Career pathway / Trust and assurance

Responsible AI, Security & Governance

Make risk, privacy, fairness, and assurance part of how intelligent systems get designed, reviewed, and shipped.

Target roles
AI governance lead, security or risk analyst
Learner level
Intermediate
Format
10 business days, online-first cohort
Commitment
6–8 hours each weekday; live sessions in CT
Prerequisites
Familiarity with software or data workflows and a willingness to investigate systems
Certificate
Certificate of pathway completion
A governance practitioner reviewing secure and responsible AI system boundaries

The study plan

Six habits for accountable systems.

Days 01–02

Responsible-AI foundations

Map who is affected, what can go wrong, and who owns the decision.

  • Harms, stakeholders, risk tiers, and governance roles
  • Lifecycle controls from intake through retirement
  • Impact scoping, decision records, and escalation paths

Deliverable: a system impact assessment with risk tier, stakeholders, and proposed controls.

Day 03

Privacy and data governance

Follow data through a system without pretending the source is the whole story.

  • Consent, minimization, provenance, retention, and sensitive data
  • Access controls, purpose limitation, and vendor boundaries
  • Data-flow mapping and practical governance questions

Deliverable: an AI data governance plan with data flows, controls, owners, and open questions.

Days 04–05

Fairness and explainability

Choose measurement and explanation practices that fit the stakes and the people affected.

  • Measurement choices, subgroup analysis, and tradeoffs
  • Interpretability, documentation, and user-facing explanations
  • Data gaps, proxy risk, and what a metric cannot establish

Deliverable: a bias and equity evaluation with subgroup results, limitations, and mitigation options.

Days 06–07

AI application security

Threat-model the seams where models, tools, data, and users meet.

  • Threat modeling, prompt injection, and insecure tool use
  • Data exfiltration, supply-chain risk, and privilege boundaries
  • Adversarial tests, severity, and remediation ownership

Deliverable: an adversarial test suite with findings, severity, and recommended fixes.

Days 08–09

Assurance and compliance operations

Turn responsible practice into evidence another reviewer can inspect.

  • Model and system cards, audit evidence, and vendor review
  • Incident response, change control, and approval records
  • Control mapping without confusing documentation for safety

Deliverable: a control evidence pack with owners, artifacts, gaps, and review cadence.

Day 10

Governance capstone

Evaluate an enterprise AI product from intake through launch recommendation.

  • Risk register, system boundary, and stakeholder review
  • Red-team report, controls, residual risk, and launch conditions
  • Executive recommendation that is clear about uncertainty

Capstone: a risk register, red-team report, control set, and executive recommendation for an AI product.

By the end

Evidence that can withstand review.

You will be able to name affected stakeholders, follow data and permissions, test threats, assess subgroup behavior, and turn findings into an accountable recommendation.

  • 01

    Scope the impact

    Identify affected people, risk tiers, lifecycle controls, and the owners who can act.

  • 02

    Trace the data

    Document provenance, purpose, retention, access, and gaps without overstating certainty.

  • 03

    Probe the boundary

    Use threat models and adversarial tests to investigate tools, prompts, data, and privilege.

  • 04

    Recommend responsibly

    Package evidence, controls, residual risk, and launch conditions for a real decision.

“The strongest part of the review was being able to say what we still did not know.”
Learner noteNadia W. · Risk program manager

Mentor profile

Dr. Imani Brooks

Responsible technology advisor focused on security boundaries, impact assessment, and the operational practice of turning principles into controls.

4.9/5 learner rating640 cumulative learners taught

Before you begin

Quick answers

Is this legal advice or a compliance certification?

No. The pathway teaches practical investigation, documentation, and governance habits through hands-on exercises. It is not legal advice, a regulatory opinion, or a compliance certification.

Can a technical person take this course?

Yes. The course is designed for people working across technical, product, security, data, or risk contexts. You should be comfortable tracing how a system works and asking precise questions.

Related pathways

Assure the systems you build.

Pathway 01 / Build

Generative AI Application Engineer

Learn the application, retrieval, and evaluation patterns that create the boundaries you review.

Explore generative AI →

Pathway 02 / Orchestrate

Agentic AI Automation Engineer

Apply governance and security judgment to agents, integrations, approvals, and workflows.

Explore agentic automation →