AI Governance Architecture Course


Reconciling NIST AI RMF, ISO/IEC 42001, the EU AI Act and right-to-explanation requirements into a single defensible governance posture is not a documentation exercise; it is an architectural challenge that most organizations are unprepared for. This course places practitioners inside that challenge, asking them to identify shared controls across all four frameworks, design a vendor risk architecture spanning the full AI procurement life cycle and sequence implementation decisions against real organizational constraints to arrive at a governance posture they can defend.
DELIVERY METHOD: ON-DEMAND | TIME: 3 HOURS | CPE CREDITS: 3 | FOCUS AREA: CYBERSECURITY LEADERSHIP | PROFICIENCY LEVEL: ADVANCED | LANGUAGE: ENGLISH | KNOWLEDGE AREA: COMPLIANCE
A stable internet connection is required. To record your completion of the online learning experience, please ensure you are connected to the internet at all times.
Refunds are not provided for ISC2 learning experiences.
This course builds a complete AI governance architecture through a series of applied decision points. Practitioners start by mapping obligations across NIST AI RMF, ISO/IEC 42001, the EU AI Act and right-to-explanation requirements, identifying where controls overlap and where gaps exist between them. From there, the course moves into vendor risk: learners design a governance structure that covers AI service providers from initial procurement through offboarding, accounting for contractual controls, monitoring mechanisms and exit conditions.
In the final phase, all prior work converges as practitioners integrate compliance obligations, vendor risk controls and organizational governance structures into a single architecture, sequenced by regulatory exposure, risk tier and maturity level. Practitioners are challenged not only to build the architecture but to defend it, making a reasoned case for their compliance posture against alternative approaches.
Learning Experience:
This course is designed for cybersecurity professionals, GRC specialists, compliance managers, security architects and risk officers responsible for establishing and operationalizing enterprise AI governance at a program or organizational level. It is built for practitioners with advanced governance, risk and compliance experience, including those holding CISSP, CGRC or equivalent certifications. Security leadership roles such as CISOs and privacy officers managing AI governance programs will also find the content directly applicable.
Learners have 60 days from the date of purchase to complete the entire course. Those who successfully complete this course will receive a digital Validation of Completion and earn continuing professional education (CPE) credits. We recommend that you download and retain the Validation of Completion for your personal records.
To receive a Validation of Completion and earn CPE credits, learners must:| CPE Credits | Group A | 3 |
| Field of Study | Cybersecurity Leadership | |
| Level | Advanced | |
| Prerequisites | Built for practitioners with advanced governance, risk and compliance experience, including those holding CISSP, CGRC or equivalent certifications. | |
| Access | Online | This is a digital product. The content will be available up to 60 days after purchase date. |
For more information, please refer to the ISC2 Certification Maintenance Handbook for additional CPE requirement details.
CPE credits earned from this learning experience will automatically be reported for ISC2 credentials on the first day of every month. Please allow up to 10 business days for processing.
CPE credits earned for this learning experience may also be eligible for continuing professional education credits for non-ISC2 certifications. Please visit the continuing education requirements established by the credentialing organization for eligibility.
For questions related to ISC2 CPE credits or the CPE portal not covered in the handbook, please contact us via our online form.
To purchase this course for someone or inquire about team discounts, please contact your regional office:
| Americas +1.866.331.4722 teamtraining@isc2.org |
EMEA +44.203.960.7800 teamtraining@isc2.org |
Asia-Pacific +852.5803.5662 teamtraining@isc2.org |
| Product | Training Access | Exam Window | Exam Attempts |
|---|---|---|---|
| Exam Only | — | 365 days | 1 |
| Exam Only with Peace of Mind Protection | — | 180 days | 2 |
| Online Instructor-Led Training | 180 days (from first session) | — | — |
| Online Instructor-Led Training + Exam | 180 days (from first session) | 365 days | 1 |
| Online Instructor-Led Training + Exam with Peace of Mind Protection | 180 days (from first session) | 180 days | 2 |
| Online Self-Paced Training (90-Day) | 90 days | — | — |
| Online Self-Paced Training (180-Day) | 180 days | — | — |
| 180-Day Online Self-Paced Training + Exam | 180 days | 365 days | 1 |
| 180-Day Online Self-Paced Training + Exam with Peace of Mind Protection | 180 days | 180 days | 2 |
| 90-Day Online Self-Paced Training + Exam | 90 days | 365 days | 1 |
| 90-Day Online Self-Paced Training + Exam with Peace of Mind Protection | 90 days | 180 days | 2 |
| Certificates, Courses, and Express Courses | 60 days | — | — |
Purchase of exam(s) only.
Access periods:
Exam code must be scheduled and administered with 365 days of purchase.
Exam-only purchase with two attempts included in the purchase price.
Applies to Online Instructor-Led Certification Education Course purchases without an exam.
Access periods:
Applies to Online Instructor-Led Certification Education Course + Exam bundles.
Access periods:
Applies to Online Instructor-Led Certification Education Course and Exam with Peace of Mind Protection bundles.
Access periods:
Available in 90-day and 180-day access options. All access periods begin from the date of purchase.
© Copyright 1996-2026. ISC2, Inc. All Rights Reserved.
All contents of this site constitute the property of ISC2, Inc. and may not be copied, reproduced or distributed without prior written permission. ISC2, CISSP, SSCP, CCSP, CGRC, CSSLP, HCISPP, ISSAP, ISSEP, ISSMP, CC, and CBK are registered marks of ISC2, Inc.




