Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Microsoft

Governance and Compliance Management

Microsoft via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
This course covers the foundational governance and compliance tasks every AI program leader needs to perform. You’ll assign AI governance accountability using a RACI matrix, benchmark existing policies against Microsoft’s Responsible AI Standard v2, manage a live remediation backlog, apply ISO/IEC 42001 controls, assess audit evidence for SOC 2 readiness, author AI security policy, and evaluate policy exception requests—giving you full coverage of the governance and compliance lifecycle. Familiarity with foundational frameworks such as the NIST Cybersecurity Framework, ISO/IEC 27001, and privacy regulations such as GDPR will provide useful context, though formal certifications in these areas are not required. By the end of the course, learners can evaluate governance maturity, align AI systems with recognized standards, communicate audit readiness, and produce governance documentation suitable for executive review, regulatory scrutiny, and organizational deployment. This course is designed for AI program leaders, governance and compliance professionals, IT security leaders, and enterprise architects responsible for establishing or maturing AI governance in regulated environments.

Syllabus

  • AI RACI: Assign Governance Accountability for an LLM Deployment
    • This module introduces the AI Governance RACI matrix as a practical accountability tool, walking learners through how to assign and validate roles across executive leadership, model owners, and audit functions in the context of an Large Language Model (LLM) rollout—and how to prepare the completed matrix for stakeholder sign-off.
  • Governance Gap: Analyze Policy Gaps Against the Responsible AI Standard v2
    • This module guides learners through a structured AI governance gap analysis process. Using the Microsoft Responsible AI Standard v2 as the benchmark, learners evaluate existing information security policies, identify misalignments or deficiencies, and translate findings into a prioritized remediation backlog. The resulting backlog serves as a governance artifact used to support audit readiness and policy alignment across AI systems.
  • Governance Gap: Evaluate KPIs and Recommend Charter or Operating Model Adjustments
    • This module develops learners' ability to interpret AI governance program health through KPI dashboards and translate quantitative trends into actionable charter or operating model recommendations—a critical skill for communicating governance status to senior leadership and program steering committees.
  • ISO 42001: Map Controls to an AI System and Update the Compliance Matrix
    • This module introduces the ISO/IEC 42001 AI management system standard and demonstrates how governance teams translate its control requirements into operational compliance documentation. Learners will map relevant ISO 42001 controls to a specific AI system by identifying where each control applies across the system's lifecycle, assessing the current implementation status (implemented, partially implemented, or not implemented), and documenting the results within a compliance control matrix. The resulting matrix becomes a core governance artifact used to track control coverage, identify compliance gaps, and support internal assurance reviews and external certification audits. By the end of the module, learners will understand how structured control mapping transforms ISO requirements into actionable governance documentation that supports both AI system oversight and audit readiness.
  • SOC 2 Audit: Inspect and Link Evidence to Controls
    • This module develops learners' ability to evaluate the quality, completeness, and traceability of audit evidence and map it to SOC 2 Security and Confidentiality Trust Services Criteria. Learners will assess whether provided evidence sufficiently supports control operation, identify gaps or insufficiencies, and determine whether controls can be considered effectively implemented in preparation for an external audit. By the end of the module, learners will be able to inspect audit artifacts and flag evidence deficiencies before formal auditor review, reducing the risk of late-stage audit findings.
  • SOC 2 Audit: Evaluate Drift and Brief Leadership on Readiness
    • This module builds applied evaluation skills for SOC 2 audit readiness. Learners interpret compliance drift findings — where previously effective controls have degraded due to process, system, or ownership changes — and assess their impact on audit readiness. Learners then translate these findings into an executive briefing that supports a clear pass/fail (go/no-go) recommendation for an upcoming SOC 2 audit. The focus is on converting technical audit findings into clear, decision-oriented leadership communication.
  • AI Security Policy: Understand the Framework and Policy Structure
    • This module builds the foundational understanding needed to draft an AI security policy section. Learners explore how AI security policy differs from traditional IT security policy, how ISO/IEC 42001 clauses—along with EU AI Act Article 15 obligations and OWASP LLM Top 10 2025 risk categories—inform policy structure, and how corporate policy templates are organized to support CISO-level review and governance approval. The focus is on understanding policy structure, standards alignment, and template design patterns that enable consistent and audit-ready AI governance documentation in later applied modules.
  • AI Security Policy: Draft and Prepare for CISO Approval
    • This module transitions learners from foundational understanding to applied policy development. Learners use a structured corporate policy template to draft an AI Model Security and Monitoring policy section, ensuring alignment with ISO/IEC 42001 clauses, EU AI Act Article 15 cybersecurity obligations, and OWASP LLM Top 10 2025 risk categories and enterprise governance requirements. Learners then self-check the draft against these frameworks before submission. The resulting artifact must be suitable for CISO submission, meaning it is structured, enforceable, and traceable to recognized AI governance standards.
  • Policy Exceptions: Understand the Exception Review Framework
    • This module introduces the policy exception review framework—covering what exception requests are, how risk is assessed against policy requirements, and what a well-structured ServiceNow exception ticket looks like before a reviewer makes an approve or deny decision.
  • Policy Exceptions: Evaluate and Document Exception Decisions
    • This module applies the policy exception review framework in a realistic governance workflow. Learners evaluate two ServiceNow-based policy exception requests submitted by product teams, assess each request using structured risk criteria, and determine whether to approve, deny, or escalate the exception. For each case, learners must document a clear and defensible rationale that reflects governance standards for risk evaluation, compensating control assessment, and alignment with policy compliance. The final output simulates real-world exception decision records used in security and AI governance programs.
  • Project Module: AI Governance & Compliance Portfolio Piece
    • In this capstone project, learners produce a portfolio-ready AI Governance and Compliance artifact—a consolidated governance deliverable that integrates accountability, compliance mapping, policy development, and exception management work. The final artifact reflects the type of governance documentation package an AI program lead or security governance manager would assemble when establishing or maturing an organizational AI governance program. Learners will synthesize governance role definitions, compliance control mapping, policy documentation, and exception review frameworks into a single structured deliverable aligned with recognized governance standards such as ISO/IEC 42001 and audit frameworks such as SOC 2. The completed portfolio piece demonstrates the learner's ability to translate governance principles into operational documentation suitable for internal leadership review, audit readiness, and program implementation.

Taught by

Microsoft

Reviews

Start your review of Governance and Compliance Management

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.