This course provides a practical, enterprise-focused approach to managing the risks associated with artificial intelligence systems by applying the NIST AI Risk Management Framework (AI RMF) in real-world environments. Learners examine how AI risk differs from traditional software and cybersecurity risk, and how data, models, users, system context, scale, decision influence, and generative AI can change the risk boundary.
The course shows how to operationalize AI governance by connecting the AI RMF with the NIST Risk Management Framework (SP 800-37), NIST SP 800-53 control thinking, and ISO/IEC 42001. Learners build AI system inventories, classify systems by purpose, impact, scale, and autonomy, map risks to business and security consequences, evaluate controls and evidence, and establish accountable approval, monitoring, and reassessment processes.
Through an evidence-centered running case, learners review the records used to support defensible AI risk decisions, including intake and categorization records, validation and fairness evidence, SSPs, SARs, POA&M items, monitoring and observability records, vendor and security evidence, model lifecycle changes, and ATO-style authorization artifacts. Exercises address bias, drift, explainability, robustness, adversarial threats, supply-chain risk, human reliance, retraining, and continued authorization so that evidence leads to measurable controls and documented decisions.
By the end of the course, participants will be prepared to apply the NIST AI RMF in practice, connect AI-specific risk evidence to enterprise governance and RMF-style authorization, and support continuous, evidence-driven oversight of AI systems throughout their lifecycle.
AI Risk Management: Implementing the NIST AI RMF Training Delivery Methods
AI Risk Management: Implementing the NIST AI RMF Training Information
AI Risk Management: Implementing the NIST AI RMF Training Outline
Chapter 1: The AI Risk Landscape
- AI Adoption and Enterprise Impact
- AI vs. Traditional Software Risk
- AI System Lifecycle
- Scale, Automation, and Data Dependency
- Generative AI and LLM Risk
- Consequences of AI Failure
Chapter 2: AI Risk Frameworks and Governance
- NIST AI RMF Core Functions
- AI RMF and NIST SP 800-37 Alignment
- ISO/IEC 42001 Overview
- AI Governance Structures
- AI Policy and Approval Workflows
- Communicating AI Risk
Chapter 3: AI Risk Mapping and Measurement
- AI System Inventory
- AI System Categorization
- Business and Security Risk Mapping
- AI Risk Measurement Methods
- Risk Ownership and Accountability
- Assessment Findings and Conditional Authorization
Chapter 4: AI Controls, Validation, and Trust
- AI-Specific Risk Identification
- Data Quality and Dataset Risk
- Bias and Fairness Evaluation
- Model Validation and Robustness Testing
- Explainability, Interpretability, and Evidence
- Authorization Evidence and Documentation
Chapter 5: AI Security and Adversarial Risk
- Poisoning and Evasion Attacks
- Model Extraction and Inference Risks
- Model Asset Protection
- AI Supply Chain Risk
- Secure AI Architecture Patterns
- AI Threat Modeling and Response
Chapter 6: AI Monitoring and Program Maturity
- Drift and Performance Monitoring
- AI Observability and Logging
- Retraining and Lifecycle Management
- AI Risk Maturity Models
- AI RMF, ISO/IEC 42001, and Program Sustainment
- Management Review and Continuous Improvement