Open for Enrolment

Live, Instructor-Led Programme

Cyber GRC & AI Governance

Build practical Cyber GRC and AI governancecapability for real organisations.

Practitioner working on cyber governance and AI risk artefacts

12 Weeks

6.5 hrs/week

across two class days

Instructor-Led, Virtual

C$999

Cyber GRC & AI Governance Programme

Master the Skills EmployersAre Hiring For in Cyber GRC & AI

This twelve-week, live online programme combines core cyber governance, risk and compliance practice with responsible AI governance. You'll learn from experienced practitioners, work through realistic organisational scenarios, and leave with an executive-ready portfolio spanning policy, risk, controls and AI oversight.

Practical & Applied

Hands-on exercises, templates and real-world scenarios.

Proven Frameworks

NIST CSF, ISO 27001, NIST AI RMF and ISO/IEC 42001.

Expert Instructors

Learn from practitioners leading GRC and AI governance work.

Peer Collaboration

Discuss challenges and share insights with peers.

Implementation-Ready

Leave with a portfolio of artefacts you can use immediately.

Certificate of Completion

Earn a ReveCyber Certificate upon successful completion.

Cyber GRC & AI Governance Programme

C$999

Instructor-Led, Virtual

12 Weeks

6.5 hrs/week

across two class days

Small class size

Live sessions, not recorded

Have questions?

Our advisors are here to help.

Secure your seat today.
Places are limited.

Practical Work You Will Complete

By the end of the programme, you will build a portfolio of cyber governance and AI governance artefacts you can apply in your organisation.

GovernanceCharter

Security PolicySet

Asset Register &Classification

Control Matrix &Test Evidence

Risk Register &Treatment Plan

FrameworkMapping & GapAssessment

AI Governance &Acceptable-UsePolicy

CapstonePortfolio

A Structured Twelve-Week Learning Journey

1
  • Governance structures, accountability and reporting lines
  • Policies and programme documents that support security
  • How GRC connects to business objectives
  • Communicating security risk clearly to stakeholders
2
  • Building an asset inventory and assigning ownership
  • Data classification and handling requirements
  • Asset lifecycle from acquisition to disposal
  • Linking assets to risk and control coverage
3
  • Administrative, technical and physical controls
  • Preventive, detective and corrective control types
  • Designing a control matrix
  • Control testing and evidence collection
4
  • Threats, vulnerabilities and scenario writing
  • Likelihood and impact scoring
  • Inherent versus residual risk
  • Building and maintaining a risk register
5
  • Treatment options: mitigate, transfer, avoid, accept
  • Risk owners, actions and timelines
  • Exceptions and risk acceptance
  • Management and board-level risk reporting
6
  • Vendor due diligence and questionnaires
  • Tiering vendors by criticality and data access
  • Contracts, SLAs and security clauses
  • Ongoing monitoring and offboarding
7
  • NIST CSF 2.0 functions and profiles
  • ISO 27001:2022 and Annex A controls
  • Statement of Applicability essentials
  • Mapping one control set across frameworks
8
  • SOC 2 trust services criteria foundations
  • Compliance gap assessment and prioritisation
  • Building evidence packs for auditors
  • Remediation planning and tracking
9
  • AI use cases and where AI risk appears
  • Shadow AI, bias and privacy exposure
  • Roles, ownership and decision rights for AI
  • Building an AI use-case inventory
10
  • NIST AI RMF functions in practice
  • ISO/IEC 42001 AIMS requirements
  • Drafting an AI acceptable-use policy
  • Human oversight and approval workflows
11
  • Running an AI risk assessment end to end
  • Controls for bias, drift, hallucination and misuse
  • AI vendor and model-provider due diligence
  • Monitoring, logging and AI incident response
12
  • End-to-end Cyber GRC and AI governance capstone
  • Executive-ready presentation and management reporting
  • Assembling your artefact portfolio
  • Explaining your work confidently in interviews

Designed for professionals leading cyber governance and responsible AI in their organisations.

Career changers, IT and security professionals, and risk, compliance, privacy and audit practitioners.