NIST AI Risk Management Framework Implementation Training Course
| Course code | SD-AI-011 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Artificial Intelligence |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
AI systems create risks that cannot be managed through cybersecurity controls, model accuracy testing, or policy statements alone. Organisations need a repeatable way to identify harmful uses, establish accountability, test models before release, monitor live performance, and act when impacts emerge. The NIST AI Risk Management Framework (AI RMF) provides that structure, but teams often struggle to translate its Govern, Map, Measure and Manage functions into operating controls, evidence, owner assignments, and decision gates for real AI products.
This five-day course teaches participants to implement the NIST AI RMF 1.0 across the AI lifecycle. Participants map AI system context, intended use, affected stakeholders, and impact pathways; build risk registers using socio-technical risk categories; define measurable trustworthiness criteria; select validation and monitoring methods; and design treatment plans with clear escalation routes. The course connects the AI RMF Core and Playbook to practical governance artefacts, including AI system inventories, impact assessments, model documentation, control matrices, test evidence packs, and residual-risk acceptance records.
Instructor-led briefings are paired with workshops based on a realistic AI-enabled decisioning case. Teams work through discovery, risk prioritisation, measurement design, control selection, and governance review using structured templates. Each participant leaves with an implementation pack for one AI use case: a mapped AI risk profile, a draft AI impact assessment, a control and evidence matrix aligned to the AI RMF, and a 90-day implementation roadmap that can be taken to risk, legal, data, engineering, or executive stakeholders.
The course suits professionals responsible for governing, building, assuring, procuring, or approving AI systems in regulated, customer-facing, or high-impact settings. It is particularly valuable where organisations need to demonstrate that AI risk decisions are traceable, proportionate, and supported by evidence.
Course objectives
By the end of this course, participants will be able to:
- Interpret the NIST AI RMF Core and Playbook to define Govern, Map, Measure and Manage activities for an AI use case
- Construct an AI system inventory entry that records intended use, model dependencies, users, affected groups and deployment context
- Facilitate an AI risk mapping workshop using impact pathways, stakeholder analysis and socio-technical risk categories
- Produce an AI risk register with likelihood, severity, uncertainty, risk owners, treatment actions and residual-risk decisions
- Define measurable trustworthiness criteria for validity, reliability, safety, security, privacy, explainability, fairness and accountability
- Design a model testing and monitoring plan with performance thresholds, drift indicators, bias tests and escalation triggers
- Build a control-to-evidence matrix that links AI RMF activities to policies, technical controls, review records and assurance evidence
- Present a phased NIST AI RMF implementation roadmap with governance roles, decision gates, priorities and 90-day actions
Benefits of attending
For you
- Gain a practical method for converting responsible AI principles into risk controls, evidence requests and owner actions
- Build credibility to lead AI risk workshops with data scientists, legal teams, product managers and senior risk owners
- Learn to challenge AI project proposals using traceable questions about context, impacts, measurement and residual risk
- Create reusable templates for AI inventories, impact assessments, control matrices and monitoring plans
- Position yourself for AI governance, responsible AI, model risk, technology assurance and digital risk responsibilities
For your organisation
- Establish a consistent NIST AI RMF-based process for assessing AI use cases before development, procurement or deployment
- Reduce unmanaged harm, compliance exposure and reputational risk through documented testing, monitoring and escalation controls
- Improve investment decisions by distinguishing low-risk automation from AI uses requiring enhanced governance and approval
- Create auditable evidence linking AI policies and trustworthiness commitments to operational controls and review records
- Give cross-functional teams a shared vocabulary for decisions involving model risk, stakeholder impacts and risk acceptance
Target competencies
Who should attend
- AI Governance Managers — who must establish accountable controls and evidence for organisation-wide AI use
- Data Science and Machine Learning Leaders — who need to embed risk testing and monitoring into model delivery practices
- Risk and Compliance Managers — who must assess AI-specific operational, regulatory and conduct risks
- Responsible AI and Ethics Leads — who translate fairness, transparency and human oversight principles into implementable controls
- Product Owners and Digital Transformation Managers — who approve AI use cases and need defensible release criteria
- Internal Auditors and Technology Assurance Specialists — who evaluate whether AI governance controls are designed and operating effectively
Requirements and prerequisites
Participants should have working experience with at least one AI, machine learning, analytics, automation, or digital product initiative. Familiarity with basic concepts such as training and test data, model outputs, data quality, model performance metrics, human-in-the-loop review, and operational risk is assumed. Experience reading policies, risk registers, control frameworks, or project documentation is helpful. Participants should bring a laptop capable of opening spreadsheets and PDF documents, plus a non-confidential AI use case if available. Coding, advanced statistics, model development experience, legal qualifications, and prior NIST certification are not required.
Training methodology
The course combines focused instructor-led teaching on the NIST AI RMF with guided analysis of an AI-enabled decisioning case. Participants use AI RMF Core and Playbook prompts to map context, identify affected stakeholders, score risks, set measurement criteria, and choose controls. Small-group workshops simulate challenge sessions between product, data science, risk and compliance functions. Each day adds an artefact to an implementation pack. On day five, participants review their pack against governance expectations and convert it into a prioritised 90-day action plan for a live or representative AI use case.
Course outline
Day 1: NIST AI RMF foundations and governance design
- NIST AI RMF 1.0 purpose, scope and voluntary risk management model
- The Govern, Map, Measure and Manage function structure
- AI lifecycle stages from use-case intake to retirement
- Trustworthy AI characteristics and their practical trade-offs
- AI governance roles, accountability models and decision rights
- AI policy, standards and procedures hierarchy
- AI system inventory fields and use-case classification criteria
Workshop: Participants create an AI system inventory entry and a draft RACI for a selected AI use case.
Day 2: Mapping context, stakeholders and impacts
- System context mapping for intended use, users and operating environment
- Intended use, foreseeable misuse and prohibited-use analysis
- Stakeholder identification including directly and indirectly affected groups
- Impact pathway mapping from data and model decisions to real-world outcomes
- Data provenance, representativeness and dependency mapping
- Socio-technical risk identification using AI RMF Map categories
- AI impact assessment scope, assumptions and documentation requirements
Workshop: Teams conduct an AI RMF Map workshop and produce a stakeholder-impact map with prioritised risk scenarios.
Day 3: Measuring trustworthiness and assurance evidence
- Operationalising validity, reliability, safety and resilience criteria
- Fairness testing approaches and subgroup performance analysis
- Explainability, transparency and user disclosure requirements
- Privacy, security and data governance measurement considerations
- Human oversight design and automation-bias safeguards
- Model validation evidence, test records and independent challenge
- Key risk indicators, thresholds and measurement limitations
Workshop: Participants design a measurement plan that specifies tests, metrics, thresholds, evidence sources and accountable reviewers.
Day 4: Managing AI risks through controls and monitoring
- AI risk register construction and inherent-risk assessment
- Risk treatment options: avoid, mitigate, transfer, accept and retire
- Preventive, detective and corrective AI control design
- Pre-deployment release gates and residual-risk acceptance
- Production monitoring for performance drift and data drift
- Incident response, user feedback and post-deployment review
- Control-to-evidence matrices and audit trail design
Workshop: Teams build a risk treatment plan and control-to-evidence matrix for the highest-priority risks in their case.
Day 5: Implementation roadmap and executive assurance
- AI RMF implementation maturity assessment and gap analysis
- Prioritising controls by impact, feasibility and risk reduction
- Integrating AI RMF activities into product delivery and procurement workflows
- Third-party AI supplier due diligence and contractual evidence requests
- Alignment considerations for ISO/IEC 42001 and the NIST Privacy Framework
- Executive reporting dashboards and risk acceptance packs
- Ninety-day implementation planning and change management actions
Workshop: Participants assemble and present an AI RMF implementation pack containing their risk profile, control matrix and 90-day roadmap.
Tools & standards covered
NIST AI Risk Management Framework 1.0, NIST AI RMF Playbook, NIST Privacy Framework, ISO/IEC 42001:2023
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
05 – 09 Oct 2026Book
Cape Town · USD 4,200 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Dubai · USD 4,500 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Kigali · USD 3,500 -
19 – 23 Oct 2026Book
Mombasa · USD 3,200 -
02 – 06 Nov 2026Book
Live Online · USD 1,500 -
09 – 13 Nov 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Artificial Intelligence
IEEE 7000 Ethical AI System Design Training Course
AI teams are increasingly asked to demonstrate that systems are not only accurate and secure, but also aligned with human values, stakeholde…
Advanced Computer Vision Model Deployment Training Course
Computer vision models that perform well in notebooks can fail under production conditions: camera feeds vary, object sizes shift, latency e…
TOGAF Architecture for Enterprise AI Solutions Training Course
Enterprise AI initiatives frequently stall between proof of concept and production because business sponsors, data teams, security specialis…
ISO IEC 42001 AI Management System Implementation Training Course
Organisations are moving AI systems from experiments into customer service, recruitment, fraud detection, forecasting and decision support, …