Certified AI Governance Leader
Your organisation is already deploying AI, governed or not. The EU AI Act’s obligations are already in force, and most of the people accountable for that risk have never had to defend a risk-tiering call or audit a model card under one. CAIGL is where CIOs, CISOs and GRC leads build that judgment against real governance exhibits — a poisoned dataset, a redlined model card, a vendor questionnaire.
Curriculum reviewed by 13 independent security and governance leaders from the CSA Bangalore network.

7 labs
Graded against a real exhibit — dataset, policy, questionnaire — not recall trivia
Portfolio
Certification earned across every lab, not one exam moment
5 frameworks
NIST AI RMF, ISO 42001 & 23894, EU AI Act, OECD
Leader-built
For CIO, CDO, CTO, CISO and GRC — not implementers
Aligned to frameworks
40% off the release price. Taught live and virtually as five 2-hour evening sessions plus a full-day Saturday immersion, with international coverage — join from any timezone.
EU AI Act obligations are already in force. Most governance leads have never had to defend a risk-tiering decision under one — next cohort starts 16 Nov 2026.
Register for the CohortSee the CAISO Programme“This was a different learning experience altogether… I recommend this learning methodology to every learner.”
— Pravinkumar Jha, Head of Product and Cloud Security
This course includes
- Five live 2-hour evening sessions plus a full-day Saturday immersion
- 7 graded hands-on labs plus a capstone audit — each judged against a real exhibit
- A real exhibit in every lab: a dataset, a policy draft, a vendor questionnaire, a model card
- 60-minute certification assessment: applied judgment + a graded practical artifact
- Built on CyBe’s CAISO leadership content plus new AI-governance curriculum
- Covers NIST AI RMF, ISO/IEC 42001 & 23894, OECD, and the EU AI Act
Why This Course
Your organisation is already deploying AI. Leave able to set the direction on what gets built, bought, and deployed safely — and defend that decision to a board or a regulator. The labs are narrative-driven, not a slide deck: you work each one as a case study inside a running scenario, and use AI itself as a force multiplier in the risk detection and response work each lab asks of you.
Built around: NIST AI RMF · ISO/IEC 42001 & 23894 · EU AI Act · OECD AI Principles
Skills You’ll Gain
Who Should Attend

Executive Decision-Makers
CIO, CDO, CTO and CISO — the people who actually sign off on AI systems and answer for them in front of a board or a regulator.

GRC & Privacy Leads
GRC leads, Data Protection Officers and techno-legal counsel who own the governance framework, the vendor gate, and the regulatory response.

Product & Architecture Leads
Product Managers and Enterprise or Security Architects who decide what gets built, what gets bought, and what controls ship with it.
The roles this maps to are already being hired for
AI governance capability is showing up inside real, currently-posted roles at large employers in India — not only under an "AI Governance" title, but inside Product, Consulting and Responsible AI functions. The two examples below are verified, currently-postable roles as of publication; they are illustrative samples, not an exhaustive or permanent listing.
AI Governance Product Lead — Unilever, Bengaluru
Supports the product roadmap for Unilever’s AI governance platform: use-case registration, risk assessment, oversight and monitoring capability, working across technology, privacy, legal and cybersecurity teams. 5+ years of relevant experience.
Responsible AI Engineer — Accenture, Bengaluru & Hyderabad
Designs and implements mitigation strategies for AI systems against responsible-AI and ethical standards, audits AI systems for gaps, and works cross-functionally on responsible AI practice.
Company names and logos are used only to identify where these roles were publicly posted at the time of writing, and do not imply that Unilever or Accenture endorse, sponsor or are affiliated with CyBe Global or this programme. Postings change frequently; verify current openings directly on each employer’s careers page.
Curriculum
6 modules · 19 lessons
Download Syllabus ↓
1Evening 1 (Mon)
Mon 16 Nov, 18:00–20:00 IST
Modern AI Systems Primer + Trustworthy AI + Two Labs
GenAI, RAG, LLMOps and agents, then the five trustworthy AI principles, then two graded labs: a live bias audit and a data-poisoning hunt
You learn to tell training from inference and why the architecture chosen (RAG, fine-tuning, agents) determines every governance obligation that follows. You learn the five trustworthy AI principles — fairness, explainability, transparency, human oversight, robustness — what each requires and where they conflict. In the first lab, you audit a live HR screening model’s decision log against the four-fifths rule, quantify the disparity, and make a go/no-go call. In the second, you audit a vendor-delivered training dataset against four integrity gates and trace contamination to a single batch.
Skill: Speak the same AI systems language as the engineers building what you govern, and prove bias or poisoning with a number, not a hunch
2Evening 2 (Tue)
Tue 17 Nov, 18:00–20:00 IST
AI Risk Management Frameworks + Global Regulation + Risk-Tiering Lab
NIST AI RMF and ISO/IEC 42001 as a diagnostic partition of the work, then the EU AI Act’s four tiers and how other jurisdictions differ, then a live risk-tiering lab
You learn to use NIST AI RMF as a diagnostic partition of governance work and what ISO/IEC 42001 certification actually proves — and does not — about a vendor’s management system. You learn the EU AI Act’s four risk tiers and its extraterritorial reach, and how India, the Gulf, the US and China regulate differently in kind rather than degree. In the lab, you classify ten live systems against EU AI Act tiers, find the one prohibited practice hiding among them, and identify which high-risk systems are already in production with no conformity assessment.
Skill: Apply the framework spine every later lab is scored against, and classify a system’s regulatory tier before it ships
3Evening 3 (Wed)
Wed 18 Nov, 18:00–20:00 IST
Shadow AI Reckoning + Discovery Sweep Lab
Why unapproved AI use is the default state, then a live discovery sweep triangulating proxy logs, expense data and amnesty interviews
You learn why unapproved AI use is structurally the default state rather than an exception, and how to discover it by triangulating three sources — proxy logs, expense data, amnesty interviews — each covering a blind spot the others miss. In the lab, you triangulate three raw discovery sources into a defensible topline count, assign a disposition to every tool found, and avoid the prohibition trap that makes the next discovery sweep find nothing.
Skill: Name what AI is already running in your estate without anyone’s sign-off
4Evening 4 (Thu)
Thu 19 Nov, 18:00–20:00 IST
Development Governance + Incident Response + Two Labs
Data lineage and model-card disclosures, then why most AI incidents never trip a conventional alert, then two labs: a model-card audit and a live incident tabletop
You learn to distinguish data lineage from data composition, the four model tests governance must require by risk tier, and the model-card disclosures that make a model auditable by someone who did not build it. You learn why three of the four AI incident types never alert on their own, what to monitor with pre-agreed thresholds, and how to respond across containment, historical remediation and disclosure. In the first lab, you audit a production model card against a twelve-disclosure standard and find the blocking gap. In the second, you run a live incident that converges two earlier findings — an undetected hiring-model disparity and a poisoned-data retrain — through containment and disclosure.
Skill: Audit a model card someone else has to trust, and run a real incident response under time pressure
5Evening 5 (Fri)
Fri 20 Nov, 18:00–20:00 IST
Vendor Risk + Programme Management + Board Reporting Lab
What you actually acquire when you buy AI, then the five components of a governance programme and how to brief a board, then a live vendor-scorecard lab
You learn what you actually acquire when you buy AI, how to read an evasive vendor questionnaire submission, and the six contract clauses that make vendor commitments enforceable rather than aspirational. You learn the five components of a governance programme, the sequence that builds them, and how to translate technical findings into decisions a board can actually make. In the lab, you score three AI vendor questionnaire submissions against a fixed rubric, apply the automatic disqualifier, and produce a decision per vendor that traces back to a specific answer.
Skill: Defend an approve, reject, or conditional vendor decision, and brief a board in language it can act on
⚔Immersion Day (Sat)
Sat 21 Nov, 11:00–16:00 IST
Capstone Policy Audit + Certification Assessment
CAPSTONEA capstone policy audit against the four NIST functions, then the certification assessment — 75 minutes auto-graded plus 30 minutes of written constructed response
You audit CyBeX’s draft AI Governance Policy against the four NIST functions and produce the prioritised findings memo that goes to the board — the same move every earlier lab built toward. The day closes with the certification assessment: 25 auto-graded scenario-judgment questions across all four domains (75 minutes), plus 4 written constructed-response prompts, human-reviewed (30 minutes). Pass mark is 75% overall with a 60% floor in every domain.
Skill: Govern AI across its lifecycle, then prove it under assessment
Upcoming cohort dates
One cohort, run with international coverage at the request of our global members. Five 2-hour evening sessions Monday to Friday, then a full-day Saturday immersion. Join from anywhere — all sessions run live and online.
November 2026 cohort
Online — international coverage
5 sessions · 18:00–20:00 IST
- Mon 16 Nov
- Tue 17 Nov
- Wed 18 Nov
- Thu 19 Nov
- Fri 20 Nov
Running a cohort for your own leadership team? The programme is also delivered privately on a date of your choosing.
What backs this up
The specifics behind the claims on this page. Open any of them for the detail.
Bias & Fairness Audit
Audit an HR screening decision log and compute the approval-rate disparity that evidences the bias.
AI Model Risk-Tiering
Tier a use-case register against EU AI Act tiers and the NIST AI RMF functions.
Shadow AI Discovery Sweep
Extend CyBeX’s own shadow AI reckoning into a full estate investigation and register what you find.
Data Poisoning Hunt
Inspect a vendor-supplied retrain dataset and decide whether it is safe to train on.
Model Card Audit
Audit a credit-risk model card against a documentation standard and redline what is missing.
Incident Response Tabletop
Contain the CV Screening Assistant incident and a poisoned retrain, decision by decision, under time pressure.
Vendor AI Risk Scorecard
Score three vendor AI questionnaires and defend an approve, reject or conditional decision.
- Risk
NIST AI RMF
Govern, Map, Measure and Manage used as the spine of the governance audit.
- Standards
ISO/IEC 42001 and 23894
AI management systems and AI risk guidance.
- Regulation
EU AI Act, OECD AI Principles
Risk tiering and obligations, plus the wider international baseline.


- Academic
SRM Executive Education
Backed by SRMIST’s NAAC A++ accreditation and UGC Category-I status, integrating faculty expertise, senior industry practitioners, live business cases and applied projects into the design.
- Advisory
Reviewed by practising security and governance leaders
The full roster, with roles and organisations, is listed at /course-advisors.
- Audience
CIO, CDO, CTO, CISO, GRC leads and techno-legal counsel
Built for decision-makers rather than for implementers.
CSA CCM v3.0.1 Addendum to the RBI Gopalakrishna Committee (GKC) Report
2018
Technology & Cloud Security Maturity Global Survey
2022, with CSA and OpenText
AI Empowering Cybersecurity
2024, with KDEM, VVCE, SDM IMD
Global Cybersecurity Skills Gap Report
2025, with KDEM, VVCE, SDM IMD
State of Agentic AI 2026
Ongoing research into how autonomous agents detect, reason and respond to security threats faster than humans.
How You’ll Be Certified
Do the Work
Seven graded hands-on labs across the cohort, plus a closing capstone audit. Each one hands you a realistic exhibit — a dataset, a policy draft, a vendor questionnaire — and grades your judgment against what it actually contains, not against recall trivia.
7 graded labs + capstone, newly authored for CAIGL
Produce the Artifacts
Every lab produces a deliverable that gets scored: a fairness-metrics memo, a tiered use-case register, a shadow AI register, a data-integrity report, an incident tabletop decision log, a redlined model card, and a vendor risk scorecard.
One graded deliverable per lab
Sit the Assessment
A closing 60-minute assessment combining short applied-judgment scenarios — each one a decision a governance leader actually has to make, not recall trivia — with one graded practical artifact submitted for scoring.
60 min · Immersion day afternoon
Certify
Certification is awarded on cumulative performance across all seven lab deliverables plus the closing assessment — not on the assessment alone. You earn it as a portfolio of work, the way the job is actually done.
Portfolio-based certification
Frameworks and standards aligned with
CAIGL is a portfolio-assessed credential in its own right. The curriculum teaches and applies these frameworks directly — every lab artifact is produced against one of them, so the governance vocabulary you leave with is the one auditors and regulators already use.
| Body | Framework / standard | Why it matters |
|---|---|---|
NIST AI Risk Management Framework NIST AI RMF | Govern, Map, Measure and Manage used as the spine of the governance audit. | |
ISO/IEC 42001 ISO 42001 | AI management systems — the certifiable standard organisations are audited against. | |
ISO/IEC 23894 ISO 23894 | AI risk management guidance, applied alongside 42001 in the labs. | |
| European Union | EU AI Act | Risk tiering and obligations, used directly in the use-case register lab. |
OECD AI Principles OECD | The trustworthy-AI baseline most national AI policies are built on. |
NIST AI Risk Management Framework
Govern, Map, Measure and Manage used as the spine of the governance audit.
ISO/IEC 42001
AI management systems — the certifiable standard organisations are audited against.
ISO/IEC 23894
AI risk management guidance, applied alongside 42001 in the labs.
EU AI Act
Risk tiering and obligations, used directly in the use-case register lab.
OECD AI Principles
The trustworthy-AI baseline most national AI policies are built on.
Framework and standard names and logos are the property of their respective owners and are used here only to identify the frameworks this curriculum maps to and applies. CyBe Global is not affiliated with, endorsed by or accredited by NIST, ISO/IEC, the European Union or the OECD, and this programme is not an official product of any of these bodies. NIST and ISO/IEC logos: Wikimedia Commons, public domain (US government work / below the threshold of originality). OECD logo: Wikimedia Commons, public domain (below the threshold of originality).
Faculty for This Course

Satyavathi Divadari
CEO & Founder · CyBe Global / CSA Bangalore

Madhukeshwar Bhat
Academia Advisor · CSA Bangalore Chapter
Course Advisors
Practising security leaders who review this curriculum and keep it current.

Amod Suresh Puranik
Director – Head Data & AI Security · Virtusa Corp

Ashwini Siddhi
Co-Founder & CEO · Securacy.AI

Dr Ram Kumar G
Cyber Security and Risk Leader · Volvo Group

Sai Lakshmi Sathyanarayana
Partner, Cyber Leader · EY GDS
What Learners Say
“This was different learning experience all together. So much fun and so much to learn. The energy was continuously high to know what’s next. Not just regular content but every time something new and different. I recommend this learning methodology to every learner.”
Pravinkumar Jha
Head of Product and Cloud Security
“That sounds like such a refreshing change from usual conferences. Learning through music and teamwork really makes complex concepts stick in a fun way.”
Rohan Pinto
CTO and Founder, 1Kosmos

