Module 0 of 14
Module 0 · Welcome

AI Governance 101

A self-paced course (~2.5 hours) on how AI governance works in practice — the global principles behind it, the frameworks that structure it, the risks it manages, and the engineering controls and operating practices that make AI systems safer before and after deployment.

By the end of this course, you will be able to:

  • Describe the OECD AI Principles and UNESCO's ethics-of-AI principles, and recognize how the same core themes recur across global principle sets — including India's 7 Sutras.
  • Compare the common Responsible AI principles and processes used across frontier AI companies — evaluations, red-teaming, model cards, frontier safety policies, and staged releases.
  • Identify core Responsible AI risks in engineering contexts, including safety, bias, privacy, security, and misuse.
  • Interpret major Responsible AI frameworks — NIST AI RMF, ISO/IEC 42001, and the EU AI Act — and connect their requirements to day-to-day engineering practice.
  • Evaluate AI use cases for potential harm, failure modes, and risk severity before deployment.
  • Apply practical controls for data-, model-, and system-level risk mitigation during development.
  • Design monitoring and escalation practices that support safer AI behavior in production.
14
learning modules with voice narration
6+5
interactive exercises + inline knowledge checks
15
question final quiz — 70% to pass

How to take this course

Work through the modules in order — later modules build on earlier ones. Each module ends with either an interactive exercise or a knowledge check; do them, they are where the learning sticks. Budget around 2.5 hours in total, or take it in three sittings: Part I — Concepts & principles (Modules 1–8), Part II — Industry & risk (Modules 9–10), Part III — Practice (Modules 11–14 + quiz). Turn on Auto-voice in the top bar to have every screen read aloud with your browser's built-in text-to-speech.

Welcome to AI Governance 101. This self-paced course takes about two and a half hours and builds seven skills, in order. You'll describe the OECD and UNESCO AI principles and India's seven sutras; compare the responsible AI principles and processes used across frontier AI companies; identify core responsible AI risks in engineering contexts, including safety, bias, privacy, security, and misuse; interpret major frameworks — the NIST AI Risk Management Framework, ISO 42001, and the EU AI Act — and connect them to engineering practice; evaluate AI use cases for harm, failure modes, and risk severity before deployment; apply practical controls at the data, model, and system levels; and design monitoring and escalation practices for safer AI in production. There are fourteen learning modules, six interactive exercises plus five knowledge checks, and a fifteen-question final quiz with a seventy percent pass mark. Work in order — later modules build on earlier ones — and consider three sittings: concepts and principles, industry and risk, then practice. Let's begin.
Course Designer

Meet your course designer — Sakthi Thangavelu

Portrait of Sakthi Thangavelu

Sakthi Thangavelu

AI GOVERNANCE CONSULTANT · ISO 42001 LEAD AUDITOR, TRAINER & IMPLEMENTATION EXPERT

A governance, risk and compliance professional with 24 years in the IT industry, practicing across AI governance, privacy, and information security. Sakthi audits and trains on ISO/IEC 42001 with multiple certification bodies, and serves as lead consultant working with AI governance startups — bringing this course the perspective of someone who implements and audits these frameworks in the field, not just reads about them.

Field experience behind this course

  • Contractor auditor & trainer for ISO 42001 with multiple certification bodies; Stage 1 & Stage 2 AIMS audits completed.
  • AI Management System (AIMS) implementation for multiple AI startups; AIMS internal audits for enterprises.
  • Senior leadership roles in global data privacy and privacy office functions at leading IT services organizations; ISMS committee member.
  • Led a 3-year information security & data de-identification program safeguarding 15M individuals' personal data in the healthcare sector.
  • 15+ batches of ISO 42001 Lead Implementer / Lead Auditor training delivered to corporate and professional audiences.

Certifications

  • Certified Lead Auditor — ISO/IEC 42001:2023, ISO/IEC 27001:2022, ISO/IEC 27701:2019
  • Certified Lead Implementer — ISO/IEC 42001:2023
  • Certified Information & Privacy Manager (IAPP)
  • Certified Responsible AI Professional & Fellow of Privacy Technology (OneTrust)

CONNECT: linkedin.com/in/sakthithangavelu

Before we begin, meet your course designer. Sakthi Thangavelu is an AI governance consultant and a certified ISO 42001 lead auditor, lead implementer, and trainer, with twenty-four years in the IT industry across AI governance, privacy, and information security. He audits and trains on ISO 42001 with multiple certification bodies, has implemented AI management systems for multiple AI startups, has held senior leadership roles in global data privacy and privacy office functions at leading IT services organizations, and led a three-year data de-identification program safeguarding fifteen million individuals' personal data in the healthcare sector. He has delivered more than fifteen batches of ISO 42001 lead implementer and lead auditor training to corporate and professional audiences. This course distills that field experience — the same frameworks you'll learn here are the ones he implements and audits every week. Now, on to module one.
Registration

Register to begin — and to receive your completion certificate

Enter your name and email ID before starting the modules. Your name appears on the completion certificate at the end of the course. Both fields are required to continue.

Please enter your name (at least 2 characters).
Please enter a valid email address.

Your details are used only to personalize your completion certificate. They stay in your browser for this session and are not transmitted or stored anywhere.

One quick step before the modules begin: registration. Enter your full name and your email ID. Your name will appear on the completion certificate at the end of the course. Your details are used only to personalize that certificate — they stay in your browser and are not sent or stored anywhere. Both fields are required — fill them in, press register and start the course, and module one will open.
Module 1 · Introduction

AI Ethics, Responsible AI, Trustworthy AI, AI Governance — what's the difference?

These four terms are often used interchangeably, but they sit at different layers. AI Ethics provides the moral compass, Responsible AI provides the roadmap and journey, Trustworthy AI is the destination, and AI Governance is the structure that implements and enforces the whole climb.

Start with an everyday story: the Ola cab driver analogy

Think of a single Ola ride. The same four layers appear — beliefs, behavior, experience, and enforcement:

LAYER 1 · VALUES

AI Ethics = what the driver believes

"Passengers should be safe, treated with respect, and charged honestly." These are moral principles — statements of what should happen. On their own, they change nothing; a driver can hold them and still drive badly.

LAYER 2 · PRACTICE

Responsible AI = what the driver actually does

Follows traffic rules, takes the shortest sensible route, drives sober, doesn't share the passenger's number. Principles applied in practice, trip after trip. For AI teams: bias testing, privacy safeguards, documentation — done, not declared.

LAYER 3 · OUTCOME

Trustworthy AI = what the passenger experiences

Rides that are consistently safe, on time, and fairly priced — earning a 5-star rating and repeat bookings. Trust is a property earned as an outcome, not an action you take. For AI: a system users find reliable, fair, explainable, and secure.

LAYER 4 · ENFORCEMENT

AI Governance = what Ola the platform runs

Driver background checks, GPS route tracking, metered fares, ratings and reviews, an SOS button, and deactivation for violations. Structures that implement and enforce the values — so good behavior doesn't depend on each driver's goodwill. For AI: policies, review boards, audits, and monitoring.

Now see it as a pyramid

Stack the four layers and you get the AI Ethics & Governance Hierarchy — Ethics at the base as the foundation of values, Responsible AI and Trustworthy AI building on it, and Governance at the top, implementing and enforcing everything below it:

Pyramid diagram of the AI Ethics and Governance Hierarchy: AI Ethics (moral principles for AI development) at the base, then Responsible AI (ethical principles applied in practice), then Trustworthy AI (reliable, explainable, and secure AI systems), with AI Governance (structures for implementing and enforcing AI ethics) at the top.
THE AI ETHICS & GOVERNANCE HIERARCHY

The subtle difference in one line each

  • AI Ethics — the beliefs: what should be true.
  • Responsible AI — the behavior: what we do to make it true.
  • Trustworthy AI — the result: what the system demonstrably is, as experienced by users.
  • AI Governance — the system: how an organization guarantees it, at scale and over time.
KNOWLEDGE CHECK

Which layer does this belong to?

Your company publishes a value statement: "Our AI will never discriminate." Six months later, an internal audit committee starts reviewing every AI feature against that statement before launch, with authority to block releases. The audit committee is an example of…

Module one. Four terms that sound alike but mean different things: AI ethics, responsible AI, trustworthy AI, and AI governance. Let's feel the difference with an everyday story — an Ola cab ride. AI ethics is what the driver believes: passengers should be safe, respected, and charged honestly. Those are values — and values alone change nothing. Responsible AI is what the driver actually does on every trip: following traffic rules, taking the sensible route, driving sober, protecting the passenger's privacy. Principles applied in practice. Trustworthy AI is what the passenger experiences as a result: rides that are consistently safe, on time, and fairly priced — earning a five-star rating. Trust is an outcome you earn, not an action you take. And AI governance is what Ola the platform runs: background checks, GPS tracking, metered fares, ratings, an SOS button, and deactivation for violations — structures that enforce good behavior so it doesn't depend on any one driver's goodwill. Now stack those four layers and you get the pyramid on your screen. At the base, AI ethics — moral principles for AI development, the foundation everything rests on. Above it, responsible AI — those principles applied in practice. Then trustworthy AI — reliable, explainable, secure systems, the destination. And at the top, AI governance — the structures that implement and enforce AI ethics all the way down. In short: ethics is the beliefs, responsible AI is the behavior, trustworthy AI is the result, and governance is the system that guarantees it. Try the knowledge check before you continue.
Module 2 · Context

AI is embedded in everyday life — governance has to catch up

223
AI-enabled medical devices approved by the FDA in 2023 — up from just six in 2015 (Stanford AI Index 2025)
150k+
autonomous rides per week by Waymo, while Baidu's Apollo Go serves numerous cities across China
1,000+
national AI policy initiatives from 69+ countries tracked in the OECD.AI repository

From healthcare to transportation, AI has moved from the lab into daily life. Scale changes the stakes: failures now affect patients, passengers, applicants, and markets — and three well-documented incidents show what happens when governance lags.

Three incidents every engineer should know

CASE 1 · BIAS

Amazon's recruiting tool (2018)

An internal AI resume-screening tool, trained on a decade of past hiring data, learned to penalize resumes containing the word "women's" and downgrade graduates of women's colleges. Amazon scrapped it. Lesson: historical data encodes historical bias; without fairness testing, the model faithfully automates it.

CASE 2 · SCALE OF HARM

Dutch childcare benefits scandal

A government risk-scoring algorithm wrongly flagged tens of thousands of families for benefits fraud, disproportionately those with dual nationality — pushing families into debt and contributing to the Dutch cabinet's resignation in 2021. Lesson: automated decisions at population scale can devastate lives; harm to people is not hypothetical.

CASE 3 · ACCOUNTABILITY

Air Canada's chatbot (2024)

The airline's website chatbot invented a bereavement-fare refund policy. A tribunal ruled Air Canada liable for its chatbot's statements and ordered compensation. Lesson: "the AI said it, not us" is not a defense — organizations own their AI's outputs.

What enterprises are doing

In McKinsey's 2025 State of AI survey, risk & compliance (57%) and data governance (46%) are the most centralized elements of AI deployment — organizations treat them as too important to leave scattered, while tech talent is often hybrid.

Gartner (June 2025) found 91% of high-maturity organizations have appointed dedicated AI leaders — and their #1 implementation barrier is security threats (48%), followed by data availability/quality (29%). Low-maturity organizations struggle first with finding the right use cases (37%).

What "AI harm" means (NIST AI RMF)

  • Harm to people — individual (civil liberties, physical or psychological safety, economic opportunity), group/community (discrimination against a sub-group), societal (democratic participation, educational access).
  • Harm to organizations — business disruption, security breaches, monetary loss, reputation.
  • Harm to ecosystems — interconnected systems: supply chains, the global financial system, natural resources and the environment.

Map the three cases: Amazon = harm to people (group) and the organization's reputation; the Dutch scandal = harm to people at societal scale; Air Canada = harm to the organization (monetary + reputation).

Module two. Why AI governance, and why now. AI has moved from the lab into daily life. In 2023 the FDA approved 223 AI-enabled medical devices, up from just six in 2015. Waymo provides over 150,000 autonomous rides each week. Because AI now touches patients, passengers, and job applicants, failures have real consequences — and three incidents show what that looks like. First, bias: Amazon built an internal AI recruiting tool trained on ten years of past hiring data. It learned to penalize resumes containing the word "women's", and Amazon scrapped it. Historical data encodes historical bias. Second, scale of harm: in the Netherlands, a government risk-scoring algorithm wrongly accused tens of thousands of families of benefits fraud, disproportionately those with dual nationality — the fallout contributed to the resignation of the Dutch cabinet in 2021. Third, accountability: Air Canada's website chatbot invented a bereavement refund policy, and a tribunal held the airline liable for what its chatbot said. "The AI said it" is not a defense. Enterprises are responding: McKinsey finds risk and compliance and data governance are the most centralized parts of AI deployment, and Gartner reports 91 percent of high-maturity organizations have dedicated AI leaders, with security threats as their top barrier. Finally, remember NIST's three harm categories — harm to people, harm to organizations, and harm to ecosystems. Every control in this course exists to reduce one of them.
Module 3 · The governance canvas

The layers of AI governance — what a program actually has to govern

"AI governance" is not one activity — it is a canvas of layers that a program must cover. Before we get into definitions and frameworks, here is the map: six layers you will see again and again, from board-level policy down to the carbon footprint of a training run.

LAYER · POLICIES & OVERSIGHT

Governing policies

  • Enterprise AI policy — what is allowed, what is prohibited, who decides
  • Ethics board / steering committee with authority to block launches
  • Board-level accountability and clear decision rights
LAYER · RESOURCES

Resources & competencies

  • Budget and named owners — governance without funding is theater
  • Skills: AI literacy for everyone, specialist training for builders and reviewers
  • Tooling for evaluation, monitoring, and documentation
LAYER · RISK

Risk management

  • Risk registers and impact assessments per use case
  • Defined risk appetite — what the organization will and won't accept
  • Controls, internal audits, and regulatory compliance mapping
LAYER · LIFECYCLE

AI system lifecycle

  • Stage gates: ideation → data → build → validate → deploy → monitor → retire
  • Change management across the whole pipeline — data, prompts, libraries, weights
  • Documentation that travels with the system, version to version
LAYER · CLIMATE

Climate & environmental impact

  • Track energy use and CO₂ emissions of training and inference workloads
  • Right-size models — the smallest model that meets the need
  • Report AI's footprint within sustainability commitments
LAYER · DATA & STAKEHOLDERS

Data, compliance & stakeholders

  • Data governance: quality, provenance, rights, privacy
  • Transparency to users, regulators, and affected communities
  • Grievance and redress channels for people impacted by AI decisions

Zooming out: the same layering repeats at every altitude

Countries govern AI with national strategies and regulation (1,000+ initiatives in the OECD.AI repository). Enterprises govern it with the six layers above. And inside the enterprise, governance cascades again — organizational level, AI-system level, model level — which is exactly where the next module picks up.

Module three. The layers of AI governance. AI governance is not one activity — it is a canvas of layers a program must cover. Layer one, governing policies and oversight: an enterprise AI policy that says what is allowed and prohibited, an ethics or steering committee with real authority to block launches, and board-level accountability. Layer two, resources and competencies: budget and named owners — governance without funding is theater — plus AI literacy for everyone, specialist training for builders and reviewers, and tooling for evaluation and monitoring. Layer three, risk management: risk registers, impact assessments per use case, a defined risk appetite, controls, audits, and compliance mapping. Layer four, the AI system lifecycle: stage gates from ideation through data, build, validation, deployment, monitoring, and retirement, with change management across the whole pipeline and documentation that travels with the system. Layer five, climate and environmental impact: track the energy and CO2 emissions of training and inference workloads, right-size your models, and report AI's footprint within sustainability commitments. Layer six, data, compliance and stakeholders: data governance, transparency to users and regulators, and grievance channels for people affected by AI decisions. And remember — this layering repeats at every altitude: countries, enterprises, and inside the enterprise from organization to system to model. That cascade is exactly where the next module picks up.
Module 4 · Foundations

What AI governance is — and how enterprises structure it

AI governance is the system by which an organization manages its development and use of AI: the governance structures, policies, skills, and practices that guide AI use, monitoring, and management — so AI aligns with stakeholder objectives, is used responsibly and ethically, and complies with applicable requirements.

Recap: what "trustworthy" means, precisely (NIST)

Module 1 said Trustworthy AI is the destination. NIST defines what that destination looks like — a trustworthy AI system is: valid & reliable, safe, secure & resilient, explainable & interpretable, privacy-enhanced, fair with harmful bias managed, and accountable & transparent — balanced according to the system's context of use. Neglecting these characteristics increases both the probability and the magnitude of negative consequences.

An enterprise AI governance program runs at three levels

LevelScope & typical artifactsApproach
Organizational levelAI policy, ethics/steering committee, roles & competencies, regulatory-compliance mapping, stakeholder expectations, risk & sustainability management, internal audits, alignment with org values.Process-driven
AI-system levelData management, impact assessments, use-case verification & validation, internal/external communications, system documentation, alignment with the AI policy.Tool and process-driven
Model levelTraining & evaluation, performance monitoring, testing, documentation, change management, alignment with system requirements.Tool-based, metrics-driven

A useful cross-check: practitioner maps of the discipline (e.g. Regulations.ai) break it into 12 recurring areas — board oversight, risk management, documentation & records, human oversight & ethical safeguards, transparency & disclosure, data governance, testing & validation, incident management, AI supply-chain governance, AI literacy & culture, compliance monitoring, and enforcement & penalties. If your program has an answer for each, you have coverage.

Standard vs. Framework vs. Regulation — tap each card to flip it

Standarde.g. ISO/IEC 42001tap to flip ↻
Benchmark of quality & interoperability. Established criteria that organizations can certify against. Usually voluntary and driven by market demand. Can become mandatory when adopted by regulators.
Frameworke.g. NIST AI RMFtap to flip ↻
Structured guidance, voluntarily adopted. A pre-established set of tools and conventions that gives structure and direction, so organizations don't reinvent the wheel.
Regulatione.g. EU AI Acttap to flip ↻
Legally enforced — non-compliance brings penalties. Specific, concrete rules protecting consumers, promoting fairness, and maintaining competition.

How they interact in real life

These instruments stack rather than compete. A bank in the EU might be required to meet the EU AI Act (regulation), choose to structure its program on NIST AI RMF (framework), and certify against ISO 42001 (standard) to demonstrate compliance to customers and auditors. Standards and frameworks are often the practical "how" behind a regulation's "what."

Module four. Foundations. AI governance is the system by which an organization manages its development and use of AI — the structures, policies, skills, and practices that guide AI use, monitoring, and management. NIST defines the trustworthy AI this aims for: valid and reliable, safe, secure and resilient, explainable, privacy-enhanced, fair with harmful bias managed, and accountable and transparent. In enterprises, governance runs at three levels. The organizational level is process-driven: AI policy, an ethics or steering committee, compliance mapping, and audits. The AI-system level combines tools and process: data management, impact assessments, use-case validation, and documentation. The model level is tool-based and metrics-driven: training, evaluation, testing, monitoring, and change management. Practitioner maps break the discipline into twelve recurring areas, from board oversight and risk management to incident management and supply-chain governance — a useful coverage checklist. Finally, three instruments. A standard, like ISO 42001, is a voluntary benchmark you can certify against. A framework, like NIST AI RMF, is structured guidance you adopt. A regulation, like the EU AI Act, is legally enforced with penalties. And they stack: a European bank might be required to meet the AI Act, choose NIST as its structure, and certify to ISO 42001 to prove it. Flip the three cards on screen before continuing.
Module 5 · Frameworks in depth

NIST AI RMF, ISO/IEC 42001, and the EU AI Act — what each actually asks of you

These are the three instruments you'll most often be asked to "comply with" or "align to." Here's what each one contains, and what it means at your desk.

NIST AI Risk Management Framework — four functions

FunctionWhat it meansEngineering translation
GovernA culture of risk management is cultivated and present — policies, roles, accountability, at the center of everything.Your team has an AI policy, a named risk owner, and review gates in the release process.
MapContext is recognized; risks related to context are identified, with contributing factors.Before building: document intended use, users, misuse potential, and affected groups.
MeasureIdentified risks are assessed, analyzed, tracked — including metrics for trustworthiness, social impact, human-AI configurations.Benchmarks, fairness metrics, red-team results, tracked over versions.
ManageRisks are prioritized and acted on based on projected impact; mitigation is monitored.Risk register with owners, mitigations shipped, monitoring dashboards, incident runbooks.

ISO/IEC 42001 — the AI Management System standard

A management system standard (MSS) for organizations that develop or deploy AI — the same species as ISO 9001 (quality), ISO 14001 (environment), ISO/IEC 27001 (information security), and ISO 27701 (privacy). MSS benefits: performance and continuous improvement, efficient resource use from leadership down, risk management, consistent products and services — applicable across sectors, sizes, and geographies.

It follows the familiar Plan-Do-Check-Act loop: context & leadership, AI policy and objectives, risk and impact assessment, operational controls, performance evaluation, audits, and continual improvement. Organizations can be certified against it — increasingly requested in procurement.

EU AI Act (2024) — the risk pyramid

Unacceptable — Prohibitedsocial scoring, mass surveillance, harmful manipulation
High — Conformity assessmentemployment, education, essential services, vehicle safety, law enforcement
Limited — Transparency obligationchatbots, emotion recognition, deepfakes ("I am a robot")
Minimal — No obligationeverything else

High-risk obligations include: risk management system, data governance, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity requirements, and registration. Penalties scale up to a percentage of global turnover.

INTERACTIVE 1

Triage the use case: which EU AI Act tier?

Assign each AI use case to the tier where it most likely belongs. Tier definitions are above.

Module five. Three frameworks in depth. First, the NIST AI Risk Management Framework, with four functions. Govern: a culture of risk management — policies, roles, and accountability at the center. Map: recognize context and identify risks before building — intended use, users, misuse potential, and affected groups. Measure: assess, analyze, and track risks — benchmarks, fairness metrics, and red-team results over versions. Manage: prioritize and act — a risk register with owners, mitigations, monitoring, and runbooks. Second, ISO 42001, the AI management system standard — the same species as ISO 9001 for quality and ISO 27001 for information security. It runs a plan-do-check-act loop: policy and objectives, risk and impact assessment, operational controls, audits, and continual improvement, and organizations can be certified against it. Third, the EU AI Act of 2024, a regulation with four risk tiers: unacceptable-risk systems like social scoring are prohibited; high-risk systems in areas like employment, education, and law enforcement need conformity assessment, documentation, logging, and human oversight; limited-risk systems like chatbots carry transparency obligations — the user must know they're talking to a machine; minimal-risk systems have no obligation. Now try the triage exercise: assign each use case to its most likely tier.
Module 6 · Global principles I

The OECD AI Principles

Adopted in 2019 and updated in 2024, the OECD AI Principles were the first intergovernmental standard on AI — endorsed by 47+ adherent countries and the basis for the G20 AI Principles. Five values-based principles for trustworthy AI, plus five recommendations for policymakers.

1

Inclusive growth, sustainable development & well-being

AI should benefit people and planet — augmenting human capabilities, advancing inclusion, and reducing inequality.
AT YOUR DESK: ask who benefits and who bears the cost of your use case; consider compute/energy footprint.

2

Human rights & democratic values, fairness & privacy

Respect the rule of law, human rights, equality, and privacy across the AI lifecycle, with safeguards such as human oversight.
AT YOUR DESK: human-in-the-loop for consequential decisions; data minimization by default.

3

Transparency & explainability

People should know when they interact with AI and be able to understand and challenge outcomes.
AT YOUR DESK: disclosure in UI, model documentation, meaningful explanations for adverse decisions.

4

Robustness, security & safety

Systems should function appropriately across their lifecycle, resist attack and misuse, and allow override or safe decommission.
AT YOUR DESK: adversarial testing, guardrails, kill switch, graceful degradation.

5

Accountability

Actors are responsible for the proper functioning of AI systems, with traceability of data, processes, and decisions.
AT YOUR DESK: audit logs, versioning, a named owner for every model in production.

+5 for governments

Policy recommendations

Invest in AI R&D · foster an inclusive AI ecosystem · shape an enabling, interoperable policy environment · build human capacity for the labour-market transition · cooperate internationally.

KNOWLEDGE CHECK

Spot the odd one out

Which of the following is NOT one of the five OECD AI Principles?

Module six. The OECD AI Principles. Adopted in 2019 and updated in 2024, these were the first intergovernmental standard on AI, and the basis for the G20 principles. There are five values-based principles, and each has a desk-level translation. One: inclusive growth, sustainable development and well-being — ask who benefits and who bears the cost of your use case. Two: respect for human rights and democratic values, including fairness and privacy — human-in-the-loop for consequential decisions and data minimization by default. Three: transparency and explainability — disclose AI in the interface, document the model, and give meaningful explanations for adverse decisions. Four: robustness, security and safety — adversarial testing, guardrails, a kill switch, and graceful degradation. Five: accountability — audit logs, versioning, and a named owner for every model in production. The OECD also gives governments five recommendations covering research investment, an inclusive ecosystem, enabling policy, workforce capacity, and international cooperation. Take the knowledge check: one of the four options on screen is not an OECD principle — find it.
Module 7 · Global principles II

UNESCO's Recommendation on the Ethics of AI

Adopted by all 193 UNESCO member states in November 2021 — the first truly global standard on AI ethics. It rests on four values (human rights & dignity; peaceful, just & interconnected societies; diversity & inclusiveness; environment & ecosystem flourishing) and ten principles.

PrincipleEngineering relevance
1. Proportionality & do no harmUse AI only to the extent needed for a legitimate aim; do a risk assessment first. If a simpler method works, prefer it.
2. Safety & securityAvoid unwanted harms (safety) and vulnerabilities to attack (security) throughout the lifecycle.
3. Fairness & non-discriminationTest for unequal performance across groups; promote inclusive access to AI's benefits.
4. SustainabilityAssess AI against sustainability goals — including energy and compute footprint.
5. Right to privacy & data protectionData minimization, consent, protection through the lifecycle; adequate data-protection frameworks.
6. Human oversight & determinationHumans retain ultimate responsibility — no unchecked autonomy for consequential decisions.
7. Transparency & explainabilityDisclosure appropriate to context; people should be able to understand and contest outcomes.
8. Responsibility & accountabilityAuditable, traceable systems; clear ownership; mechanisms for redress.
9. Awareness & literacyEducate users and the public — distinctive to UNESCO among the major sets.
10. Multi-stakeholder & adaptive governanceInclusive participation; governance that evolves with the technology.

The convergence insight

Lay UNESCO next to OECD, the EU AI Act, NIST, Singapore PDPC, Hong Kong PCPD, and Australia's AI Ethics Principles, and the same rows keep appearing: transparency/explainability, fairness, safety/robustness, privacy, human oversight, accountability. Wording differs — "auditability" here, "interpretability" there — but the themes converge. Practically, this means one well-designed internal control set can satisfy many frameworks at once.

INTERACTIVE 2

Match the shared theme to the framework-specific wording

Click a theme on the left, then click its framework wording on the right.

Module seven. UNESCO's Recommendation on the Ethics of AI, adopted by all 193 member states in 2021, is the first truly global AI ethics standard. It rests on four values — human rights and dignity; peaceful, just and interconnected societies; diversity and inclusiveness; and a flourishing environment — and ten principles: proportionality and do no harm; safety and security; fairness and non-discrimination; sustainability; the right to privacy and data protection; human oversight and determination; transparency and explainability; responsibility and accountability; awareness and literacy; and multi-stakeholder, adaptive governance. Two of these — proportionality, and awareness and literacy — are distinctive to UNESCO. Here's the key insight: across OECD, UNESCO, NIST, the EU AI Act, and national sets from Singapore, Hong Kong, and Australia, the same themes keep recurring under different names. NIST says "fair with harmful bias managed" where UNESCO says "fairness and non-discrimination." That convergence means one well-designed internal control set can satisfy many frameworks at once. Try the matching exercise to see the pattern for yourself, then continue.
Module 8 · Global principles III

The 7 Sutras — India's AI Governance Guidelines (MeitY)

On 5 November 2025, India's Ministry of Electronics and Information Technology (MeitY) released the India AI Governance Guidelines under the IndiaAI Mission. At their heart are seven guiding principles — the Sutras — adapted from the RBI's FREE-AI Committee Report (August 2025) for the financial sector, made technology-agnostic and sector-neutral for the whole economy.

SUTRA 1

Trust is the Foundation

Trust is the precondition for AI adoption at population scale. Every other sutra exists to build and preserve it — without trust, even beneficial AI fails.

SUTRA 2

People First

Human-centric design and human oversight: AI must serve people and improve lives, with humans retaining ultimate control over consequential outcomes.

SUTRA 3

Innovation over Restraint

India's distinctive stance: prefer responsible innovation to pre-emptive restriction. No standalone AI law for now — existing laws (IT Act, DPDP Act, consumer protection) are extended to AI, with sandboxes and adaptive risk mitigation.

SUTRA 4

Fairness & Equity

Inclusive development — "AI for All." Actively test for and reduce bias in training data and outcomes, so AI doesn't create discriminatory results in service delivery.

SUTRA 5

Accountability

Clear allocation of responsibility across the AI value chain, with a graded, risk-proportionate liability approach — the backbone of enforcement.

SUTRA 6

Understandable by Design

Transparency and explainability built in from the start — disclosures, documentation, and explainable-AI design rather than opaque "black boxes."

SUTRA 7

Safety, Resilience & Sustainability

Systems must be safe and robust against failure and misuse, resilient in operation, and sustainable in societal and environmental impact — the counterweight that keeps "innovation over restraint" proportionate and risk-based.

How the sutras are operationalized

  • Six pillars of recommendations: infrastructure, capacity building, policy & regulation, risk mitigation, accountability, and institutions.
  • New institutions: an AI Governance Group (AIGG) to coordinate policy, a Technology & Policy Expert Committee (TPEC) to advise it, and an AI Safety Institute (AISI) for testing, standards, and evaluation.
  • Techno-legal tools: content authentication and provenance (watermarking), an AI incidents database, regulatory sandboxes, and India-specific risk frameworks.

How the sutras map to what you've learned

  • People First → OECD/UNESCO "human oversight & determination"
  • Fairness & Equity → "fairness & non-discrimination"
  • Understandable by Design → "transparency & explainability"
  • Safety, Resilience & Sustainability → "robustness, security & safety" + "sustainability"
  • Accountability → "responsibility & accountability"

The distinctive one is Innovation over Restraint — a deliberate "lightweight," principle-based alternative to the EU AI Act's prescriptive tiers: guidance and existing law first, hard regulation only where evidence demands it.

KNOWLEDGE CHECK

India's distinctive choice

Which sutra most clearly distinguishes India's approach from the EU AI Act's prescriptive, tier-based regulation?

Module eight. India's seven sutras. In November 2025, India's Ministry of Electronics and Information Technology released the India AI Governance Guidelines, anchored in seven guiding principles called sutras, adapted from the Reserve Bank of India's FREE-AI committee report. Sutra one: trust is the foundation — trust is the precondition for AI adoption at scale. Sutra two: people first — human-centric design with human oversight. Sutra three: innovation over restraint — India's distinctive choice to extend existing laws and use sandboxes instead of enacting a standalone AI law. Sutra four: fairness and equity — AI for all, with active bias testing. Sutra five: accountability — clear, graded responsibility across the AI value chain. Sutra six: understandable by design — transparency and explainability built in, not bolted on. And sutra seven: safety, resilience and sustainability — the counterweight that keeps innovation proportionate and risk-based. The guidelines operationalize these through six pillars and new institutions: an AI governance group, an expert committee, and an AI safety institute, plus techno-legal tools like watermarking, sandboxes, and an AI incidents database. Take the knowledge check: which sutra most clearly distinguishes India's path from the EU's?
Module 9 · Industry practice

Common Responsible AI principles & processes across frontier AI companies

Anthropic, OpenAI, Google/DeepMind, Microsoft, Meta, and AWS publish their own Responsible AI frameworks. The vocabulary differs, but a common core has converged — in the principles they commit to, the processes they run, and the artifacts they publish.

Shared principles

  • Safety & reliability — prevent harmful output and misuse (AWS: "Safety"; Microsoft: "Reliability & safety").
  • Fairness — consider impacts on different groups of stakeholders; manage harmful bias.
  • Privacy & security — appropriately obtain, use, and protect data and models.
  • Transparency / explainability — help users understand and evaluate system outputs.
  • Accountability & controllability — mechanisms to monitor and steer AI behavior; clear human responsibility (AWS lists "Controllability" explicitly).
  • Human oversight & societal benefit — human-centered values; broadly distributed benefits.

Shared processes

  • Pre-deployment evaluation & red-teaming — adversarial testing for dangerous capabilities, jailbreaks, and misuse before release.
  • Frontier safety policies — capability thresholds that trigger stronger safeguards before scaling further.
  • Model / system cards — published documentation of capabilities, limitations, and evaluation results.
  • Usage policies & enforcement — acceptable-use rules plus classifiers and monitoring to enforce them.
  • Staged / phased releases — limited rollouts, trusted-tester programs, gradual capability exposure.
  • Alignment & safety training — techniques such as RLHF and constitution-based training to shape model behavior.
  • Impact assessments & incident response — formal templates, bug bounties, and post-incident review.

Named examples — who calls it what

CompanySignature responsible-AI artifacts
AnthropicResponsible Scaling Policy (AI Safety Levels), Constitutional AI training, usage policy, model/system cards.
OpenAIPreparedness Framework, system cards, external red-teaming network, usage policies.
Google / DeepMindAI Principles, Frontier Safety Framework, Secure AI Framework (SAIF), model cards (Google popularized the format), Responsible AI practices site.
MicrosoftResponsible AI Standard v2, Responsible AI Impact Assessment Guide & Template (publicly downloadable), Office of Responsible AI, annual RAI Transparency Report.
MetaResponsible Use Guides for Llama, open safety tooling (e.g. Llama Guard / Purple Llama), Frontier AI Framework.
AWSCore dimensions of responsible AI: fairness, explainability, privacy & security, safety, controllability, veracity & robustness, governance, transparency; AI Service Cards.

Why this matters for you

These company processes are the industrial translation of the OECD/UNESCO principles: red-teaming operationalizes robustness & safety; model cards operationalize transparency; usage policies and monitoring operationalize accountability. When you build with these models or ship your own, you inherit the same pattern: evaluate → document → gate → monitor.

KNOWLEDGE CHECK

Pick the right artifact

A customer asks: "Before we adopt your model, we need a published document describing its capabilities, known limitations, and evaluation results." Which artifact answers this?

Module nine. Common responsible AI practices across frontier AI companies. Anthropic, OpenAI, Google DeepMind, Microsoft, Meta, and AWS each publish their own frameworks, but a common core has converged. On principles, six shared commitments: safety and reliability, fairness, privacy and security, transparency and explainability, accountability and controllability, and human oversight with broad societal benefit. On processes, seven shared practices: pre-deployment evaluation and red-teaming; frontier safety policies with capability thresholds; published model and system cards; usage policies with active enforcement; staged releases; alignment training such as reinforcement learning from human feedback and constitutional AI; and formal impact assessments with incident response. Each company has signature artifacts: Anthropic's Responsible Scaling Policy with AI safety levels; OpenAI's Preparedness Framework; Google's Frontier Safety Framework and Secure AI Framework, plus the model-card format it popularized; Microsoft's Responsible AI Standard and its publicly downloadable Impact Assessment template; Meta's responsible-use guides and open safety tooling like Llama Guard; and AWS's core dimensions, which explicitly include controllability. Remember the pattern these all follow: evaluate, document, gate, and monitor. Take the knowledge check, then continue to the risk landscape.
Module 10 · Risk landscape

Core Responsible AI risks in engineering contexts

AI risk overlaps with — but is not the same as — cyber risk and privacy risk. Engineers need to recognize all three, know the risk domains unique to AI, and see where each risk enters the lifecycle.

Seven AI risk domains (MIT AI Risk Repository)

  • Discrimination & toxicity — unfair discrimination and misrepresentation; exposure to toxic content; unequal performance across groups.
  • Privacy & security — leaking or correctly inferring sensitive information; AI system vulnerabilities and attacks.
  • Misinformation — false or misleading information; pollution of the information ecosystem and loss of consensus reality.
  • Malicious use — disinformation, surveillance and influence at scale; cyberattacks and weapon development; fraud, scams, targeted manipulation.
  • Human–computer interaction — overreliance and unsafe use; loss of human agency and autonomy.
  • Socioeconomic & environmental — power centralization, inequality, devaluation of human effort, governance failure, environmental harm.
  • AI safety, failures & limitations — goal misalignment, dangerous capabilities, lack of robustness, lack of transparency or interpretability.

MIT also classifies each risk by entity (AI / human / other), intent (intentional / unintentional), and timing (pre- vs post-deployment) — useful axes when you log risks in a register.

Risks by lifecycle phase (IBM AI Risk Atlas, condensed)

  • Training & tuning — input — data poisoning, unrepresentative or biased data, personal/confidential info in training data, unclear data usage rights, data transfer restrictions.
  • Inference — input — prompt injection, jailbreaking, prompt leaking, personal or confidential data in prompts, membership/attribute inference attacks, extraction and evasion attacks.
  • Output — hallucination, toxic or harmful output, output bias, exposing personal information, copyright infringement, harmful code generation, unexplainable or untraceable output, over/under-reliance.
  • Non-technical — lack of model/system transparency, incomplete or unrepresentative risk testing, legal accountability, generated-content ownership, impact on jobs, environment, and human agency.

Generative AI amplifies traditional risks (bias, privacy) and adds new ones (prompt injection, jailbreaking, hallucination) — your controls must cover both.

INTERACTIVE 3

Classify the risk: cyber, privacy, AI — or several?

Check every category that applies to each scenario, then verify. Several scenarios belong to more than one category.

ScenarioCyberPrivacyAI
Module ten. Core responsible AI risks. First, separate three overlapping categories: cyber risk, privacy risk, and AI risk. A SQL injection is pure cyber. Online tracking without consent is pure privacy. Bias in an AI recruitment tool is pure AI risk. But AI-powered phishing with deepfakes hits all three at once. The MIT AI Risk Repository organizes AI risk into seven domains: discrimination and toxicity; privacy and security; misinformation; malicious use; human-computer interaction problems like overreliance and loss of agency; socioeconomic and environmental impact; and AI safety failures, including misalignment, brittleness, and lack of interpretability. MIT also tags each risk by entity, intent, and timing — useful columns for your risk register. IBM's Risk Atlas adds the lifecycle lens. At training time: data poisoning, biased or unrepresentative data, and unclear data rights. At inference time: prompt injection, jailbreaking, prompt leaking, and inference attacks. At output: hallucination, toxic content, bias, personal-information exposure, copyright infringement, and harmful code. Plus non-technical risks like incomplete testing and legal accountability. Note that generative AI amplifies traditional risks and adds brand-new ones, so controls must cover both. Now try the classifier: nine scenarios — tick cyber, privacy, AI, or any combination, then check.
Module 11 · Build safely I

Evaluate the use case before you build or ship it

Most AI harm is cheaper to prevent at the use-case evaluation stage than to fix in production. A structured pre-deployment evaluation answers four questions and produces two artifacts: a risk rating and an impact assessment.

The four questions

QuestionHow to answer it
1. Who can be harmed, how badly?Map stakeholders to NIST's harm categories (people / organization / ecosystem). Score each harm on severity × likelihood — a simple 3×3 or 5×5 matrix is enough; consistency matters more than precision. Severity considers reversibility: a wrong movie recommendation is trivially reversible; a wrongly denied loan is not.
2. What are the failure modes?Walk the standard list: hallucination, bias/unequal performance, brittleness on edge cases and distribution shift, prompt injection, misuse by bad actors, overreliance by users, and cascading failures into downstream systems.
3. What tier does it fall in?Use the EU AI Act pyramid as a triage heuristic even outside the EU — anything touching employment, credit, health, education, or law enforcement is high-risk and needs formal impact assessment, documentation, and human oversight.
4. Is AI proportionate here?UNESCO's "proportionality & do no harm": if a simpler, more explainable method (rules, regression, lookup) achieves the aim, prefer it. "We could use an LLM" is not a reason to.

The impact assessment artifact

Record the answers in a structured template — Microsoft's publicly available Responsible AI Impact Assessment Guide & Template is a good starting point: intended uses, stakeholders and potential harms, fitness for purpose, known limitations, failure modes, and mitigations. The completed assessment becomes the review gate: it is what your governance committee approves, and what your auditors (and increasingly, regulators) ask to see. No assessment, no launch.

INTERACTIVE 4

Scenario: triage the feature request

A product manager asks your team to add an LLM feature that auto-summarizes patient discharge notes and recommends follow-up medication schedules, shipping in four weeks to beat a competitor. What is the right evaluation posture?

Module eleven. Evaluating use cases before deployment. Most AI harm is cheaper to prevent at evaluation than to fix in production. Ask four questions. One: who can be harmed and how badly? Map stakeholders to NIST's harm categories and score severity times likelihood — and weigh reversibility: a bad movie recommendation is reversible, a wrongly denied loan is not. Two: what are the failure modes? Hallucination, bias, brittleness on edge cases, prompt injection, misuse, overreliance, and cascading failures downstream. Three: what tier does it fall in? Use the EU AI Act pyramid as a triage heuristic everywhere — employment, credit, health, education, and law enforcement are high-risk. Four: is AI proportionate here? If a simpler, more explainable method achieves the aim, prefer it. Record the answers in an impact assessment — Microsoft's publicly available template is a solid start — covering intended uses, stakeholders, harms, limitations, and mitigations. That document becomes your review gate: no assessment, no launch. Now try the triage scenario: an LLM feature that summarizes discharge notes and recommends medication schedules, due in four weeks. Choose the right posture.
Module 12 · Understand harm

AI harms — naming what can go wrong, for whom, and how badly

Risk is potential; harm is the realized negative impact on real people, organizations, and ecosystems. Before choosing controls, you need a shared vocabulary of harm — three references give you that: ISO/IEC 42005 tells you how to assess impact, the MIT AI Incident Tracker tells you what kinds of harm exist and how severe, and OECD.AI shows you the evidence of harms actually occurring.

ISO/IEC 42005 — the AI system impact assessment standard

Published in 2025 — the how-to companion to ISO/IEC 42001: where 42001 requires impact assessment, 42005 shows how to do it well. Its core moves:

  • Define the scope and context of the AI system
  • Identify affected stakeholders — including vulnerable groups
  • Analyze reasonably foreseeable benefits and harms, including misuse
  • Assess sensitive uses; document the results
  • Feed findings into risk management and design decisions

Think of it as the standardized, auditable version of Module 11's four questions.

MIT AI Incident Tracker — the harm taxonomy

The MIT AI Risk Repository's Incident Tracker (airisk.mit.edu) grades real incidents using a harm taxonomy built on CSET's AI Harm Framework:

  • 10 types of harm — e.g. physical harm, property damage, financial loss, human rights
  • Severity scored 1–5 — from "Negligible" to "Catastrophic"
  • Tangible harm (observable: injury, financial loss, damage) vs intangible (detrimental content, differential treatment, rights, privacy)
  • Harm event (occurred) vs harm issue (could occur) vs near-miss
  • Each incident also tagged by domain & causal taxonomies and EU AI Act risk level
  • Dutch benefits scandal = mixed harm: tangible financial loss + intangible differential treatment

OECD.AI — definitions and real-world evidence

The OECD supplies the internationally agreed vocabulary and the evidence base:

  • AI incident = harm actually caused; AI hazard = could plausibly cause harm
  • Harm categories: physical, psychological, reputational, economic/financial, environmental, human rights, public interest
  • AI Incidents Monitor (AIM) tracks reported incidents worldwide, searchable by industry and harm type
  • Checking AIM for your domain = one of the fastest, cheapest inputs to an impact assessment

Grading a harm: four dimensions

Whatever taxonomy you use, grade each identified harm on: severity (how bad at its worst), reversibility (can the person be made whole — a refund is reversible, a wrongful arrest is not), scale (one user or a population), and vulnerability (are children, patients, or benefit-dependent families among the affected?). High marks on any dimension push the use case up the risk tiers from Module 5 — and demand the stronger controls coming in Module 13.

KNOWLEDGE CHECK

Pick the right reference

Your governance committee asks: "We need standardized, auditable guidance on how to conduct an AI system impact assessment that plugs into our ISO 42001 management system." Which reference answers this directly?

Module twelve. AI harms. Risk is potential; harm is the realized negative impact on real people, organizations, and ecosystems. Three references give you a shared vocabulary. First, ISO/IEC 42005, published in 2025 — the AI system impact assessment standard, and the natural companion to ISO 42001: where 42001 requires impact assessment, 42005 tells you how to do it well. Define scope, identify affected stakeholders including vulnerable groups, analyze foreseeable benefits and harms including misuse, assess sensitive uses, document, and feed the results into risk management. Second, the MIT AI Risk Repository's AI Incident Tracker and its harm taxonomy, built on CSET's AI harm framework. It distinguishes ten types of harm — such as physical harm, property damage, financial loss, and violations of human rights — and scores every incident's impact from one, negligible, to five, catastrophic. Underneath sit two powerful distinctions. Tangible harm is observable and verifiable — injury, financial loss, property damage. Intangible harm is not directly observable — detrimental content, bias and differential treatment, rights violations, privacy. And a harm event, where harm actually occurred, differs from a harm issue, where harm plausibly could occur, with near-misses in between. Remember the Dutch benefits scandal from module two? A textbook mixed harm: tangible financial loss plus intangible differential treatment. Third, OECD.AI — the agreed definitions: an AI incident has actually caused harm, an AI hazard plausibly could; harm categories spanning physical, psychological, reputational, economic, environmental, human rights, and public interests. And the OECD AI Incidents Monitor tracks real incidents worldwide — searching it for your domain is one of the cheapest inputs to any impact assessment. Finally, grade every harm on four dimensions: severity, reversibility, scale, and vulnerability of those affected. High marks on any of them push the use case up the risk tiers and demand stronger controls — which is exactly where we go next. Take the knowledge check first.
Module 13 · Build safely II

Apply controls at four layers: organization, data, model, system

Once a use case is approved, mitigation happens in the build — inside an organizational envelope that applies to every AI system you run. Controls stack in four layers, and the layers back each other up: a bias missed in the data audit can still be caught by model fairness metrics; a jailbreak that beats model training can still be caught by system guardrails; and organization-level policy decides that those checks exist at all. Defense in depth.

ORGANIZATION LEVEL
  • Enterprise AI policy, ethics/steering committee & board oversight
  • Roles, resources & competencies — budget, accountable owners, AI literacy training
  • Defined AI lifecycle processes with stage gates (ideation → development → deployment → monitoring → retirement)
  • Sustainability tracking — CO₂/energy emissions of training & inference workloads
  • Regulatory compliance mapping, vendor/supply-chain governance & internal audits
DATA LEVEL
  • Provenance & usage-rights verification (can we legally use this data for training?)
  • Representativeness & bias audits before training
  • De-identification, anonymization & data minimization
  • Poisoning screening & outlier detection
  • Documented data lineage & versioned datasets
MODEL LEVEL
  • Fairness metrics across demographic groups (e.g. selection-rate parity, equalized odds)
  • Robustness & adversarial testing; red-teaming
  • Safety fine-tuning & alignment training
  • Evaluation benchmarks tracked across versions
  • Model cards; versioned change management for weights, prompts, and hyperparameters
SYSTEM LEVEL
  • Input/output guardrails & content filters
  • Prompt-injection defenses (input sanitization, privilege separation, tool-use allow-lists)
  • Human-in-the-loop for consequential decisions
  • Rate limits, authentication & access control
  • Audit logging of decisions; AI disclosure in the UI

Rule of thumb for placement — run each control through this checklist

  • Applies across the whole company — policy, people, processes, sustainability? → Organization level
  • Acts before training — on datasets, rights, lineage? → Data level
  • Shapes or evaluates the model itself — training, testing, metrics, cards? → Model level
  • Wraps the running application — anything a user or attacker touches at inference? → System level
  • And at every layer: change management — the Air Canada and resume-screening incidents both began with an untracked change.
INTERACTIVE 5

Sort the control to its layer

Assign each of the 15 controls to the layer where it belongs: Organization, Data, Model, or System.

Module thirteen. Controls at four layers: organization, data, model, and system. The layers back each other up — defense in depth — and the organization layer decides that the other three exist at all. Organization-level controls apply across the whole company: an enterprise AI policy with board oversight and an ethics committee; roles, resources, and competencies, including budget, accountable owners, and AI literacy training; defined AI lifecycle processes with stage gates from ideation through development, deployment, monitoring, and retirement; sustainability tracking, including CO2 and energy emissions of training and inference workloads; and regulatory compliance mapping, vendor governance, and internal audits. Data-level controls act before training: provenance and usage-rights verification, representativeness and bias audits, de-identification and minimization, poisoning screening, and versioned data lineage. Model-level controls shape or evaluate the model itself: fairness metrics across groups, adversarial testing and red-teaming, safety fine-tuning, benchmark tracking across versions, model cards, and change management for weights and prompts. System-level controls wrap the running application: input and output guardrails, prompt-injection defenses like privilege separation and tool allow-lists, human-in-the-loop review for consequential decisions, rate limits and access control, audit logging, and AI disclosure in the interface. The rule of thumb: company-wide, organization. Before training, data. Shaping or evaluating the model, model. Wrapping the running app, system. Now sort the fifteen controls into their layers.
Module 14 · Operate safely

Monitoring and escalation in production

Governance doesn't end at launch. NIST's Measure and Manage functions run continuously: track trustworthiness metrics, detect drift and incidents, and escalate through defined paths — this is also the continual-improvement loop at the heart of ISO 42001.

What to monitor — five signal families

  • Quality & drift — accuracy against golden sets; input distribution shift; degradation after upstream changes (data pipelines, libraries, prompts, model versions).
  • Safety signals — guardrail trigger rates, jailbreak attempts, toxic-output flags, refusal-rate anomalies.
  • Fairness in production — outcome parity across user segments on live traffic, not just in offline tests.
  • Usage & misuse — anomalous access patterns, policy-violating prompts, scraping or extraction attempts.
  • Human factors — override rates, user complaints, appeal volume. A rising override rate is one of the earliest warnings a model has drifted.

Escalation design — six elements

  • Thresholds & ownership — every metric has a numeric threshold and a named owner. "Everyone's problem" means no one's problem.
  • Tiered response — auto-mitigation (filter, fallback, safe mode) → on-call engineer → AI risk/ethics committee for systemic issues.
  • Kill switch & rollback — the ability to disable a model or revert versions quickly, tested like any other disaster-recovery procedure.
  • Incident records & review — log AI incidents like security incidents: severity, timeline, root cause, corrective action; feed lessons back into evaluations.
  • Change management coverage — monitor the whole pipeline: upstream libraries, prompt templates, and data sources, not only model weights.
  • Regulatory reporting — high-risk systems may carry mandatory incident-reporting duties (EU AI Act; India's guidelines propose an AI incidents database).
INTERACTIVE 6

Scenario: the drifting screening model

Your team runs an AI resume-screening assistant. Monitoring shows that over the last month, the shortlisting rate for one demographic group dropped 18% with no change in applicant quality metrics. The model wasn't retrained, but an upstream resume-parsing library was upgraded. What is the best first response?

Module fourteen. Monitoring and escalation in production. Governance continues after launch — this is NIST's measure and manage functions running continuously, and the continual-improvement loop at the heart of ISO 42001. Monitor five signal families. Quality and drift, including input distribution shift and degradation after upstream changes. Safety signals: guardrail trigger rates, jailbreak attempts, toxic-output flags. Fairness in production: outcome parity on live traffic, not just offline tests. Usage and misuse: anomalous access and policy-violating prompts. And human factors: override rates, complaints, and appeals — a rising override rate is one of the earliest warnings. Escalation needs six design elements. Give every metric a threshold and a named owner. Build a tiered response: automatic mitigation, then on-call engineer, then the AI risk committee. Keep a tested kill switch and rollback path. Record incidents with severity, timeline, root cause, and corrective action, and feed lessons back into evaluations. Extend change management to the whole pipeline — libraries, prompts, and data sources, not just model weights. And know your reporting duties: the EU AI Act mandates incident reporting for high-risk systems, and India proposes a national AI incidents database. Finish with the scenario: a resume screener drifts after a parser upgrade. Choose the best first response.
Module 15 · Assessment

Final quiz

Fifteen questions covering the whole course. You need 70% (11/15) to pass. Choose an answer for every question, then submit.

Module fifteen. The final quiz. Fifteen questions covering everything in this course — the hierarchy, principles, frameworks, industry practices, risks, evaluation, controls, and monitoring. You need seventy percent, that's eleven out of fifteen, to pass. Take your time, answer every question, and press submit when you're ready. Good luck.
Complete

You've finished the course

AramGRC
THE AI ASSURANCE PLATFORM
CERTIFICATE OF COMPLETION

This is to certify that

has successfully completed the course

AI Governance 101

Principles · Frameworks · Industry practice · Risk & harm evaluation · Engineering controls · Production monitoring

Date: —

Sakthi Thangavelu
Sakthi Thangavelu
Co-Founder, AramGRC — AI Assurance Platform and Consulting

Download your certificate

Click the button below and a JPG image of your certificate — with your registered name and today's date — will be saved to your device (usually the Downloads folder; on mobile, check your gallery or Files app). You can then print it, attach it to your CV, or share it on LinkedIn.

If no file appears in Downloads, your certificate will be shown below — right-click it (desktop) or press-and-hold it (mobile) and choose "Save image as…" / "Save to Photos".

Where to go deeper

  • OECD.AI Policy Navigator — 1,000+ national AI policies and strategies across 80+ jurisdictions.
  • NIST AI RMF 1.0 and its Playbook — the Govern / Map / Measure / Manage functions in detail.
  • ISO/IEC 42001 — the AI management-system standard, in the same family as ISO 9001 and 27001.
  • India AI Governance Guidelines (MeitY, Nov 2025) and the RBI FREE-AI Committee Report — the 7 Sutras in full.
  • MIT AI Risk Repository and IBM AI Risk Atlas — comprehensive risk taxonomies.
  • Microsoft Responsible AI Impact Assessment Guide & Template — a ready-to-use evaluation process.
  • NASSCOM Responsible AI Resource Kit — governance framework, maturity assessment, and architect's guide.
  • UK AI Standards Hub and AI Security Institute — standards tracking and safety research.
Congratulations — you've completed AI Governance 101. You can now describe the OECD and UNESCO AI principles and India's seven sutras, compare responsible AI practices across frontier companies, identify core AI risks, interpret the major frameworks, evaluate use cases before deployment, apply data, model, and system level controls, and design monitoring and escalation for production. To go deeper, explore the OECD policy navigator, the NIST AI RMF playbook, ISO 42001, India's AI governance guidelines, the MIT AI risk repository, and Microsoft's impact assessment template. Your certificate is on this screen, made out in your registered name and signed by the course designer — press the download button to save it as a JPG image to your device, then print it or share it on LinkedIn. One more screen after this: a thank-you from the team behind this course.
Thank you

Thank you for learning with us

BROUGHT TO YOU BY

AramGRC

AramGRC helps organizations build and prove trustworthy AI — AI governance consulting, ISO/IEC 42001 implementation and audits, corporate training, and privacy & information-security programs — led by practitioners who audit and implement these frameworks every week.

Consult

AI governance programs, AIMS (ISO 42001) implementation, risk & impact assessments, privacy and infosec advisory.

Audit

ISO 42001 internal audits and certification-readiness, with certified lead auditors.

Train

Lead Implementer / Lead Auditor batches, executive masterclasses, and courses like this one — tailored to your teams.

Reach out

Web: www.aramgrc.com
Email: Sakthi@AramGRC.com  ·  Anand@AramGRC.com

Questions about this course, ISO 42001 certification, or setting up an AI governance program? We'd love to hear from you.

Thank you for learning with us. This course was brought to you by AramGRC — helping organizations build and prove trustworthy AI through AI governance consulting, ISO 42001 implementation and audits, corporate training, and privacy and information-security programs, led by practitioners who implement and audit these frameworks every week. To continue the conversation — whether about this course, ISO 42001 certification, or setting up your AI governance program — visit www dot aram G R C dot com, or write to Sakthi at aram G R C dot com, or Anand at aram G R C dot com. We'd love to hear from you. Goodbye, and govern well.