Use your browser's print dialog and choose Save as PDF.

Back to the CAIGL course page

Course Syllabus

Certified AI Governance Leader

Your organisation is already deploying AI, governed or not. The EU AI Act’s obligations are already in force, and most of the people accountable for that risk have never had to defend a risk-tiering call or audit a model card under one. CAIGL is where CIOs, CISOs and GRC leads build that judgment against real governance exhibits — a poisoned dataset, a redlined model card, a vendor questionnaire.

6 sessions · 19 lessons · cybe.global/caigl

What You Will Be Able to Do

  • Audit an AI system for bias and fairness, and compute the approval-rate disparity that proves it.
  • Risk-tier an organisation’s AI use-case register against EU AI Act tiers and the NIST AI RMF functions.
  • Find unapproved AI in your own estate — proxy logs, expense exports, amnesty interviews — and register it.
  • Inspect a vendor-supplied training dataset for poisoning and decide whether it is safe to retrain on.
  • Audit a model card against a documentation standard and redline what is missing.
  • Run an AI security incident in a live war-room simulation, under time pressure.
  • Score vendor AI questionnaires and defend an approve, reject, or conditional decision.
  • Audit a governance policy against Govern, Map, Measure and Manage — and produce a board-ready fix list.

Curriculum

Evening 1 (Mon) — Modern AI Systems Primer + Trustworthy AI

155 min content & labs

GenAI, RAG, LLMOps and agents, then the five trustworthy AI principles, then two graded labs: a live bias audit and a data-poisoning hunt

You learn to tell training from inference and why the architecture chosen (RAG, fine-tuning, agents) determines every governance obligation that follows. You learn the five trustworthy AI principles — fairness, explainability, transparency, human oversight, robustness — what each requires and where they conflict. In the first lab, you audit a live HR screening model’s decision log against the four-fifths rule, quantify the disparity, and make a go/no-go call. In the second, you audit a vendor-delivered training dataset against four integrity gates and trace contamination to a single batch.

Skill: Speak the same AI systems language as the engineers building what you govern, and prove bias or poisoning with a number, not a hunch

  • Modern AI Systems Primer — GenAI, RAG, LLMOps, Agents, LAM25 min
  • Trustworthy AI Principles — fairness, explainability, transparency, oversight, robustness25 min
  • LAB — Bias & Fairness Audit: CyBeX HR Screening Decision Log45 min
  • LAB — Data Poisoning / Garbage-In Hunt: CyBeX vendor training dataset60 min

Evening 2 (Tue) — Risk Frameworks + Global Regulation

95 min content & lab

NIST AI RMF and ISO/IEC 42001 as a diagnostic partition of the work, then the EU AI Act’s four tiers and how other jurisdictions differ, then a live risk-tiering lab

You learn to use NIST AI RMF as a diagnostic partition of governance work and what ISO/IEC 42001 certification actually proves — and does not — about a vendor’s management system. You learn the EU AI Act’s four risk tiers and its extraterritorial reach, and how India, the Gulf, the US and China regulate differently in kind rather than degree. In the lab, you classify ten live systems against EU AI Act tiers, find the one prohibited practice hiding among them, and identify which high-risk systems are already in production with no conformity assessment.

Skill: Apply the framework spine every later lab is scored against, and classify a system’s regulatory tier before it ships

  • AI Risk Management Frameworks — NIST AI RMF, ISO/IEC 42001 & 2389430 min
  • Global AI Regulatory Landscape — EU AI Act, US state laws, India, China30 min
  • LAB — AI Model Risk-Tiering Exercise: CyBeX AI Use-Case Register35 min

Evening 3 (Wed) — Shadow AI Reckoning

70 min content & lab

Why unapproved AI use is the default state, then a live discovery sweep triangulating proxy logs, expense data and amnesty interviews

You learn why unapproved AI use is structurally the default state rather than an exception, and how to discover it by triangulating three sources — proxy logs, expense data, amnesty interviews — each covering a blind spot the others miss. In the lab, you triangulate three raw discovery sources into a defensible topline count, assign a disposition to every tool found, and avoid the prohibition trap that makes the next discovery sweep find nothing.

Skill: Name what AI is already running in your estate without anyone’s sign-off

  • Shadow AI Reckoning — discovery, triangulation, AI Tool Register, Acceptable Use Policy25 min
  • LAB — Shadow AI Discovery Sweep: CyBeX full estate investigation45 min

Evening 4 (Thu) — Development Governance + Incident Response

120 min content & labs

Data lineage and model-card disclosures, then why most AI incidents never trip a conventional alert, then two labs: a model-card audit and a live incident tabletop

You learn to distinguish data lineage from data composition, the four model tests governance must require by risk tier, and the model-card disclosures that make a model auditable by someone who did not build it. You learn why three of the four AI incident types never alert on their own, what to monitor with pre-agreed thresholds, and how to respond across containment, historical remediation and disclosure. In the first lab, you audit a production model card against a twelve-disclosure standard and find the blocking gap. In the second, you run a live incident that converges two earlier findings — an undetected hiring-model disparity and a poisoned-data retrain — through containment and disclosure.

Skill: Audit a model card someone else has to trust, and run a real incident response under time pressure

  • AI Development Governance — data lineage, model testing, model cards20 min
  • AI Incident Response and Deployment Monitoring — drift, poisoning, silent failure20 min
  • LAB — Model Card Audit: CyBeX production credit-risk model35 min
  • LAB — Incident Response Tabletop: converging hiring-model bias and a poisoned retrain45 min

Evening 5 (Fri) — Vendor Risk + Board Reporting

75 min content & lab

What you actually acquire when you buy AI, then the five components of a governance programme and how to brief a board, then a live vendor-scorecard lab

You learn what you actually acquire when you buy AI, how to read an evasive vendor questionnaire submission, and the six contract clauses that make vendor commitments enforceable rather than aspirational. You learn the five components of a governance programme, the sequence that builds them, and how to translate technical findings into decisions a board can actually make. In the lab, you score three AI vendor questionnaire submissions against a fixed rubric, apply the automatic disqualifier, and produce a decision per vendor that traces back to a specific answer.

Skill: Defend an approve, reject, or conditional vendor decision, and brief a board in language it can act on

  • Vendor and Third-Party AI Risk — procurement clauses, risk tiering20 min
  • AI Governance Programme Management and Board Reporting20 min
  • LAB — Vendor AI Risk Scorecard: 3 vendor submissions35 min

Immersion Day (Sat) — Capstone & Certification

165 min capstone & certification, single-day immersion

A capstone policy audit against the four NIST functions, then the certification assessment — 75 minutes auto-graded plus 30 minutes of written constructed response

You audit CyBeX’s draft AI Governance Policy against the four NIST functions and produce the prioritised findings memo that goes to the board — the same move every earlier lab built toward. The day closes with the certification assessment: 25 auto-graded scenario-judgment questions across all four domains (75 minutes), plus 4 written constructed-response prompts, human-reviewed (30 minutes). Pass mark is 75% overall with a 60% floor in every domain.

Skill: Govern AI across its lifecycle, then prove it under assessment

  • CAPSTONE LAB — The Policy Audit: CyBeX draft AI Governance Policy60 min
  • CERTIFICATION ASSESSMENT — 25 auto-graded scenario questions75 min
  • CERTIFICATION ASSESSMENT — 4 written constructed-response prompts, human-reviewed30 min

Certification Process

  1. 1. Do the Work(7 graded labs + capstone, newly authored for CAIGL)

    Seven graded hands-on labs across the cohort, plus a closing capstone audit. Each one hands you a realistic exhibit — a dataset, a policy draft, a vendor questionnaire — and grades your judgment against what it actually contains, not against recall trivia.

  2. 2. Produce the Artifacts(One graded deliverable per lab)

    Every lab produces a deliverable that gets scored: a fairness-metrics memo, a tiered use-case register, a shadow AI register, a data-integrity report, an incident tabletop decision log, a redlined model card, and a vendor risk scorecard.

  3. 3. Sit the Assessment(60 min · Immersion day afternoon)

    A closing 60-minute assessment combining short applied-judgment scenarios — each one a decision a governance leader actually has to make, not recall trivia — with one graded practical artifact submitted for scoring.

  4. 4. Certify(Portfolio-based certification)

    Certification is awarded on cumulative performance across all seven lab deliverables plus the closing assessment — not on the assessment alone. You earn it as a portfolio of work, the way the job is actually done.

Curriculum subject to change. For the latest version and enrolment, visit cybe.global/caigl