
AI Governance for Directors Course: Board, Legal and Risk Oversight
A practical online course for directors, board committee members, General Counsel, CEOs, Company Secretaries and senior risk, legal, governance and technology leaders responsible for overseeing AI risk, accountability, reporting and assurance.
AI is now embedded in enterprise platforms, vendor systems, automated decision-making, generative AI tools and emerging agentic workflows. For boards and senior leaders, the central issue is not whether AI is innovative. It is whether the organisation has sufficient visibility, accountability, reporting, escalation and assurance to govern AI within risk appetite and legal obligations.
This course gives directors and senior executives a practical framework for understanding AI in governance terms, asking the right questions of management, assessing whether information flows to the board are adequate, and documenting oversight of AI risk in a disciplined and defensible way.
Key details:
Online and self-paced | Approx. 5 hours | 2 Modules | 12 months' access | Certificate of Completion | Individual and corporate pricing available
Enrol in the Directors Course Request Board or Executive Team Pricing Enquire About a Facilitated Board Briefing
Course Overview
AI adoption is accelerating across every sector. Generative AI is now embedded in everyday tools and business processes, and more autonomous agentic uses are moving from experimentation to deployment. For boards and governing bodies, the central governance risk is not AI in the abstract. It is the gap between the AI the organisation is using, including embedded enterprise tools and vendor-supplied systems, and the visibility, accountability, information flows and assurance evidence needed to govern it responsibly.
AI Governance for Directors: Oversight, Risk and Assurance equips directors, governing body members and senior executives with a practical, board-level approach to oversight of AI and automated decision-making. It is designed for organisations at different stages of maturity, whether the immediate challenge is obtaining visibility over AI use, embedding AI into enterprise risk management, or strengthening board reporting, escalation triggers and assurance coverage.
The course is structured in two integrated modules. Module 1 establishes the governance foundation: what AI is in board terms, where it is likely to be operating, why it creates distinct governance challenges, and how existing legal, regulatory and standards settings shape directors' oversight responsibilities. Module 2 addresses how boards govern AI in operation, including ERM integration, risk appetite, reporting, escalation, accountability, governance structure, third-party oversight and assurance.
Participants work through practical governance questions that boards should be able to ask management, what evidence they should require, and how oversight decisions and risk acceptance should be documented. The course focuses on what boards need to know, what they need to require of management, and what good governance evidence looks like in practice.
Directors will leave this course with a clear framework for board oversight of AI, a practical question set for challenging management, a clear view of the minimum reporting and assurance evidence boards should require, and a practical way to assess whether AI governance is fit for purpose.
Review the sections below for the detailed course outline, online course pricing, certificate information, and options for facilitated board briefings, executive workshops and tailored in-house delivery.
Which AI Governance course is right for me
Sibenco offers two specialist AI governance courses designed for different audiences and responsibilities. AI Governance for Directors: Oversight, Risk and Assurance is designed specifically for directors, governing body members and senior executives with board-level accountability. It focuses on the board’s role in overseeing AI and automated decision-making, including directors’ duties, enterprise risk management integration, risk appetite, board reporting, escalation, accountability and assurance.
By contrast, AI Governance: Risk, Accountability and Assurance is designed for the broader group of professionals involved in AI governance, implementation and operational oversight, including legal, privacy, risk, compliance, records, data, technology and governance practitioners. It provides a more detailed practitioner-level treatment of governance implementation across the organisation (access the AI Governance: Risk, Accountability and Assurance course here).
This directors course is not simply a shorter version of the professional course. It is a distinct board-focused programme designed for those responsible for governance from the top down. It concentrates on what directors and governing bodies need to know, what they should require from management, what reporting and evidence they should expect to see, and how to exercise informed oversight in practice.
In summary:
- choose this course if your role is board, committee or governing body oversight for:
- a board and committee oversight lens
- guidance on directors’ duties and governance expectations
- practical direction on board reporting, escalation and assurance
- a fit-for-purpose approach to board-level AI governance
- choose the professional course if your role is hands-on governance design, implementation, operational management or assurance
- choose the Board Package if your board or executive team wants a shared governance learning experience with facilitated discussion and live Q&A
AI governance is a board-level responsibility. AI and automated decision-making are now embedded in core organisational functions across every sector: customer onboarding, credit and lending decisions, service delivery, compliance monitoring, workforce management, and risk triage. The shift to agentic AI is accelerating this further, as systems take decisions and actions with greater autonomy and at a scale not previously experienced by boards.
Recent Australian guidance confirms that AI governance is moving from principle to supervisory expectation. The Australian Signals Directorate’s 2026 guidance on the careful adoption of agentic AI services highlights the cybersecurity, privilege, monitoring and accountability risks that arise when AI systems can plan, access tools and take actions across systems.
APRA’s April 2026 letter to regulated entities is particularly important for boards of APRA-regulated entities, including banks, insurers and superannuation trustees. APRA links AI governance directly to prudential expectations around risk appetite, operational resilience, third-party dependency management, information security and assurance. Its observations are also relevant beyond the financial sector because they identify common governance weaknesses: boards developing AI literacy too slowly, over-reliance on vendor presentations, weak post-deployment monitoring, insufficient lifecycle governance, gaps in AI-specific security testing, supplier concentration and assurance practices that are not keeping pace with the scale, speed and complexity of AI adoption.
ASIC’s 8 May 2026 open letter to AFS licensees and market participants is also relevant for boards in the financial services sector. ASIC warns that frontier AI models are changing the cyber threat landscape by increasing the speed, scale and accessibility of sophisticated cyber activity. ASIC’s message is not that boards should panic or wait for perfect regulatory clarity, but that they should act with discipline, strengthen cyber resilience fundamentals, and ensure cyber risk governance, reporting, escalation and assurance remain proportionate to the evolving threat environment.
Chief Justice Bell’s 2026 Harold Ford Memorial Lecture, Corporate responsibility and directors’ duties in the era of Artificial Intelligence, further reinforces that directors need to distinguish between governing organisational AI use and using AI themselves in board processes. It highlights the need for AI literacy, independent judgment, careful use of AI in board materials and meetings, and appropriate controls over confidentiality, privilege, records and boardroom deliberation.
Together, these developments reinforce the central premise of this course: boards need sufficient visibility, literacy, reporting and assurance evidence to challenge management and govern AI within risk appetite.
Directors and governing members are being asked to demonstrate that their organisations are using AI responsibly, that risks are identified and controlled, that information reaching the board is accurate and complete, and that accountability is clearly defined when things go wrong.
The AI risk landscape for Directors needs to be viewed through the lens of developing domestic and international regulations. New transparency obligations for entities under the Privacy Act 1988 (Cth) in relation to automated decision-making commence on 10 December 2026.
The Federal Court’s March 2026 liability judgment in ASIC v Bekier [2026] FCA 196 reinforces the practical importance of board information flows and executive escalation. The judgment contains notable judicial observations about directors’ use of AI tools to assist with board materials. For directors overseeing organisations that use AI, the message is that AI governance now extends to the boardroom itself.
Experience from major corporate governance failures has reinforced a consistent lesson: the most significant risk in complex, fast-moving environments is not the risk itself, but the failure of information to reach those responsible for oversight in a form that enables a meaningful response. This course equips directors and governing body members to strengthen oversight of AI use, and to ensure that risks are identified, controlled, and reported in a form that enables a timely and meaningful oversight.
For directors, the practical issue is immediate: what should the board now require from management so that AI risk is visible, governed and challengeable before problems emerge.
By the end of this course, participants will be able to demonstrate the following board-level capabilities:
- Explain AI and automated decision-making in a governance context, recognising where they are being used across the organisation, including in vendor-supplied systems, embedded enterprise tools, and generative and agentic AI, and assess whether governance coverage is adequate.
- Describe Australia's AI regulatory and governance context, understanding why existing obligations under Australian law already apply to AI deployment and why the absence of a standalone AI Act does not reduce director accountability or legal exposure.
- Translate director and governing body duties into practical oversight requirements, specifying what to require of management, how to challenge reporting effectively, and how to document risk decisions in a well-reasoned, evidence-based manner.
- Apply a board-level oversight model aligned to Australia's leading AI adoption guidance, using the NAIC Guidance for AI Adoption as the practical governance benchmark, including the six responsible-AI practices, risk classification, proportional controls, lifecycle governance, and transparency requirements.
- Embed AI risk into enterprise risk management and non-financial risk reporting, including risk appetite statements, board dashboards, escalation triggers, and internal audit coverage.
- Establish reliable information flows to the board by specifying the minimum reporting set for AI and automated decisions, the evidence required to support it, and the indicators that reporting may be incomplete, overly aggregated, or selectively filtered.
- Prepare for the automated decision-making transparency obligations commencing 10 December 2026, understanding what triggers those obligations and what governance evidence should already be in place.
What You Will Take Away
Participants leave with practical board-useable outputs, not just a better understanding of AI governance.
- Board oversight question set
- Minimum board reporting and evidence expectations
- Governance readiness and maturity lens
- Practical model for ERM integration and risk acceptance
- Documentation and accountability expectations
- Automated decision-making transparency readiness lens.
These are consolidated in a practical Director Resource Pack that participants can use selectively as board and committee needs arise, and include board questions, dashboard, ERM check, assurance checklist and transparency readiness lens.
The course covers:
- how AI and automated decision-making appear in organisations, including embedded tools, vendor systems, generative AI and agentic AI
- the board’s role in obtaining visibility over AI use and ensuring accountability, controls and evidence
- directors’ duties and the application of existing Australian law and governance expectations to AI oversight
- alignment with Australia’s National AI Centre Guidance for AI Adoption, relevant ISO/IEC standards and ASX governance expectations
- cybersecurity and operational resilience implications, including ASD guidance on agentic AI
- ERM integration, risk appetite, escalation, risk acceptance and board reporting
- AI assurance, internal audit expectations and evidence-based reporting
- third-party and supplier governance for vendor-supplied AI
- AI use in board papers, board preparation, transcription, minutes and confidentiality controls
- preparation for automated decision-making transparency obligations commencing on 10 December 2026
- practical board scenarios and a downloadable Director Resource Pack.
Director Resource Pack
Participants receive a practical Director Resource Pack containing board-level prompts, checklists and templates to support:
- AI visibility and management reporting
- board oversight questions
- risk classification and escalation
- ERM integration
- assurance and internal audit scoping
- procurement and third-party AI governance
- automated decision-making transparency readiness
- board minutes and evidence of active oversight
- applied board discussion scenarios.
The Resource Pack is designed as a working reference for board, committee and governing body use.
The self-paced online course is delivered in two integrated modules and takes approximately 5 to 6 hours to complete. Together, the modules move from governance foundation to governance operation. Module 1 equips directors to understand the subject matter they are being asked to govern. Module 2 then addresses how boards operationalise that oversight through enterprise risk management, reporting, escalation, accountability and assurance. Both modules use practical board-level examples and governance scenarios. Each module is designed to help directors improve board judgement, management challenge and the quality of information reaching the board.
Module 1: AI, Law and Directors’ Responsibilities
This module establishes the governance foundation directors need in order to oversee AI and automated decision-making with confidence. It is the “what and why” module. It explains what AI is in board terms, where it is likely to be operating in the organisation, why it creates distinct governance challenges, and how existing legal, regulatory and standards settings shape directors’ oversight responsibilities.
The module introduces AI as a governance issue rather than a purely technical one. It focuses on the central board challenge of visibility, information flow, accountability and evidence, particularly where AI is embedded in enterprise platforms, vendor systems, workflow tools and decision-support processes. It also introduces a lifecycle lens so directors can understand that AI governance is not a one-off approval event, but a continuing discipline extending from planning and procurement through deployment, use, monitoring, change and retirement.
The module then translates these governance foundations into directors’ duties and the Australian legal and regulatory environment. It explains the continuing relevance of existing obligations, including directors’ duties, privacy and information obligations, and the practical significance of contemporary governance and standards frameworks. It also places Australia’s approach in its international context so directors can understand the significance of cross-border supply chains, overseas providers and emerging global regulation.
Module 2: AI Governance and ERM Integration, Board Reporting and Assurance
This module addresses the practical question that follows from Module 1: how boards govern AI in operation. It is the board operating module. Its purpose is to explain how directors ensure AI and automated decision-making are embedded in enterprise risk management and non-financial risk frameworks so that AI is governed as part of the organisation’s core risk architecture.
The module focuses on the disciplines that allow boards and risk committees to act on reliable, timely and decision-useful information. It addresses the point at which governance most commonly falls short, not in recognising that AI creates risk, but in translating that recognition into repeatable disciplines in reporting, escalation, accountability and assurance. It explains how boards should approach AI risk appetite, risk tolerance, escalation thresholds and risk acceptance, and how they should assess whether management reporting is genuinely integrated, evidence-based and complete.
The module also examines governance structure design, information flows to the board, governance maturity, accountability allocation, internal audit and assurance expectations, third-party and procurement governance, minimum documentation and evidence, and readiness for the automated decision-making transparency obligations commencing on 10 December 2026. Throughout, the focus remains practical and board-centred: what management should be required to demonstrate, what evidence should exist, what should be escalated, and what the board should be able to rely upon.
Participants also receive a Director Resource Pack, including board-level prompts, checklists and practical tools to support discussion, reporting, escalation, assurance and governance review.
The course is available in three delivery formats:
- Self-paced online course Participants complete the course online via the Sibenco Learning Hub. The online course includes two integrated modules, downloadable resources, practical governance scenarios, knowledge review assessments and a Certificate of Completion. Participants receive 12 months’ access to the course content and resources.
Estimated time commitment: approximately 5 to 6 hours.
- Board and executive team package A facilitated package is available for boards, board committees and executive leadership teams seeking a shared governance learning experience. This option may include online course access for agreed participants, a facilitated board briefing, live Q&A, and discussion of board oversight priorities, reporting expectations and practical next steps.
- Private workshops and tailored in-house delivery Private workshops and course packages are available for organisations seeking facilitated delivery, sector-specific emphasis, tailored board or executive discussion, or broader organisational participation.
Certificate: Participants who complete the online course requirements receive a Certificate of Completion in AI Governance: Oversight, Risk and Assurance, issued by Sibenco.
Course Fee
- A$875 AUD + GST
- 3 or more non-members from the same organisation A$700 AUD + GST per participant
Includes two modules, downloadable resources, practical governance scenarios, knowledge review assessments, and Certificate of Completion.
Board and Executive Team Package
A premium package is available for boards, board committees and executive leadership teams seeking a shared governance learning experience.
Price on application
Board packages can include:
- course access for the agreed participants
- a 2-hour facilitated virtual briefing
- live Q&A with an Sibenco facilitator or Dr Susan Bennett
- discussion of board oversight priorities, reporting expectations and practical next steps
This option is designed for organisations seeking a more tailored governance discussion in addition to the self-paced course.
- AI governance for superannuation trustee directors
- AI governance for APRA-regulated boards
- AI governance for government and automated decision-making transparency
- AI governance for health, aged care and human services
- AI governance for universities and research organisations
Private workshop and course combinations are also available for organisations seeking facilitated delivery, tailored discussion or larger group participation.
Price on application
Options can include:
- tailored delivery for boards or executive teams
- sector or regulatory emphasis where relevant
- discussion of practical governance priorities, reporting and assurance expectations
- broader organisational participation where appropriate
Access
Participants receive 12 months online access to the course content and resources.
Facilitated Board Briefings and In-House Workshops
In addition to the self-paced online course, Sibenco offers facilitated board briefings, executive workshops and tailored in-house sessions for organisations seeking a shared governance discussion with Dr Susan Bennett, Founder and Executive Director of Sibenco and Principal of Sibenco Legal & Advisory.
These sessions can be tailored for boards, board committees, executive leadership teams or mixed governance groups. They may focus on board oversight priorities, AI risk appetite, reporting and escalation expectations, assurance evidence, AI use in the boardroom, sector-specific regulatory issues, or practical next steps for strengthening AI governance.
Facilitated options can be delivered as a standalone board briefing, a workshop linked to the online course, or a tailored programme for a board or executive team.
Further information on the available package types is set out in the Pricing and Delivery Options section above. Pricing is available on application.
Educational purpose only
This course is provided for general information and educational purposes only. It does not constitute legal advice, regulatory advice, cybersecurity advice, risk advice, assurance advice, professional advice, or assurance of compliance.
Participants and organisations should obtain independent legal, regulatory, cybersecurity, risk, assurance or other professional advice appropriate to their circumstances before acting on information contained in this course.
No guarantee of compliance or outcomes
Completion of this course does not guarantee compliance with any law, regulation, government guidance, standard, prudential requirement or framework, including Australian Government AI guidance, ISO/IEC standards, privacy obligations, cybersecurity obligations, recordkeeping obligations or directors’ duties.
Implementation outcomes will depend on each organisation’s governance arrangements, systems, data, risk appetite, legal and regulatory context, sector, operating model, third-party dependencies and assurance arrangements.
Templates, tools and examples
Any templates, checklists, examples, scenarios or tools provided in this course are illustrative and educational only. They are not endorsed, approved or certified by any regulator, government agency, standards body or professional body.
Participants remain responsible for assessing whether any materials are appropriate for their organisation, validating them internally, obtaining appropriate professional advice where required, and securing all necessary internal approvals before operational use.
Currency of information
AI, privacy, cybersecurity, corporate governance, prudential, information governance and recordkeeping laws, standards and guidance are evolving. While this course reflects guidance current at the time of publication, Sibenco does not warrant that the materials remain current, complete or suitable for any particular organisation or use case.
Participants and organisations are responsible for checking and relying on the latest versions of relevant laws, standards, regulatory guidance and organisational policies.
Third-party content and links
This course refers to third-party guidance, tools, standards, cases, speeches, regulatory materials and other publications, including materials published by Australian Government agencies, regulators, courts, standards bodies and international organisations.
Sibenco does not control, endorse or warrant the accuracy, completeness, currency or availability of third-party content and accepts no responsibility for reliance on those materials.
No endorsement or affiliation
This course is an independent training product. References to government guidance, regulators, courts, standards bodies, professional bodies, frameworks or third-party materials do not imply endorsement, approval, certification, partnership or affiliation.
Participant responsibility
Participants and organisations remain responsible for:
- decisions made using or in connection with AI systems
- ensuring appropriate governance, oversight, accountability, controls and assurance
- complying with applicable laws, regulatory obligations and organisational policies
- determining whether further legal, regulatory, cybersecurity, risk or assurance advice is required.
Limitation of liability
To the extent permitted by law, Sibenco excludes liability for any loss, damage, cost or expense arising from or in connection with reliance on this course or its materials, whether direct, indirect, consequential or otherwise.
Nothing in these Terms excludes, restricts or modifies any guarantee, right or remedy that cannot lawfully be excluded, restricted or modified under applicable law.
Governing law
These Terms are governed by the laws of New South Wales, Australia.
Intellectual Property, Acknowledgement and Permitted Use
Source
This course, including the Director Resource Pack, forms part of AI Governance for Directors: AI Governance for Directors: Oversight, Risk and Assurance, developed and delivered by Information Governance ANZ Pty Ltd.
Intellectual property
All intellectual property rights in the course materials, module content, slides, templates, checklists, scenarios, tools, assessments, resource pack and related materials are owned by Information Governance ANZ Pty Ltd, unless otherwise stated. All rights are reserved.
Permitted participant use
Course participants may use the materials for their own personal learning and professional development.
Where a course place has been purchased by, or for, an organisation, participants may refer to the materials internally within that organisation for board, committee, governance and professional development purposes.
Restrictions on use
The materials must not be copied, reproduced, adapted, modified, distributed, published, uploaded, shared, sold, licensed, sublicensed or otherwise made available to any other person or organisation, except as expressly permitted in writing by Information Governance ANZ Pty Ltd.
The materials must not be used to develop, deliver or support any external course, workshop, consulting service, advisory product, client deliverable, training programme, template library, publication or commercial offering, whether free or paid, without prior written permission from Information Governance ANZ Pty Ltd.
The materials must not be uploaded into, ingested by, used to train, fine-tune, prompt, populate or benchmark any AI system, knowledge base, chatbot, template library or searchable repository, except as expressly agreed in writing by Information Governance ANZ Pty Ltd.
No external advisory or training use
Consultants, advisers, training providers and other organisations must not use the course materials, tools, templates, scenarios or resource pack to provide services to clients, develop competing or derivative training, or create external governance materials, unless expressly agreed in writing by Information Governance ANZ Pty Ltd.
Attribution
Suggested attribution: Sibenco, AI Governance for Directors: Oversight, Risk and Assurance.
Where referring specifically to the Director Resource Pack:
Sibenco, AI Governance for Directors: Oversight, Risk and Assurance, Director Resource Pack.
Contact
For information about Sibenco membership, courses, workshops and tailored board briefings on AI governance and information governance: www.sibenco.com
Is this course also available through InfoGovANZ? This course is developed and presented by Dr Susan Bennett. Sibenco delivers the course for directors, boards, senior executives, General Counsel and governance, legal and risk leaders. Related professional AI governance training is also available through InfoGovANZ for information governance, privacy, records, data, risk, compliance and assurance professionals.
Is this a technical AI course? No. This is a governance and risk course for directors and those with governing body responsibilities. It focuses on how to govern AI and automated decision-making through accountability, controls, reporting, escalation, and assurance. No technical background is required.
Is this course only for board directors? No. The course is designed for anyone responsible for overseeing AI or governing an organisation that uses it, approached from the top down rather than from implementation. That includes company directors and governing body members, as well as senior executives with board-level accountability across risk, compliance, technology, data, legal and company secretarial functions, including Chief Risk Officers, Chief Information Officers, Chief Information Security Officers, General Counsel, Company Secretaries and equivalent roles.
What will I be able to do differently after the course? You will be able to specify what the board needs to receive, at what cadence, and in what form, so that AI risk is visible and actionable at board level. You will also be able to assess whether reporting is evidence-based and aligned to risk appetite, rather than reliant on management narrative.
How practical is the course for current board agendas? The course is designed around the kinds of questions that arise in real board and committee discussions, including management reporting, incidents, vendor updates, risk acceptance and assurance.
Does it cover regulator expectations? Yes. The course draws on ASIC's expectations on non-financial risk oversight and board information flows, APRA's prudential guidance for prudentially regulated entities. OAIC guidance on AI and privacy, the Australian Signals Directorate’s guidance on agentic AI cybersecurity risks, AUSTRAC obligations where relevant, and the regulatory obligations of critical infrastructure operators. It also covers the Federal Court's 2026 decision in ASIC v Bekier on board information flows, directors' duties and AI use in governance, and the international context, including the EU AI Act.
How is this different from a general 'AI for directors' briefing? Most director AI briefings focus on what AI is and broad risk themes. This course goes further: it focuses on the mechanics of governance, how directors set accountability, embed AI into enterprise risk management, require proportionate controls, and insist on reporting and assurance evidence that supports well-informed board decisions.
Is it relevant outside financial services? Yes. The course is designed for directors and governing body members across all sectors: corporate, government, higher education, health, and not-for-profit. The regulatory context covers obligations that apply broadly under the Corporations Act and the Privacy Act, as well as sector-specific obligations that may apply.
How is the course delivered? The course is available as a self-paced online course through the Sibenco Learning Hub. It can also be delivered through facilitated board briefings, executive workshops or tailored in-house sessions. Facilitated board and executive sessions can be delivered as 2 x 2.5 hour sessions or tailored to organisational requirements.
What concrete tools or take-aways do participants receive? Participants receive a practical board question set, guidance on the minimum AI reporting and assurance evidence boards should require, a framework for assessing whether AI governance is fit for purpose, and a practical Director Resource Pack for ongoing board and committee reference.
Will participants receive a certificate? Yes. Participants who complete the online course requirements receive a Certificate of Completion in AI Governance for Directors: Oversight, Risk and Assurance, issued by Sibenco.