What is this course about?
Three frameworks overlap substantially and organizations often run three programs. This course builds one: an AI system inventory (the step everyone skips), EU AI Act risk classification applied to real systems, NIST AI RMF as an operating rhythm, and documentation that satisfies an auditor without stopping delivery.
Who is this course for?
- Chief risk and compliance officers
- AI governance and responsible AI leads
- Internal audit
- Legal counsel with technology responsibility
What do I need before starting?
- Familiarity with your organization's existing risk framework
- No technical background required
What will I be able to do afterwards?
- Explain what each framework is for and where they genuinely overlap
- Build an AI system inventory that captures shadow deployments
- Classify systems under EU AI Act risk tiers with defensible reasoning
- Run NIST AI RMF as an operating rhythm rather than a document
- Produce audit evidence without creating a delivery bottleneck
What does each module cover?
What is each framework actually for?
50 minPurpose, scope, and overlap across the three, and where running one satisfies another.
Objectives
- State each framework's purpose and legal status
- Map the genuine overlaps
- Choose a primary framework and map the others onto it
Topics
Activity. Build the three-way crosswalk and mark where one framework's evidence satisfies another.
How do you build an AI system inventory?
50 minThe first deliverable and the one organizations skip, including how to find shadow AI.
Objectives
- Define what counts as an AI system for inventory purposes
- Discover shadow deployments across the organization
- Maintain the inventory as systems change
Topics
Activity. Run a discovery exercise in one business unit and inventory what you find.
How do you classify systems under the EU AI Act?
55 minApplying risk tiers to real systems, including the extraterritorial reach question.
Objectives
- Classify systems into the Act's risk tiers
- Determine whether the Act reaches your organization
- Document classification reasoning defensibly
Topics
Activity. Classify five of your inventoried systems with written reasoning for each.
How does NIST AI RMF become an operating rhythm?
50 minGovern, Map, Measure, and Manage as recurring activity rather than a one-off assessment.
Objectives
- Translate the four functions into recurring activities
- Assign ownership for each function
- Set cadence tied to real triggers
Topics
Activity. Design the operating rhythm with named owners and trigger conditions.
What does ISO 42001 certification actually require?
45 minScope, evidence, and effort — presented so the organization can decide whether to pursue it.
Objectives
- Describe the certification scope and process
- Estimate the evidence and effort burden
- Decide whether certification is worth pursuing
Topics
Activity. Perform a readiness gap assessment against the management system requirements.
Which controls actually mitigate AI risk?
50 minSelecting controls that change outcomes rather than generating documentation.
Objectives
- Select controls proportionate to classified risk
- Distinguish effective controls from documentation exercises
- Assign control ownership to people who can execute
Topics
Activity. Select and assign controls for one high-risk classified system.
How do you produce evidence without blocking delivery?
45 minDocumentation designed into the delivery process rather than bolted on before an audit.
Objectives
- Embed evidence generation in the delivery workflow
- Automate evidence collection where possible
- Prepare for an audit continuously rather than in a scramble
Topics
Activity. Redesign one delivery workflow so it emits audit evidence as a by-product.
Building the governance package
55 minThe workshop module: inventory, classifications, controls, and rhythm assembled.
Objectives
- Assemble the complete governance package
- Verify coverage against all three frameworks
- Plan the rollout across business units
Topics
Activity. Assemble the package and check coverage against the three-way crosswalk.
What is the capstone project?
Unified AI governance program
Produce a governance program covering all three frameworks: system inventory with shadow AI discovery results, EU AI Act classifications with written reasoning, selected controls with named owners, the NIST operating rhythm, and an embedded evidence workflow.
Deliverable: A governance package with a three-way framework crosswalk demonstrating coverage.
How are learners assessed?
- Inventory assessed on whether discovery found systems governance did not know about
- Classification reasoning reviewed for defensibility
- Evidence workflow tested — does it emit evidence without extra steps?
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for enterprise.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- AI Risk Management Framework
NIST
The primary framework the program is built around.
- EU Artificial Intelligence Act
EU AI Act resource
Risk tier definitions and obligations used in Module 3.
- ISO/IEC 42001, AI management systems
ISO
Management system requirements assessed in Module 5.
- NIST AI 600-1, Generative AI Profile
NIST
Generative-AI-specific risks the controls must address.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 2's shadow AI discovery is the module that produces the most surprise and the most value. Build a real discovery methodology — expense reports, network egress, browser extensions — rather than a survey.
- EU AI Act obligations phase in over time and the timeline must be verified at each revision. Do not ship dated compliance deadlines without checking them.
- Module 6 must distinguish controls that change outcomes from controls that produce paper. Governance courses default to the latter and the audience knows it.
- Have counsel review the EU AI Act material. Classification has legal consequences and the course should frame it as analysis requiring legal sign-off.
- Keep ISO 42001 proportionate. Most organizations will not certify, and presenting it as the destination makes the whole program look unachievable.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act course cover?
Three frameworks overlap substantially and organizations often run three programs. This course builds one: an AI system inventory (the step everyone skips), EU AI Act risk classification applied to real systems, NIST AI RMF as an operating rhythm, and documentation that satisfies an auditor without stopping delivery. It runs 6.5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Unified AI governance program.
Who should take AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act?
It is written for Chief risk and compliance officers, AI governance and responsible AI leads, Internal audit, Legal counsel with technology responsibility. Prerequisites: Familiarity with your organization's existing risk framework; No technical background required.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for enterprise teams that cannot send work to a public AI tool.
How do we get access to AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for enterprise cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.