2-Day Course
Governance · 2-Day

AISVS and the EU AI Act

Map the OWASP AISVS standard to the EU AI Act obligations and build the evidence that proves compliance, in two days.

Code GOV-541 Level Governance
EU AI Act AISVS Governance
Grounded in the standards

Built on AISVS and the EU AI Act

This course is taught by the former OWASP-AISVS Co-Leader (v1.0). It connects the AISVS controls to the EU AI Act articles, so every obligation in the Act lands on a testable requirement you can verify and evidence.

You leave with a working mapping of AISVS control families to the Act articles: the technical documentation, logging and record-keeping, human-oversight design, and robustness and cybersecurity testing that a conformity file needs, and the AISVS requirement behind each one.

From obligation to evidence, article by article

The Act sets the obligations: Article 9 risk management, Article 10 data governance, Articles 11 and 12 technical documentation and automatic logging and record-keeping, Article 13 transparency, Article 14 human oversight, Article 15 accuracy, robustness and cybersecurity. AISVS gives you the controls that satisfy them and a way to test that each control actually holds. The course walks that mapping in both directions, so a compliance requirement always has a technical check behind it.

You will be able to

What you can do after the course

GOV-541. The syllabus

Two days, from obligation to evidence

Classes are custom built from the following learning modules. Instructors select ~16 hours for a 2-day delivery. Custom formats from 1 to 3 days available. (Times are approximate.)

The EU AI Act

The Regulation in Plain Language

80-00 The Act in Plain Language 1.5 hrs

What the EU AI Act actually says, stripped of legal padding. The risk classification system (unacceptable, high-risk, limited, minimal), who it applies to (providers, deployers, importers, distributors), and the territorial scope that catches non-EU companies serving EU users. We read the key articles, not a summary of them. Art. 6Annex III

80-01 High-Risk Classification 1 hr

How to determine whether your AI system is high-risk. Annex III categories, the self-assessment path, and the cases where you think you are minimal-risk but the Act says otherwise. Worked examples across financial services, healthcare, HR and law enforcement.

80-02 The Enforcement Timeline 0.5 hr

What is enforceable now, what comes into force in the next 12 months, and what is still waiting on implementing acts. The dates that matter for your compliance programme.

80-03 Penalties and Enforcement 0.5 hr

Fines of up to 35 million EUR or 7% of global turnover. Who enforces (national market surveillance authorities), how complaints work, and what "placed on the market" means for SaaS and API-delivered AI.

Article-by-Article Control Mapping

Every Obligation Mapped to AISVS

81-00 Article 9: Risk Management (AISVS C01) 1 hr

The Act requires a risk management system that runs throughout the AI lifecycle. We map Article 9's obligations to AISVS C01 (governance and risk) requirement by requirement. What evidence satisfies both. Art. 9

81-01 Article 10: Data and Data Governance (AISVS C01, C03, C08) 1 hr

Training, validation and testing data must meet quality criteria. We map Article 10 to AISVS data governance requirements in C01, model lifecycle in C03 and data protection in C08. What "relevant, representative, free of errors and complete" means in practice. Art. 10

81-02 Article 11: Technical Documentation (AISVS C01, C12) 0.5 hr

The Act requires technical documentation before the system is placed on the market. We map Article 11 to the AISVS documentation and audit trail requirements and show what a documentation pack looks like. Art. 11Annex IV

81-03 Article 12: Record-Keeping and Logging (AISVS C12) 1 hr

Automatic logging of events throughout the system's lifetime. We map Article 12 to AISVS C12 monitoring and logging requirements. Tamper-evident logs, retention periods and what "allow the tracing of the AI system's operation" means technically. Art. 12

81-04 Article 13: Transparency (AISVS C01, C07) 0.5 hr

Users must be informed that they are interacting with an AI system. We map Article 13 to AISVS transparency and output requirements. What transparency looks like for chatbots, agents and embedded AI features. Art. 13

81-05 Article 14: Human Oversight (AISVS C09) 1 hr

High-risk AI systems must be designed for effective human oversight. We map Article 14 to AISVS C09 orchestration and agent requirements, especially the human-in-the-loop and kill switch controls. What "ability to intervene" and "ability to halt" mean in an agent context. Art. 14

81-06 Article 15: Accuracy, Robustness and Cybersecurity (AISVS C02, C04, C05, C11) 1.5 hrs

The Act requires an "appropriate level of accuracy, robustness and cybersecurity." This is the broadest article and maps to the most AISVS controls: input validation (C02), model serving (C04), access control (C05) and adversarial robustness (C11). We walk through each mapping and what "appropriate level" means when you have AISVS verification levels to point to. Art. 15

81-07 Article 50: Transparency for General-Purpose AI (AISVS C01, C07) 0.5 hr

Providers of general-purpose AI models must disclose that content is AI-generated. We map Article 50 to AISVS output and transparency requirements and discuss the practical challenges for agent-generated content. Art. 50

Conformity Assessment

Assess Once, Satisfy Both

82-00 The Conformity Assessment Process 1.5 hrs

How conformity assessment works under the Act: self-assessment for most high-risk systems, third-party assessment for biometric systems. How to run a conformity assessment using AISVS as the technical framework so you assess once and satisfy both requirements. Annex VIAnnex VII

82-01 Building the Conformity Evidence Pack 1.5 hrs

Hands on: build a conformity evidence pack from AISVS verification output. For each article, we show what evidence satisfies the obligation, where the evidence comes from (Claw scan reports, audit logs, policy documents, test results), and how to package it for a notified body or market surveillance authority.

82-02 The Declaration of Conformity 0.5 hr

What goes in the EU declaration of conformity. How to write it, what it commits you to, and the ongoing obligations it creates.

82-03 Post-Market Monitoring 1 hr

The Act requires post-market monitoring plans for high-risk systems. We map this to AISVS C12 monitoring requirements and show how continuous AISVS verification serves as your post-market monitoring system. Art. 72

Practical Application

Sectors, Jurisdictions and Governance

83-00 Sector-Specific Guidance 1.5 hrs

How the Act applies differently across sectors. Financial services (credit scoring, insurance, fraud detection), healthcare (clinical decision support, diagnostics), HR (recruitment, performance management) and public sector (benefits, law enforcement). Sector-specific evidence requirements and regulatory expectations.

83-01 Multi-Jurisdiction Considerations 1 hr

EU AI Act alongside GDPR, sector regulations (DORA, MDD, MDR) and non-EU frameworks (UK AI regulation, Saudi PDPL, NIST AI RMF). How to build a compliance programme that handles multiple jurisdictions without duplicating effort.

83-02 The AI Governance Programme 1 hr

Building an internal AI governance programme that satisfies the Act and sustains compliance over time. Roles, responsibilities, processes, tooling and the connection to existing risk management and compliance programmes.

Labs

Hands-On Compliance Labs

84-00 Risk Classification Lab 1.5 hrs

Given five AI systems, classify each under the Act. Determine whether each is high-risk, what obligations apply, and what AISVS verification level maps to each.

84-01 Conformity Evidence Lab 2 hrs

Build a conformity evidence pack for a provided high-risk AI system. Map articles to AISVS controls, gather evidence from Claw scan output and audit logs, and package the result.

84-02 Article 15 Verification Lab 1.5 hrs

Run AISVS verification (C02, C04, C05, C11) against a lab system and map the results to Article 15 obligations. Produce the evidence that satisfies "appropriate level of accuracy, robustness and cybersecurity."

~28 hrs
Total instructional hours
24
Individual modules across 5 sections
1-3 days
Flexible delivery
Hands-on tooling

Tools and labs you will use

Hands-on with the CyberSecAI tooling, not slideware.

AI-DAST

Dynamic scanner that runs live EU AI Act and AISVS conformance checks against a running application.

RegMap

Maps each AISVS control to the EU AI Act article it satisfies and emits a gap report.

ConformKit

Generates the Annex IV technical-documentation pack from your scan output.

AgentPass Ledger

Signed, hash-chained evidence receipts for the audit trail.

Who it is for

Built for the people who carry the obligation

GRC & compliance leads

Own the conformity file and prove it holds under assessment.

Security architects

Turn each Act article into a control you can test.

AI product owners

Place your system in the right tier and ship it compliant.

DPOs & legal-technical staff

Read the Act and the AISVS control behind each duty.

Auditors

Check the evidence against a mapping you can rely on.

The certification

Counts toward the CyberSecAI AISVS assurance track

Completing this course counts toward the CyberSecAI AISVS assurance track. The work is practical: you place a system in the right risk tier, map its obligations to AISVS requirements, and assemble the conformity evidence the EU AI Act expects. That progress carries into the wider assurance track.

Reserve a place

Turn the EU AI Act into evidence you can show.

Two days, from obligation to evidence, taught by the former OWASP-AISVS Co-Leader (v1.0). You leave with a working mapping of AISVS control families to the Act articles. Places are limited.

2 days intensive Course code GOV-541 Private corporate cohorts available
Reserve a Place

Corporate & sovereign cohorts, and bespoke on-site delivery, on request.