AI governance and assurance · Level 4 to 6. Security, risk, compliance, engineering and technology leadership
AI governance and assurance
Tiered access, dual use capability, human control points, and the evidence an auditor will ask for.
- 2modules
- 4.5CPD hours
- 240guided minutes
- Freemodule 1
About this course
Access to capable AI systems has stopped being a single switch and become a set of tiers. Broad access for ordinary work, a verified tier for people whose legitimate work looks exactly like misuse, and restricted tiers negotiated commercially. Anyone responsible for security, risk or engineering needs to understand why that structure exists and what it does and does not grant.
This course teaches the pattern rather than any supplier's version of it, because the names change and the structure does not. It covers dual use capability and why it is gated; verification as an organisational control rather than a personal one; the difference between being permitted to use a capability and being authorised to use it against a particular target; and the controls that have to sit around access before it is safe to have.
The second module is the assurance half: identity binding, scoping, logging and retention, validation of output, the human approval point before anything changes state, and how all of that maps onto the published frameworks an assessor will arrive holding.
What you will be able to do
- Explain why capability access is tiered and what each tier typically grants
- Define dual use capability and give examples from defensive security work
- Distinguish organisational verification from individual authorisation
- Explain why access to a capability is never permission to act on a target
- Specify the identity, scoping, logging and retention controls around access
- Place a human approval point correctly in an automated workflow
- Map controls onto published AI management and risk frameworks
- Describe the evidence an assessor will ask for and where it comes from
Modules
Assessment and certificate
Knowledge check after each module and a final assessment at 80 per cent, with unlimited attempts.
A free digital certificate showing 4.5 CPD hours with a verification code. It evidences knowledge of governance and assurance practice. It does not confer any access, verification status or testing authority, all of which are granted by the organisations that own the systems concerned.
Questions
Why is any capability restricted if the same information is in a textbook?
Because restriction is aimed at scale and speed rather than at secrecy. The concern is not that a technique becomes known but that the effort required to apply it at volume collapses. A control that reduces the number of people who can do something quickly is doing useful work even when it does not reduce the number who could eventually do it at all.
Does a verified tier mean the organisation is trusted to do anything?
No, and this is the most common misreading. Verification establishes that an organisation has a legitimate reason to use a category of capability. It says nothing about any particular piece of work. Whether a given action is acceptable still depends on scope, authorisation from the system owner, and the law that applies where the work is done.
We are a small firm with no governance team. Is any of this proportionate?
The structure scales down further than people expect. A named owner, a written statement of what these tools may and may not be used for, access tied to individual accounts rather than a shared credential, a log that is kept, and a human approving anything that changes a live system. That is five controls and it answers most of what an assessor asks.
Is a human approval step just a formality?
It becomes one if it is designed badly. An approval presented as a single confirmation on a batch of two hundred items, with no way to see what any of them will do, produces consent without understanding. A meaningful control shows the specific change, gives the reviewer the standing to refuse, and records the refusal as readily as the approval.