# AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act

> Enterprise · AI Course · ENT-5
> Source: https://ibl.ai/solutions/enterprise/course/ai-governance-nist-iso-eu-ai-act
> Last updated: 2026-08-25

**Operationalize three overlapping frameworks into one governance program — inventory, risk classification, controls, and the evidence auditors ask for.**

## The Short Answer

**NIST AI RMF, ISO 42001, and the EU AI Act overlap enough to run as one governance program rather than three. ibl.ai supports that program on infrastructure you control, where you own all the code and the data — which matters because most framework evidence requirements assume you can inspect the system, and managed AI services do not permit it.**

On ibl.ai you own all the code and the data, run it model-agnostic across any LLM, and pay with no per-seat pricing — so you can deploy anywhere, from your own cloud to a fully air-gapped network.

[Request Access](https://ibl.ai/contact) · [Explore Enterprise](https://ibl.ai/solutions/enterprise)

## Course facts

- **Level:** Intermediate
- **Duration:** 6.5 hours across 8 modules
- **Format:** Cohort workshop producing governance artifacts
- **Modules:** 8
- **Catalog code:** ENT-5
- **Frameworks covered:** NIST AI RMF, ISO/IEC 42001, EU AI Act, NIST AI 600-1

## What is this course about?

Three frameworks overlap substantially and organizations often run three programs. This course builds one: an AI system inventory (the step everyone skips), EU AI Act risk classification applied to real systems, NIST AI RMF as an operating rhythm, and documentation that satisfies an auditor without stopping delivery.

## Who is this course for?

- Chief risk and compliance officers
- AI governance and responsible AI leads
- Internal audit
- Legal counsel with technology responsibility

### What do I need before starting?

- Familiarity with your organization's existing risk framework
- No technical background required

## What will I be able to do afterwards?

- Explain what each framework is for and where they genuinely overlap
- Build an AI system inventory that captures shadow deployments
- Classify systems under EU AI Act risk tiers with defensible reasoning
- Run NIST AI RMF as an operating rhythm rather than a document
- Produce audit evidence without creating a delivery bottleneck

## What does each module cover?

### Module 1 — What is each framework actually for?

Purpose, scope, and overlap across the three, and where running one satisfies another. _(50 min)_

**Objectives**

- State each framework's purpose and legal status
- Map the genuine overlaps
- Choose a primary framework and map the others onto it

**Topics:** Framework purposes · Legal versus voluntary · Overlap mapping · Primary framework selection

**Activity:** Build the three-way crosswalk and mark where one framework's evidence satisfies another.

### Module 2 — How do you build an AI system inventory?

The first deliverable and the one organizations skip, including how to find shadow AI. _(50 min)_

**Objectives**

- Define what counts as an AI system for inventory purposes
- Discover shadow deployments across the organization
- Maintain the inventory as systems change

**Topics:** Inventory scope · Shadow AI discovery · Attribute capture · Maintenance

**Activity:** Run a discovery exercise in one business unit and inventory what you find.

### Module 3 — How do you classify systems under the EU AI Act?

Applying risk tiers to real systems, including the extraterritorial reach question. _(55 min)_

**Objectives**

- Classify systems into the Act's risk tiers
- Determine whether the Act reaches your organization
- Document classification reasoning defensibly

**Topics:** Risk tiers · Prohibited practices · High-risk categories · Extraterritorial reach

**Activity:** Classify five of your inventoried systems with written reasoning for each.

### Module 4 — How does NIST AI RMF become an operating rhythm?

Govern, Map, Measure, and Manage as recurring activity rather than a one-off assessment. _(50 min)_

**Objectives**

- Translate the four functions into recurring activities
- Assign ownership for each function
- Set cadence tied to real triggers

**Topics:** Govern · Map · Measure · Manage · Cadence and triggers

**Activity:** Design the operating rhythm with named owners and trigger conditions.

### Module 5 — What does ISO 42001 certification actually require?

Scope, evidence, and effort — presented so the organization can decide whether to pursue it. _(45 min)_

**Objectives**

- Describe the certification scope and process
- Estimate the evidence and effort burden
- Decide whether certification is worth pursuing

**Topics:** Certification scope · Management system requirements · Evidence burden · Cost-benefit

**Activity:** Perform a readiness gap assessment against the management system requirements.

### Module 6 — Which controls actually mitigate AI risk?

Selecting controls that change outcomes rather than generating documentation. _(50 min)_

**Objectives**

- Select controls proportionate to classified risk
- Distinguish effective controls from documentation exercises
- Assign control ownership to people who can execute

**Topics:** Control selection · Proportionality · Effectiveness testing · Ownership

**Activity:** Select and assign controls for one high-risk classified system.

### Module 7 — How do you produce evidence without blocking delivery?

Documentation designed into the delivery process rather than bolted on before an audit. _(45 min)_

**Objectives**

- Embed evidence generation in the delivery workflow
- Automate evidence collection where possible
- Prepare for an audit continuously rather than in a scramble

**Topics:** Embedded evidence · Automation · Continuous readiness · Auditor expectations

**Activity:** Redesign one delivery workflow so it emits audit evidence as a by-product.

### Module 8 — Building the governance package

The workshop module: inventory, classifications, controls, and rhythm assembled. _(55 min)_

**Objectives**

- Assemble the complete governance package
- Verify coverage against all three frameworks
- Plan the rollout across business units

**Topics:** Package assembly · Coverage verification · Rollout planning · Change management

**Activity:** Assemble the package and check coverage against the three-way crosswalk.

## What is the capstone project?

**Unified AI governance program.** Produce a governance program covering all three frameworks: system inventory with shadow AI discovery results, EU AI Act classifications with written reasoning, selected controls with named owners, the NIST operating rhythm, and an embedded evidence workflow.

_Deliverable:_ A governance package with a three-way framework crosswalk demonstrating coverage.

## How are learners assessed?

- Inventory assessed on whether discovery found systems governance did not know about
- Classification reasoning reviewed for defensibility
- Evidence workflow tested — does it emit evidence without extra steps?

## What ships with the course?

- **Facilitator guide.** Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
- **Learner workbook.** Exercises, checklists, and the templates each module's activity produces.
- **Hands-on lab environment.** A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
- **Assessment bank.** Scenario questions and rubric criteria mapped to each stated learning outcome.
- **Source bibliography.** Every primary regulation and standard cited on this page, linked and dated.

## Which AI agents does this course use?

- [Knowledge Agent](https://ibl.ai/solutions/enterprise/agent/knowledge-agent)
- [Operations Agent](https://ibl.ai/solutions/enterprise/agent/operations-agent)
- [HR Agent](https://ibl.ai/solutions/enterprise/agent/hr-agent)
- [Enterprise Assistant](https://ibl.ai/solutions/enterprise/agent/enterprise-assistant)

## Where does the course material come from?

Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.

- [AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) — NIST. The primary framework the program is built around.
- [EU Artificial Intelligence Act](https://artificialintelligenceact.eu/) — EU AI Act resource. Risk tier definitions and obligations used in Module 3.
- [ISO/IEC 42001, AI management systems](https://www.iso.org/standard/42001) — ISO. Management system requirements assessed in Module 5.
- [NIST AI 600-1, Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf) — NIST. Generative-AI-specific risks the controls must address.

## Delivery notes

Binding guidance for anyone preparing and delivering this course:

- Module 2's shadow AI discovery is the module that produces the most surprise and the most value. Build a real discovery methodology — expense reports, network egress, browser extensions — rather than a survey.
- EU AI Act obligations phase in over time and the timeline must be verified at each revision. Do not ship dated compliance deadlines without checking them.
- Module 6 must distinguish controls that change outcomes from controls that produce paper. Governance courses default to the latter and the audience knows it.
- Have counsel review the EU AI Act material. Classification has legal consequences and the course should frame it as analysis requiring legal sign-off.
- Keep ISO 42001 proportionate. Most organizations will not certify, and presenting it as the destination makes the whole program look unachievable.

## Why run AI training on a platform you own?

- **You own the course, not a licence to it.** Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
- **Model-agnostic delivery.** Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
- **No per-seat training licences.** Usage-based or self-hosted, so cost tracks actual use rather than headcount.
- **Deploy anywhere.** Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.

## Frequently asked questions

### What does the AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act course cover?

Three frameworks overlap substantially and organizations often run three programs. This course builds one: an AI system inventory (the step everyone skips), EU AI Act risk classification applied to real systems, NIST AI RMF as an operating rhythm, and documentation that satisfies an auditor without stopping delivery. It runs 6.5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Unified AI governance program.

### Who should take AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act?

It is written for Chief risk and compliance officers, AI governance and responsible AI leads, Internal audit, Legal counsel with technology responsibility. Prerequisites: Familiarity with your organization's existing risk framework; No technical background required.

### Can we run this course on our own infrastructure?

Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for enterprise teams that cannot send work to a public AI tool.

### How do we get access to AI Governance in Practice: NIST AI RMF, ISO 42001, EU AI Act?

Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.

### How much does AI training for enterprise cost on ibl.ai?

There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

## More Enterprise courses

- [Agentic AI for the Enterprise: From Chatbot to Workforce](https://ibl.ai/solutions/enterprise/course/agentic-ai-for-the-enterprise): What separates an agent from a chatbot — tools, memory, autonomy — and the orchestration patterns that let agents finish multi-step work without supervision.
- [RAG on Enterprise Knowledge: Architecture, Chunking, Evals](https://ibl.ai/solutions/enterprise/course/rag-on-enterprise-knowledge): Production retrieval over enterprise content — chunking strategy, hybrid search, permission-aware retrieval, and the eval harness that proves it works.
- [The Enterprise AI Cost Model: Per-Seat vs Token vs Owned](https://ibl.ai/solutions/enterprise/course/enterprise-ai-cost-model): Model AI spend across pricing shapes at real headcount — where per-seat licensing breaks, what tokens actually cost, and when owning the stack wins.
- [AI Security: The OWASP LLM Top 10 in Production](https://ibl.ai/solutions/enterprise/course/ai-security-owasp-llm-top-10): Securing deployed LLM systems — prompt injection, data leakage, supply chain, and excessive agency — with the controls and tests for each.
- [Building an LLM Eval Harness That Ships](https://ibl.ai/solutions/enterprise/course/llm-eval-harness-that-ships): Move from vibes to measurement — task-specific eval design, LLM-as-judge and its limits, regression gates, and production monitoring.
- [Model Context Protocol: Connecting Agents to Enterprise Systems](https://ibl.ai/solutions/enterprise/course/model-context-protocol-enterprise): MCP as the integration layer for enterprise agents — server design, authentication, authorization, and exposing internal systems without exposing them to everyone.
