Live, Instructor-Led Programme
Cyber GRC & AI Governance
Build practical Cyber GRC and AI governancecapability for real organisations.

12 Weeks
6.5 hrs/week
across two class days
Instructor-Led, Virtual
C$999
Cyber GRC & AI Governance Programme
Master the Skills EmployersAre Hiring For in Cyber GRC & AI
This twelve-week, live online programme combines core cyber governance, risk and compliance practice with responsible AI governance. You'll learn from experienced practitioners, work through realistic organisational scenarios, and leave with an executive-ready portfolio spanning policy, risk, controls and AI oversight.
Practical & Applied
Hands-on exercises, templates and real-world scenarios.
Proven Frameworks
NIST CSF, ISO 27001, NIST AI RMF and ISO/IEC 42001.
Expert Instructors
Learn from practitioners leading GRC and AI governance work.
Peer Collaboration
Discuss challenges and share insights with peers.
Implementation-Ready
Leave with a portfolio of artefacts you can use immediately.
Certificate of Completion
Earn a ReveCyber Certificate upon successful completion.
Cyber GRC & AI Governance Programme
C$999
Instructor-Led, Virtual
12 Weeks
6.5 hrs/week
across two class days
Small class size
Live sessions, not recorded
Have questions?
Our advisors are here to help.
Secure your seat today.
Places are limited.
Practical Work You Will Complete
By the end of the programme, you will build a portfolio of cyber governance and AI governance artefacts you can apply in your organisation.
GovernanceCharter
Security PolicySet
Asset Register &Classification
Control Matrix &Test Evidence
Risk Register &Treatment Plan
FrameworkMapping & GapAssessment
AI Governance &Acceptable-UsePolicy
CapstonePortfolio
A Structured Twelve-Week Learning Journey
- Governance structures, accountability and reporting lines
- Policies and programme documents that support security
- How GRC connects to business objectives
- Communicating security risk clearly to stakeholders
- Building an asset inventory and assigning ownership
- Data classification and handling requirements
- Asset lifecycle from acquisition to disposal
- Linking assets to risk and control coverage
- Administrative, technical and physical controls
- Preventive, detective and corrective control types
- Designing a control matrix
- Control testing and evidence collection
- Threats, vulnerabilities and scenario writing
- Likelihood and impact scoring
- Inherent versus residual risk
- Building and maintaining a risk register
- Treatment options: mitigate, transfer, avoid, accept
- Risk owners, actions and timelines
- Exceptions and risk acceptance
- Management and board-level risk reporting
- Vendor due diligence and questionnaires
- Tiering vendors by criticality and data access
- Contracts, SLAs and security clauses
- Ongoing monitoring and offboarding
- NIST CSF 2.0 functions and profiles
- ISO 27001:2022 and Annex A controls
- Statement of Applicability essentials
- Mapping one control set across frameworks
- SOC 2 trust services criteria foundations
- Compliance gap assessment and prioritisation
- Building evidence packs for auditors
- Remediation planning and tracking
- AI use cases and where AI risk appears
- Shadow AI, bias and privacy exposure
- Roles, ownership and decision rights for AI
- Building an AI use-case inventory
- NIST AI RMF functions in practice
- ISO/IEC 42001 AIMS requirements
- Drafting an AI acceptable-use policy
- Human oversight and approval workflows
- Running an AI risk assessment end to end
- Controls for bias, drift, hallucination and misuse
- AI vendor and model-provider due diligence
- Monitoring, logging and AI incident response
- End-to-end Cyber GRC and AI governance capstone
- Executive-ready presentation and management reporting
- Assembling your artefact portfolio
- Explaining your work confidently in interviews
Designed for professionals leading cyber governance and responsible AI in their organisations.
Career changers, IT and security professionals, and risk, compliance, privacy and audit practitioners.
