Develop AI Augmented Cybersecurity Skills. Programs designed and delivered by Cybersecurity practitioners.Learn more
CAIGL·Advanced

Build the judgment to defend your AI risk decisions to a board or regulator.

Your organisation is already deploying AI, governed or not. The EU AI Act’s obligations are already in force, and most of the people accountable for that risk have never had to defend a risk-tiering call or audit a model card under one. CAIGL is where CIOs, CISOs and GRC leads build that judgment against real governance exhibits — a poisoned dataset, a redlined model card, a vendor questionnaire.

Curriculum reviewed by 13 independent security and governance leaders from the CSA Bangalore network.

Powered bySRM Executive Education

7 labs

Graded against a real exhibit — dataset, policy, questionnaire — not recall trivia

Portfolio

Certification earned across every lab, not one exam moment

5 frameworks

NIST AI RMF, ISO 42001 & 23894, EU AI Act, OECD

Leader-built

For CIO, CDO, CTO, CISO and GRC — not implementers

Aligned to frameworks

NISTNIST AI RMF
ISO/IECISO 42001
ISO/IECISO 23894
European UnionEU AI Act
OECDOECD
₹19,999Inaugural Offer Early Bird · Valid for limited seats only
₹33,500This cohort Special Price
₹61,500List price

Discounted price ₹33,500 (this cohort only). List price ₹61,500. Taught live and virtually as five 2-hour evening sessions plus a full-day Saturday immersion, with international coverage — join from any timezone.

EU AI Act obligations are already in force. Most governance leads have never had to defend a risk-tiering decision under one — next cohort starts 16 Nov 2026.

Register for the CohortSee the CAISO ProgrammeCorporate & group discounts — Contact usGet your employer to pay →

“This was a different learning experience altogether… I recommend this learning methodology to every learner.”

— Pravinkumar Jha, Head of Product and Cloud Security

This course includes

  • Five live 2-hour evening sessions plus a full-day Saturday immersion
  • 7 graded hands-on labs plus a capstone audit — each judged against a real exhibit
  • A real exhibit in every lab: a dataset, a policy draft, a vendor questionnaire, a model card
  • 60-minute certification assessment: applied judgment + a graded practical artifact
  • Built on CyBe’s CAISO leadership content plus new AI-governance curriculum
  • Covers NIST AI RMF, ISO/IEC 42001 & 23894, OECD, and the EU AI Act

Why This Course

Your organisation is already deploying AI. Leave able to set the direction on what gets built, bought, and deployed safely — and defend that decision to a board or a regulator. The labs are narrative-driven, not a slide deck: you work each one as a case study inside a running scenario, and use AI itself as a force multiplier in the risk detection and response work each lab asks of you.

Audit an AI system for bias and fairness, and compute the approval-rate disparity that proves it.
Risk-tier an organisation’s AI use-case register against EU AI Act tiers and the NIST AI RMF functions.
Find unapproved AI in your own estate — proxy logs, expense exports, amnesty interviews — and register it.
Inspect a vendor-supplied training dataset for poisoning and decide whether it is safe to retrain on.
Audit a model card against a documentation standard and redline what is missing.
Run an AI security incident in a live war-room simulation, under time pressure.
Score vendor AI questionnaires and defend an approve, reject, or conditional decision.
Audit a governance policy against Govern, Map, Measure and Manage — and produce a board-ready fix list.

Built around: NIST AI RMF · ISO/IEC 42001 & 23894 · EU AI Act · OECD AI Principles

Skills You’ll Gain

NIST AI RMFISO/IEC 42001ISO/IEC 23894EU AI ActOECD AI PrinciplesBias & Fairness AuditingAI Risk TieringShadow AI DiscoveryData Poisoning DetectionModel CardsAI Incident ResponseVendor AI RiskBoard ReportingAI Acceptable Use PolicyLLMOps & Agents

Who Should Attend

A senior executive looking out over the city from a corner office

Executive Decision-Makers

CIO, CDO, CTO and CISO — the people who actually sign off on AI systems and answer for them in front of a board or a regulator.

A GRC lead holding a tablet in an open-plan office

GRC & Privacy Leads

GRC leads, Data Protection Officers and techno-legal counsel who own the governance framework, the vendor gate, and the regulatory response.

A product and architecture team reviewing plans together around a table

Product & Architecture Leads

Product Managers and Enterprise or Security Architects who decide what gets built, what gets bought, and what controls ship with it.

The roles this maps to are already being hired for

AI governance capability is showing up inside real, currently-posted roles at large employers in India — not only under an "AI Governance" title, but inside Product, Consulting and Responsible AI functions. The two examples below are verified, currently-postable roles as of publication; they are illustrative samples, not an exhaustive or permanent listing.

Unilever

AI Governance Product Lead — Unilever, Bengaluru

Supports the product roadmap for Unilever’s AI governance platform: use-case registration, risk assessment, oversight and monitoring capability, working across technology, privacy, legal and cybersecurity teams. 5+ years of relevant experience.

Posted on Unilever Careers

Accenture

Responsible AI Engineer — Accenture, Bengaluru & Hyderabad

Designs and implements mitigation strategies for AI systems against responsible-AI and ethical standards, audits AI systems for gaps, and works cross-functionally on responsible AI practice.

Posted on Accenture Careers

What these roles pay

Industry compensation trackers report AI governance and responsible-AI specialist roles in India in the ₹10–28 LPA range, with senior/lead positions (the CIO/CISO/GRC-lead level this programme targets) reported materially higher in metro and GCC hubs. These are third-party estimates, not a CyBe Global placement guarantee — check the source and a primary board (Glassdoor, AmbitionBox, Naukri) for your own role and city before treating any figure as fixed.

Compensation estimates via Glassdoor and industry salary trackers

Company names and logos are used only to identify where these roles were publicly posted at the time of writing, and do not imply that Unilever or Accenture endorse, sponsor or are affiliated with CyBe Global or this programme. Postings change frequently; verify current openings directly on each employer’s careers page. Salary figures are third-party market estimates, not a placement or compensation guarantee.

Curriculum

6 modules · 19 lessons

Download Syllabus ↓
A human hand reviewing a report beside a robotic hand — the human-AI collaboration this primer session grounds in vocabulary1

Evening 1 (Mon)

Mon 16 Nov, 18:00–20:00 IST

Modern AI Systems Primer + Trustworthy AI + Two Labs

GenAI, RAG, LLMOps and agents, then the five trustworthy AI principles, then two graded labs: a live bias audit and a data-poisoning hunt

You learn to tell training from inference and why the architecture chosen (RAG, fine-tuning, agents) determines every governance obligation that follows. You learn the five trustworthy AI principles — fairness, explainability, transparency, human oversight, robustness — what each requires and where they conflict. In the first lab, you audit a live HR screening model’s decision log against the four-fifths rule, quantify the disparity, and make a go/no-go call. In the second, you audit a vendor-delivered training dataset against four integrity gates and trace contamination to a single batch.

Skill: Speak the same AI systems language as the engineers building what you govern, and prove bias or poisoning with a number, not a hunch

155 min content & labs · 4 lessons
A human hand and a robotic hand shaking hands — the trust this session teaches how to earn and verify2

Evening 2 (Tue)

Tue 17 Nov, 18:00–20:00 IST

AI Risk Management Frameworks + Global Regulation + Risk-Tiering Lab

NIST AI RMF and ISO/IEC 42001 as a diagnostic partition of the work, then the EU AI Act’s four tiers and how other jurisdictions differ, then a live risk-tiering lab

You learn to use NIST AI RMF as a diagnostic partition of governance work and what ISO/IEC 42001 certification actually proves — and does not — about a vendor’s management system. You learn the EU AI Act’s four risk tiers and its extraterritorial reach, and how India, the Gulf, the US and China regulate differently in kind rather than degree. In the lab, you classify ten live systems against EU AI Act tiers, find the one prohibited practice hiding among them, and identify which high-risk systems are already in production with no conformity assessment.

Skill: Apply the framework spine every later lab is scored against, and classify a system’s regulatory tier before it ships

95 min content & lab · 3 lessons
A small robot figure sheltering under an umbrella — the protective framework structure this session builds3

Evening 3 (Wed)

Wed 18 Nov, 18:00–20:00 IST

Shadow AI Reckoning + Discovery Sweep Lab

Why unapproved AI use is the default state, then a live discovery sweep triangulating proxy logs, expense data and amnesty interviews

You learn why unapproved AI use is structurally the default state rather than an exception, and how to discover it by triangulating three sources — proxy logs, expense data, amnesty interviews — each covering a blind spot the others miss. In the lab, you triangulate three raw discovery sources into a defensible topline count, assign a disposition to every tool found, and avoid the prohibition trap that makes the next discovery sweep find nothing.

Skill: Name what AI is already running in your estate without anyone’s sign-off

70 min content & lab · 2 lessons
A magnifying glass focused on a torn paper reading REGULATIONS — the global regulatory landscape this session maps4

Evening 4 (Thu)

Thu 19 Nov, 18:00–20:00 IST

Development Governance + Incident Response + Two Labs

Data lineage and model-card disclosures, then why most AI incidents never trip a conventional alert, then two labs: a model-card audit and a live incident tabletop

You learn to distinguish data lineage from data composition, the four model tests governance must require by risk tier, and the model-card disclosures that make a model auditable by someone who did not build it. You learn why three of the four AI incident types never alert on their own, what to monitor with pre-agreed thresholds, and how to respond across containment, historical remediation and disclosure. In the first lab, you audit a production model card against a twelve-disclosure standard and find the blocking gap. In the second, you run a live incident that converges two earlier findings — an undetected hiring-model disparity and a poisoned-data retrain — through containment and disclosure.

Skill: Audit a model card someone else has to trust, and run a real incident response under time pressure

120 min content & labs · 4 lessons
Sticky notes spelling UNKNOWN — the undiscovered shadow AI estate this session surfaces through its discovery sweep5

Evening 5 (Fri)

Fri 20 Nov, 18:00–20:00 IST

Vendor Risk + Programme Management + Board Reporting Lab

What you actually acquire when you buy AI, then the five components of a governance programme and how to brief a board, then a live vendor-scorecard lab

You learn what you actually acquire when you buy AI, how to read an evasive vendor questionnaire submission, and the six contract clauses that make vendor commitments enforceable rather than aspirational. You learn the five components of a governance programme, the sequence that builds them, and how to translate technical findings into decisions a board can actually make. In the lab, you score three AI vendor questionnaire submissions against a fixed rubric, apply the automatic disqualifier, and produce a decision per vendor that traces back to a specific answer.

Skill: Defend an approve, reject, or conditional vendor decision, and brief a board in language it can act on

75 min content & lab · 3 lessons
Wooden blocks spelling RISK beside a rising arrow — the full-day risk lifecycle and certification this immersion day covers⚔

Immersion Day (Sat)

Sat 21 Nov, 11:00–16:00 IST

Capstone Policy Audit + Certification Assessment

CAPSTONE

A capstone policy audit against the four NIST functions, then the certification assessment — 75 minutes auto-graded plus 30 minutes of written constructed response

You audit CyBeX’s draft AI Governance Policy against the four NIST functions and produce the prioritised findings memo that goes to the board — the same move every earlier lab built toward. The day closes with the certification assessment: 25 auto-graded scenario-judgment questions across all four domains (75 minutes), plus 4 written constructed-response prompts, human-reviewed (30 minutes). Pass mark is 75% overall with a 60% floor in every domain.

Skill: Govern AI across its lifecycle, then prove it under assessment

165 min capstone & certification, single-day immersion · 3 lessons

Upcoming cohort dates

One cohort, run with international coverage at the request of our global members. Five 2-hour evening sessions Monday to Friday, live online, then a full-day Saturday immersion — in person at SRM Executive Education’s Chennai campus, or live online for members who can’t travel.

November 2026 cohort

Online (Mon–Fri) — immersion day in person at SRM Chennai or online

5 sessions · 18:00–20:00 IST

  1. Mon 16 Nov
  2. Tue 17 Nov
  3. Wed 18 Nov
  4. Thu 19 Nov
  5. Fri 20 Nov
Sat 21 NovImmersion day11:00–16:00 IST — SRM Chennai campus or online

Running a cohort for your own leadership team? The programme is also delivered privately on a date of your choosing. International and remote members can join the immersion day online — the in-person option at SRM’s Chennai campus is available to those who can travel.

What backs this up

The specifics behind the claims on this page. Open any of them for the detail.

  • Bias & Fairness Audit

    Audit an HR screening decision log and compute the approval-rate disparity that evidences the bias.

  • AI Model Risk-Tiering

    Tier a use-case register against EU AI Act tiers and the NIST AI RMF functions.

  • Shadow AI Discovery Sweep

    Extend CyBeX’s own shadow AI reckoning into a full estate investigation and register what you find.

  • Data Poisoning Hunt

    Inspect a vendor-supplied retrain dataset and decide whether it is safe to train on.

  • Model Card Audit

    Audit a credit-risk model card against a documentation standard and redline what is missing.

  • Incident Response Tabletop

    Contain the CV Screening Assistant incident and a poisoned retrain, decision by decision, under time pressure.

  • Vendor AI Risk Scorecard

    Score three vendor AI questionnaires and defend an approve, reject or conditional decision.

How You’ll Be Certified

1

Do the Work

Seven graded hands-on labs across the cohort, plus a closing capstone audit. Each one hands you a realistic exhibit — a dataset, a policy draft, a vendor questionnaire — and grades your judgment against what it actually contains, not against recall trivia.

7 graded labs + capstone, newly authored for CAIGL

2

Produce the Artifacts

Every lab produces a deliverable that gets scored: a fairness-metrics memo, a tiered use-case register, a shadow AI register, a data-integrity report, an incident tabletop decision log, a redlined model card, and a vendor risk scorecard.

One graded deliverable per lab

3

Sit the Assessment

A closing 60-minute assessment combining short applied-judgment scenarios — each one a decision a governance leader actually has to make, not recall trivia — with one graded practical artifact submitted for scoring.

60 min · Immersion day afternoon

4

Certify

Certification is awarded on cumulative performance across all seven lab deliverables plus the closing assessment — not on the assessment alone. You earn it as a portfolio of work, the way the job is actually done.

Portfolio-based certification

Frameworks and standards aligned with

CAIGL is a portfolio-assessed credential in its own right. The curriculum teaches and applies these frameworks directly — every lab artifact is produced against one of them, so the governance vocabulary you leave with is the one auditors and regulators already use.

NIST

NIST AI Risk Management Framework

Govern, Map, Measure and Manage used as the spine of the governance audit.

ISO/IEC

ISO/IEC 42001

AI management systems — the certifiable standard organisations are audited against.

ISO/IEC

ISO/IEC 23894

AI risk management guidance, applied alongside 42001 in the labs.

European Union

EU AI Act

Risk tiering and obligations, used directly in the use-case register lab.

OECD

OECD AI Principles

The trustworthy-AI baseline most national AI policies are built on.

Framework and standard names and logos are the property of their respective owners and are used here only to identify the frameworks this curriculum maps to and applies. CyBe Global is not affiliated with, endorsed by or accredited by NIST, ISO/IEC, the European Union or the OECD, and this programme is not an official product of any of these bodies. NIST and ISO/IEC logos: Wikimedia Commons, public domain (US government work / below the threshold of originality). OECD logo: Wikimedia Commons, public domain (below the threshold of originality).

Faculty for This Course

Satyavathi Divadari

Satyavathi Divadari

Founder and CEO · CyBe Global · Founder, CSA Bangalore Chapter

28 years on the hiring side of enterprise security, CISSP, US patent holder

CISSPUS Patent HolderCSA Chapter of Excellence ×328 Years Enterprise Security

Satyavathi Divadari spent twenty-eight years as the buyer before becoming the builder. Across security roles at Wells Fargo, Cognizant, Capgemini and IBM, holding a CISSP and a US patent, she spent those years deciding which governance frameworks a real enterprise could actually run, and which of them just looked good in a slide deck.

She also founded the CSA Bangalore Chapter and built it into a community that has won the Cloud Security Alliance’s global Chapter of Excellence award three years running — the same practitioner network that reviews CAIGL’s curriculum today.

Why this facilitator, for this course

CAIGL teaches AI governance as it is actually practised inside a large enterprise — policy that survives contact with legal, procurement and a regulator, not governance theory. Satyavathi built and ran governance and risk programmes at four global employers before she built a course about it, so the frameworks taught here are the ones she was accountable for getting right.

Course Advisors

Practising security leaders who review this curriculum and keep it current.

See all 13 advisors →

Amod Suresh Puranik

Director – Head Data & AI Security · Virtusa Corp

Ashwini Siddhi

Co-Founder & CEO · Securacy.AI

Dr Ram Kumar G

Cyber Security and Risk Leader · Volvo Group

Sai Lakshmi Sathyanarayana

Partner, Cyber Leader · EY GDS

What Learners Say

“This was different learning experience all together. So much fun and so much to learn. The energy was continuously high to know what’s next. Not just regular content but every time something new and different. I recommend this learning methodology to every learner.”

PJ

Pravinkumar Jha

Head of Product and Cloud Security

“That sounds like such a refreshing change from usual conferences. Learning through music and teamwork really makes complex concepts stick in a fun way.”

RP

Rohan Pinto

CTO and Founder, 1Kosmos

Frequently Asked Questions