Identifying, measuring, treating, and assuring AI risks across the full lifecycle — for the second and third lines of defence.
Who this is for
- Risk managers whose portfolio now includes AI
- Internal auditors auditing AI systems
- Assurance consultants offering AI risk services
- Second-line control owners
What you will be able to do
- Structure an AI risk taxonomy that maps to enterprise risk
- Design controls appropriate to each identified risk
- Perform an AI risk assessment that survives scrutiny
- Build an assurance programme (self-assurance, second-line, external)
- Present AI risk credibly to the risk committee and the board
Syllabus
Each module comprises a mix of structured reading, worked examples, and applied exercises. Every programme concludes with an integrated written assessment marked against the published rubric.
Module 1. AI risk taxonomy
Constructing a taxonomy that makes sense of the many AI risk types. Mapping to enterprise risk categories.
Module 2. Risk identification
Techniques: workshop, structured interview, red-team, walkthrough. Common blind spots.
Module 3. Risk measurement
Likelihood and impact for AI risks. Where quantification helps and where it misleads. Bayesian and frequentist approaches.
Module 4. Risk treatment
Design patterns for AI risk control: preventive, detective, corrective. Where controls typically fail.
Module 5. AI risk assessment in practice
End-to-end AIRA on a real (fictionalised) system. Reviewing the artefacts a regulator will want to see.
Module 6. Assurance approaches
Self-assurance, second-line assurance, internal audit, external attestation. Choosing the right depth.
Module 7. The AI audit
What an internal audit of an AI system looks like. Scoping, evidence-gathering, opinion. Working with model owners and data scientists.
Module 8. Reporting and escalation
The reporting stack — control operator, risk committee, board. What each audience needs.
Assessment
Brief
Perform a full AI risk assessment on a system of your choice (real, anonymised, or fictional). Deliver: (1) the completed AIRA (~2,500 words), (2) the treatment plan, and (3) a one-page board summary.
Sample question
You are auditing a fraud-detection model that has been running in production for 18 months. What are the twelve questions your audit programme should answer, and what evidence would convince you the answers are true?
Assessments are marked by a named human examiner against the four-dimension rubric: regulatory accuracy (30%), applied judgement (30%), artefact quality (25%), communication (15%). Pass at 60, distinction at 75.
Prerequisites
Working knowledge of enterprise risk or internal audit. EU AI Act Foundations is helpful.
Certification
On successful completion (pass mark 60), you receive a SAAII Certified Practitioner (CP) — AI Risk and Assurance credential. The credential is CPD-accredited, verifiable at thesaaii.com/verify, and forms one component toward higher-tier credentials. See the certification ladder for how it stacks.
Ready to enrol?
AI Risk and Assurance runs continuously with rolling enrolment. Founding-cohort discount (25%) applies to the first 100 enrolments across the whole programme portfolio.
Cohort licensing available from £395/seat (10+). Public sector, education, and registered charity: 20% discount. Instalment plans available for programmes at £495 and above. See For organisations and the FAQ for detail.