AI Governance and Assurance: EU AI Act, ISO 42001 and NIST AI RMF

A three-day programme for the people accountable when an auditor asks who approved an AI system. Covers the revised EU AI Act timeline, the transparency and literacy obligations already in force, ISO/IEC 42001 management systems, the NIST AI risk framework, the OWASP LLM and Agentic risk taxonomies, and hands-on red teaming. Produces a control set mapped across all four frameworks rather than four separate exercises.

ai-governance-training

Intermediate

Artificial Intelligence

3 Days

Artificial Intelligence

artificial-intelligence

Online
On-site
Hybrid

AI Governance and Assurance: EU AI Act, ISO 42001 and NIST AI RMF

A three-day programme for the people accountable when an auditor asks who approved an AI system. Covers the revised EU AI Act timeline, the transparency and literacy obligations already in force, ISO/IEC 42001 management systems, the NIST AI risk framework, the OWASP LLM and Agentic risk taxonomies, and hands-on red teaming. Produces a control set mapped across all four frameworks rather than four separate exercises.

Duration:
3 Days
Rating:
4.8/5.0
Level:
Intermediate
1500+ users onboarded

Who will Benefit from this Training?

Training Objectives

Build a high-performing, job-ready tech team.

Personalise your team’s upskilling roadmap and design a befitting, hands-on training program with Uptut

Key training modules

Comprehensive, hands-on modules designed to take you from basics to advanced concepts
Download Curriculum
  • The AI Regulatory and Standards Landscape
    1. What actually applies: horizontal regulation, sectoral rules and voluntary standards
    2. How the AI Act, data protection law, operational resilience rules and security standards interact
    3. Approaches taken in the UK, US, India, Singapore and the Gulf, and where they diverge
    4. Extraterritorial reach: when EU obligations bind a non-EU organisation
    5. Hands-on: build an applicability map for your own AI estate
  • EU AI Act: Structure, Scope and the Revised Timeline
    1. Risk tiers and how a system is classified in practice
    2. Prohibited practices, including the categories added in the 2026 amendments
    3. Actor roles: provider, deployer, importer, distributor, and why the distinction matters
    4. General purpose AI model obligations and where they sit
    5. The 2026 deferral: what moved to December 2027 and August 2028, and what did not move at all
    6. Hands-on: rebuild a compliance calendar against the current legal position
  • Obligations Already in Force: Transparency and AI Literacy
    1. Disclosure when a person is interacting with an AI system
    2. Marking and labelling of synthetic audio, image, video and text
    3. Deepfake disclosure and public interest content rules
    4. Notices for emotion recognition and biometric categorisation systems
    5. The AI literacy duty and how to evidence it across a workforce
    6. Legacy systems, the December 2026 transition and technical marking solutions
  • High-Risk Obligations and Conformity Assessment
    1. Annex III standalone systems against Annex I embedded systems
    2. The required risk management system and its lifecycle
    3. Data and data governance requirements, including bias testing
    4. Technical documentation, record keeping and automatic logging
    5. Human oversight design, accuracy, robustness and cybersecurity requirements
    6. Conformity assessment routes, notified bodies and the state of harmonised standards
  • ISO/IEC 42001: Building an AI Management System
    1. Management system structure and the clause-by-clause requirements
    2. Annex A controls and selecting an applicable control set
    3. Integrating with an existing ISO 27001 management system rather than duplicating it
    4. Scoping decisions and defining the boundary of the AI management system
    5. AI system impact assessment as a repeatable process
    6. Internal audit, management review and the certification path
    7. Hands-on: draft a scope statement and initial control selection
  • NIST AI Risk Management Framework
    1. The govern, map, measure and manage functions as an operating loop
    2. Trustworthiness characteristics and how to make them measurable
    3. The generative AI profile and what it adds for foundation model use
    4. Using the framework where no regulation compels you, and why that still helps
    5. Hands-on: run a mapping exercise on a real AI use case
  • OWASP Top 10 for LLM Applications
    1. The current risk categories and what changed in the latest edition
    2. Treating a model as a component against treating it as an actor
    3. Containment-first architecture: harden the surroundings rather than the model
    4. Mapping to adversarial threat knowledge bases and weakness taxonomies
    5. Where these risks land inside a management framework's risk register
  • OWASP Top 10 for Agentic Applications
    1. Why agents need a separate taxonomy: planning, memory, tools, identity, inter-agent calls
    2. Goal hijack as the agentic counterpart of prompt injection, with action consequences
    3. Agent identity: distinct scoped workload identity rather than borrowing a user token
    4. Memory poisoning, supply chain risk and rogue or ownerless agents
    5. Inter-agent trust and privilege escalation across an agent fleet
    6. The AI bill of materials as the inventory artefact auditors now expect
  • Red Teaming and Assurance Testing
    1. Threat modelling an AI system before it ships
    2. Direct and indirect prompt injection testing through documents, retrieval and tools
    3. Jailbreak, refusal bypass and harmful output evaluation
    4. Tool poisoning, excessive permission and exfiltration path testing
    5. Behavioural baselines and detecting a hijacked agent from a productive one
    6. Building a repeatable test suite and capturing results as evidence
    7. Hands-on: red team a running system, then document the findings
  • Standing Up the Governance Programme
    1. AI inventory and use case registration as the foundation for everything else
    2. Risk register, risk appetite and treatment decisions
    3. Roles, accountability and the approval workflow for new AI use
    4. Intake triage: fast lanes for low risk, real scrutiny for high risk
    5. Third-party and vendor AI assessment, including model and connector supply chain
    6. Incident response, kill-switch procedures and post-incident review
    7. Board and regulator reporting that is accurate without being unreadable
  • Evidence, Audit and Certification Readiness
    1. Mapping one control set across regulation, management standard and risk taxonomy
    2. The documentation set: policies, assessments, logs, test results, decision records
    3. Answering the questions auditors ask: who approved permissions, where are the logs, how fast can it stop
    4. Running a gap assessment against your current state
    5. Building a prioritised remediation roadmap with owners and dates
    6. Hands-on: produce a gap assessment and roadmap for your organisation

Hands-on Experience with Tools

Training Delivery Format

Flexible, comprehensive training designed to fit your schedule and learning preferences
Opt-in Certifications
AWS, Scrum.org, DASA & more
100% Live
on-site/online training
Hands-on
Labs and capstone projects
Lifetime Access
to training material and sessions

How Does Personalised Training Work?

Skill-Gap Assessment

Analysing skill gap and assessing business requirements to craft a unique program

1

Personalisation

Customising curriculum and projects to prepare your team for challenges within your industry

2

Implementation

Supplementing training with consulting support to ensure implementation in real projects

3

Why this course

  • The calendar just changed: July 2026 amendments moved some deadlines and left others in force. Most compliance plans are now wrong.
  • One control set, four frameworks: Map controls once and satisfy the AI Act, ISO 42001, NIST and OWASP together.
  • Assurance, not awareness: Includes adversarial testing so you can evidence controls rather than assert them.
  • Built around audit questions: Structured on what auditors actually ask: who approved it, where are the logs, how fast can it stop.

Training objectives

  • Map which AI regulations and standards apply to your organisation and systems
  • Explain the EU AI Act's risk tiers, actor roles and extraterritorial reach
  • Apply the revised compliance timeline correctly, distinguishing what moved from what did not
  • Meet transparency and AI literacy obligations that are already in force
  • Prepare for high-risk obligations including risk management, data governance and human oversight
  • Build an AI management system aligned to ISO/IEC 42001 and integrate it with ISO 27001
  • Operate the NIST AI risk framework functions as a working governance loop
  • Apply the OWASP LLM and Agentic risk taxonomies as your security vocabulary
  • Establish non-human identity, permissioning and an AI bill of materials for agents
  • Design and run red-team tests for prompt injection, tool abuse and data exfiltration
  • Stand up an AI inventory, risk register, intake workflow and incident process
  • Produce the documentation set an auditor or client security review will accept

Who will benefit

  • Risk, compliance and internal audit professionals
  • Security architects and CISO-office teams
  • Legal, privacy and data protection officers
  • AI programme owners and enterprise architects
  • Consultants advising on AI assurance

Lead the Digital Landscape with Cutting-Edge Tech and In-House " Techsperts "

Discover the power of digital transformation with train-to-deliver programs from Uptut's experts. Backed by 70,000+ professionals across the world's leading tech innovators.

Frequently Asked Questions

1. What are the pre-requisites for this training?
Faq PlusFaq Minus

The training does not require you to have prior skills or experience. The curriculum covers basics and progresses towards advanced topics.

2. Will my team get any practical experience with this training?
Faq PlusFaq Minus

With our focus on experiential learning, we have made the training as hands-on as possible with assignments, quizzes and capstone projects, and a lab where trainees will learn by doing tasks live.

3. What is your mode of delivery - online or on-site?
Faq PlusFaq Minus

We conduct both online and on-site training sessions. You can choose any according to the convenience of your team.

4. Will trainees get certified?
Faq PlusFaq Minus

Yes, all trainees will get certificates issued by Uptut under the guidance of industry experts.

5. What do we do if we need further support after the training?
Faq PlusFaq Minus

We have an incredible team of mentors that are available for consultations in case your team needs further assistance. Our experienced team of mentors is ready to guide your team and resolve their queries to utilize the training in the best possible way. Just book a consultation to get support.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.