
AI Governance Course: Legal, Risk, Accountability and Assurance
A practical online AI governance course for legal, risk, privacy, compliance, audit, assurance, data, technology and governance professionals who need to implement responsible AI governance across an organisation.
The course translates Australia’s AI governance guidance, privacy and accountability obligations, AI risk management principles and assurance expectations into practical implementation steps. Participants learn how to identify AI use, allocate accountability, assess AI risks, maintain AI registers, integrate privacy and records controls, test and monitor systems, maintain human oversight and report assurance outcomes to senior leaders and boards.
This Sibenco course is particularly suited to General Counsel teams, senior risk and compliance teams, privacy leaders, records and information governance professionals, internal audit, cyber and technology risk teams, and executives responsible for AI governance implementation.
Key details:
Online and self-paced | Approx. 8 hours | 3 Modules | 12 months' access | Certificate of Completion | Individual and corporate pricing available
Enrol in the AI Governance Course Request Board or Executive Team Pricing Enquire About a Facilitated Board Briefing
Course Overview
Artificial Intelligence is now being adopted through enterprise platforms, vendor systems, generative AI tools, automation, analytics and emerging agentic AI capabilities. These tools promise innovation, productivity gains and significant efficiencies, but they also increase legal, privacy, cybersecurity, operational and accountability risks unless supported by robust governance, clear accountability, effective assurance and fit-for-purpose reporting.
AI Governance: Risk, Accountability and Assurance is a practical professional course for people responsible for implementing, managing or assuring responsible AI. It gives participants a structured way to identify AI use, allocate accountability, assess risk, maintain AI registers, integrate privacy and records obligations, test and monitor systems, and report assurance outcomes to senior leaders and governance committees.
The course is grounded in the National Artificial Intelligence Centre's Guidance for AI Adoption and aligns with key standards and frameworks including AS ISO/IEC 42001 and 5338, the OECD AI Principles and the NIST AI Risk Management Framework.
Participants work through applied governance and assurance scenarios drawn from corporate, government and higher-education contexts, including Microsoft Copilot, embedded generative AI, third-party AI systems, unapproved employee AI use, AI-enabled cyber risk and emerging agentic AI.
Which AI governance course is right for me
Choose AI Governance: Risk, Accountability and Assurance if your role involves designing, implementing, managing, documenting or assuring AI governance across the organisation.
Choose AI Governance for Directors: Oversight, Risk and Assurance if your role is board, governing body or senior executive oversight, and you need to understand what to require from management, what reporting to expect, and how to exercise informed oversight of AI risk (view this course).
Organisations are adopting AI faster than their governance systems are adapting. AI is already operating through enterprise software, vendor platforms, analytics tools, productivity suites, chatbots, workflow automation and employee use of public or approved generative AI tools.
This creates practical governance questions: What AI systems are in use? Who owns them? What risks have been assessed? What data is being accessed? What records are created? What testing and monitoring evidence exists? What should be escalated, when and to whom?
This course helps organisations move from AI principles to practical controls, evidence and defensible oversight.
Explore the course outline, pricing and certificate information below.
This course is designed for professionals responsible for, or involved in, AI system use, management or assurance in corporate, not-for-profit and government sectors, including:
- Governance, risk, compliance, and audit professionals
- Privacy, records, and information managers
- Legal, privacy, ethics, and assurance professionals
- Data, analytics, and IT managers implementing AI solutions
- Cybersecurity, technology risk and operational resilience professionals
- Business leaders and project teams responsible for deploying AI-enabled tools or vendor systems
- Policy advisers overseeing AI adoption or evaluation
Across all three modules, participants will gain the skills and confidence to:
- Build and apply AI governance frameworks aligned with national and international standards;
- Implement policies and registers that ensure transparency and accountability;
- Measure and report AI system performance, fairness, and ethical outcomes; and
- Embed continuous improvement and assurance maturity across the organisation.
Each module includes:
- Reflection activities and interactive knowledge checks
- Practical tools and templates
- Downloadable resources
- Each module concludes with a short Knowledge Review Assessment to reinforce learning. A final cumulative assessment confirms understanding of key principles across the full course. Participants may retake assessments if required to achieve a passing score of 75 % or higher. On successful completion, participants receive an Sibenco Certificate of Completion in AI Governance: Risk, Accountability and Assurance.
By the end of this course, participants will be able to:
- Explain how AI differs from traditional automation and the governance implications.
- Identify and assess legal, ethical, operational and cybersecurity risks across the AI lifecycle.
- Apply the NAIC Six Responsible-AI Practices using templates and tools.
- Develop and implement AI governance policies and accountability structures.
- Measure and evidence AI performance, fairness, and transparency.
- Conduct assurance reviews, including privacy, cybersecurity, data governance, and model risk controls, and integrate findings into continuous improvement.
- Prepare governance and board reports that demonstrate ethical and regulatory compliance.
The course is delivered across three integrated modules, guiding professionals through the complete responsible-AI lifecycle from governance foundations to implementation, assurance and reporting.
The course addresses contemporary organisational AI risks through practical, applied scenarios, including the governance and assurance challenges posed by embedded enterprise AI tools such as Microsoft Copilot, third-party and vendor-supplied AI systems, and unapproved or informal employee AI use. Participants work through realistic examples covering AI registers, data access and reuse, record creation, accountability, human oversight, and ongoing assurance, to ensure visibility, defensible decision-making, and effective risk management across the organisation.
Each module includes reflection activities, case studies, downloadable tools and templates, and a knowledge review assessment to consolidate learning.
Module 1 – Foundations: Understanding AI and Governance
This introductory module provides a clear foundation for understanding artificial intelligence (AI), how it operates, and why strong governance is essential for its responsible and compliant use. It demystifies key concepts such as algorithms, agentic AI and the AI lifecycle, and explains how governance principles, risk management, and legal compliance intersect across both public and private sectors.
Learners will explore Australia and New Zealand’s evolving regulatory and policy environment for AI, including the AI Ethics Principles, the OECD AI Principles, national assurance and standards frameworks, best-practice international frameworks, and the latest guidance from the National Artificial Intelligence Centre (NAIC). The course highlights international developments, including the EU AI Act and its extra-territorial application, recognising that Australian and New Zealand organisations may be affected through global supply chains and digital services.
The module also introduces the organisational capabilities, leadership, culture, and skills, that underpin responsible AI implementation, providing a foundation for the applied practices in Module 2. The module concludes with a realistic organisational scenario and governance checklist to help you identify risks and apply the principles in practice.
Module 2 – Practices: Implementing Responsible AI
This module focuses on operationalising responsible AI governance. It guides learners through the six essential practices defined by the National AI Centre (NAIC) 2025 for the accountable adoption and oversight of AI. Using detailed implementation steps, tools, and real-world examples, the module shows how to translate principles and frameworks into practical processes that manage risk, ensure accountability, and maintain trust.
Learners will explore how to embed governance into the AI lifecycle, from system design and procurement through to testing, monitoring, and decommissioning. The module aligns with the Australian government’s latest guidance on AI adoption, AI Ethics Principles, and international benchmarks such as ISO 42001 AI Management Systems, ISO 23894 AI Risk Management, and the NIST AI Risk Management Framework (2023).
This module integrates privacy, recordkeeping, and information-governance requirements, ensuring that governance practices remain compliant and auditable.
Finally, the module highlights the leadership, culture, and skills needed to implement AI responsibly. It concludes with a practical case study, a cross-sector application summary, and a comprehensive AI Implementation Checklist that supports real-world adoption.
By the end of Module 2, participants will know how to identify high-risk AI use cases, document them appropriately, and implement internal controls that enable transparency and accountability.
Module 3 – Assurance: Audit and Continuous Improvement
This module shows how to measure performance, audit and act on findings through continuous improvement, and report outcomes for responsible oversight of AI at executive, risk committee and Board levels.
Participants learn the benefits of and how to apply assurance frameworks, including AS ISO/IEC 42001:2024, the NIST AI Risk Management Framework, and the Australian Government AI Assurance Framework.
The module covers establishing assurance metrics and dashboards, managing continuous improvement processes, and reporting outcomes to senior leadership and boards.
Cross-sector case studies from government, corporate, and university contexts demonstrate how assurance findings lead to improvements.
By completion, participants will understand how to design an AI assurance process that supports responsible innovation and builds stakeholder trust.
- 100 % online and self-paced via the Sibenco Learning Hub
- Approx. 8 hours total learning time
- 12 months’ access to all content and updates
- Certificate in AI Governance: Risk, Accountability and Assurance issued by Sibenco.
Course Fees
Individuals
- $875 AUD (plus GST)
Includes three modules, downloadable policy and assurance templates, case studies, and Certificate of Completion.
Corporate and Enterprise Options
- Corporate Group Licence (5–20 users): $595 per participant (plus GST)
- Enterprise Licence (20 + users): Price on Application (POA) – options include co-branding, SSO access, analytics, tailored onboarding, and bespoke content reflecting organisation’s AI Policy Framework and inclusion of organisation’s relevant policies and tailored Knowledge Review Assessment for internal training.
- Contact Us for Enterprise Pricing
Participants receive 12 months’ access, including any updates to standards or frameworks.
Value-Added Options
A. Corporate Briefing – “Applying the Lessons”Organisations enrolling 10 or more participants may request a one-hour virtual briefing with an Sibenco facilitator or Dr Susan Bennett. The session helps teams:
- Translate course learnings into organisational governance frameworks,
- Identify practical next steps for AI risk and assurance, and
- Align AI governance with existing information-governance and compliance programs. (Available within six months of enrolment; subject to availability.)
- Contact Us for Corporate Briefing Pricing
Enterprise clients can access a custom-branded Sibenco Learning Portal with:
- Internal hosting or single-sign-on integration,
- Usage analytics and completion reporting,
- Annual content updates aligned with evolving AI standards, and
- Optional inclusion of organisational policies or modules.
- Contact Us for Tailored LMS Hosting Pricing
Pricing Summary
| Category | Price (AUD, excl GST) | Inclusions |
| Non-Member (Individual) | $875 | Three modules, resources, certificate. |
| Member (Individual) | $700 | 20 % discount for Sibenco members. |
| Corporate Group (5–20) | $595 per person | Group licence; optional one-hour briefing. |
| Enterprise Licence (20 +) | POA | Custom LMS, analytics, updates; optional briefing. |
Contact Us for Corporate Access or Enterprise Pricing
Key Benefits
- Built for professionals responsible for AI governance and assurance.
- Practical, framework-aligned training using case studies.
- Strengthens capability in risk, ethics, accountability, and compliance.
- Recognised by Sibenco for continuing professional development (CPD).
Educational purpose only
This course is provided for general information and educational purposes only. It does not constitute legal advice, regulatory advice, cybersecurity advice, risk advice, assurance advice, professional advice, or assurance of compliance.
Participants and organisations should obtain independent legal, regulatory, cybersecurity, risk, assurance or other professional advice appropriate to their circumstances before acting on information contained in this course.
No guarantee of compliance or outcomes
Completion of this course does not guarantee compliance with any law, regulation, government guidance, standard, prudential requirement or framework, including Australian Government AI guidance, ISO/IEC standards, privacy obligations, cybersecurity obligations, recordkeeping obligations or directors’ duties.
Implementation outcomes will depend on each organisation’s governance arrangements, systems, data, risk appetite, legal and regulatory context, sector, operating model, third-party dependencies and assurance arrangements.
Templates, tools and examples
Any templates, checklists, examples, scenarios or tools provided in this course are illustrative and educational only. They are not endorsed, approved or certified by any regulator, government agency, standards body or professional body.
Participants remain responsible for assessing whether any materials are appropriate for their organisation, validating them internally, obtaining appropriate professional advice where required, and securing all necessary internal approvals before operational use.
Currency of information
AI, privacy, cybersecurity, corporate governance, prudential, information governance and recordkeeping laws, standards and guidance are evolving. While this course reflects guidance current at the time of publication, Sibenco does not warrant that the materials remain current, complete or suitable for any particular organisation or use case.
Participants and organisations are responsible for checking and relying on the latest versions of relevant laws, standards, regulatory guidance and organisational policies.
Third-party content and links
This course refers to third-party guidance, tools, standards, cases, speeches, regulatory materials and other publications, including materials published by Australian Government agencies, regulators, courts, standards bodies and international organisations.
Sibenco does not control, endorse or warrant the accuracy, completeness, currency or availability of third-party content and accepts no responsibility for reliance on those materials.
No endorsement or affiliation
This course is an independent training product. References to government guidance, regulators, courts, standards bodies, professional bodies, frameworks or third-party materials do not imply endorsement, approval, certification, partnership or affiliation.
Participant responsibility
Participants and organisations remain responsible for:
- decisions made using or in connection with AI systems
- ensuring appropriate governance, oversight, accountability, controls and assurance
- complying with applicable laws, regulatory obligations and organisational policies
- determining whether further legal, regulatory, cybersecurity, risk or assurance advice is required.
Limitation of liability
To the extent permitted by law, Sibenco excludes liability for any loss, damage, cost or expense arising from or in connection with reliance on this course or its materials, whether direct, indirect, consequential or otherwise.
Nothing in these Terms excludes, restricts or modifies any guarantee, right or remedy that cannot lawfully be excluded, restricted or modified under applicable law.
Governing law
These Terms are governed by the laws of New South Wales, Australia.
Intellectual Property, Acknowledgement and Permitted Use
Source
This course forms part of AI Governance: Risk, Accountability and Assurance, developed and delivered by Information Governance ANZ Pty Ltd.
Intellectual property
All intellectual property rights in the course materials, module content, slides, templates, checklists, scenarios, tools, assessments, resource pack and related materials are owned by Information Governance ANZ Pty Ltd, unless otherwise stated. All rights are reserved.
Permitted participant use
Course participants may use the materials for their own personal learning and professional development.
Restrictions on use
The materials must not be copied, reproduced, adapted, modified, distributed, published, uploaded, shared, sold, licensed, sublicensed or otherwise made available to any other person or organisation, except as expressly permitted in writing by Information Governance ANZ Pty Ltd.
The materials must not be used to develop, deliver or support any external course, workshop, consulting service, advisory product, client deliverable, training programme, template library, publication or commercial offering, whether free or paid, without prior written permission from Information Governance ANZ Pty Ltd.
The materials must not be uploaded into, ingested by, used to train, fine-tune, prompt, populate or benchmark any AI system, knowledge base, chatbot, template library or searchable repository, except as expressly agreed in writing by Information Governance ANZ Pty Ltd.
No external advisory or training use
Consultants, advisers, training providers and other organisations must not use the course materials, tools, templates, scenarios or resource pack to provide services to clients, develop competing or derivative training, or create external governance materials, unless expressly agreed in writing by Information Governance ANZ Pty Ltd.
Attribution
Suggested attribution: Sibenco, AI Governance: Risk, Accountability and Assurance.
Contact
For information about Sibenco membership, courses, workshops and tailored board briefings on AI governance and information governance: www.Sibenco.com
Is this course also available through InfoGovANZ? This course is developed and presented by Dr Susan Bennett. Sibenco delivers the course for directors, boards, senior executives, General Counsel and governance, legal and risk leaders. Related professional AI governance training is also available through InfoGovANZ for information governance, privacy, records, data, risk, compliance and assurance professionals.
Is this a technical AI course? No. This is a governance, risk and assurance course for professionals responsible for implementing, managing or assuring responsible AI. It explains key AI concepts where needed, but the focus is on governance frameworks, accountability, risk assessment, controls, documentation, privacy, transparency, human oversight, monitoring and assurance. No technical background is required.
Who is this course designed for? The course is designed for professionals involved in AI governance, implementation, risk management, compliance or assurance. This includes legal, privacy, risk, compliance, records, information governance, data governance, cybersecurity, technology, procurement, audit, policy and governance professionals. It is also relevant for managers and senior professionals who need to understand how AI and automated decision-making should be governed across the organisation.
How is this course different from AI Governance for Directors? AI Governance for Directors is designed for directors, governing body members and senior executives with board-level accountability. It focuses on oversight, board reporting, escalation, risk appetite and assurance evidence. This professional course is more detailed and implementation-focused. It is designed for the people who need to establish AI governance frameworks, maintain AI registers, assess use cases, manage privacy and records obligations, engage vendors, implement controls, monitor AI systems and support assurance reporting to senior leaders and governance committees.
What will I be able to do differently after the course? You will be able to identify AI use across an organisation, assess AI risks, allocate accountability, apply screening and risk assessment processes, maintain an AI register, identify relevant privacy and records obligations, design proportionate controls, and support testing, monitoring, incident response and assurance reporting. You will also be better equipped to brief senior leaders and boards on whether AI governance is fit for purpose.
How practical is the course? The course is designed around practical implementation issues that arise when organisations adopt AI through enterprise platforms, vendor systems, generative AI tools, automation, analytics and emerging agentic AI capabilities. It includes practical examples, governance tools, templates and scenarios to help participants move from policy statements to operational controls, documentation and assurance.
Does it cover regulator expectations? Yes. The course draws on current Australian and international AI governance developments, including Australia’s National AI Centre Guidance for AI Adoption, privacy and automated decision-making obligations, cybersecurity guidance for AI and agentic AI, records and information governance obligations, procurement and vendor risk issues, and relevant international frameworks including ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF and the EU AI Act.
Does the course cover the Privacy Act and automated decision-making? Yes. The course addresses privacy governance for AI, including transparency, collection, use, disclosure, data quality, security, retention, and the automated decision-making transparency obligations commencing under the Privacy Act from 10 December 2026. It also considers the governance records needed to explain when AI is used, how decisions are supported or made, who is accountable, and how affected individuals can question or seek review of decisions that affect them.
Does the course cover AI registers and risk assessments? Yes. A core focus of the course is how to identify and document AI use across the organisation. Participants learn how AI registers, screening tools, impact assessments, risk assessments and risk treatment plans work together to support visibility, accountability, transparency, control and assurance.
Does it cover generative AI and agentic AI? Yes. The course addresses generative AI, embedded AI features in enterprise platforms, automated decision-making systems and emerging agentic AI capabilities. It explains why these systems can create different governance issues, including autonomy, tool access, prompt injection, excessive privileges, data leakage, unreliable outputs, weak monitoring, vendor dependency and unclear accountability.
Is it relevant outside government or financial services? Yes. The course is designed for professionals across corporate, government, higher education, health, legal, not-for-profit and regulated sectors. While it addresses specific legal and regulatory obligations where relevant, the core governance issues apply broadly wherever AI is used to support decisions, automate processes, generate content, interact with people, analyse data or operate across systems.
How is the course delivered? The course is available as a self-paced online course through the Sibenco Learning Hub. It can also be delivered through facilitated team training, executive workshops or tailored in-house sessions. Tailored sessions can be adapted for particular sectors, risk profiles, governance maturity levels or implementation priorities.
What concrete tools or take-aways do participants receive? Participants receive practical governance tools and templates to support AI implementation, including resources for identifying AI use, maintaining an AI register, screening AI use cases, assessing risk, allocating accountability, considering privacy and records obligations, managing vendor and supply chain issues, and supporting monitoring, reporting and assurance.
Will participants receive a certificate? Yes. Participants who complete the online course requirements receive a Certificate of Completion in AI Governance: Risk, Accountability and Assurance, issued by Sibenco.
This course is a must have for anyone that is involved in or has an interest in AI Governance. It covers a lot of reference material, explains various frameworks and then applies them to various scenarios and case studies throughout the AI lifecycle. This course provides you with step by step practical guidance, plus lots of templates and checklists to ensure you have everything you need to implement a strong and successful responsible AI Governance program at your organisation. I am very grateful to have access to the course materials for the next 12 months because I will be referring to them quite regularly.
As a governance practitioner working in complex, regulated environments, I found this course to be a thoughtful and practical exploration of AI governance in an Australian context.
The clarity of the governance frameworks was a particular strength, along with the way they were explained as an integrated, multi-layered approach rather than as isolated controls. The information about the frameworks was set out in an easy to follow manner that was directly relevant to real organisational settings.
The practical tools, models, and artefacts were immediately applicable and can be readily adapted to support governance discussions and decision-making. The course materials were clear and accessible, with a considered visual design that helped highlight key concepts without distraction.
The course effectively integrated ethical considerations, risk management, legal obligations, and operational realities. I particularly valued the sections that linked AI governance to established disciplines such as information governance, enterprise risk management, privacy, and records management, anchoring AI within existing organisational systems.
The case studies were well chosen, spanning government, private sector, and university contexts, with the additional inclusion of Robodebt providing an important Australian example. The use of Examples in Practice, Reflective Prompts, and Common Pitfalls supported reflection and consolidation of learning.
As a mid-level leader, I found this course highly beneficial. It would also be valuable for project managers, team leaders, senior executives, board members, and practitioners working across governance, risk, privacy, knowledge & records management, data governance, and security.