AI Risk Management: Implementing the NIST AI RMF
Course 2079
3 DAY COURSE

Course Outline

This course provides a practical, enterprise-focused approach to managing the risks associated with artificial intelligence systems by applying the NIST AI Risk Management Framework (AI RMF) in real-world environments. Learners examine how AI risk differs from traditional software and cybersecurity risk, and how data, models, users, system context, scale, decision influence, and generative AI can change the risk boundary.

The course shows how to operationalize AI governance by connecting the AI RMF with the NIST Risk Management Framework (SP 800-37), NIST SP 800-53 control thinking, and ISO/IEC 42001. Learners build AI system inventories, classify systems by purpose, impact, scale, and autonomy, map risks to business and security consequences, evaluate controls and evidence, and establish accountable approval, monitoring, and reassessment processes.

Through an evidence-centered running case, learners review the records used to support defensible AI risk decisions, including intake and categorization records, validation and fairness evidence, SSPs, SARs, POA&M items, monitoring and observability records, vendor and security evidence, model lifecycle changes, and ATO-style authorization artifacts. Exercises address bias, drift, explainability, robustness, adversarial threats, supply-chain risk, human reliance, retraining, and continued authorization so that evidence leads to measurable controls and documented decisions.

By the end of the course, participants will be prepared to apply the NIST AI RMF in practice, connect AI-specific risk evidence to enterprise governance and RMF-style authorization, and support continuous, evidence-driven oversight of AI systems throughout their lifecycle.

AI Risk Management: Implementing the NIST AI RMF Benefits

  • Course Benefits

    • Explain how AI risk differs from traditional software and cybersecurity risk
    • Apply the NIST AI Risk Management Framework to real-world AI systems
    • Identify and classify AI systems based on purpose, impact, scale, and autonomy
    • Map AI risks to governance, controls, accountability, and audit evidence
    • Evaluate controls for bias, drift, explainability, robustness, and adversarial threats
    • Integrate AI governance with NIST RMF, 800-53 control thinking, and ISO/IEC 42001

    Prerequisites

    Attendees should have foundational knowledge in cybersecurity, risk management, or governance frameworks. Familiarity with machine learning concepts is helpful but not required.

AI Risk Management: Implementing the NIST AI RMF Training Outline

Learning Objectives

Chapter 1: The AI Risk Landscape

  • AI Adoption and Enterprise Impact
  • AI vs. Traditional Software Risk
  • AI System Lifecycle
  • Scale, Automation, and Data Dependency
  • Generative AI and LLM Risk
  • Consequences of AI Failure

Chapter 2: AI Risk Frameworks and Governance

  • NIST AI RMF Core Functions
  • AI RMF and NIST SP 800-37 Alignment
  • ISO/IEC 42001 Overview
  • AI Governance Structures
  • AI Policy and Approval Workflows
  • Communicating AI Risk

Chapter 3: AI Risk Mapping and Measurement

  • AI System Inventory
  • AI System Categorization
  • Business and Security Risk Mapping
  • AI Risk Measurement Methods
  • Risk Ownership and Accountability
  • Assessment Findings and Conditional Authorization

Chapter 4: AI Controls, Validation, and Trust

  • AI-Specific Risk Identification
  • Data Quality and Dataset Risk
  • Bias and Fairness Evaluation
  • Model Validation and Robustness Testing
  • Explainability, Interpretability, and Evidence
  • Authorization Evidence and Documentation

Chapter 5: AI Security and Adversarial Risk

  • Poisoning and Evasion Attacks
  • Model Extraction and Inference Risks
  • Model Asset Protection
  • AI Supply Chain Risk
  • Secure AI Architecture Patterns
  • AI Threat Modeling and Response

Chapter 6: AI Monitoring and Program Maturity

  • Drift and Performance Monitoring
  • AI Observability and Logging
  • Retraining and Lifecycle Management
  • AI Risk Maturity Models
  • AI RMF, ISO/IEC 42001, and Program Sustainment
  • Management Review and Continuous Improvement
Course Dates
Attendance Method
Additional Details (optional)

Private Team Training

Interested in this course for your team? Please complete and submit the form below and we will contact you to discuss your needs and budget.