Enterprise AI Governance and Compliance
Build an AI governance program that works: model inventories, risk tiering, approval gates, documentation, and control mapping to the EU AI Act, GDPR, and NIST AI RMF.
Course Overview
AI governance fails in two directions. Programs built purely from policy documents produce binders nobody reads while shadow AI proliferates unchecked. Programs built purely from engineering habit cannot answer basic questions when a regulator or customer asks them. This course builds the version that works: governance implemented as engineering practice, with the documentation falling out of the pipeline rather than being assembled by hand.
The starting point is inventory, because you cannot govern what you cannot enumerate, and most organizations genuinely do not know how many models and LLM integrations are running. From there the course covers risk tiering so that a marketing copy generator and a credit decisioning model are not subject to the same process, proportionate approval gates, and the model documentation that serves both internal review and external obligations.
The regulatory material is treated as a set of engineering requirements rather than a legal seminar. You will map controls across the EU AI Act, GDPR automated decision-making provisions, and the NIST AI Risk Management Framework, find where they overlap so one control satisfies several, and build the evidence trail that makes an audit a query rather than a project.
Duration: 2 days|Delivery: onsite, virtual, or hybrid
Prerequisites
- Familiarity with how AI and ML systems are built and deployed
- Exposure to risk, compliance, or governance processes
- No hands-on coding required, though technical readers will get more from the control detail
Who Should Attend
- Risk, compliance, and governance leads who now own AI oversight
- Engineering leaders who must make governance work without stalling delivery
- Security architects defining approval requirements for AI systems
- Product and legal stakeholders accountable for AI risk decisions
Course Outline
- 1Why AI governance programs fail: binder governance and shadow AI
- 2Building a model and AI system inventory, including discovering what you did not know existed
- 3Risk tiering: proportionate classification so low-risk systems are not over-governed
- 4Approval gates that match risk tier and do not become rubber stamps
- 5Model documentation: model cards, system cards, and data sheets that stay current
- 6Data governance for AI: lineage, consent, retention, and purpose limitation
- 7Fairness and bias assessment: metrics, their conflicts, and defensible choices
- 8Human oversight: meaningful review versus rubber-stamping, and how to tell
- 9The EU AI Act: risk categories, obligations, and timelines as engineering requirements
- 10GDPR and automated decision-making: explanation rights and their practical implications
- 11NIST AI Risk Management Framework as an organizing structure
- 12Control mapping across frameworks to avoid duplicated work
- 13Third-party and vendor AI risk assessment
- 14Continuous monitoring and periodic revalidation of deployed systems
Learning Outcomes
- Build a defensible inventory of AI systems including previously undiscovered ones
- Design a risk tiering scheme that applies scrutiny proportionately
- Implement approval gates that hold without becoming a bottleneck
- Produce model documentation that satisfies both internal and external review
- Choose and justify fairness metrics for a specific use case
- Map one set of controls across the EU AI Act, GDPR, and NIST AI RMF
- Stand up evidence collection so audit becomes a query rather than a project
What You Will Build
- An AI system inventory template and discovery approach
- A risk tiering rubric with proportionate control requirements per tier
- A model documentation template aligned to regulatory expectations
- A control mapping matrix spanning the frameworks that apply to you
Frequently Asked Questions
- Is this legal advice?
- No. It is engineering and program guidance on building auditable AI systems and mapping controls to published frameworks. Your counsel remains the authority on legal interpretation and on what your specific obligations are.
- Does the EU AI Act apply to us?
- It applies extraterritorially where AI output is used in the EU, so many non-EU organizations are in scope. The course covers determining applicability, classifying systems by risk category, and the obligations that attach to each, so you can scope the work rather than assume the worst.
- How do we govern AI without slowing everything down?
- By tiering risk and being honest about it. A marketing copy generator and a credit decisioning model should not face the same process. The course covers proportionate gates, automated evidence collection so documentation is a build artifact rather than manual work, and the fast-path criteria that keep low-risk work moving.
- What about shadow AI already in use?
- Assume it exists, because it almost always does. The course covers discovery through network, expense, and SaaS audit signals, plus an amnesty-style onboarding approach that surfaces existing usage rather than driving it further underground.
- Who should attend from our organization?
- It works best with a mixed group: risk or compliance leads together with the engineering leaders who will implement the controls. Governance designed without engineering input consistently produces requirements that cannot be met.
Related Courses
Securing AI Pipelines
Secure the infrastructure around your models: data provenance, artifact integrity, secrets, least-privilege access, and audit evidence across the ML lifecycle.
AI Model Security
Attack and defend machine learning models: adversarial examples, data poisoning, model extraction, membership inference, and defenses that survive contact with a real attacker.
Enterprise GenAI Strategy
Decide where generative AI actually pays: use case selection, build-versus-buy, platform architecture, cost modeling, and moving beyond stalled pilots.
Agentic AI Security & Governance
Day 3 focuses on securing autonomous, tool-using AI agents at enterprise scale. Architect zero-trust controls, map threats with MITRE ATLAS & STRIDE-AI, and align deployments with EU AI Act, NIST RMF, and ISO 42001.
Ready to Get Started?
Contact us to schedule training for your team or inquire about upcoming sessions.