AI Governance & Risk Management Micro-Credential

AI Governance & Risk Management Micro-Credential

Duration: 3-4 Hours

Description

Most organizations don’t have an AI ethics problem so much as an AI governance gap — nobody owns the question of which AI risks matter, who signs off on them, and how that gets documented. This session gives a practical, hands-on introduction to the frameworks organizations are actually being measured against: the NIST AI Risk Management Framework, ISO/IEC 42001, and the risk tiers of the EU AI Act. Participants leave having run a real system through a lightweight risk assessment, not just discussed governance in the abstract.

Audience

This session is for anyone who needs a working, applied introduction to AI governance without committing to a full two-day program — compliance and risk staff, product managers, and technical leads who need to speak the language of governance, not just the people who own the policy. No technical background is required.

Objectives

  • Explain the purpose and structure of the NIST AI RMF, ISO/IEC 42001, and the EU AI Act’s risk tiers
  • Identify which framework applies to a given organization or use case
  • Run a lightweight AI risk assessment on a real or representative system
  • Outline the basics of ownership, documentation, and review cadence for AI governance

Prerequisites

No technical background is required. Familiarity with AI Ethics and Bias Micro-Credential content is helpful but not required.

Related AI Courses

See the full AI training roadmap and course directory for how this fits into a broader learning path.

For the fairness and accountability side of AI systems, pair this with AI Ethics and Bias Micro-Credential. For a full, two-day, organization-level treatment of governance, policy, and roadmap-building, see AI Governance & Risk. For the technical, hands-on security counterpart, see AI Security & Red-Teaming Micro-Credential.

Course Outline

Module 1: Why AI Governance, Why Now

  • From Principles to Requirements: What Changed
  • The Three Frameworks at a Glance
  • Who Should Own AI Risk in an Organization
  • Lab – Map Your Organization’s AI Use Cases to Risk Categories

Module 2: Applying the Frameworks

  • The NIST AI RMF Functions: Govern, Map, Measure, Manage
  • ISO/IEC 42001 in Practice
  • EU AI Act Risk Tiers: Unacceptable, High, Limited, Minimal
  • Lab – Conduct a Mini Risk Assessment on a Sample AI System

Module 3: Making Governance Stick

  • Documentation That Survives an Audit
  • Vendor and Third-Party AI Risk
  • Building a Review Cadence
  • Lab – Draft a One-Page Governance Charter