This course is educational content only. Nothing here constitutes legal advice. Regulatory analysis covers publicly available law and guidance documents for learning purposes. Consult qualified legal counsel before making compliance decisions.

DecipherU · Course 6

AI Governance and Risk

The working practitioner's path to cybersecurity AI governance and risk.

For the compliance, risk, privacy, or in-house counsel professional who knows AI governance is the table-stakes responsibility of the leaner cybersecurity and Applied AI C-suite. This 12-module course is for the practitioners liability has a name for, built on NIST AI RMF (AI 100-1, AI 600-1), the EU AI Act, ISO/IEC 42001, and sectoral regulations in healthcare, finance, and employment. 45-55 hours of study plus a rubric-evaluated capstone. Designed by Julian Calvo, Ed.D., M.S.

What completing this course actually does for your comp

BLS OES May 2024 + Lightcast 2024 AI premium

Target role after completion

AI Governance Lead

Base comp band: $141K$170K (BLS median ± Enterprise tier).

With AI fluency (this course)

$167K$182K

+13% to +23% lift on AI-fluent postings (Lightcast 2024).

Time investment

~70 hours

Self-paced. Most learners ship the capstone within 8–12 weeks of focused study.

What this replaces

  • · IAPP AI governance training ($1.5K+ per cert)
  • · Self-study across NIST AI RMF + EU AI Act + ISO/IEC 42001 (no mapped curriculum)
  • · Big-4 advisory engagements buyers commission instead of hiring in-house

Pricing posture

Standalone: $497. Bundled inside Operator ($129/mo) and Frontier ($299/mo), pays for itself if you would buy 3+ standalone courses.

CC available

Course author

Julian Calvo, Ed.D., M.S.

Founder of DecipherU. Doctoral research in applied AI and education. Background spans software engineering, AI infrastructure, and the cybersecurity-AI convergence. Every regulatory citation in this course is reviewed by a legal co-reviewer before publication. Reviews the capstone personally.

What you will be able to do

After completing the course and capstone, you can run a full AI governance program: from risk assessment through regulatory conformity, vendor management, bias review, incident response, and audit.

  • Implement NIST AI RMF with a control map per system

    Run the full Govern, Map, Measure, Manage cycle. Build a NIST AI RMF profile for a real use case, including the Generative AI Profile (NIST AI 600-1) for LLM deployments.

  • Run an EU AI Act conformity assessment end-to-end

    Classify systems under the risk-based framework, apply provider and deployer obligations, build a technical file, and prepare for notified body review where applicable.

  • Build an enterprise AI governance program

    Design the charter, RACI, committee structure, policy framework, and operating cadence. Communicate the program to executives, boards, and regulators.

  • Manage AI vendor risk with a 6-domain questionnaire

    Assess foundation model providers and AI tool vendors. Build contract addenda covering data ownership, output liability, model deprecation, and AI Act compliance language.

  • Design AI privacy architecture

    Build the data flow map, apply minimization, design a data subject rights workflow that handles AI-specific requests, and implement privacy-preserving ML where warranted.

  • Run a fairness assessment with disaggregated metrics

    Apply the harm taxonomy, choose appropriate fairness metrics, build a measurement plan, and produce a remediation report suitable for internal audit and regulator review.

  • Manage an AI incident under EU AI Act and GDPR timing

    Classify the incident, trigger the response process, meet EU AI Act Article 73 reporting obligations alongside GDPR Article 33 timing, and conduct a post-incident review.

  • Run an internal AI audit program

    Build the evidence map, apply the ForHumanity audit criteria alongside NIST AI RMF controls, and produce a board-level report that satisfies audit committee expectations.

Curriculum

Twelve modules cover the full governance stack: landscape and disciplines, NIST AI RMF, EU AI Act compliance, sectoral regulations, enterprise program design, vendor risk, privacy, bias and fairness, transparency, incident management, and auditing. Module 12 is a capstone: design a complete AI governance program for a real or representative organization.

01Module 1, AI governance environment and disciplines5 lessons
  • Lesson 1.1, What AI governance is and isn'tFree preview28 min
  • Lesson 1.2, The convergence: AI governance, risk, compliance, ethicsFree preview28 min
  • Lesson 1.3, Roles: AI ethics officer, AI risk manager, AI compliance officer30 min
  • Lesson 1.4, The AI governance career25 min
  • Lesson 1.5, Reporting structures and team design28 min
02Module 2, NIST AI Risk Management Framework deep look6 lessons
  • Lesson 2.1, AI RMF architecture: the four functions and why they are ordered that way40 min
  • Lesson 2.2, GOVERN: building the governance foundation50 min
  • Lesson 2.3, MAP: identifying and classifying AI risk50 min
  • Lesson 2.4, MEASURE: quantifying AI risk45 min
  • Lesson 2.5, MANAGE: treating and monitoring AI risk45 min
  • Lesson 2.6, AI RMF Profiles and the Generative AI Profile (NIST AI 600-1)45 min
03Module 3, EU AI Act compliance6 lessons
  • Lesson 3.1, The EU AI Act: structure, scope, and enforcement timeline40 min
  • Lesson 3.2, Risk classification: prohibited, high-risk, limited risk, and minimal risk50 min
  • Lesson 3.3, High-risk AI systems: provider obligations50 min
  • Lesson 3.4, High-risk AI systems: deployer obligations45 min
  • Lesson 3.5, General-purpose AI models and the GPAI Code of Practice45 min
  • Lesson 3.6, Conformity assessment, post-market monitoring, and enforcement45 min
04Module 4, Sectoral AI Regulations6 lessons
  • Lesson 4.1, Healthcare AI: FDA SaMD, HIPAA, and the clinical AI compliance stack55 min
  • Lesson 4.2, Financial services AI: SR 11-7 model risk management and banking AI obligations55 min
  • Lesson 4.3, Fintech, insurance, and credit: NYDFS, NAIC, and FCRA AI requirements50 min
  • Lesson 4.4, Employment AI: EEOC, NYC Local Law 144, and state hiring laws50 min
  • Lesson 4.5, Education AI: FERPA, Department of Education guidance, and student data protection45 min
  • Lesson 4.6, Public sector and critical infrastructure AI45 min
05Module 5, Building Enterprise AI Governance Programs5 lessons
  • Lesson 5.1, Governance committee design: structure, charter, RACI, and operating cadence55 min
  • Lesson 5.2, AI policy framework: the policy stack from acceptable use to incident response55 min
  • Lesson 5.3, AI inventory and use case management45 min
  • Lesson 5.4, AI ethics review: process design, criteria, and case studies55 min
  • Lesson 5.5, AI governance metrics and board-level reporting50 min
06Module 6, AI vendor risk management5 lessons
  • Lesson 6.1, Why AI vendor risk is structurally different from conventional TPRM48 min
  • Lesson 6.2, Assessing foundation model providers52 min
  • Lesson 6.3, Assessing AI tool vendors and AI-powered SaaS46 min
  • Lesson 6.4, Contractual risk allocation in AI vendor agreements50 min
  • Lesson 6.5, Ongoing monitoring and vendor concentration risk44 min
07Module 7, Privacy in AI systems5 lessons
  • Lesson 7.1, The AI privacy environment: GDPR, CCPA/CPRA, HIPAA, and the regulatory convergence50 min
  • Lesson 7.2, Data minimization and purpose limitation in AI systems46 min
  • Lesson 7.3, Automated decisions and the right to explanation (GDPR Article 22)48 min
  • Lesson 7.4, The right to erasure vs. model training: the unlearning problem52 min
  • Lesson 7.5, Privacy-preserving AI: differential privacy and federated learning54 min
08Module 8, AI bias and fairness5 lessons
  • Lesson 8.1, What AI bias is and where it enters the system55 min
  • Lesson 8.2, Harm taxonomy: allocative versus representational harm45 min
  • Lesson 8.3, Fairness metrics and the impossibility theorem50 min
  • Lesson 8.4, Bias measurement: disaggregated evaluation and auditing50 min
  • Lesson 8.5, Mitigation strategies and the go/no-go decision50 min
09Module 9, AI transparency and explainability4 lessons
  • Lesson 9.1, The transparency obligation: regulation, ethics, and trust50 min
  • Lesson 9.2, Model cards and data cards: the documentation standard50 min
  • Lesson 9.3, Explainability techniques: LIME, SHAP, and interpretability50 min
  • Lesson 9.4, User-facing explanation and the decision-recipient's right45 min
10Module 10, AI incident management4 lessons
  • Lesson 10.1, What makes an AI incident different35 min
  • Lesson 10.2, AI incident classification and severity tiering40 min
  • Lesson 10.3, AI incident response process45 min
  • Lesson 10.4, Disclosure, regulatory reporting, and post-incident review40 min
11Module 11, Auditing AI systems5 lessons
  • Lesson 11.1, The AI audit environment: internal, external, regulatory40 min
  • Lesson 11.2, ISO/IEC 42001 audit requirements and the NIST AI RMF GOVERN controls50 min
  • Lesson 11.3, EU AI Act conformity assessment and third-party audit45 min
  • Lesson 11.4, Conducting the AI audit: fieldwork, evidence, and findings50 min
  • Lesson 11.5, Reporting, remediation tracking, and the board report45 min
12Module 12, Capstone: build an AI governance program1 lessons
  • Capstone rubric, AI Governance and Risk15 min

Framework synthesis

The course makes the framework layering explicit. Rather than presenting a single house approach, it shows which source applies where and how they interact, so practitioners can defend their choices to auditors and regulators.

Framework / regulationWhat it contributes
NIST AI RMF (AI 100-1, AI 100-2, AI 600-1)AI RMF core functions (Govern, Map, Measure, Manage), AI RMF profiles, Generative AI Profile for LLM-specific risks (Tabassi et al., Vassilev et al.).
EU AI Act (Regulation 2024/1689)Risk-based classification (prohibited, high-risk, limited risk, minimal risk), provider and deployer obligations, GPAI model rules, conformity assessments, CE marking, post-market monitoring.
ISO/IEC 42001 and ISO/IEC 23894AI management system standard (42001) and AI risk management guidance (23894). Controls and certification pathway for organizations seeking third-party audit.
US Executive Order 14110Federal AI governance requirements, safety and security standards for foundation models, sector-specific guidance issued under the EO.
IAPP AI Governance CenterPractitioner-grade regulatory analysis, AIGP certification context, DPA and FTC enforcement tracking, international law comparison.
Sectoral regulationsHIPAA / FDA SaMD for healthcare AI; SR 11-7 / OCC 2011-12 for financial model risk; EEOC AI hiring guidance; NYC Local Law 144; NYDFS Part 500; FERPA for education AI.
Corporate AI governance frameworksMicrosoft Responsible AI Standard, Google AI Principles and Responsible AI Practices, Anthropic Responsible Scaling Policy, OpenAI Preparedness Framework. These are the operating templates from organizations at the frontier.
Audit canonIIA Three Lines model for AI governance structure; Raji et al. (ACM FAccT) algorithmic audit framework; Mitchell et al. Model Cards; Gebru et al. Datasheets for Datasets.

Who the AI governance course is for

The privacy lead asked to add AI Act compliance to their GDPR practice

You run GDPR compliance today. Your organization is deploying AI systems and your DPO or General Counsel has asked you to own the EU AI Act mapping. The course covers exactly that overlap: where GDPR and the AI Act interact, where they diverge, and what new governance structures you need to build.

The financial services risk manager folding AI into SR 11-7 model risk

You manage model risk under SR 11-7 and your bank is deploying AI at scale. The course covers the model risk management lineage, where AI pushes beyond SR 11-7's assumptions, how the OCC's evolving guidance applies, and how to build an AI model risk framework that satisfies regulators and your board's risk committee.

The compliance director building the company's first AI governance committee

You have been asked to stand up an AI governance committee from nothing. The course delivers the committee charter template, RACI design, escalation paths, ethics review criteria, and the operating cadence that keeps a governance committee from becoming a rubber stamp.

Prerequisites

Required

  • Working knowledge of at least one privacy or risk regime (GDPR, HIPAA, SR 11-7, FERPA, or equivalent)
  • Basic legal-research literacy (ability to read regulatory text and cross-reference definitions)
  • Familiarity with GRC or compliance workflows at a functional level
  • Willingness to commit 45 to 55 hours of study plus 20 to 40 hours for the capstone

Recommended

  • Prior privacy or compliance certification (CIPP, CIPM, CRCM, CRISC, or equivalent) is helpful but not required
  • Experience advising on or operating a formal compliance program
  • Exposure to an AI deployment (building, buying, auditing, or advising on one)
  • A real organization you can use as the subject for module exercises and the capstone

Reviews

First cohort enrollment opens Q2 2026. Reviews from practitioners who completed the capstone will appear here once the first cohort finishes. Approved capstones in the top 10% become anonymized case studies with explicit permission.

Frequently asked questions

Is this cybersecurity AI governance course legal advice?

No. This is educational content only. Nothing in the course constitutes legal advice. Regulatory analysis covers publicly available law, guidance, and framework documents for learning purposes. Before making compliance decisions, consult qualified legal counsel with expertise in the relevant jurisdiction and sector.

Does the EU AI Act apply to my company if we are not based in the EU?

Yes, if your AI systems are placed on the EU market or their outputs are used in the EU, the Act applies regardless of where your company is incorporated. Module 3 covers territorial scope in detail, including the provider and deployer definitions that determine your obligations.

Is NIST AI RMF mandatory?

The NIST AI RMF (AI 100-1) is voluntary for most organizations in the United States. However, federal contractors and critical infrastructure operators face increasing pressure to align with it, and several state AI bills reference it. The course covers where it is voluntary, where it is effectively required, and how to build a defensible program either way.

How does this course handle sectoral overlap (healthcare, finance, and employment) simultaneously?

Module 4 maps every regulated sector. The capstone exercise requires a multi-sector organization. The course teaches you to build a unified controls library that satisfies overlapping requirements rather than running parallel siloed programs.

How does this course map to my existing GDPR or HIPAA practice?

Module 7 covers AI privacy specifically and explicitly maps to GDPR and HIPAA. The course is designed for practitioners who already understand one privacy regime and need to extend it to cover AI-specific risks: data provenance, training data rights, output privacy, and automated decision-making.

What credential does the course issue, and does IAPP recognize it?

Approved capstones earn the AI Governance and Risk verifiable credential, signed with Ed25519 and embeddable on LinkedIn. IAPP does not currently recognize third-party credentials against the AIGP certification. As IAPP recognition develops over time, the course positioning will be updated. The credential reflects demonstrated practitioner capability, not exam passage.

How much time does the AI governance course require?

45 to 55 hours of study across 12 modules. At 4 to 6 hours per week, most practitioners finish modules in 9 to 12 weeks. The capstone (40 to 60 page governance program design) adds 20 to 40 hours depending on the complexity of your chosen organization.

How does this course compare to the IAPP AI Governance Professional (AIGP) certification?

The AIGP is an exam-based credential from the IAPP. This course is a practitioner program: you build deliverables (governance charters, NIST AI RMF profiles, EU AI Act conformity assessments, vendor questionnaires, audit plans) rather than studying for a multiple-choice test. The two serve different purposes and are not substitutes for each other.

What is the refund policy?

Seven-day full refund from purchase, while you have completed less than 10% of the course. Email support@decipheru.com with your order number; refunds process within 3 business days. After 7 days or above 10% completion, refunds are case-by-case. A refund triggers a 90-day lockout on re-purchasing this course or subscribing to a tier that bundles it.

What if I don't have the stated prerequisites?

The required prerequisite is working knowledge of at least one privacy or risk regime (GDPR, HIPAA, SR 11-7, FERPA, or equivalent). Without that baseline, the regulatory cross-mapping in Modules 3, 4, and 7 will be harder to absorb. Practitioners without a prior framework can take the GRC and Compliance Fundamentals course first.

Free · No accountRead a full sample lesson before you enrollOpen the sample →

Pair this course with cert prep

2 add-ons · from $147

Each cert-prep add-on translates this practitioner course into a focused exam ramp for a named industry credential. The parent course teaches the discipline; the add-on bridges to the specific exam blueprint.

This course is part of a packaged path

Or see the packaged paths that use this course

Each path bundles the curriculum sequence, the compensation delta it unlocks, and the recommended courses (this one is on the list). If you are not sure which path matches your starting point, the 2-minute AI Risk Score routes you to the right one.

Related cybersecurity courses

Last verified: April 2026?Report an inaccuracy

Enroll · $497

7-day refund · Self-paced · Lifetime access

Enroll →