AI Governance & AI Security
Govern and secure the AI your organization uses and builds. For governance, risk, and compliance leads: why AI needs its own governance, the frameworks and regulations you now own (NIST AI RMF, ISO/IEC 42001, EU AI Act), how to build the program (AI inventory, risk classification, policies, roles), the AI security risks you must govern (OWASP LLM, agents/RAG/MCP, the AI supply chain) and the controls and assurance to require, and how to run it (monitoring, incident response, audit). Build a complete AI governance & security (AI TRiSM) program. Defensive and vendor-neutral; educational, not legal advice.
"We can see every AI system we use and build, we've tiered the risk, we require the right controls and assurance from our teams and vendors, and we can show a regulator or auditor exactly how we govern it"
6 Interactive Sessions
Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.
- 1
Why AI needs its own governance — it isn't just another IT system
You already govern IT. AI breaks the assumptions that governance was built on — so it needs its own frame: govern the AI you buy, the AI you build, and the AI risk to the business, to enable safe adoption rather than block it.
- 2
The frameworks & regulatory landscape — pick a baseline, map once
You don't need to master every framework and law — you need one baseline to run your program against, and a map from it to everything else you already answer to, so one set of controls satisfies many obligations.
- 3
Building the AI governance program — from framework to operating machine
A baseline on paper governs nothing. The program is the machine that runs it: you can't govern what you can't see, so start with an inventory, tier the risk, set the rules, name who's accountable, and put a gate in front of new AI.
- 4
AI security risks you must govern — risk → control → verify
You don't need to hack an LLM to govern one. You need to know the AI-specific risk classes well enough to require the right control and check that it's actually in place — that's the literacy that lets you govern builders and vendors.
- 5
Controls, assurance & third-party AI risk — from knowing the risk to proving it's handled
Knowing the risks isn't enough — you need a standard set of controls to require of every AI system, and independent evidence that they're real, whether the AI was built by your team or bought from a vendor.
- 6
Running it — monitoring, incident response & audit (capstone)
A program you set up once and never watch is a program that drifts. Governance is an operating rhythm: watch continuously, respond when AI fails, report up and out, and keep audit-ready evidence — then assemble the whole thing into a living program.
Production patterns you'll master
Synthetic data included
- AI inventory & risk-register template
- Governance frameworks crosswalk (NIST AI RMF / ISO 42001 / EU AI Act)
- AI security risk reference
- AI control baseline + third-party assurance
What you walk away with
Shareable portfolio
A public URL showing your module timeline, patterns mastered, and completion status.
All the code
Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.
Module walkthrough
Each module documented with deliverables and the production pattern you implemented.
Ready to build your ai governance & ai security?
First course free. $20 per course after that.