Most AI governance programmes fail in the same place. The policy gets written, the committee gets constituted, the framework gets adopted, and eighteen months later nobody can produce a current list of the AI systems the organisation is actually running. Everything downstream of that list, meaning risk classification, impact assessment, oversight arrangements and regulatory obligations, is then built on a picture of the organisation that was accurate on the day of the workshop.
This course treats the inventory as the load-bearing artefact and works outward from it. Policies matter, but a policy governing systems you have not enumerated governs nothing.
What the course covers
The starting work is discovery and inventory. Learners build a register of AI systems that captures what the system does, who owns it, whether the organisation is provider or deployer or both, what data it touches, what decisions it influences, and what happens when it is wrong. The awkward part is scope, since shadow use of assistants, AI features switched on inside procured software, and models embedded by vendors without announcement all belong in the register and none of them arrive through a project gate.
From the inventory the course moves to classification, meaning sorting systems by regulatory exposure and by consequence. This is where the EU AI Act enters as an operational instrument rather than a legal summary. Learners work through the Article 5 prohibitions, which have applied since 2 February 2025 and carry penalties up to 35 million EUR or 7 percent of worldwide annual turnover, the Article 4 literacy duty applying since the same date, the general purpose model obligations applying since August 2025, the Article 50 transparency duties applying since 2 August 2026, and Annex III high-risk classification, which Regulation (EU) 2026/1744 deferred to 2 December 2027. Classification decisions get recorded with reasons, because an unreasoned classification cannot be defended when challenged.
The course then covers the control set: AI impact assessment distinct from data protection impact assessment, model and system documentation, human oversight design that gives the overseer real authority and real information, vendor and model due diligence, incident detection and response, production monitoring, change control when a vendor updates a model underneath you, and decommissioning. Each is taught as a procedure with an output, an owner and a retention location.
Framework alignment comes last rather than first, which is deliberate. Learners map their inventory and controls onto ISO/IEC 42001 clauses 4 to 10 and its Annex A controls, referenced by number and paraphrased rather than reproduced, and onto the NIST AI Risk Management Framework, which is public domain and quotable in full. Adopting a framework before knowing what you run produces a framework-shaped folder rather than governance.
The final module covers reporting upward, meaning what a board actually needs to see, how to express AI risk without inventing numbers, and how to report honestly when the answer is that a control is not yet in place.
Governance that produces checkable artefacts
The design principle behind the course comes from our engineering work. Our open-ontologies repository, which carries 462 stars on GitHub, exists to express constraints over structured records so that machines can evaluate them, using OWL and SHACL. Applied to governance, that means an AI inventory is not a spreadsheet of prose but a record with fields that can be validated: every high-risk classification has a recorded reason, every system has a named owner who still works here, every deployed system has a documented oversight arrangement. Constraints of that kind can be run nightly. Governance that can be checked automatically stops decaying quietly between audits, which is the normal fate of a governance programme.
Who it is for
Compliance, risk and legal professionals given AI in addition to their existing portfolio. Data protection officers absorbing AI oversight. Technology leaders asked to evidence control of systems they inherited. Internal auditors preparing to audit the function. Public sector officials working to procurement and transparency duties. The course assumes no technical background but does not avoid technical content where the governance question depends on it.
Frequently asked questions
What is AI governance? AI governance is the set of arrangements by which an organisation decides what AI systems it will run, on what terms, with what oversight, and how it evidences those decisions to people entitled to ask.
Who should own AI governance in an organisation? Ownership sits best with an accountable executive supported by a cross-functional group, since the work spans legal, security, data protection, procurement and engineering. Placing it solely inside legal or solely inside engineering reliably produces gaps at the boundary.
What goes in an AI inventory? System purpose, owner, provider or deployer role, data used, decisions influenced, affected people, risk classification with reasons, oversight arrangement, vendor and model dependencies, and the date the entry was last verified.
Does AI governance require a new committee? Usually not. Existing risk and change governance can absorb the work if the classification criteria and escalation thresholds are explicit. New committees are often created to avoid deciding those thresholds.
How does AI governance relate to data protection? They overlap where personal data is processed and diverge elsewhere. An AI impact assessment covers matters a data protection impact assessment does not, including performance limits, oversight capability and effects on people who are not data subjects.
What is the difference between AI governance and AI compliance? Compliance is meeting specified external obligations. Governance is the wider question of controlling what the organisation does with AI, including uses that are lawful but unwise.
Enrol
The AI governance course takes you from inventory to board report with an artefact at every step, mapped to the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework. If your governance position already exists and you want it stress-tested instead, our two-week AI assurance claim audit examines the evidence behind a specific claim and reports what holds. Contact us through the site.