AI Governance, Risk and Assurance
Proves you can build AI governance that produces real assurance evidence, not paperwork theatre.
An advanced examination for risk officers, security leaders, auditors and compliance engineers who are accountable for AI systems in production. It assesses AI risk framing, inventory and tiering, regulatory obligations at a conceptual level, meaningful human oversight, vendor assurance, and the evidence and metrics that demonstrate controls actually operate. Candidates should already own or audit governance processes for deployed AI.
- AI risk framing: how probabilistic, drifting systems break classic IT risk assumptions
- Inventory and tiering: a system of record for AI use, and impact-based risk classification
- Regulatory landscape: risk-tiered obligations, transparency duties, and deployer responsibilities
- Oversight and documentation: meaningful human oversight, model cards, system cards and datasheets
- Third-party assurance: contracts, evidence and monitoring for hosted and vendor-embedded models
- Assurance in operation: audit evidence, incident classification, drift obligations and control metrics
Learn the material
7 modules, about 51 minutes of reading. Work through them in order, or jump to whatever you need. The assessment is drawn from exactly this material.
- 01 Why AI Risk Breaks the Classic IT Control Model How probabilistic, drifting systems invalidate the assumptions underneath configuration baselines, change control and point-in-time assessment. 7 min
- 02 Inventory: The System of Record for AI Use Why an inventory scoped to internally built models guarantees shadow AI, what fields make a record governable, and how to discover what you actually run. 6 min
- 03 Tiering by Impact, and the Shape of Risk-Tiered Regulation Classifying AI by the consequence of failure rather than by technical scale, and the conceptual structure that risk-tiered regulation and transparency duties share. 8 min
- 04 Meaningful Human Oversight The conditions that separate genuine human control from documented rubber-stamping, and the evidence that distinguishes them. 7 min
- 05 Documentation and the Approval Gate Model cards, system cards and datasheets as distinct artefacts, and why the people who build a model cannot be the people who approve it. 7 min
- 06 Third-Party and Vendor Assurance Which contract terms carry real assurance weight, what a security attestation covers, and why behavioural risk sits outside its scope. 7 min
- 07 Assurance in Operation: Evidence, Monitoring, Incidents and Metrics The evidence a regulator actually weights, continuous monitoring versus point-in-time review, incident classification by harm, and metrics that show controls work. 9 min
Take the assessment
18 questions drawn from the material above. Pass and you can put your name to a certificate with a serial anyone can verify.
How it is marked
- Questions and answer options are shuffled for every sitting.
- Multi-answer questions are marked as a set: you need all of the correct options and none of the wrong ones. There is no partial credit.
- You need 75% to pass.
- You can revisit and change any answer until you submit.
- Afterwards you see every question, the answer you gave, and whether it was right. The answer key is never printed.
- The reasoning behind each answer is released once you pass. Held back on a fail, it would hand over most of the key to anyone willing to sit the paper once and read it, which is why the taught material above is the intended route back.
- You can re-sit the paper, but not immediately: there is a ten minute wait between attempts on the same course.