Professional Certification · v5.0 · 2026 Edition

AI Governance, Risk & Safety

A practitioner-grade certification for the people who actually run AI safely in organisations. Now with a dedicated module on Agentic AI Governance — the part of the framework that fails first, that examiners are about to start testing, and that nobody else is teaching properly. Twelve weeks. Fifty hours of instructor-led teaching. Business-first, with optional technical depth.

Duration
12 weeks · ~4 hrs / week
Live teaching
50 instructor-led hours
Structure
7 modules + capstone
Assessment
Proctored exam + capstone

What's included

i.
50 hours live teaching

12 weekly sessions, ~4 hours each. Live, online or blended cohorts.

ii.
Self-paced study materials

Reading packs, annex videos, regulatory primers, glossary.

iii.
Real-world case studies

15+ anonymised incidents and use cases across regulated sectors, including agent failures.

iv.
Exercises & labs

Per-module exercises plus hands-on labs in Microsoft, AWS, and OSS tooling.

v.
Office hours & mentoring

Weekly Q&A and 1:1 mentor sessions with practising AI governance leads.

vi.
Capstone portfolio

Finish with a defensible artefact pack — register entry, risk assessment, policy, workflow, agent control plan.

12-week schedule at a glance

Each week = ~4 hours instructor-led + ~2–3 hours self-paced study.

Week
Topic
Module
01
AI in business terms; where AI goes wrong; first case studies
M1 · Foundations
02
Responsible AI principles, governance vs management, key roles
M1 · Foundations
03
EU AI Act deep dive — risk tiers, obligations, GPAI, timelines
M2 · Regulation
04
UK, US, global regimes; standards (ISO 42001, NIST AI RMF); sector rules
M2 · Regulation
05
AI risk taxonomy; data & model risk; AI risk and impact assessment
M3 · Risk & Safety
06
Generative AI risks; AI security & MLSecOps; safety engineering & evals
M3 · Risk & Safety
07
Governing AI Agents — why agents differ from models; inventory, scope, revocation, accountability, examiner readiness
M4 · AI Agents ◆
08
Designing the AI governance framework; 3 lines of defence; policies
M5 · Framework
09
Lifecycle governance, AI TRiSM, KRIs, board reporting, vendor risk
M5 · Framework
10
AI in project management, risk management, internal audit workflows
M6 · GRC Practice
11
Implementation tour: Microsoft (Purview, Foundry, Copilot) + multi-cloud + OSS
M6 · GRC Practice
12
Capstone presentations, panel defence, proctored exam, career briefing
M7 · Capstone
01

Foundations of AI & AI Governance

Foundational ~7 hrs Weeks 1–2
Tier 01
▾
Module goal

Bring AI and non-AI people to a common baseline so everyone can meaningfully discuss governance and risk by the end of week 2.

CH 1.1

What is AI & Generative AI in business terms

  • Plain-English concepts: data, models, training, inference, the AI lifecycle
  • Types of AI: classical ML, generative AI, foundation models, agentic systems
  • Typical enterprise use cases: customer service, scoring, forecasting, copilots, agents
  • Tech drilldownOptional annex: how transformers, embeddings and RAG actually work
CH 1.2

Where things go wrong — case studies

  • Bias and unfair outcomes, hallucinations, privacy breaches, security issues, automation over-reliance
  • Real incidents: Apple Card credit limits, Air Canada chatbot, Dutch SyRI, COMPAS, agent jailbreaks, deepfake fraud
  • Anatomy of an AI failure: root causes and missing controls
  • Reference sources you will keep tracking: AIAAIC, OECD AI Incidents Monitor
CH 1.3

What “AI governance” means

  • Governance vs. management vs. technical controls — clean distinctions
  • Responsible AI principles: fairness, accountability, transparency, safety, privacy, human oversight, robustness
  • Ethics, society, environment — including AI literacy obligations under EU AI Act Article 4
  • The Govern / Map / Measure / Manage framing (NIST) and the PDCA loop (ISO/IEC 42001)
CH 1.4

Key roles & the three perspectives

  • Model developer / data scientist / MLOps engineer
  • Product owner, business sponsor, AI sponsor at executive level
  • AI governance function, RAI lead, risk, compliance, legal, internal audit, security
  • Three perspectives carried through the course: PM view · GRC view · business-owner view
◆ Exercise: map your organisation's existing or planned AI use cases and assign roles using a RACI template
02

Laws, Regulations & Standards

Foundational ~7 hrs Weeks 3–4
Tier 01
▾
Module goal

Give learners a working map of the regulatory environment so they can identify obligations and design compliant processes.

CH 2.1

EU AI Act — Deep Dive

  • Scope, extraterritoriality, prohibited practices, risk tiers
  • High-risk system obligations: risk management, data, documentation, oversight, accuracy, robustness, cybersecurity
  • General-purpose AI (GPAI), systemic risk thresholds, the Code of Practice
  • Conformity assessment, CE marking, post-market monitoring, serious incident reporting
  • Full enforcement August 2026 — penalties up to €35M; the first enforcement actions to watch
CH 2.2

UK, US & global regulatory landscape

  • UK pro-innovation approach; ICO, FCA, PRA, MHRA, Ofcom, CMA guidance; UK AISI
  • US: NIST AI RMF + Generative AI Profile, OMB M-24-10, FTC, SEC 2025 examination priorities on AI governance
  • State laws: Colorado AI Act, NYC Local Law 144, California AB 2013
  • Global: China deep-synthesis rules, Singapore AI Verify, Canada AIDA, Japan, Korea, Brazil, India
CH 2.3

Interaction with adjacent law

  • GDPR, UK GDPR, and Article 22 automated decision-making
  • DSA, DMA, Data Act, NIS2, Cyber Resilience Act, Product Liability Directive, AI Liability Directive
  • IP and copyright in training data; live litigation landscape
  • Consumer protection, equality & non-discrimination law, employment law
CH 2.4

Standards ecosystem

  • ISO/IEC 42001 AI Management System — clauses, controls, certification path
  • ISO/IEC 23894 (AI risk), 5338 (AI lifecycle), 23053, 42005 (impact assessment), 42006 (audit bodies)
  • NIST AI RMF + Generative AI Profile (AI 600-1)
  • ISO/IEC 27001 / security standards crossover; IEEE 7000 series; CEN-CENELEC harmonised standards
CH 2.5

Sector-specific obligations

  • Financial services: SR 11-7, EBA, PRA SS1/23, FCA AI discussion paper, FFIEC IT Handbook on third-party risk
  • Healthcare: FDA SaMD/PCCP, MHRA AI as a Medical Device, EU MDR
  • HR & employment: NYC LL144, Illinois AI Video Interview Act, EEOC guidance
  • Critical infrastructure, public sector procurement, defence and dual-use
◆ Exercise: map a real use case to EU AI Act Annex III, list obligations, and identify the technical file documents you will need
03

AI Risk, Safety & Trustworthiness

Practitioner ~9 hrs Weeks 5–6
Tier 02
▾
Module goal

Build the AI risk mindset and a working knowledge of safety and security themes that any role can act on, with optional technical depth. Agent-specific governance is then covered in depth in Module 4.

CH 3.1

AI risk taxonomy & assessment

  • Model risks: bias, robustness, drift, adversarial behaviour
  • Data risks: quality, lineage, privacy, security, IP
  • Operational risks: change management, third-party, shadow AI
  • Ethical & societal risks: discrimination, misinformation, reputational damage
  • AI-specific risk and impact assessment (AI RIA), DPIA, Fundamental Rights Impact Assessment (FRIA)
  • Use-case risk scoring and the AI risk register
CH 3.2

Data & model governance

  • Data lifecycle, lineage, quality, drift, ground-truth management
  • Bias detection and mitigation; privacy-preserving techniques (DP, federated learning, synthetic)
  • SR 11-7 / PRA SS1/23 model risk management principles applied to AI/ML
  • Evaluation, validation, benchmarking, robustness, stress testing, monitoring, drift, lifecycle controls
  • Documentation artefacts: model cards, datasheets, system cards
CH 3.3

Generative AI risks

  • Hallucinations, groundedness, factuality — causes, detection, mitigation
  • Prompt injection (direct and indirect), jailbreaks, data leakage
  • Content provenance: C2PA, watermarking (SynthID), deepfake disclosure (EU AI Act Art. 50)
  • NoteAgent-specific risks — composition, runtime drift, accountability across chains — are covered as a dedicated module next week
CH 3.4

AI security (MLSecOps essentials)

  • AI attack surface mapped to OWASP LLM Top 10 (2025) and MITRE ATLAS
  • Adversarial attacks: evasion, model inversion, membership inference, poisoning
  • Supply-chain risk: weight integrity, open-source model risk, serialisation attacks
  • AI Bill of Materials (AI-BOM): SPDX-AI and CycloneDX ML-BOM
  • AI incident response: detection, containment, forensics, disclosure
CH 3.5

AI safety, alignment & evaluation

  • Safety engineering: safe-by-design, defence-in-depth, fail-safe, kill-switches, staged rollouts
  • Human oversight models: human-in-the-loop, human-on-the-loop, human-over-the-loop
  • Red teaming, evals, continuous assurance pipelines
  • Frontier and catastrophic risks: CBRN, cyber, autonomy; responsible scaling policies; AISI work
  • A control library: preventive, detective, corrective
◆ Exercise: produce an AI risk and impact assessment plus a threat model for a real generative-AI use case
04

Governing AI Agents: Risks, Safety & Accountability

◆ NEW · Flagship Practitioner ~6 hrs Week 7
Tier 02
▾
Why this module matters

Traditional AI governance was designed for systems that predict things. Agentic AI is different. Agents do not just make predictions — they take actions: they read information, use tools, call APIs, send messages, trigger workflows, and even hand work to other agents. In regulated organisations, this creates new risks around control, accountability, safety, oversight and legal exposure. This module teaches you how to govern agentic systems in a safe, controlled and auditable way.

Core idea

Approval alone is not enough. A real control must also let you limit, monitor and revoke an agent's access when needed.

“Approval without revocation is not a control. It is a hope.” — The principle that reframes this module
CH 4.1

Why agents are different from models

  • Most existing AI governance was built for models that produce outputs from inputs. A model answers a question.
  • An agent acts across systems. In a single task an agent may:
    • read a CRM record
    • draft an email
    • query a vendor system
    • update a ticket
    • trigger a workflow
    • call another agent to continue the task
  • The governance challenge is therefore no longer just the model itself. It is the full chain of action across people, systems, tools and vendors.
  • Agents are already appearing inside platforms such as Microsoft 365, Salesforce, ServiceNow, core banking platforms, and other enterprise SaaS.
  • In many organisations, business teams are also building their own internal agents without going through formal governance.
CH 4.2

Where current governance frameworks break down

  • Current AI governance frameworks do not fully fit agentic systems. They break in four main ways.
Break 01
Inventories assume fixed systems
Traditional governance assumes each AI system can be listed once and reviewed periodically. Agents compose actions dynamically at runtime, so the workflow may change during execution.
Break 02
Validation assumes stable behaviour
Many AI controls assume the system behaves consistently between reviews. Agent behaviour depends on the prompt, available tools, memory, context, permissions and previous actions.
Break 03
Accountability becomes unclear
If Agent A calls Agent B, and Agent B uses a vendor tool to complete the action, it becomes difficult to say who is responsible for the final outcome. This creates a serious accountability gap.
Break 04
Approval is not enough
With agentic systems, the more important question is whether the organisation can quickly remove access, stop action execution, and prove that the stop worked.
CH 4.3

Inventorying agents at runtime

  • A static list of AI systems is not enough for agentic environments. Organisations need a live understanding of what agents exist, what they can access, and what they are doing.
  • The inventory must include:
    • internal agents built by business teams
    • vendor-shipped agents inside enterprise platforms
    • agents activated indirectly through software updates or platform changes
  • For each agent, capture: tools and APIs it can use, sub-agents it can call, memory or retrieval sources, identities and credentials, systems it can affect
  • Governance must shift from a one-time inventory to continuous discovery and monitoring
CH 4.4

Authorised scope, approval and revocation

  • An agent should not just be described in policy. Its limits must be enforced by the system.
  • Important control patterns: human approval for sensitive actions, sandboxing, budget limits, rate limits, restricted tool lists, session time limits
  • Identity and access management for agents: agents need their own identities, permissions and secrets handling, following least-privilege principles
  • Revocation must be a first-class control. If an agent behaves unexpectedly, the organisation should be able to disable its permissions, shut down its access, and confirm that the revocation worked.
  • Target a 90-second revocation, with evidence the control fired. Tested regularly, not just documented.
CH 4.5

Accountability across agent chains

  • When multiple agents and tools work together, accountability must be defined at two levels:
    • who owns the agent at design time — accountable for what it is authorised to do
    • who owns the agent at runtime — accountable for what it actually did in a specific session
  • For every production agent, the organisation should be able to answer four questions:
    • 1. Who is the named owner of the agent at design time?
    • 2. Who is the named owner during runtime?
    • 3. What actions is the agent allowed to take, and how is that enforced?
    • 4. How can the agent be revoked, and when was that revocation last tested?
  • Contracts alone do not solve the accountability problem. The organisation still needs a clear internal ownership model.
CH 4.6

Safety and examiner readiness

  • Regulators and examiners are increasingly likely to ask how organisations govern agents that can take real-world actions.
  • Existing rules on model risk, IT control, operational risk, and AI governance already support these oversight expectations — no new authority is required.
  • The likely examiner questions:
    • Can you show your full inventory of production agents?
    • Can you name the individual accountable for each agent?
    • Can you demonstrate how an agent is prevented from acting outside its authorised scope?
    • Can you produce evidence that revocation worked the last time it was tested?
Evidence a regulator or auditor may expect
  • A live inventory of agents in production
  • Owner records — design-time and runtime, by name
  • Scope controls enforced by the system
  • Revocation records and the date of the last test
  • Proof that controls were tested and that they fired correctly
◆ Capstone-feeder lab: (a) identify agents in your environment · (b) select one agent · (c) define the design-time owner · (d) define the runtime owner · (e) describe the system-enforced scope · (f) test or document the revocation path. This artefact carries directly into the Module 7 capstone.
05

Governance Frameworks, Policies & Operating Model

Practitioner ~7 hrs Weeks 8–9
Tier 02
▾
Module goal

Translate principles, obligations and agent controls into concrete governance structures, policies and lifecycle controls — the operating model your organisation will actually run.

CH 5.1

Designing AI governance frameworks

  • Comparison and mapping: ISO 42001 vs. NIST AI RMF vs. industry RAI frameworks
  • Mapping AI governance onto existing IT, data, security and model-risk governance — without rebuilding from scratch
  • Policy hierarchy: principles → policies → standards → procedures → guidelines
  • Adapting the framework to cover both models and agents (lessons from Module 4)
CH 5.2

Operating model, roles & three lines of defence

  • Operating models: centralised, federated, hub-and-spoke, embedded
  • Governance bodies: AI Council, Responsible AI Board, Use-Case Review Panel, Ethics Committee
  • Three lines of defence applied to AI: 1LoD (product, MLOps), 2LoD (risk, compliance, validation), 3LoD (audit, external assurance)
  • RACI for AI use-case approval, model lifecycle, monitoring, incident handling — and for agent design-time and runtime ownership
CH 5.3

Policies, standards & guidelines

  • AI acceptable use policy (including consumer GenAI tools and shadow AI)
  • AI development and validation standard
  • Agent-specific policy: scope, approval, revocation testing cadence, vendor-agent activation review
  • Data governance extensions for AI; AI literacy programme (EU AI Act Art. 4) tailored by role
CH 5.4

Lifecycle governance & monitoring

  • Use-case intake, triage, stage gates
  • Design-time checks, testing, validation, explainability reviews
  • Deployment, monitoring, incident management, decommissioning
  • AI risk register, KRIs and KCIs (including agent-specific: revocation-test freshness, scope-violation rate, vendor-agent activation count)
  • Board-level reporting and dashboards
CH 5.5

AI TRiSM, tooling & vendor / third-party risk

  • Gartner AI TRiSM pillars: explainability, ModelOps, AI app security, privacy
  • Governance-platform landscape: Credo AI, Holistic AI, Fairly, Trustible, ModelOp
  • Procurement & vendor due-diligence questionnaires (NIST AI RMF mapping)
  • Contractual clauses: indemnities, data use, IP, audit rights, sub-processors, agent-activation notice, revocation guarantees
  • Foundation-model provider risk and exit planning
◆ Exercise: design an AI governance operating model and draft an AI acceptable use policy plus an agent-specific addendum for your sector
06

AI in GRC Practice, Audit & Implementation

Practitioner / Implementer ~10 hrs Weeks 10–11
Tier 03
▾
Module goal

Show how AI governance and risk management fit into real project, risk, audit and procurement workflows — and tour the toolchain you will actually use to implement controls.

CH 6.1

AI in project & product management

  • Adding AI risk and governance checkpoints to project lifecycles (waterfall and agile)
  • Requirements, acceptance criteria and documentation for AI features, including agentic features
  • Working with technical teams on explainability, data, and testing — the questions to ask
  • Reconciling agile delivery with stage-gated governance
CH 6.2

AI in risk management

  • Updating risk taxonomies to include AI-specific and agent-specific risks
  • AI risk appetite statements, KRIs and KCIs
  • Integration with enterprise risk management, operational risk and model risk management
  • Board reporting and risk-committee packs
CH 6.3

AI in compliance & internal audit

  • Testing AI controls: sampling, evidence collection, walkthroughs
  • Algorithmic, technical, impact and outcome audits
  • Conformity assessment dry runs against EU AI Act and ISO 42001
  • Bias audits (NYC LL144); DPIA / FRIA / AIA bundles
  • Auditing agent inventory, scope enforcement and revocation — direct application of Module 4
  • Whistleblowing, contestability, redress, mandatory incident reporting
CH 6.4

Using AI to support GRC

  • AI for compliance monitoring, policy analysis, control mapping
  • Anomaly detection in GRC systems and audit data
  • Copilots for risk, audit and legal teams — and the governance of those copilots
  • Risks of AI-assisted GRC: over-reliance, automation bias, hallucination in evidence
CH 6.5

Implementation tour: Microsoft + multi-cloud + OSS

  • Microsoft Responsible AI Standard, Responsible AI dashboard, Fairlearn, InterpretML
  • Purview AI Hub, DSPM for AI, Communication Compliance, Insider Risk Management
  • Azure AI Foundry: model catalogue, evaluations, Content Safety (prompt shields, groundedness), agent governance
  • M365 Copilot & Copilot Studio agents: Conditional Access, data boundary, oversharing controls, Restricted SharePoint Search, eDiscovery, Defender for Cloud Apps shadow AI, agent identity
  • AWS: Bedrock Guardrails, Bedrock Agents, SageMaker Clarify, Model Monitor
  • Google: Vertex AI Safety, Model Garden, Agent Builder, Responsible AI Toolkit
  • Open-source: Guardrails AI, NeMo Guardrails, LangSmith, Promptfoo, Garak, PyRIT, Giskard, AgentOps
◆ Lab pack (graded): (a) Purview AI Hub setup + shadow-AI remediation · (b) Build a RAG app with Azure Content Safety + groundedness eval · (c) Red-team a Copilot agent with PyRIT · (d) M365 Copilot oversharing audit · (e) Agent inventory and revocation drill on a real tenant
07

Capstone Case Study, Exam & Career Track

◆ Applied ~4 hrs live + project Week 12
Tier 03
▾
Module goal

Apply everything to a realistic scenario — including an agentic component — defend it before a panel, sit a proctored exam, and leave with a portfolio piece and a credible next career step.

CH 7.1

Capstone case study

  • Scenario: a regulated organisation deploying a generative or agentic AI use case (e.g. AI-based hiring agent, credit-scoring assistant, healthcare triage agent, customer-service agent)
  • Identify risks; map regulatory obligations against EU AI Act / NIST AI RMF / ISO 42001
  • Propose governance, controls and oversight structure
  • Produce a Responsible AI impact assessment, DPIA and FRIA bundle
  • Design controls across data, model, prompt, output, agent, identity — including a tested revocation path
CH 7.2

Practical artefacts — your portfolio

  • AI / agent use-case register entry
  • AI risk assessment template (completed for your scenario)
  • AI policy snippet (acceptable use or development standard) plus agent addendum
  • Governance workflow diagram for your organisation
  • Agent Accountability Test answers for one production-class agent
  • Board-reporting pack and KRI dashboard mock
CH 7.3

Certification assessment

  • Proctored exam: 60–80 multiple-choice and scenario-based questions across all seven modules
  • Focused on understanding, application and decision-making — not coding or statistics
  • Capstone submission and panel defence with examiners drawn from regulators, industry and academia
CH 7.4

Career pathways & continuing education

  • Role map: AI Governance Lead, AI Risk Officer, Responsible AI Manager, AI Compliance Officer, AI Auditor, Model Validator, MLSecOps Engineer, AI Ethics Lead, AI Project / Product Manager, Agent Governance Lead
  • Stackable certifications: IAPP AIGP, ISACA AAIA, ISO/IEC 42001 LA/LI, CertNexus CAIP, BCS AI Ethics, GARP Risk & AI, CSA TAISE
  • Alumni network, mentor pool, public-speaking and writing routes
  • CPE: 40 hours over 2 years for recertification; recommended reading list and regulator feeds to follow

Careers this certification targets

Agent-governance-fluent candidates command a premium at the top end of each role.

AI Governance Lead
Agent Governance Lead
AI Risk Officer
Responsible AI Manager
AI Compliance Officer
AI Project / Product Manager
AI Auditor
Model Validator (AI/ML)

Ready to get certified?

Explore the full AI Academy catalogue, register for the next cohort, or speak with an adviser about corporate enrolment.