AI risk, governance and compliance

For managers, compliance, legal, risk and IT leaders who need to inventory, assess, buy and oversee AI under fast-changing US, state and EU rules.

For: Managers, compliance, legal, risk, IT and policy owners

  • 3 contact hours
  • 9 modules
  • 8 interactives
  • 5 job aids
  • Updated October 11, 2026

What you will be able to do

  • Classify an organization's AI uses into risk tiers based on decisions about people, domain, data sensitivity, exposure and autonomy.
  • Explain the US federal approach to AI (existing laws, 2025-2026 executive orders, OMB memos), the federal-state tension, and when the EU AI Act reaches a US organization.
  • Determine which state, city and sector rules (Colorado, California, Utah, NYC, Illinois, FTC, EEOC, credit, health care, insurance) apply to a given AI use.
  • Design governance structures: roles, an AI inventory, an AI use policy, and alignment with the NIST AI RMF and ISO/IEC 42001.
  • Conduct impact assessments with fairness testing and perform AI vendor due diligence and contracting.
  • Implement meaningful human oversight, post-launch monitoring and AI incident response, and report AI risk to leadership.

Learn how to build an AI governance program that holds up: find every AI use (including features hidden inside software you already own), sort uses into risk tiers, map the federal, state, sector and EU rules each one triggers, assess and test high-risk uses before launch, buy AI responsibly, and oversee it with real human review, monitoring and incident response.

Built for leaders who own AI risk: compliance and risk managers, in-house counsel, IT and security leaders, HR and operations heads, and policy owners. You will work through realistic cases from a retailer, a lender, a health system, an insurer and a software vendor, and practice with a launch simulation, a legal-trigger decision tool and a vendor dilemma.

AI law in the US is moving in two directions at once: federal efforts to limit state AI laws, and new state and city rules that already apply. This course gives you a dated, honest map of where things stand as of October 2026 and a governance approach, built on the NIST AI RMF and ISO/IEC 42001, that works however the law settles.

What you’ll be able to do Monday morning

  1. Start an AI inventory that captures AI features inside existing software, with a named owner for each use.
  2. Apply a one-page tiering rule to your current AI tools and flag any Tier 1 use without an impact assessment.
  3. Check one AI vendor contract for data use limits, model change notice and incident notice.
  4. Ask for the override rate on your highest-risk AI-assisted decision and investigate if it is near zero.
  5. Add an "as of" date to every AI policy and legal summary you own and set a review trigger for law changes.

Curriculum

9 modules · 36 lessons · about 3 contact hours

01What makes AI risk different, and which uses are high risk?Free preview18 min
  1. Why doesn't ordinary IT risk management cover AI?
  2. What are the main categories of AI risk?
  3. How do you tell a high-risk AI use from a low-risk one?
  4. What should a leader do first?
  • Sort activity: Which risk tier does this AI use belong in?

Diagram · In practice checklist · 3-question knowledge check

02How is the US federal government approaching AI?18 min
  1. Is there a comprehensive federal AI law?
  2. How did federal AI policy change in 2025 and 2026?
  3. What is the federal-state tension, and what does it mean for compliance?
  4. How should leaders track a moving target?

Diagram · In practice checklist · 3-question knowledge check

03Which state and local AI laws could apply to you?20 min
  1. Why do state AI laws reach companies headquartered elsewhere?
  2. What does Colorado require now?
  3. What do California, Utah, New York City and Illinois require?
  4. How do you build a state-law map for your organization?
  • Decision tree: Which AI obligations might this use trigger?

Diagram · In practice checklist · 2-question knowledge check

04What do sector regulators expect from AI users?20 min
  1. What does the FTC expect from any business using AI?
  2. What do employment and credit regulators expect?
  3. What do health care regulators expect?
  4. Which other regulators should be on the radar?

Diagram · In practice checklist · 3-question knowledge check

05Does the EU AI Act reach your US organization?16 min
  1. Why can an EU law apply to a US company?
  2. How does the EU AI Act sort AI by risk?
  3. When do the obligations apply, and what are the penalties?
  4. How do US organizations prepare without building two programs?

Diagram · In practice checklist · 2-question knowledge check

06What governance structure does an AI program need?20 min
  1. Who should own AI governance?
  2. What goes into an AI inventory?
  3. What should an AI use policy say?
  4. How do the NIST AI RMF and ISO/IEC 42001 fit together?
  • Spot the issue: Spot the weaknesses in a draft AI policy

Diagram · In practice checklist · 3-question knowledge check

07How do you assess an AI use before and after launch?20 min
  1. What is the difference between a risk assessment and an impact assessment?
  2. What questions should an assessment answer?
  3. How do you test for bias in practice?
  4. How should results be documented and acted on?
  • Branching scenario: Launch day for the pay-later model

Diagram · In practice checklist · 2-question knowledge check

08How do you buy AI responsibly from vendors?18 min
  1. Why is AI vendor risk different from ordinary software risk?
  2. What should you ask vendors before buying?
  3. Which contract terms matter most?
  4. How do you keep overseeing a vendor after signing?
  • Ethics dilemma: The vendor will not share its bias testing

Diagram · In practice checklist · 2-question knowledge check

09How do you oversee, monitor and respond when AI goes wrong?22 min
  1. What does meaningful human oversight look like?
  2. What should you monitor after launch?
  3. How should you respond to an AI incident?
  4. How does it all fit together, and what should leaders report?
  • Spot the issue: Spot the gaps in an AI incident report
  • Self-assessment: How mature is our AI governance?
  • Matching activity: Match the law or framework to what it does

Diagram · In practice checklist · 3-question knowledge check

Final assessment: 29 questions, 80% to pass, then your certificate

Try it now, no account needed

Launch day for the pay-later model

A branching scenario from this course. Your choices are not saved.

Free sample activity

Launch day for the pay-later model

You are the chief risk officer. Your data science team wants to launch a new "buy now, pay later" eligibility model on Monday. It predicts defaults better than the old model.

Inside the course

Practice activities

  • Sort activity1
  • Decision tree1
  • Spot the issue2
  • Branching scenario1
  • Ethics dilemma1
  • Self-assessment1
  • Matching activity1

Job aids you keep

  • AI Use Policy StarterPolicy starter
  • AI Use Intake and Tiering ChecklistChecklist
  • Pre-Launch Verification Checklist for High-Risk AIChecklist
  • AI Vendor Due Diligence WorksheetWorksheet
  • Prompt Sheet for Governance WorkReference sheet

Credit and approval status

Certificate of completion

This course awards a certificate of completion for 3 contact hours of instruction. It is not approved or accredited by any licensing board, state agency, continuing education accreditor or certification body, and it does not award continuing professional education units. Check with your certifying body, licensing board or employer whether this course meets your specific requirement.

Pathways we may pursue include continuing education review with privacy-profession and accountancy CPE sponsors and with a training accreditor. None of these approvals exists today; the course page will show an approval only after it is granted.

Our full approvals list

Questions about this course

Who is this course for?

It is designed for managers, compliance and risk professionals, in-house counsel, IT and security leaders, and policy owners who are responsible for how their organization adopts and oversees AI. It assumes you already know what AI tools are. If you need the basics of safe everyday AI use first, start with our AI Foundations course.

Does this course earn continuing education credit or count toward a certification?

No approval exists today. You receive a certificate of completion for 3 contact hours of instruction. We may pursue continuing education pathways with privacy, accounting and training accreditors, but nothing is approved yet. Check with your certifying body or employer whether they accept this certificate for your requirement.

Is this legal advice for my company?

No. The course explains federal, state and EU AI rules as they stood on 10/11/2026 so you can ask better questions and build a governance program. AI law is changing fast, especially state effective dates and federal preemption efforts. Confirm how any law applies to your organization with qualified counsel before acting.

How long does it take?

Plan on about 3 hours: nine modules of 16 to 22 minutes each with scenarios, a decision tool, a branching launch simulation and knowledge checks, followed by the final assessment of 29 questions. You need 80 percent to pass. You can pause and resume at any point.

Does it cover state AI laws?

Yes, at the level leaders need: Colorado's replaced AI law, California's ADMT and civil rights regulations, Utah's disclosure rules, New York City Local Law 144 and Illinois HB 3773, plus how to build a state-law map. HR-specific detail is covered in our AI in Hiring and HR course.

What will I be able to download?

An AI use policy starter, an intake and tiering checklist, a pre-launch verification checklist for high-risk AI, a vendor due diligence worksheet and a prompt sheet for governance tasks. All are editable starting points to adapt with your legal and compliance teams.

This course is general education and training awareness from CE Courses Hub on AI risk, governance and compliance. It is not legal, medical or professional advice and does not replace your employer's policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.