Governance in Practice
Building and running a real AI governance program
- Designing the AI Governance Operating Model — How to turn AI principles into working machinery: program sequencing and maturity, centralized vs hub-and-spoke structures, committee and CAIO design, three lines of defense, RACI discipline, policy architecture, metrics, and the culture that makes any of it real. (5 lessons, 60 min)
- The AI Center of Excellence: Organizing for AI Adoption — The organizational delivery vehicle for AI adoption: what the cloud CoE story teaches, the dual enable-and-govern mandate, three operating models and when to migrate between them, the team, the intake-to-production machinery, the artifact library, and a first-year roadmap that ends with the center making itself less necessary. (6 lessons, 60 min)
- AI Inventory, Use-Case Intake, and Risk Triage — Step zero of every governance program: finding the AI you already have — including the shadow and embedded kind — building a registry that stays true, designing proportionate intake, and triaging every use case to a risk tier mapped to the laws that bite. (5 lessons, 55 min)
- AI Risk and Impact Assessment Methodologies — How practitioners actually run AI assessments: the taxonomy of instruments (AIA, DPIA, FRIA, validation), Canada’s scored AIA, GDPR and AI Act triggers, severity scoring and its critiques, residual-risk sign-off, and how to run one assessment machine instead of five. (5 lessons, 60 min)
- Data Governance and Documentation Artifacts for AI — Provenance and lineage, lawful and licensed training data, synthetic data and the unlearning problem, and the documentation stack — datasheets, model cards, system cards, and the regulator-facing tech file — with a map of who writes what, when, and which law demands it. (5 lessons, 55 min)
- Testing and Evaluation: Fairness Math, Red-Teaming, and Explainability — The technical core of AI assurance: where bias enters, the fairness metrics and their impossibility results in full detail, disparate-impact math and bias audits, benchmarks and red-teaming, and the explainability toolkit — SHAP, LIME, counterfactuals — matched to the audiences governance must serve. (6 lessons, 60 min)
- Human Oversight, Post-Deployment Monitoring, and Incident Response — What happens after launch: designing human oversight that actually works, catching drift before it becomes harm, governing model changes and logs, running AI incident response against real regulatory clocks, and learning from the world’s incident databases. (5 lessons, 55 min)
- Third-Party AI, Generative AI, Agentic AI, and Frontier Governance — Governing the AI you did not build: vendor due diligence and the contract clauses that actually matter, generative AI controls from acceptable use to prompt injection, agentic AI permissioning and action logging, and how to read frontier safety frameworks as an enterprise buyer. (5 lessons, 60 min)
- Guardrails in the Cloud: Implementing Controls on AWS, Azure, and GCP — How legal obligations become running configuration: the enterprise LLM gateway pattern, Amazon Bedrock Guardrails, Azure AI Content Safety and the Foundry stack, the Vertex AI safety stack — and how to map every control back to the audit. (5 lessons, 50 min)
- The GenAI Security Scoping Matrix: Know What You’re Securing — AWS’s Generative AI Security Scoping Matrix turns one hard question — what exactly are we securing? — into five workload scopes and five security disciplines. Learn to place any genAI use case on the buy-to-build spectrum and read off what governance, legal, risk, controls, and resilience demand at that position. (5 lessons, 50 min)
- The Generative AI Lens: AWS Well-Architected for GenAI — How to run a Well-Architected review on a generative AI workload: the six pillars through AWS’s GenAI lens, the GENOPS-to-GENSUS best-practice grammar, and how the review’s findings map onto ISO/IEC 42001, NIST AI RMF, and your guardrail stack. (5 lessons, 50 min)
- The Responsible AI Lens: Well-Architected for Trustworthy AI — How to interrogate a single AI use case with AWS’s Responsible AI Lens: ten dimensions of responsible AI, eight lifecycle focus areas from use case to decommissioning, the RAIUC-to-RAIMON best-practice grammar, and how release criteria, system cards, and monitoring evidence map onto ISO/IEC 42001, NIST AI RMF, and the EU AI Act. (5 lessons, 55 min)
- Legal Intersections, Liability, and the Failure Files — Where AI governance meets the courtroom: GDPR Article 22 and the SCHUFA doctrine, the liability regimes that decide who pays when AI fails, and the forensic post-mortems — COMPAS, Amazon, the toeslagenaffaire, Clearview, Air Canada, NEDA Tessa — each traced to the control that would have caught it. (5 lessons, 60 min)