 42001, and the EU AI Act; define roles and risk appetite.
Explore how COBIT 2019 anchors AI governance by linking board-level oversight to management and operations. Learn roles of EDM, APO, BI, and DSS across AI risk, accountability, and lifecycle governance.
Combine COBIT governance with ISO/IEC 42001 AI management to create a comprehensive AI governance framework and map AI risk using COSO ERM's five components.
Identify, assess, and respond to AI risks within the COSO ERM performance component using the four risk responses, while integrating the AI risk register into ERM for enterprise-wide governance.
Internal audit provides independent assurance on AI risk, assessing AI controls, model validation, and bias evaluations, with expanding scope under high-risk AI and the EU AI Act.
AI projects require iterative management with formal risk gates at every phase, enforce change control and rollback, and apply SOPIT DSS05 and BAE guidance to govern AI risk.
Explore how artificial intelligence fits into business continuity planning, highlighting AI-specific recovery challenges. Learn about rollback risks, manual fallback planning, and governance with COBIT and COSO.
The governing body sets AI direction, approves risk appetite, and bears non-delegable accountability for AI outcomes, aligning policy and oversight with NIST AIRMF, EU AI Act, and ISO 42001.
See how a real-world AI charter enforces fairness, requires explainability for credit decisions, and drives downstream controls, audits, and vendor contracts across a cross-functional AI steering committee.
Clarify accountability in ai governance as owning outcomes across design, deployment, and operation, distinct from responsibility, and address accountability gaps, including multi-vendor supply chains.
Learn how the EU AI Act assigns provider and deployer accountability, sets high-risk requirements and penalties, and how ISO-IEC 4-2001, COBIT 2019, and COSO shape AI governance and roles.
Explore how human oversight enforces ai accountability through three levels—human in the loop, on the loop, and in command—under the eu ai act for high-risk systems, with explainability.
Assign a single accountable owner per AI system to avoid accountability diffusion, and codify contractual accountability among manufacturers, vendors, and operators for multi-party AI oversight.
Explore how RACI clarifies accountability in AI governance, mapping roles from govern to manage, and aligning with NIST AI RMF and the EU AI Act for provider and deployer responsibilities.
Identify common RACI breakdowns in AI programs—shared accountability, missing consultations, and excluded stakeholders. Always assign an accountable owner to every AI output and apply COVID RACI templates across the lifecycle.
Master RACI for AI solutions by defining the four roles: responsible, accountable, consulted, informed, and mapping them to NIST, EU AI Act, ISO 42001, and COBITE.
Define the AI acceptable use policy to set who may use AI, what is allowed, and accountability, ensuring alignment with the EU AI Act and ISO-IEC 42001 for risk reduction.
Discover how an AI acceptable use policy defines allowed use, requires human review and data classification, and ties ownership, accountability, and training to ISO/IEC 42001 governance.
Assess unverified ai outputs' regulatory risk and implement mandatory human review within an acceptable use policy (AUP), extend governance to third-party tools, and establish annual reviews and executive approvals.
Explore how the EU AI Act shapes high-risk AI policies within a QMS, including prohibitions and transparency, along with policy lifecycle alignment to COBIT APO, COSO, and NIST RMF.
Learn risk-based AI policy design that scales rigor to the system's risk level, with cross-functional governance, senior leadership approval, and clear controls for high-risk applications like healthcare AI.
Explore AI governance foundations by distinguishing policies, standards, procedures, and manuals, and learn how procedures translate policy into action across development, monitoring, and data governance.
Outline deployment risk assessments, approvals, change control, rollback plans, and monitoring, drift detection, retraining triggers, incident response, plus data governance with provenance and consent under the EU AI Act.
Explore human oversight in AI risk governance and the MAP function for risk identification. Learn how EU AI Act Article 14 requires override authority and formal review for high-risk systems.
Define role-based owners and apply the raki model to keep ai procedures current and enforceable, with annual and event-driven reviews ensuring version control and training to prevent governance gaps.
Communicate AI procedures through accessible, role-based channels and reinforce them with documented training to measure governance effectiveness, aligning with NIST AI RMF, ISO 42001, and EU AI Act requirements.
Culture anchors ai risk governance beyond policies, embedding responsible ai behavior across the organization, while risk tolerance and risk appetite shape frameworks—NIST AIRMF govern, ISO/IEC 42001, and COBIT APO 1.2.
Consolidate culture as a governance control shaping AI risk decisions, align with NIST AIRMF and ISO-IEC 42001, and define risk appetite and tolerance while updating policies and training.
Explore how AI workforce impact reshapes roles through displacement, augmentation, and re-skilling across all organizational levels, and how governance frameworks and laws address training and competence.
Master automation bias and skills gaps in AI risk management. Apply change management, reskilling, and upskilling to foster governance-aligned AI adoption.
recognize human oversight is a shared workforce duty demanding trained staff and clear roles, aligning with NIST AIRMF and EU AI Act article 14, and reskilling to counter automation bias.
Explore ai legal compliance foundations within the aair framework, covering privacy, fairness, transparency, and cross-border rules that shape ai risk management.
high-risk AI systems under the EU AI Act require ongoing risk management, data governance, logging, and human oversight; privacy laws like GDPR article 22 shape automated decision-making and explainability.
Navigate cross-border AI compliance by understanding extraterritorial EU AI Act and GDPR data transfers, and apply governance frameworks like ISO/IEC 42001, NIST AI RMF, COBIT APO12, and COSO ERM.
The lecture examines GDPR enforcement against Clearview AI, focusing on unlawful basis, DPIA, and transparency, and covers proxy discrimination, disparate impact testing, EU AI Act audits, and penalties.
Layer EU AI Act, GDPR, and sector laws to achieve multi-layered compliance. Map and manage AI risk using DPIAs, logging, human oversight, bias audits, and explainability, then apply jurisdiction-based sequencing.
Identify regulatory gaps in AI, including sector and technology gaps, and why they persist as AI outpaces law. Use generative AI and employment screening examples to guide proactive compliance.
Regulatory arbitrage exploits weaker rules to deploy high-risk AI, risking end-user harm, reputational and legal exposure, while signaling gaps in explainability, deepfakes, agentic AI, and EU AI Act governance.
Explore legal mapping for ai systems, linking activities to sector-specific and cross-sector regulations, navigating multi-jurisdictional rules across the ai lifecycle to reduce compliance risk and strengthen governance.
Default to the strictest standard when regulations clash, and seek formal clarification with documented decisions. Build a living legal register and use a requirements traceability matrix aligned with ISO/IEC 42001.
Monitor regulatory developments continuously, trigger remapping when laws change, and maintain audit-ready documentation that links to NIST AI RMF, ISO IEC 42001, and the EU AI Act.
Learn how internal and external audits verify AI conformance under the EU AI Act, with third-party reviews by notified bodies and ISO/IEC 42001, plus NIST AIRMF, for ongoing post-deployment monitoring.
Apply the NIST AI RMF’s govern and manage functions to establish accountable governance, due diligence, and liability controls, augmented by ISO/IEC 42001 impact assessments and supplier agreements.
Examine contractual liability gaps in AI vendor agreements, indemnification, and the role of human-in-the-loop oversight under EU AI Act; learn documentation and pre-deployment impact assessments to mitigate high-risk AI liability.
Explore how IP risk fits into AI governance, covering creation, training, and outputs, including infringement, loss of own assets, and unclear ownership, with training data and leakage safeguards.
Contracts serve as frontline controls for AI IP risk, highlighting indemnification, output ownership, data use restrictions, and confidentiality, while governance and internal policies prevent IP leakage.
Navigate EU AI Act article 53 obligations for GPAI providers and deployers, ensuring copyright compliance, vendor documentation, and ISO/IEC 42001 governance with data provenance and SCA.
Review contract clauses to manage AI vendor risk, clarifying data ownership, model IP rights, explainability obligations, audit rights, liability, indemnification, and regulatory compliance within governance.
Require AI vendors to meet ISO 27001 security standards and respond to incidents promptly, with contracts binding GDPR and EU AI Act compliance and termination rights.
Understand shared responsibility between vendors and deployers, including vendor accuracy and security, client oversight, and the need for explicit contracts, RACI, and EU AI Act compliance.
Examine a biased hiring ai case to show shared responsibility; deployers bear liability, and contracts must address bias audits and key data ownership, liability, and security clauses.
Responsible AI means ethical and accountable AI aligned with human values across the lifecycle, with fairness, transparency, accountability, privacy, safety, reliability, governance, risk management, and legal obligations.
Explore the EU AI Act as the primary regulatory framework for responsible AI, detailing transparency, human oversight, data governance, high-risk requirements, and conformity assessments for providers and deployers.
Explore accountability in responsible AI through ownership, audit trails, and redress, then examine transparency and EU acts, bias, and privacy risks with design-based mitigations.
Analyze how AI impacts society at scale, focusing on workforce displacement and the digital divide, and apply responsible AI principles within regimes like the EU AI Act and post-deployment monitoring.
Identify how AI bias is systematic and harms real-world decisions. Outline data bias types—historical, representation, measurement—and note bias during design, evaluation, and deployment within the NIST AI RMF.
Examine ISO-IEC 42001's management-system approach to AI fairness, embedding bias controls, post-deployment review, and ethics alignment, with real-world cases like Amazon and COMPASS to illustrate proxy discrimination and metric trade-offs.
Detect bias in AI systems through disparate impact analysis, fairness audits, and explainability tools like SHAP and LINE. Apply bias mitigation across pre-processing, in-processing, and post-processing with governance and monitoring.
Explore transparency as a core pillar of AI governance, covering data, model, and process transparency, and compare explainability, interpretability, and global versus local explanations for risk, audit, and compliance.
Explore lime and shap as post hoc explainability tools for black box ai, revealing local feature contributions and supporting governance, transparency, and accountability under the nist ai risk management framework.
Explore the EU AI Act's transparency requirements for high-risk AI systems and general purpose models, including documentation, instructions for use, and training data disclosures.
Explore the trade-offs between transparency, intellectual property, and adversarial risk, and learn how explainability and audience-specific communication enable effective human oversight in AI risk governance.
Explore explainability and transparency in healthcare AI to protect patient safety and meet EU AI Act disclosure requirements. Learn how APO and BAI governance and AI auditing establish traceability.
Consolidate topic 1.23 on transparency and explainability by outlining openness across data, models, and processes, explainable reasoning, and interpretable designs, with tools like LIME, SHAP, model cards, data sheets.
Explore AI governance foundations by defining trust as evidence-based, transparency-driven confidence, and examining safety as a proactive design requirement; learn how NIST and AAIR frame trust, safety, and risk management.
Examine human oversight in AI, including human in the loop and human on the loop models, EU AI Act requirements, and lessons from the Amazon and Uber cases.
Examine how transparency builds trust in AI and meets EU and NIST guidelines. Quantify trust with accuracy, drift, audits, and stakeholder feedback within governance frameworks.
AI decisions at scale amplify bias and create societal harm, exposing accountability gaps. Examine governance frameworks for risk management and disparate impact classifications.
Explore how AI infrastructure drives environmental impact, energy and water use, and unequal access, while analyzing vendor concentration and systemic risk within governance frameworks like COBIT.
Explore AI sustainability as a two-sided concept of resource consumption and environmental enablement, and compare training versus inference energy costs, water use, hardware waste, and carbon footprint.
Understand how the NIST AI RMF treats environmental impact as a trustworthiness risk, handled by map, govern, and manage, with EU act and ISO standards guiding transparency and carbon reporting.
Assess AI-driven greenwashing risks and ethical AI trustworthiness; practice independent auditing of environmental claims, applying COBIT APO12, green AI design, and sustainable lifecycle management to manage energy and carbon disclosures.
AI is classified by functionality into four types: reactive, limited memory, theory of mind, and self-aware, driving risk and governance.
Map privacy by design across the EU AI Act and GDPR article 25 with ISO 42001, and apply differential privacy and anonymization to prevent model memorization and data risks.
Map MLSecOps to NIST AIRMF and NIST SP800218A, and apply ISO/IEC 42001 for secure ML development, while examining scalability across training, inference, and data pipelines with governance under COBIT.
Explore structured, unstructured, and semi-structured data and their roles in AI risk and model training. Compare storage, processing, and risk, and outline preprocessing and data governance basics.
Explore structured and unstructured data risks—model drift, incomplete fields, bias, hidden pii—under governance across the AI lifecycle and privacy frameworks.
Assess AI systems with a due diligence checklist covering model accuracy, data lineage, and governance; align vendor risk with NIST AI RMF, ISO/IEC 42001, and EU AI Act.
Define data ownership, restrict vendor training on client data, and secure IP ownership and licensing for AI outputs; manage liability, exit rights, and third-party risks under EU AI Act.
Explore ISO/IEC 42001 clause 8.4 and annex b to evaluate externally provided AI systems, manage procurement, and address open source and shadow AI risks.
Model documentation records an AI system’s design and behavior, anchoring governance, auditability, and reproducibility, with data provenance, architecture, and performance, aligned to NIST AIRMF, ISO 42001, and EU AI Act.
Model cards provide a standardized transparency document for AI models, detailing model details, intended use, limitations, and disaggregated performance to support fairness, accountability, and governance.
Explore how missing, incomplete, or outdated model cards create deployment risks and governance failures, and learn ownership, shared responsibility, and layered, versioned documentation aligned with NIST AI RMF.
Procure third-party AI models by reviewing vendor model cards and technical documentation, verify completeness and updates, and uphold buyer accountability under EU AI Act and COSO governance.
Identify how data set sourcing shapes AI risk by weighing internal and external data sources for quality and representativeness. Relate data provenance to governance, accountability, and regulatory compliance.
Identify privacy risks in AI data sourcing, including consent, PII, re-identification, and GDPR/CCPA limits. Recognize controls such as anonymization, pseudonymization, differential privacy, and data minimization.
Explore data collection methods for AI, including crowdsourcing, web scraping, and surveys, and their risks to labeling and bias. Understand how data governance, catalogs, and regulations shape training data quality.
Consolidate dataset sourcing by distinguishing internal, external, open, and synthetic data; trace provenance; assess licensing, bias, privacy; align with EU AI Act article 10, NIST, ISO/IEC 42001, COBIT APO10 governance.
Apply data validation as a governance control to ensure data fitness before AI model training, covering accuracy, completeness, consistency, timeliness, validity, and uniqueness.
Master data provenance and data lineage to enable auditable, trustworthy AI training data and traceability; learn how NIST AI RMF, EU AI Act Article 10, and ISO-IEC 42001 require provenance.
Identify missing data types—MCAR, MAR, MNAR—and apply bias-aware imputation and validation to prevent fairness risks in AI, including class imbalance techniques like SMOTE, undersampling, and cost-sensitive learning.
Identify and measure bias in training data before model training, including sampling, label, and historical bias, using metrics like demographic parity, equalized odds, and disparate impact.
Explore three-way data splitting—training, validation, and test sets—and guard against data leakage, using cross-validation and governance practices to ensure honest AI risk assessment and regulatory compliance.
Align data validation across stewardship, risk ownership, and audit to ensure governance and accountability in AI systems. Validate data from pre-training to post-deployment with six quality dimensions and framework mappings.
Analyze how AI governance frameworks address unintentional drift and intentional changes, via NIST AI RMF MISHA and MANAGE, ISO/IEC 42001 improvement controls, and EU AI Act monitoring.
Analyze adversarial training limits, including incomplete protection, robustness-accuracy trade-offs, and high computational cost, while mapping these risks to NIST AIRMF, EU AI Act Article 15, and ISO 42001.
Examine how NIST AI RMF, ISO/IEC 42001, and EU AI Act Article 10 address data quality and provenance to prevent model collapse, with practical detection and mitigation strategies.
Explore performance metrics for ai risk governance, from accuracy, precision, recall to F1 score, aucroc and rmse, and learn how metric selection supports validation, audit, and regulatory compliance.
Choosing metrics matters for AI governance; accuracy can mislead in imbalanced data. fairness and bias testing—data, algorithmic, and deployment bias—are regulatory requirements protecting risk and compliance.
Examine how bias testing is mandated across NIST AIRMF, the EU AI Act, and ISO-IEC 42001, using map and measure to identify and quantify bias.
Analyze scenario analysis as a key tool for AI model validation, guiding risk mitigation planning and governance across NIST AI RMF, EU AI Act Article 15, and COSO ERM.
Explore model cards, data sheets, and validation reports to ensure transparent AI governance, independent validation, and robust audit trails across NIST, EU, and COBIT/COSO frameworks.
Explore fine-tuning risks, including missed older fraud patterns and amplified biases that can drive discriminatory outcomes. Enforce full revalidation after every fine-tune, aligning with governance requirements and avoiding partial checks.
Explore how APIs enable external AI services, compare public, private, and hybrid models, and assess data privacy under GDPR, the EU AI Act, and ISO/IEC 42001, plus related security risks.
Explore API risk in AI systems, focusing on dependency, availability, and versioning threats from external vendors; learn why continuous monitoring and governance with inventories, ownership, and audit rights are essential.
Explore AI deployment via public, private, and hybrid APIs and the security, privacy, availability, and governance risks, including NIST AI RMF and EU AI Act.
Explores how robustness is embedded in the NIST AI risk management framework and the EU AI Act, including article 15, with testing techniques, scalability, monitoring, and governance for exam readiness.
Develop a governance-driven approach to AI scalability by applying load testing, continuous monitoring, and aligned risk management across ISO 42001, NIST AIRMF, and the EU AI Act.
Consolidate robustness and scalability for AI systems by applying adversarial training, input validation, and fallback mechanisms while mapping to NIST AI Risk Management Framework and EU AI Act Article 15.
Explore model drift, including data drift, concept drift, and label drift, and how environment changes erode performance; learn PSI, KS test, and sequential methods for monitoring.
Map drift to the NIST AIRMF major and manage functions, detecting degradation and guiding retraining or decommissioning, as EU act articles 9 and 72 and ISO 42001 clauses 9–10 mandate.
Align monitoring with AI risk, using continuous drift checks for high-risk systems and periodic reviews for low-risk ones, and establish a documented baseline with PSI-based drift detection.
Explore data dependency in AI systems and how upstream data changes alter model outputs, including structural, statistical, and source dependencies, and how governance frameworks manage these risks.
Identify what constitutes an ai model change and why governance, approval, and traceability matter. Categorize changes as major, minor, or patch, with pre-deployment validation, bias testing, and cab approval.
Significant AI changes trigger regulatory reassessment under the EU AI Act, with high-risk systems especially scrutinized. Organizations must perform post-market monitoring and bias evaluations before deployment, and document societal impact.
Emergency changes rapidly modify AI systems to prevent harm, security breaches, or regulatory mandates. They require expedited approval, full documentation, and a post-implementation review, per COVID-BAI-06 and related frameworks.
Maintain AI model performance over time by preventing data, concept, and performance drift and decay; comply with EU AI Act post-market monitoring and NIST AI risk management governance.
Explore the Tay chatbot failure, emphasize adversarial input filtering and human-in-the-loop oversight, and map continuous learning governance to NIST manage, EU AI Act, and ISO/IEC 42001 change management.
Explain data disposition at AI end-of-life, detailing deletion, anonymization, archival, and transfer of training data, model weights, and logs under NIST AI RMF, ISO 42001, and EU AI Act.
Mitigate decommissioning risk by enforcing a formal data disposition plan that addresses data remanence, insider transfers, and third-party vendor retention.
AI is transforming industries—but it is also introducing a completely new class of risks.
From model bias and data leakage to regulatory scrutiny and operational failures, organizations today need structured, practical, and audit-ready approaches to manage AI risk.
This course is designed to help you master Advanced in AI Risk Management (AAIR) aligned with real-world enterprise expectations and global frameworks such as NIST AI RMF, ISO/IEC 42001, and the EU AI Act.
Important upfront clarity
This is a deep and detailed (verbose) course.
It is intentionally designed to cover each topic and subtopic comprehensively, with clear explanations and real-world risk scenarios.
If you are looking for a quick overview, this may feel extensive.
If you are serious about mastering AI risk management, this is exactly what you need.
What you will learn
End-to-end AI risk lifecycle management
AI governance structures, ownership models, and accountability
Risk identification, assessment, and prioritization using real frameworks
AI threat modeling (including STRIDE for AI)
Model risk, bias risk, and validation approaches
Control design: preventive, detective, corrective, compensating
AI incident response and risk treatment strategies
Vendor and third-party AI risk management
Regulatory alignment with NIST, ISO 42001, EU AI Act
AI risk is not optional anymore—it is a board-level concern.
This course equips you with the depth, structure, and practical knowledge required to confidently manage AI risks in real-world environments.