# AI Governance, Risk and Compliance

> An online, self-paced AI course from ARFA, the TIBLOGICS AI Academy. Advanced level, about 20 hours, in English and French, with a verifiable certificate.

Web page: https://tiblogics.com/learning-box/ai-governance · All tracks: https://tiblogics.com/learning-box.md

## Key facts

- Level: Advanced
- Time: about 20 hours including hands-on work (6 modules, 26 lessons, 6 labs); self-paced, no deadline
- Price: $677 one time for lifetime access to this track, or every track for $89 a month (cancel anytime)
- Certificate: TIBLOGICS Certified: AI Governance, Risk and Compliance, with a public verification page
- Languages: English and French

## About

AI is already inside most organisations: in tools staff chose themselves, in features switched on in software you already pay for, and in vendor systems that help make decisions about people. This track is for the people responsible for making that safe, fair and lawful without stopping the useful work. You will learn what goes wrong with AI and why governance is a system of incentives and feedback loops, not a document. You will learn how risk-based regulation is structured, using the EU AI Act as the main example, how data protection law applies to AI, and how the NIST AI Risk Management Framework, ISO/IEC 42001, ISO/IEC 23894 and the OECD AI Principles fit together. Then you will do the work: build a use-case register, classify risk, write impact assessments, test for unfair outcomes, govern the data behind AI from provenance to retirement, design human oversight, write policies people follow, respond to AI incidents, question vendors and their contracts, and run a governance programme with metrics leadership can act on. The labs are done on the platform, and the capstone is a full AI governance pack for an organisation you know, reviewed by a person. Skills this track builds also appear in professional AI governance certifications. This track is general education, not legal advice, and it is independent: it is not affiliated with, or official preparation for, any certification body or standard.

Who it is for: Managers, compliance, risk, legal, HR and IT leads, public sector staff and founders responsible for how AI is used and bought in their organisation.

## What you will be able to do

- Explain how AI fails in organisations and map governance as a system of owners, incentives and feedback loops
- Describe risk-based AI regulation, data protection duties and the main frameworks and standards in accurate general terms
- Build an AI use-case register, classify risk consistently and write impact assessments including DPIAs
- Design acceptable use policies, human oversight, documentation, monitoring and incident response that work in practice
- Run vendor due diligence, spot weak contract terms and set governance gates for in-house builds
- Set up and run an AI governance programme with clear roles, paired metrics and a realistic 90-day plan

## Curriculum

### Module 1: Why AI Needs Governance

See the five ways AI use goes wrong in organisations, turn responsible AI principles into commitments you can check, and treat governance as a system of incentives, feedback loops and clear ownership rather than a document.

- What can go wrong when organisations use AI (24 min)
- Principles you can check, not just admire (25 min)
- Governance as a system: incentives and feedback loops (26 min)
- Who owns what: accountability and proportionate governance (24 min)
- Module quiz

### Module 2: The Regulatory Landscape

Understand risk-based AI regulation through the EU AI Act's structure, how data protection law applies to AI, the main international frameworks and standards (NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894, OECD principles), sector rules, and how to keep track of change without drowning in it.

- Risk-based regulation: how the EU AI Act is built (26 min)
- Data protection law and AI (25 min)
- Frameworks and standards: NIST, ISO and the OECD (25 min)
- Sector rules and keeping track of change (24 min)
- Module quiz

### Module 3: Assessing AI Risk

Find the AI your organisation already uses and record it in a use-case register, classify risk consistently, run impact assessments including data protection impact assessments, test for bias and unfair outcomes, assess third-party models and document every decision so it can be explained later.

- Finding your AI: the inventory and use-case register (24 min)
- Classifying risk and recording the decision (26 min)
- Impact assessments, including DPIAs (27 min)
- Bias and fairness testing basics, including third-party models (27 min)
- Module quiz

### Module 4: Controls and Operations

Put governance into daily operation: an acceptable use policy people follow, human oversight that works, model and data documentation, access control and security for AI, monitoring, incident response for AI failures, and audit trails that can answer hard questions later.

- Policies and acceptable use that people actually follow (24 min)
- Designing human oversight that works (26 min)
- Documentation and security for AI systems (26 min)
- Monitoring, incident response and audit trails (27 min)
- From checklist to controls: the 30 doors in governance (25 min)
- Module quiz

### Module 5: Buying and Building Responsibly

Ask vendors the due diligence questions that matter, know the contract terms that protect you (data use, training on your data, liability, audit rights, exit), run procurement with checks scaled to risk, test vendor claims instead of believing them, build in-house AI through clear governance gates, and govern the data behind AI from provenance to retirement.

- Vendor due diligence: the questions that matter (25 min)
- Contracts: data, training, liability, audit and exit (27 min)
- Procurement checklists and testing vendor claims (25 min)
- Building in-house with governance gates (26 min)
- Data governance for AI: provenance, lineage, rights and retention (26 min)
- Module quiz

### Module 6: Running an AI Governance Programme

Turn everything into a working programme: clear roles for a committee, owners and champions, an AI management system that runs on a plan-do-check-act cycle, role-based training and AI literacy, metrics and reporting that leadership can act on, continuous improvement, and a realistic 90-day plan.

- Roles: the committee, owners and champions (25 min)
- An AI management system in practice (26 min)
- AI literacy, training, metrics and reporting (26 min)
- Your first 90 days (27 min)
- Module quiz

## How you are assessed

- A quiz after each module (80% to pass, retakes allowed).
- A timed final exam: 35 questions in 60 minutes, 75% to pass, 90% for distinction, 3 attempts.
- A capstone project reviewed by a person against a published rubric (70% to pass).
- Each certificate has a public page at https://tiblogics.com/certificates/<reference> that anyone can open to check it.
