Academy

AI Governance as a Practitioner

Stand up and run an AI governance programme: inventory, risk classification, impact assessment, controls, monitoring and audit readiness. Assumes you already know what a model is.

  1. Foundations

    AI governance distinguished from AI ethics, model risk management and data governance.

    • The regulatory landscape

      EU AI Act tiers and roles, the Swiss position, and sector guidance.

      • Frameworks and standards

        NIST AI RMF, ISO/IEC 42001, 23894 and 42005, and how they fit together.

        • Governance operating model

          Roles, RACI, the AI committee and three lines of defence.

          • Inventory and risk classification

            Intake that surfaces shadow AI, and tiering you can defend.

            • Impact and risk assessments

              FRIA, DPIA, bias, explainability, robustness, privacy and security.

              • Data governance for AI

                Lineage, quality, consent and training-data rights.

                • Third-party and generative AI

                  Vendor due diligence, contract clauses, and generative and agentic risks.

                  • Monitoring, incidents and audit

                    KPIs and KRIs, drift, the reporting clock and audit readiness.

                    • Capstone: insurance claims triage

                      One system taken end to end, from intake to audit readiness.