Skip to main content

About this course

Regulators and boards now expect banks to govern artificial intelligence with the same rigour as cyber security. This intensive 2-day program (12 contact hours) builds that governance backbone. Working through case studies and hands-on workshops, parti

What you'll learn

  • Understand the convergence of Cyber GRC and AI GRC and regulatory expectations in 2026
  • Apply NIST CSF 2.0, NIST AI RMF, ISO 27001, ISO 42001 and COSO ERM to banking
  • Design governance structures, policies and 3 Lines of Defense for AI
  • Build and maintain an AI Inventory, Risk Register and Impact Assessment
  • Implement and test key controls for data, model, vendor and incident response
  • Prepare Board reports and audit evidence for RBZ, POPIA and external audit

Who should attend

Chief Internal Auditors Internal Audit Managers Risk Officers CISO / InfoSec Compliance Data / AI Leads Senior Management Board Risk Committee

Course curriculum

1. Cyber Meets AI: The New Risk Landscape 3 topics
  • The convergence of Cyber GRC and AI GRC
  • Regulatory expectations for 2026
  • Cyber risk vs AI-specific risks: bias, hallucination, prompt injection, model drift
2. Frameworks That Work 5 topics
  • NIST CSF 2.0 essentials
  • NIST AI RMF: Govern-Map-Measure-Manage
  • ISO 27001 and ISO 42001
  • COSO ERM integration
  • Gap analysis workshop using NIST AI RMF
3. Governance Structures, Policies & 3 Lines of Defense 3 topics
  • Designing AI governance structures
  • AI Use Policy and Acceptable Use Policy - covering Shadow AI
  • Three Lines of Defense for AI systems
4. AI Inventory, Risk Register & Impact Assessment 3 topics
  • Building and maintaining the AI System Inventory
  • Linking AI risks to the Enterprise Risk Register
  • Conducting AI impact assessments
5. Controls Across Data, Models & Vendors 3 topics
  • Key controls for data and models
  • Evaluating third-party AI vendor risk
  • Incident response playbook for cyber + AI incidents
6. Reporting, Assurance & Audit Evidence 3 topics
  • Board-level Cyber & AI Risk Dashboard with KRIs
  • Drafting an Internal Audit work program to test AI governance controls
  • Preparing evidence for RBZ, POPIA and external audit
Go Further

Want a Full Diploma?

Turn your short-course knowledge into an accredited National Diploma with Masc Academy.