Stand up an AI management system that satisfies boards, auditors and regulators. ISO 42001 and NIST AI RMF, applied.
Two-day instructor-led foundation course. Module order and grouping can be adjusted for private deliveries.
The risks that are unique to AI systems and that traditional risk frameworks do not cover. You study model hallucination, training data bias, adversarial manipulation and emergent behaviour, and you learn why each one requires controls that your existing risk register probably does not contain.
The difference between model risk and operational risk and why they need separate treatment. You examine how a model can produce incorrect outputs even when the surrounding infrastructure is working perfectly, and why model validation is a distinct discipline from operational monitoring.
How AI supply chain risk differs from software supply chain risk. You trace the path from training data through pre-trained weights to fine-tuned models and identify the points where a poisoned dataset, a backdoored model or a compromised dependency can enter your system without detection.
The reputational and legal consequences when an AI system fails publicly. You study real incidents where model failures caused regulatory action, litigation or brand damage, and you build the risk scenarios that boards and legal teams need to see before deployment.
Setting the context and scope of your AI management system under ISO 42001. You identify interested parties, determine the boundaries of the AIMS and write the scope statement that defines what is in and what is out.
What ISO 42001 requires from leadership: commitment, policy, roles and responsibilities. You draft the AI policy, assign accountabilities and set the governance structure that makes the management system work in practice, not just on paper.
Planning the AIMS including risk assessment, objectives and the Statement of Applicability. You identify AI risks, select the Annex A controls that treat them and produce the Statement of Applicability that maps your controls to the standard.
The support and operation clauses: resources, competence, awareness, communication, documented information and operational planning. You build the evidence framework and operational procedures that keep the AIMS running day to day.
Measuring how well the AIMS is working through internal audit, management review and continual improvement. You set up the monitoring, measurement and review cycle that turns the management system into something that improves over time instead of decaying.
The Govern function of the NIST AI RMF. You set the accountability structures, decision-making processes and organisational culture that underpin everything else in the framework. Without Govern, the other three functions have no authority behind them.
The Map function: understanding the context and framing the risks. You build an AI risk profile by identifying the AI systems in scope, the stakeholders affected, the intended uses and the failure modes that matter, so the risks you manage later are grounded in your actual situation.
The Measure function: putting numbers on the risks and selecting controls. You choose metrics that tell you whether a control is working, set thresholds that trigger action, and implement the measurement processes that turn subjective risk into objective evidence.
The Manage function: acting on what you measured and feeding the results back in. You build treatment plans for the risks you found, track their implementation and set up the feedback loop that makes the whole framework self-correcting over time.
Finding the AI-specific risks in your organisation. You work through structured identification exercises covering model risks, data risks, deployment risks and third-party risks, building a register that reflects your actual AI estate, not a generic template.
Scoring each risk for likelihood and impact using a consistent method. You apply a scoring framework that accounts for the unique characteristics of AI risks, assign owners to each risk and record the rationale so the scores hold up under review.
Linking each risk to one or more controls and tracking treatment through to completion or acceptance. You assign controls, set treatment deadlines, document acceptance decisions and build the tracking process that keeps the register alive and current.
Standing up an AI compliance programme from scratch. You define the programme scope, set objectives, choose the frameworks you will align to and design the operating model that connects governance decisions to engineering controls and evidence collection.
Defining who does what in the AI compliance programme and integrating it with your existing GRC tooling. You assign roles for AI risk owners, control owners and evidence producers, and wire the programme into the tools and workflows your organisation already uses.
Reporting AI risk and compliance status to the board in a format that drives decisions. You build a board report that covers the risk posture, control effectiveness, open issues and upcoming regulatory changes, all in plain language that a non-technical audience can act on.
A structured lab where you build an AI risk register from scratch. You identify risks, score them, assign controls and owners, and produce a register you can take back to your organisation and adapt for your own AI systems.
A hands-on lab where you run a gap analysis against ISO 42001. You assess your current state against each clause, identify the gaps, prioritise the remediation work and produce a gap analysis report that can drive a real implementation plan.
A lab focused on designing the compliance programme itself. You define the scope, assign roles, choose frameworks, design the reporting cadence and produce a programme charter that you can present to leadership as a proposal.
Hands-on with the CyberSecAI tooling, not slideware.
Crosswalks controls across ISO 42001, NIST AI RMF and AISVS and shows the gaps.
Produces the technical conformance evidence auditors ask for.
An immutable, hash-chained audit trail for governance evidence.
Records human sign-off decisions into the ledger.
Own the AI risk register and the control set behind it.
Answer auditors and regulators with evidence that holds.
Bring AI systems into your control framework.
Govern AI data use with clear roles and records.
Run the programme and prepare for assessment.
This course counts toward the CyberSecAI AISVS assurance track. Governance sets the programme; AISVS makes the technical controls verifiable. Take them together and the two sides of your AI assurance meet in the middle.
Two days, from framework to running programme, taught by the former OWASP-AISVS Co-Leader (v1.0) and the author of "Breach 20/20". ISO 42001 and NIST AI RMF, applied, with an AI risk register, a control set mapped to AISVS, and reporting that holds. Places are limited.
Corporate & sovereign cohorts, and bespoke on-site delivery, on request.