The AI Risk Management Specialist is a comprehensive self-paced online course and professional certification programme for individuals responsible for identifying, assessing, treating and monitoring risks associated with artificial intelligence systems.

The programme provides a structured and practical approach to AI governance, regulatory compliance, risk and impact assessment, third-party oversight, generative and autonomous AI, information security, privacy, human oversight, monitoring and management reporting across the full AI system lifecycle.

The programme is aligned with recognised international standards, regulatory requirements and risk management frameworks, including the EU AI Act, ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, ISO 31000, the NIST AI Risk Management Framework and related ISO, NIST and BSI publications.

Delivery format and estimated workload

The course is delivered entirely online and may combine presentation-based lessons, recorded video instruction, written guidance, downloadable templates, practical exercises and scenario-based quizzes.

The current estimated workload is:

  • Course modules: approximately 39.5 hours
  • Final certification assessment: approximately 1.5 hours
  • Total programme workload: approximately 41 hours

Intended audience

The programme is intended for:

  • AI governance and responsible AI professionals;
  • enterprise and operational risk managers;
  • compliance and regulatory professionals;
  • cybersecurity and information security specialists;
  • privacy and data protection professionals;
  • internal and external auditors;
  • legal and technology advisers;
  • AI system and product owners;
  • procurement and third-party risk specialists;
  • consultants and project managers;
  • managers responsible for approving or overseeing AI use cases.

Programming experience or advanced knowledge of machine learning is not required.

Learning outcomes

After completing the programme, participants will be able to:

  • Identify AI systems, models, use cases, stakeholders and lifecycle dependencies.
  • Establish and maintain an organisational AI system inventory.
  • Determine organisational roles and applicable regulatory requirements.
  • Classify AI systems according to regulatory, operational and business risk.
  • Identify legal, ethical, security, privacy, safety, reliability and societal risks.
  • Conduct structured AI risk and impact assessments.
  • Evaluate inherent risk, control effectiveness and residual risk.
  • Select proportionate technical, organisational and contractual controls.
  • Assess third-party AI services, models and suppliers.
  • Establish monitoring, incident management and reassessment processes.
  • Prepare AI risk registers, treatment plans and management reports.
  • Support organisational alignment with the EU AI Act and recognised AI management standards.
  • Provide clear, evidence-based risk recommendations to management and governance bodies.

Course structure

Module 1. Introduction to AI systems and the AI lifecycle

Estimated duration: 2 hours 30 minutes

1.1. Artificial intelligence concepts and terminology
1.2. Machine learning, deep learning and neural networks
1.3. Generative AI and large language models
1.4. Foundation models and general-purpose AI models
1.5. Autonomous and agentic AI systems
1.6. Distinction between an AI model, AI system, application and AI-enabled product
1.7. Internally developed, externally supplied and embedded AI systems
1.8. Intended purpose and operational context
1.9. Reasonably foreseeable misuse
1.10. AI system boundaries, interfaces and dependencies
1.11. AI system stakeholders and affected persons
1.12. Data, model, application and infrastructure layers
1.13. AI lifecycle stages
1.14. Concept, design and feasibility
1.15. Data collection and preparation
1.16. Model development, training and validation
1.17. Procurement, integration and configuration
1.18. Testing, deployment and release
1.19. Operation, monitoring and modification
1.20. Retirement and decommissioning
1.21. Practical exercise: AI system description and lifecycle map
1.22. Module quiz

Module 2. Foundations, standards and frameworks for AI risk management

Estimated duration: 4 hours 30 minutes

2.1. Emerging risks and evolving AI risk scenarios
2.2. Positive and negative effects of AI
2.3. Continuous and iterative AI risk management
2.4. Integration with enterprise risk management
2.5. Integration with compliance, privacy and information security management
2.6. ISO/IEC 23894 — Guidance on AI risk management
2.7. ISO/IEC 42001 — Artificial intelligence management systems
2.8. ISO/IEC 42005 — AI system impact assessment
2.9. ISO/IEC 38507 — Governance implications of the use of AI
2.10. Relationship between AI governance, management systems, risk management and system-level impact assessment
2.11. ISO/IEC 22989 — AI concepts and terminology
2.12. ISO/IEC 23053 — Framework for AI systems using machine learning
2.13. ISO/IEC 5338 — AI system lifecycle processes
2.14. Applying common terminology across risk, legal, technical and management teams
2.15. Applying ISO/IEC 5259 data quality requirements to training, validation, testing and operational data
2.16. ISO/IEC TR 24027 — Bias in AI systems and AI-assisted decision-making
2.17. ISO/IEC TR 24028 — Overview of trustworthiness in AI
2.18. ISO/IEC TR 24029-1 — Overview of neural-network robustness assessment
2.19. ISO/IEC 24029-2 — Use of formal methods for robustness assessment
2.20. ISO/IEC TR 24030 — AI use cases
2.21. ISO/IEC TR 24368 — Ethical and societal concerns
2.22. Relationship between trustworthiness characteristics and organisational risk
2.23. Integration of AIMS, ISMS and PIMS processes
2.24. Reusing existing security and privacy controls for AI systems
2.25. Identifying AI-specific risks not fully covered by traditional ISMS controls
2.26. NIST AI Risk Management Framework: Govern, Map, Measure, Manage functions, AI RMF profiles, AI RMF Playbook
2.27. Trustworthy AI characteristics in the NIST AI RMF
2.28. Selecting Playbook actions according to organisational context
2.29. NIST AI 600-1 — Generative AI Profile
2.30. Generative AI risks and recommended risk management actions
2.31. Mapping NIST AI RMF outcomes to organisational controls
2.32. NIST AI 100-2 — Adversarial machine-learning taxonomy
2.33. Extending of SP 800-218A secure development practices to generative AI and foundation models
2.34. BSI IT-Grundschutz methodology for modelling AI-related systems within an information-security architecture
2.35. BSI AIC4 criteria catalogue for AI cloud services
2.36. BSI guidance on the secure use of AI systems
2.37. Creating an integrated AI risk management model
2.38. Mapping ISO/IEC 42001 to ISO/IEC 23894 and ISO/IEC 42005
2.39. Mapping ISO approaches to NIST AI RMF functions
2.40. Practical exercise: comparative framework mapping
2.41. Module quiz

Module 3. AI governance, accountability and organisational roles

Estimated duration: 2 hours 30 minutes

3.1. Purpose and scope of AI governance
3.2. Responsible AI principles
3.3. Relationship between governance, management and operational control
3.4. Responsibilities of the governing body
3.5. Responsibilities of senior management
3.6. AI governance committees
3.7. Enterprise risk and compliance functions
3.8. Legal and regulatory functions
3.9. Information security and privacy functions
3.10. Internal audit and independent assurance
3.11. AI system owner
3.12. Business process owner
3.13. Risk owner and control owner
3.14. Data owner and model owner
3.15. Product, development and operations teams
3.16. The Three Lines Model in AI governance
3.17. Segregation of duties
3.18. AI policies and supporting procedures
3.19. AI literacy and competence requirements
3.20. Approval and escalation authorities
3.21. Documenting AI-related decisions
3.22. Managing conflicts between innovation, performance and risk
3.23. Practical exercise: AI governance structure and RACI matrix
3.24. Module quiz

Module 4. The EU AI Act and the AI regulatory landscape

Estimated duration: 4 hours

4.1. Purpose and structure of the EU AI Act
4.2. Territorial and material scope
4.3. Definition of an AI system
4.4. Exclusions and special cases
4.5. AI value-chain participants
4.6. Provider obligations
4.7. Deployer obligations
4.8. Importer and distributor obligations
4.9. Product manufacturer responsibilities
4.10. Determining the organisation’s regulatory role
4.11. Prohibited AI practices
4.12. High-risk AI systems
4.13. High-risk systems under product-safety legislation
4.14. High-risk use cases listed in the AI Act
4.15. Transparency obligations
4.16. Limited-risk and other AI systems
4.17. General-purpose AI models
4.18. General-purpose AI models with systemic risk
4.19. AI literacy requirements
4.20. Risk management system requirements
4.21. Data and data-governance requirements
4.22. Technical documentation
4.23. Record-keeping and logging
4.24. Information for deployers
4.25. Human oversight
4.26. Accuracy, robustness and cybersecurity
4.27. Quality management
4.28. Conformity assessment and registration
4.29. Post-market monitoring
4.30. Serious incident reporting
4.31. Fundamental rights impact assessment
4.32. Interaction with GDPR and data protection
4.33. Interaction with consumer, employment and product-safety law
4.34. Interaction with sector-specific regulation
4.35. Regulatory evidence and accountability
4.36. Practical exercise: EU AI Act role and system classification
4.37. Module quiz

Module 5. AI inventory and use-case classification

Estimated duration: 2 hours 30 minutes

5.1. Purpose of an AI system inventory
5.2. Scope and inventory boundaries
5.3. Internally developed AI
5.4. Purchased and subscribed AI services
5.5. Embedded AI functionality
5.6. General-purpose AI tools
5.7. Shadow AI and unauthorised use
5.8. Identifying AI within existing business applications
5.9. AI use-case intake process
5.10. System name and description
5.11. Intended purpose
5.12. Business process and organisational owner
5.13. Provider and model information
5.14. Data categories and data sources
5.15. Affected individuals and stakeholder groups
5.16. Geographic and regulatory scope
5.17. Level of autonomy
5.18. Human involvement and decision authority
5.19. System criticality
5.20. Business impact classification
5.21. Regulatory classification
5.22. Security and privacy classification
5.23. Third-party dependency classification
5.24. Approval status and lifecycle status
5.25. Inventory review and update requirements
5.26. Practical exercise: AI inventory record and classification questionnaire
5.27. Module quiz

Module 6. AI risk taxonomy and risk scenario identification

Estimated duration: 3 hours

6.1. Purpose of an AI risk taxonomy
6.2. Organisation-wide and system-specific taxonomies
6.3. Strategic and business risk
6.4. Regulatory and compliance risk
6.5. Fundamental rights risk
6.6. Ethical and societal risk
6.7. Health and safety risk
6.8. Privacy and data protection risk
6.9. Information security risk
6.10. Data quality and data-governance risk
6.11. Bias and discrimination
6.12. Fairness and unequal outcomes
6.13. Transparency and explainability risk
6.14. Accuracy and reliability risk
6.15. Robustness and resilience risk
6.16. Hallucination and misleading output
6.17. Model and concept drift
6.18. Human oversight failure
6.19. Automation bias and overreliance
6.20. Intellectual property and copyright risk
6.21. Third-party and supply-chain risk
6.22. Financial and reputational risk
6.23. Environmental and sustainability risk
6.24. Misuse, abuse and dual-use risk
6.25. Systemic and concentration risk
6.26. Cross-domain and cascading risk
6.27. Risk scenario structure
6.28. Risk source, event and consequence
6.29. Assets, individuals and stakeholders affected
6.30. Foreseeable misuse scenarios
6.31. Scenario assumptions and dependencies
6.32. Practical exercise: AI risk taxonomy and scenario library
6.33. Module quiz

Module 7. AI risk and impact assessment

Estimated duration: 4 hours

7.1. Purpose of AI risk and impact assessment
7.2. Assessment initiation and triggering events
7.3. Defining assessment scope
7.4. Establishing the assessment team
7.5. Collecting system and use-case information
7.6. Defining intended purpose and operational context
7.7. Mapping system stakeholders
7.8. Identifying affected persons and groups
7.9. Identifying vulnerable groups
7.10. Mapping data, models, interfaces and dependencies
7.11. Identifying hazards, threats and risk sources
7.12. Identifying reasonably foreseeable misuse
7.13. Identifying potential positive and negative impacts
7.14. Assessing business and operational impact
7.15. Assessing impacts on individuals and groups
7.16. Assessing legal and regulatory impact
7.17. Assessing security and privacy impact
7.18. Assessing health, safety and fundamental-rights impact
7.19. Evaluating severity
7.20. Evaluating scale and number of affected persons
7.21. Evaluating duration and reversibility
7.22. Evaluating likelihood
7.23. Evaluating uncertainty and evidence quality
7.24. Determining inherent risk
7.25. Identifying existing controls
7.26. Evaluating control design
7.27. Evaluating control implementation
7.28. Evaluating control effectiveness
7.29. Determining residual risk
7.30. Comparing residual risk with acceptance criteria
7.31. Risk escalation and acceptance
7.32. Documenting assumptions and limitations
7.33. Relationship with data protection impact assessments
7.34. Relationship with fundamental rights impact assessments
7.35. Relationship with information security risk assessments
7.36. Reassessment requirements
7.37. Practical exercise: complete AI Risk and Impact Assessment
7.38. Module quiz

Module 8. AI risk treatment and control selection

Estimated duration: 3 hours 30 minutes

8.1. Purpose of risk treatment
8.2. Avoiding AI risk
8.3. Reducing AI risk
8.4. Transferring or sharing AI risk
8.5. Accepting residual AI risk
8.6. Selecting proportionate controls
8.7. Preventive controls
8.8. Detective controls
8.9. Corrective controls
8.10. Technical, organisational and contractual controls
8.11. Human-in-the-loop arrangements
8.12. Human-on-the-loop arrangements
8.13. Human authority and intervention points
8.14. Data quality controls
8.15. Validation and testing controls
8.16. Bias and fairness controls
8.17. Accuracy and performance controls
8.18. Transparency and disclosure controls
8.19. Explainability measures
8.20. Access and identity management
8.21. Logging and traceability
8.22. Output verification
8.23. Usage restrictions
8.24. Prohibited-use rules
8.25. Fallback and fail-safe mechanisms
8.26. Change and release management
8.27. Security and privacy controls
8.28. Supplier and contractual controls
8.29. Business continuity and exit controls
8.30. Linking controls to identified risks
8.31. Assessing expected control effectiveness
8.32. Preparing the AI Risk Treatment Plan
8.33. Residual risk approval
8.34. Tracking treatment actions
8.35. Practical exercise: AI Risk Treatment Plan and control matrix
8.36. Module quiz

Module 9. Generative and autonomous AI risk

Estimated duration: 2 hours 30 minutes

9.1. Characteristics of generative AI systems
9.2. Large language model use cases
9.3. Multimodal generative AI
9.4. Generative AI supply chains
9.5. Hallucination and confabulation
9.6. Inaccurate or misleading output
9.7. Harmful and inappropriate content
9.8. Sensitive information disclosure
9.9. Prompt injection and indirect prompt injection
9.10. Copyright and intellectual property risk
9.11. Training-data and provenance concerns
9.12. Deepfakes and synthetic content
9.13. Impersonation and fraud
9.14. Automation bias and overreliance
9.15. Acceptable-use requirements
9.16. Output verification and approval
9.17. Retrieval-augmented generation risks
9.18. Plugins, tools and external integrations
9.19. Autonomous and agentic AI
9.20. Agent goals and operating boundaries
9.21. Tool access and excessive permissions
9.22. Unintended and irreversible actions
9.23. Agent-to-agent interactions
9.24. Human approval points
9.25. Emergency interruption and shutdown
9.26. Monitoring autonomous activity
9.27. Practical exercise: generative AI assistant or AI agent assessment
9.28. Module quiz

Module 10. Third-party AI and supplier risk management

Estimated duration: 2 hours 30 minutes

10.1. AI supply-chain structures
10.2. Model, platform, application and infrastructure providers
10.3. Organisational responsibility when using external AI
10.4. Supplier criticality classification
10.5. Pre-contract AI due diligence
10.6. Provider governance and accountability
10.7. Model and system documentation
10.8. Model cards and system cards
10.9. Training and evaluation data transparency
10.10. Security and resilience assessment
10.11. Privacy and data-protection assessment
10.12. Performance and reliability evidence
10.13. Bias, fairness and explainability evidence
10.14. Regulatory compliance evidence
10.15. Subcontractors and fourth parties
10.16. Data location and transfer
10.17. Data retention and deletion
10.18. Model and service changes
10.19. Performance and service commitments
10.20. Audit and information rights
10.21. Incident notification obligations
10.22. Cooperation with regulatory investigations
10.23. Intellectual property and liability
10.24. Business continuity and service availability
10.25. Concentration and dependency risk
10.26. Portability and exit planning
10.27. Continuous supplier monitoring
10.28. Practical exercise: AI supplier risk assessment
10.29. Module quiz

Module 11. AI security and operational resilience

Estimated duration: 3 hours

11.1. AI security within enterprise risk management
11.2. AI assets and attack surfaces
11.3. AI development and deployment environments
11.4. Data poisoning
11.5. Model poisoning
11.6. Adversarial inputs and evasion
11.7. Prompt injection
11.8. Model extraction and theft
11.9. Membership inference
11.10. Sensitive information leakage
11.11. Insecure model and application interfaces
11.12. Insecure plugins and external tools
11.13. Excessive agency
11.14. Compromised models and third-party components
11.15. AI software and model supply-chain risk
11.16. Abuse and misuse of AI capabilities
11.17. Threat modelling for AI systems
11.18. Secure development and acquisition
11.19. Identity and access management
11.20. Environment segregation
11.21. Logging and security monitoring
11.22. Testing and AI red teaming
11.23. Vulnerability and patch management
11.24. Incident detection and response
11.25. Business continuity and disaster recovery
11.26. Operational resilience requirements
11.27. Integration with ISMS and cybersecurity frameworks
11.28. Practical exercise: AI security and resilience scenarios
11.29. Module quiz

Module 12. Monitoring, incidents and continual improvement

Estimated duration: 2 hours 30 minutes

12.1. Purpose of post-deployment monitoring
12.2. Monitoring responsibilities
12.3. Performance indicators
12.4. Key risk indicators
12.5. Control effectiveness indicators
12.6. Accuracy and reliability monitoring
12.7. Bias and harmful-outcome monitoring
12.8. Data and model drift
12.9. System and environmental changes
12.10. User feedback and complaints
12.11. Human override and intervention data
12.12. Supplier notifications and model updates
12.13. Monitoring thresholds
12.14. Alert and escalation processes
12.15. AI incident definition
12.16. Incident severity classification
12.17. Safety, security, privacy and rights-related incidents
12.18. Incident containment and response
12.19. Investigation and root-cause analysis
12.20. Internal and external reporting
12.21. Regulatory notification
12.22. Corrective and preventive actions
12.23. Lessons learned
12.24. Reassessment triggers
12.25. Significant system changes
12.26. Periodic risk review
12.27. Continual improvement
12.28. Practical exercise: AI Monitoring and Incident Management Plan
12.29. Module quiz

Module 13. AI risk reporting, assurance and management decision-making

Estimated duration: 2 hours 30 minutes

13.1. Purpose of AI risk reporting
13.2. Reporting audiences and information needs
13.3. AI risk register structure
13.4. Risk status and treatment reporting
13.5. Key risk indicators and dashboards
13.6. Risk trends and emerging risks
13.7. Reporting significant control weaknesses
13.8. Reporting incidents and harmful outcomes
13.9. Executive and board reporting
13.10. Management decision papers
13.11. Recommendations to approve an AI system
13.12. Recommendations for conditional approval
13.13. Recommendations to restrict or suspend use
13.14. Recommendations to reject or retire an AI system
13.15. Residual risk acceptance records
13.16. Evidence and audit trails
13.17. Internal control testing
13.18. Internal audit and independent assurance
13.19. Preparing for regulatory review
13.20. Corrective actions and assurance findings
13.21. AI risk management maturity assessment
13.22. Development of an AI risk management roadmap
13.23. Practical exercise: executive AI risk report
13.24. Module quiz

Practical learning approach

Each module combines structured learning content with examples, downloadable tools, a practical exercise and a knowledge quiz. Participants apply the course methodology to realistic AI use cases.

AI Risk Management Toolkit

Participants receive editable templates that can be adapted for organisational use:

  • AI System Inventory.
  • AI Use-Case Intake Form.
  • AI System Description Template.
  • AI Lifecycle and Stakeholder Map.
  • EU AI Act Applicability Checklist.
  • AI System Classification Questionnaire.
  • AI Risk Taxonomy.
  • AI Risk Scenario Library.
  • AI Risk and Impact Assessment Template.
  • AI Risk Register.
  • AI Supplier Assessment.
  • AI Risk Treatment Plan.
  • AI Control Catalogue.
  • AI Monitoring Plan.
  • AI Incident Report.
  • AI Risk Acceptance Form.
  • AI Governance RACI Matrix.
  • AI Management Reporting Template.

Final certification assessment

Estimated duration: 1.5 hours

The final certification assessment verifies the candidate’s ability to apply AI risk management principles to a realistic organisational scenario.

The assessment covers:

  • AI system and lifecycle identification.
  • Organisational and regulatory role determination.
  • AI system classification.
  • Risk and impact identification.
  • Inherent risk evaluation.
  • Existing control assessment.
  • Residual risk evaluation.
  • Risk treatment and control selection.
  • Third-party, security and privacy considerations.
  • Monitoring and incident-management requirements.
  • Management reporting.
  • Final risk-based recommendation.

The final assessment combines random selection of multiple-choice questions and scenario-based questions. Candidates must complete all mandatory modules and achieve the required passing score in the final assessment.

Successful candidates receive the CyberKreuz AI Risk Management Specialist certificate and badge, confirming that they have demonstrated the knowledge and practical skills required to support the governance, identification, assessment, treatment, monitoring and reporting of AI-related risks within an organisation.

Log in to enroll

The course will become enrollable when its learning modules are published.