AI Risk and Regulation Essentials for GRC Engineers

AI Risk and Regulation Essentials for GRC Engineers

38mBeginner2026-07-23

Authors

AJ Yawn

AJ Yawn

Cybersecurity Expert, Founder and CEO at ByteChek

Course details

AI is being deployed across enterprises faster than governance structures can keep up, and regulators are responding with frameworks that professionals are expected to understand and apply. In this course, cybersecurity expert AJ Yawn introduces you to the rapidly evolving intersection of AI and governance, risk, and compliance (GRC), and gives you the foundations you need to navigate the emerging regulatory landscape. Learn what AI is at a high level, why AI governance matters, and why regulations are emerging so quickly. This course covers the three dominant frameworks shaping enterprise AI governance—ISO 42001, NIST AI RMF, and the EU AI Act—and places these topics in the broader context of GRC engineering, so you can connect AI-specific requirements to the compliance processes your organization already runs.

Learning objectives
Explain the fundamentals of AI and how it differs from traditional software in terms of risk.
Define the key requirements and controls of ISO 42001.
Apply the NIST AI Risk Management Framework’s core functions (Govern, Map, Measure, and Manage) to GRC processes.
Navigate the obligations and risk tiers of the EU AI Act.
Operationalize AI governance using practical tools like risk registers, model cards, and CI/CD integration.

Skills covered

AI Governance and ComplianceDeploying and Operating AI SystemsEthics and LawGovernance, Risk, and ComplianceIncident ResponseCybersecurityBusiness Analysis and StrategyOne-Off

Concepts

Introduction

  • Exploring AI risk and regulation for GRC engineers

AI Fundamentals for GRC

  • What is modern AI
  • The AI model lifecycle
  • Why AI is different - Understanding the risk
  • The evolution of GRC engineering and self-assessment

ISO 42001

  • Introduction to ISO 42001
  • Structure and key requirements
  • The controls mindset - Parallels to ISO 27001
  • Organizational impact and certification

NIST AI Risk Management Framework

  • Overview of NIST AI RMF
  • The four core functions - Govern and map
  • The four core functions - Measure and manage
  • Tying NIST AI RMF to continuous assessment

EU AI Act

  • The EU AI Act - A risk-based approach
  • Obligations for high-risk systems
  • Transparency and technical documentation
  • Enforcement and timelines

Implementation and Future Outlook

  • Operationalizing governance - Risk registers and model cards
  • Monitoring and evidence collection
  • Integrating with CI CD pipelines
  • The future of AI regulation - Convergence and outlook
  • The AI governance readiness assessment

Conclusion

  • Next steps
40,000 Toman