
AI Governance & Risk Management
Course Overview
Artificial intelligence holds extraordinary potential to transform how organizations operate and deliver value to stakeholders—but only if it is governed and managed effectively. Whether you are a risk professional integrating AI into enterprise frameworks or a technology leader responsible for AI initiatives, this course equips you with the structures, processes, and tools to harness innovation safely and confidently.
Through relatable stories, real-world examples and case studies, you’ll learn how to design and implement AI governance, integrate AI risk into your enterprise risk management processes, and apply controls that protect your organization while enabling opportunity. We cover the full AI lifecycle—from strategy and design, to deployment, monitoring, and continual improvement—ensuring you can provide assurance to both internal and external stakeholders that AI is used responsibly.
Our trainers David Tattam – Chief Research & Content Officer, Michael Howell – Head of Risk Research & Knowledge provide you with a complete, ready-to-use toolkit to embed robust AI governance and risk management in your organisation, aligned with emerging regulations, industry standards, and best practice.
Course description
In this course, you’ll learn:
1. The Need for AI Governance and Risk Management
o Introductory definitions
o How governance and risk management work together
o Effect of poor governance
o Overview of the global regulatory landscape
o Speed of change
2. Defining AI
o A brief history of artificial intelligence
o The broad types of AI
o A focus on Large Language Models and agentic AI
3. Defining AI Risks
o Definitions of risk, AI risk, and AI risk management
o How Ai relates to organizational objectives
o Differentiating AI-related strategic risk and operational risk
o Breaking risk into its key components using risk bow tie analysis
o Exploring AI-specific risks
o How AI fits into a risk taxonomy
4. Defining AI Controls
o Definition of controls
o 7 treatment methods to manage AI risk
o How to map controls to components of risk
o The use of AI-related control frameworks and standards
o Contrasting compliance and risk, and handling controls that aren’t controls
5. AI Governance and Risk Management Frameworks & Processes
o Applying ISO 31000 steps to AI risk management
o Applying an Enterprise Risk Management Framework to AI
o Aligning AI-specific frameworks to Enterprise Risk Management frameworks
o Common risk management processes applied to AI
6. AI Risk Appetite
o Setting appetite for objectives and risks
o Setting risk appetite for AI
o Qualitative and quantitative risk appetite
o How to use risk appetite
7. AI Governance & AI Policy
o Why you need an AI policy
o Key elements to consider in your AI policy
o An AI policy toolkit
o Tailoring to your organization
8. AI Risk Assessment
o Stages of a risk assessment
o An overview of risk assessment techniques
o Impact assessment versus risk assessment
-
The difference between impact assessment and risk assessment
-
Key considerations for an impact assessment
-
Integrating impact assessment into risk assessment
o Scoping the risk assessment
o Analysing risk
-
Understanding risk and control using bow ties
-
Assessing level of risk using qualitative, semi-quantitative or quantitative approaches
o Considering inherent risk, residual risk, and the effect of controls
o Evaluating risk assessment against risk appetite
o Considering alignment with NIST AI RMF
9. AI Risk Metrics
o The purpose of risk metrics
o The types of risk metrics
o Characteristics of good metrics and pitfalls to avoid
o Defining zones and thresholds
o A practical risk metrics process to collect and collate risk information
o How to use metrics for escalation, reporting and response
o An AI risk metrics library
10. AI Controls Management
o The need for controls assurance
o Difference between governance controls and technical controls
o Documenting controls information
o Mapping control frameworks
o Control testing versus controls assessment
o A control testing process
-
Importance of Control objectives
-
Assessing design effectiveness
-
Assessing operating effectiveness
o Controls assessment over a group of controls
o Considering automated controls
o Applying outcomes of controls management activities
o A Control library and testing template
11. AI Governance & Risk Management Reporting
o The purpose of reporting
o Main types of reports
o What to report
o Considering stakeholders
o Collecting data for reporting
o Report examples
12. Integrating with Enterprise Risk Management
o Benefits of integration
o Integrating AI risk processes within the ERMF ‘House’
o Managing Risk In Change related to AI initiatives
o AI Compliance Management
o Integrating AI into an Operational Resilience framework
o Third Party Risk Management & AI
o Alignment with Model Risk Management
13. Responsibility for AI Governance & Risk Management
o Governance structures
o Everyone as a risk manager
o The Three Lines Model
o Enabling your frontline through AI Literacy
o Key behaviors that support strong risk culture
Course expectations
• Watch 14 videos
• Answer 10 knowledge tests
• 4 interactive examples
• Access 14 downloadable materials
• Answer 10 quiz questions
Timings
• 5.5 hours of video content
• Approximately 6.5 hours for the whole course
Cost: RiskNZ Members: $875+GST | Non-member: $1000+GST
Next steps: Register Via: [email protected], Receive Invoice, Payment, Set-up with Log In To Course