AI Risk and Regulation Essentials for GRC Engineers
38mBeginner2026-07-23
Authors

AJ Yawn
Cybersecurity Expert, Founder and CEO at ByteChek
Course details
AI is being deployed across enterprises faster than governance structures can keep up, and regulators are responding with frameworks that professionals are expected to understand and apply. In this course, cybersecurity expert AJ Yawn introduces you to the rapidly evolving intersection of AI and governance, risk, and compliance (GRC), and gives you the foundations you need to navigate the emerging regulatory landscape. Learn what AI is at a high level, why AI governance matters, and why regulations are emerging so quickly. This course covers the three dominant frameworks shaping enterprise AI governance—ISO 42001, NIST AI RMF, and the EU AI Act—and places these topics in the broader context of GRC engineering, so you can connect AI-specific requirements to the compliance processes your organization already runs.
Learning objectives
Explain the fundamentals of AI and how it differs from traditional software in terms of risk.
Define the key requirements and controls of ISO 42001.
Apply the NIST AI Risk Management Framework’s core functions (Govern, Map, Measure, and Manage) to GRC processes.
Navigate the obligations and risk tiers of the EU AI Act.
Operationalize AI governance using practical tools like risk registers, model cards, and CI/CD integration.
Learning objectives
Explain the fundamentals of AI and how it differs from traditional software in terms of risk.
Define the key requirements and controls of ISO 42001.
Apply the NIST AI Risk Management Framework’s core functions (Govern, Map, Measure, and Manage) to GRC processes.
Navigate the obligations and risk tiers of the EU AI Act.
Operationalize AI governance using practical tools like risk registers, model cards, and CI/CD integration.
Concepts
Introduction
- Exploring AI risk and regulation for GRC engineers
AI Fundamentals for GRC
- What is modern AI
- The AI model lifecycle
- Why AI is different - Understanding the risk
- The evolution of GRC engineering and self-assessment
ISO 42001
- Introduction to ISO 42001
- Structure and key requirements
- The controls mindset - Parallels to ISO 27001
- Organizational impact and certification
NIST AI Risk Management Framework
- Overview of NIST AI RMF
- The four core functions - Govern and map
- The four core functions - Measure and manage
- Tying NIST AI RMF to continuous assessment
EU AI Act
- The EU AI Act - A risk-based approach
- Obligations for high-risk systems
- Transparency and technical documentation
- Enforcement and timelines
Implementation and Future Outlook
- Operationalizing governance - Risk registers and model cards
- Monitoring and evidence collection
- Integrating with CI CD pipelines
- The future of AI regulation - Convergence and outlook
- The AI governance readiness assessment
Conclusion
- Next steps