AI Security & Governance Training
About Course
Organisations are deploying AI faster than they are governing it. This programme is for the people who have to close that gap — security engineers, risk leads, data protection officers and architects who need a defensible answer to “what AI do we run, what data does it touch, and who signed off on it?”
You will build an AI governance programme end to end: inventory and classify AI systems, assess them against recognised frameworks, put technical controls around model inputs and outputs, and produce the evidence an auditor or regulator will ask for. The emphasis throughout is on operating practice rather than theory — every module ends in an artefact you could take back to your own estate.
What you will learn
- Build and maintain an inventory of AI systems, including shadow and embedded AI
- Classify AI use cases by risk and map them to obligations under the EU AI Act
- Apply the NIST AI Risk Management Framework and ISO/IEC 42001 to real systems
- Trace which datasets reach training, fine-tuning and retrieval pipelines
- Threat-model AI applications against the OWASP LLM Top 10
- Design input and output guardrails, and understand their limits
- Plan and run red-team exercises against a deployed AI feature
- Define monitoring, escalation and incident handling for AI-specific failures
- Assemble an audit evidence pack that survives external scrutiny
Course Outline
Module-1 THE AI GOVERNANCE PROBLEM
- Why conventional application governance misses AI systems
- Where AI enters an organisation: procured, embedded, built, and unofficial
- Mapping stakeholders across security, legal, privacy, data and product
- Exercise: draw the AI decision path in your own organisation
Module-2 DISCOVERY AND INVENTORY
- Finding AI inside SaaS you already pay for
- Detecting API calls to model providers from your own network
- What to record about a model: purpose, data, owner, provider, deployment mode
- Keeping an inventory current without a manual survey
- Exercise: design an inventory schema and populate three rows
Module-3 RISK CLASSIFICATION AND REGULATORY MAPPING
- Risk tiering that a business will actually use
- EU AI Act categories: prohibited, high risk, limited risk, minimal risk
- Obligations attaching to each tier, and who carries them
- Sector overlays: financial services, healthcare, employment, education
- Exercise: tier five real use cases and defend the boundaries
Module-4 FRAMEWORK APPLICATION
- NIST AI RMF: govern, map, measure, manage
- ISO/IEC 42001 as a management system rather than a checklist
- Choosing between frameworks, and running more than one without duplication
- Translating framework language into engineering tickets
- Exercise: map one AI system through all four NIST functions
Module-5 DATA LINEAGE INTO AI
- Training data, fine-tuning data, retrieval corpora and prompt context
- Why “we do not train on customer data” is harder to prove than to say
- Personal, special category and confidential data in pipelines
- Retention, deletion, and data already absorbed into weights
- Exercise: trace one dataset from source to model output
Module-6 THREAT MODELLING AI APPLICATIONS
- The OWASP LLM Top 10 applied to a working architecture
- Prompt injection: direct, indirect, and via retrieved content
- Data exfiltration through model outputs and tool calls
- Excessive agency: when the model can act, not only answer
- Supply chain risk in models, adapters and embeddings
- Exercise: threat-model a retrieval-augmented assistant
Module-7 TECHNICAL CONTROLS AND GUARDRAILS
- Input validation, allow-listing and context isolation
- Output filtering, grounding checks and refusal behaviour
- Tool and permission scoping for agentic systems
- Human-in-the-loop as a control: when it works and when it is theatre
- Honest limits: what guardrails cannot prevent
- Exercise: specify the control set for a customer-facing assistant
Module-8 EVALUATION AND RED-TEAMING
- Building an evaluation set that reflects your actual risk
- Regression testing prompts and model versions
- Structuring a red-team exercise: scope, rules, reporting
- Measuring residual risk without false precision
- Exercise: write ten adversarial test cases and score the results
Module-9 MONITORING, INCIDENTS AND CHANGE
- What to log for an AI system, and what not to retain
- Detecting drift, degradation and abuse in production
- AI-specific incident classes and escalation paths
- Handling model and provider changes you did not choose
- Exercise: draft an AI incident runbook
Module-10 EVIDENCE, AUDIT AND OPERATING RHYTHM
- The evidence an assessor asks for, in the order they ask
- Approval gates that do not stall delivery
- Reporting AI risk to a board without jargon
- A review cadence that survives staff turnover
- Exercise: assemble a one-system evidence pack
Student Ratings & Reviews
No Review Yet