Skip to main content

Certified AI Governance Professional (CAIGP): every lesson, free to read

All 98 lessons, in the order they are taught, each with its full lesson and the chance to prove you understood it. Reading is free. Being able to show it is what the program is for.

Taking Command

  1. Why decisions, not information, will make you the expertThe scarcity moved
  2. Meet your systems: mapping the AI your own organization already runsYou cannot govern what you cannot see
  3. Your command tools: the Briefcase, the professor, the dossier you will buildThree tools, carried all program
  4. The first decision: your 90-day AI priorities memo for your own organization (and why you will revise it in shame later)The memo is your first command act

Build Before You Govern

  1. Train a model with your own hands and watch what it actually learnsA model learns exactly what its data and objective make it learn
  2. Where the bias came from: tracing a bad prediction to its dataA bad prediction is a symptom, not the disease
  3. Fixing the model, breaking it again: why fixes are never freeThere is no local edit to a model
  4. Prompts, context, and why the same model gives different companies different answersThe model is shared; the behavior is yours
  5. What a model cannot know: hallucination produced on demand, then caughtHallucination is structural, not a bug
  6. The license to govern: explaining to a skeptic exactly how your model failsThe failure account is the license

Data Reality

  1. Auditing your own data: provenance, gaps, and quiet poisonThree distinct problems, three distinct fixes
  2. Consent archaeology: what this data was collected for versus what you want to doThe governing question is permission, not possession
  3. The retention decision: what you must keep, what you must destroy, and proving bothRetention is a decision, not a default
  4. Synthetic data: when it saves you and when it launders a biasSynthetic data is a tool with two opposite faces
  5. Third-party data and the vendor claims you must verify yourselfYou inherit the liability, not the excuse
  6. The provenance file: your data map an auditor could followThe provenance file is the followable map

Shipping AI and Surviving the Incident

  1. Scoping the deployment: what your organization actually needs versus what the demo showedA demo is a performance, not a proof of fitness
  2. Build, buy, or wrap: the decision framework with your organization's real budgetThree options, one accountability
  3. The vendor interrogation: questions that expose what the sales deck hidesThe deck is edited truth, not lies
  4. Shipping the feature: rollout, monitoring, and the rollback you hope not to useShipping an AI feature is a governance act, not an engineering event
  5. The 2 a.m. incident: your system fails live, stakeholders are calling, run the responseAn incident is a role you step into, not a mood you fall into
  6. The post-incident review: what you missed, written without blaming the toolA post-incident review is understanding plus change, and it is none of the three documents it is often confused with
  7. Telling the customer: the disclosure decision and the words you actually sendDisclosure is a decision, not a reflex
  8. The AI contract: the clauses that protect you when the vendor's model failsThe contract is where your Module 3 judgments become enforceable, or fail to
  9. The First 48 Hours of an AI IncidentThe first hour and the next forty-seven are different jobs

Evaluation and Trust

  1. Distrust is a skill: why demos convince and evals do not lieA demo answers "is it possible?" and nothing more
  2. Building the eval suite that would have caught your Module 3 incidentAn eval suite is not a demo, a unit test, or a benchmark
  3. Red-teaming your own system: attacks a motivated user will findEvaluation and red-teaming are different jobs
  4. The trust boundary: what this system may decide alone and where a human signsA trust boundary is an explicit, per-decision line, not a slogan
  5. Model drift: detecting the quiet degradation nobody reportsTrust is a rate, not a fact
  6. The evaluation report: evidence that your trust levels are earned, not hopedAn evaluation report is a decision, not a score
  7. Independent Challenge: The Second Line Reads the ModelAn independent challenge is a structured, adversarial re-examination, not a second glance
  8. The Model Inventory and Tiering That Survives an ExaminerAn examiner asks for the inventory before any single evaluation report

The EU AI Act: The Executive Map

  1. The two gates: is it an AI system, and does the Act apply to your organization at allApplicability is two gates, run in order
  2. Article 4 executed: the literacy program you must actually stand up, with evidenceArticle 4 is the EU AI Act's first live obligation, and it is about people, not paperwork
  3. Risk classification: which of your organization's systems is high-risk and proving whyClassification is the hinge of the whole Act
  4. The hiring-AI problem: bias audits, notices, and the law already watching hiring AIHiring AI is the most-watched AI you run
  5. GPAI upstream: what your foundation-model vendor owes you and what you must verify yourselfYou cannot govern the vendor's model, only the seam between you
  6. The conformity file: assembling the evidence for the system you shipped in Module 3The file is assembled, not authored
  7. Answering a regulator's letter: responding with documents, not assurances, anchored to real enforcement patternsDocuments, not assurances

The World's Rulebooks

  1. The US mosaic: federal signals, state laws, and the agencies that already reach workplace AI"No federal AI law" is true and nearly irrelevant
  2. NIST AI RMF as an operating system: mapping your organization onto govern, map, measure, manageThe framework is an operating system, not a checklist
  3. ISO/IEC 42001: standing up an AI management system without drowning in itISO/IEC 42001 is the certifiable shell
  4. China, the UK, and the divergence problem: one product, three rulebooksOne product is never one legal thing
  5. Standards versus law: what certification buys you and what it never willThe test is "who can punish me for ignoring it."
  6. The cross-border decision: where your organization may ship its AI feature, defended with citationsThe cross-border decision is the module's payoff
  7. The Singapore stack: voluntary on paper, adopted in practiceVoluntary and adopted are not opposites
  8. MAS runs the hardest AI regime in APAC, and it has never been a lawA guidelines-based regime is not an optional regime
  9. ASEAN is not one market: the regional HQ problemTen states endorsing one guide does not create one regional law
  10. The one-document lab: one AI system, three regimes, zero duplicate workThe crosswalk is the second payoff of Module 6
  11. Evidence Standards for Policy ClaimsGrade the claim, not the confidence of the sentence carrying it

Agents Under Command

  1. What changes when the AI acts instead of answers: the agent risk modelAn agent is a system whose decisions become effects with no human in between
  2. Permissioning an agent: tools, budgets, and the actions it may never take aloneAn agent is a model that acts through tools, and its permission set is what it can actually do
  3. The oversight pattern: human-in-the-loop, on-the-loop, and out-of-the-loop, chosen per task with reasonsThree patterns, defined by when the human can act
  4. The agent audit trail: logging actions so you can reconstruct any decision it madeThe audit trail is defined by one test: reconstruction
  5. You deploy an agent: scoping, containment, and the kill switch you test before launchAn agent is the one system you must be able to stop
  6. The runaway afternoon: your agent misbehaves in a loop, contain it liveA runaway loop is a self-reinforcing sequence, not a single bad output
  7. Agent governance policy: the one-page rules for every agent your organization runsSix controls are a toolbox; the policy is what makes them law
  8. Map your agent policy to the world's first agentic frameworkGrade the policy you have; do not rebuild it from zero

The Money: Budgets, ROI, and Risk

  1. The honest ROI: measuring what the AI actually changed at your organization, not what the vendor promisedThe vendor's number is a sales artifact
  2. The cost nobody budgets: verification, oversight, and the supervision taxThe supervision tax is the recurring human cost of keeping an AI system safe to use
  3. Build, buy, or kill: the quarterly portfolio review with real numbersA portfolio review judges every system together, on a schedule
  4. Insuring the risk: what AI liability coverage exists, what it excludes, and what that tells youAn exclusion is a free risk assessment
  5. The hostile board: defending your AI budget to directors who interruptA defensible decision is not the same as a delivered defense
  6. The investment memo: one page that survives a CFOThe memo is where governance meets money
  7. The Ten AI Clauses and What Each One MovesA contract clause always has a beneficiary
  8. Continuity When the Model Goes DownEvery AI-dependent process has a default continuity plan already, whether anyone wrote it down or not

The Humans: Leading People Through AI Change

  1. The workforce map: which roles in your organization change, which grow, and which endA role is a bundle of tasks, and that is the unit of analysis
  2. The hard conversation: telling a 20-year employee their role is transforming, roleplayed until it is humane and clearThe conversation is a governance act, not a soft skill
  3. Resistance is information: what the sales team's quiet refusal is telling youResistance is a data source, not an obstacle
  4. The literacy rollout: training 400 people who did not ask for thisA rollout changes behavior; it does not deliver information
  5. The union question, the works council, and consultation done rightInvolving the workforce is a ladder, not a step
  6. The change narrative: why we are doing this, in words a warehouse shift believesThe change narrative is a governance artifact, not a communications product
  7. The Working Group That Outlives Its FounderA working group is four written design decisions, not a calendar invite with a name
  8. Influence Without Authority: The Governance Analyst's ToolkitBeing right and being heeded are different skills

Evidence Engineering

  1. Evidence is designed, not gathered: building systems whose proof exists before anyone asksEvidence is designed, not gathered
  2. The logging architecture: what your organization's systems must record, for whom, for how longEvidence is designed into the system as a logging architecture
  3. Model cards and system cards for your own systems, written so an outsider could act on themTwo cards, two jobs
  4. The DPIA and FRIA, run jointly: one assessment, two regimes, no duplicate workOne investigation, two sign-offs
  5. Who owns the output: IP, training-data provenance, and the liability chain when AI work goes wrong"Who owns the output" is three questions, not one
  6. The evidence annex: wiring every artifact so the Module 13 audit finds a paper trail, not a scrambleThe side with the paper trail wins
  7. Designing a Control That Can Be TestedA control has to be able to fail, or it is not a control
  8. Operating-Effectiveness Testing: The Sample, the Exception, the FindingDesign effectiveness and operating effectiveness are two different claims

Adversarial Governance

  1. Your conformity file under attack: the red team finds what you missedA file that has never been attacked is an essay
  2. Defending the file: the live challenge and the amendments you concedeEvery challenge sorts into defend, concede, or check
  3. Attacking to learn: you red-team a governance file and discover how thin most areExecute the file, do not debate it
  4. Incident forensics: reconstructing a failure from logs when memories disagreeReconstruct from records, do not adjudicate memories
  5. The whistleblower memo: what you do when the report is about your own projectWhen the report is about your own project, run the honest evaluation anyway
  6. Governance that survives: rebuilding the file so the next attack finds lessA patch closes the hole; a rebuild closes the reason the hole existed

Staying Current: The Frontier Discipline

  1. Reading the primary source: a model card, a system card, and what they do not sayThe card is a primary source written by an interested party
  2. Reproducing a claim: testing a vendor benchmark yourself in an afternoonA benchmark score is a claim, not a fact
  3. The weekly frontier hour: a sustainable practice for staying current for a careerStaying current is a duty, not a hobby
  4. Separating signal from theater: which AI news changes your decisions and which is noiseThe whole test is one question
  5. Your successor's briefing: documenting your organization's AI estate so command can transferA running estate is not a governed estate

The Capstone: The Board Audit and Viva

  1. Assembling the dossier: every artifact, every decision, one evidence fileA dossier is a structured argument; a folder is a pile
  2. The board inspection: the seven-seat AI board audits your organization end to endThe board inspects evidence, not adjectives
  3. The viva: defending your command live against the examinerThe viva tests command, not knowledge
  4. The handover: what you now know that no essay could have taught you, and where you take itThe handover is the topic where your work stops being about you