Training module

AI Risk Management

Assess AI risks across use context, affected parties, GenAI and agency, then turn findings into treatment, monitoring and residual risk

Artificial IntelligenceManagement System Manager
Abstract digital interface with layered circular indicators and data rings, representing structured AI risk management, harm analysis and defensible governance decisions.

AI risk management that holds up in deployment decisions

AI risk management is more than a scoring template. This module shows how to define the use case, identify affected parties, reason about harm scenarios, stress-test GenAI and agentic risks, and turn findings into treatment, monitoring and assurance evidence.

Overview

What this module is about

Generic statements about AI risk rarely improve decisions. Effective governance requires a structured understanding of what is being assessed, who may be affected, how harm can occur, and when an AI system no longer behaves like passive software.

This module teaches practical AI risk management for management-system environments. Participants define assessment units and intended use, identify affected parties, build harm pathways, use FRIA-style prompts, stress-test GenAI and agentic risk sources, apply risk criteria, compare treatment and deployment-gate options, and document residual-risk, monitoring and assurance decisions.

The focus is on producing assessment evidence that is traceable, defensible and useful to governance, legal, risk, audit, customer assurance and operational stakeholders, without pretending that the module replaces legal advice, technical red teaming or operational-control design.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

need to perform practical AI system impact assessments for real use cases.

must explain who could be harmed, how harm could occur and why it matters.

need to connect AI impact findings to treatment, deployment, monitoring and residual-risk decisions.

want to recognise when GenAI, autonomy, goal pursuit or capability-control limits change the assessment.

support ISO/IEC 42001, EU AI Act interface, risk, audit or customer assurance work.

It may not be the best fit if you…

are primarily looking for general AI awareness or AI fundamentals.

need legal advice or a full EU AI Act classification course.

want technical red teaming, model evaluation or prompt-engineering training.

want to design and operate day-to-day AI controls in detail.

already run a mature, evidence-rich AI system impact assessment process.

Agenda

What is taught

7 parts
01Assessment frame, intended use and role assumptions

Define the system boundary, workflow, data and lifecycle state

Clarify intended use, foreseeable misuse and human decision points

Record provider/deployer role assumptions and obligation interfaces

02Affected parties and FRIA-style impact prompts

Identify affected parties, vulnerable groups and indirect stakeholders

Use FRIA-style prompts to surface rights, access and redress concerns

Connect governance measures, complaints and escalation routes to the assessment

03Harm pathways and decision-ready risk statements

Trace AI behaviour, human reliance and workflow conditions into harm scenarios

Separate causes, controls, impacts and affected-party consequences

Write risk statements that support treatment and deployment decisions

04GenAI, agency and capability-control stress testing

Recognise risks from generative outputs, retrieval and prompt dependence

Test delegated action, tool access, proxy optimisation and autonomy creep

Challenge weak oversight, capability-control mismatches and escalation triggers

05Criteria, uncertainty and evidence confidence

Apply organisational risk criteria without hiding uncertainty

Rate severity, likelihood and confidence using available evidence

Mark weak evidence, not-assessable conditions and specialist review needs

06Treatment, usage conditions and deployment gates

Compare constraints, oversight, reduced autonomy and removed tool access

Set pilot limits, specialist review, escalation and pause conditions

Connect treatment choices to deployment gates and usage conditions

07Residual risk, monitoring, assurance and currency

Record residual-risk acceptance with authority, rationale and conditions

Separate deployer monitoring from provider post-market information needs

Define reassessment triggers, assurance evidence and guidance-update routines

Outcomes

Learning outcomes

01

Define AI system impact assessment units across intended use, context, role assumptions, affected parties and lifecycle state

02

Build credible harm pathways and risk statements using affected-party, FRIA-style and evidence-confidence reasoning

03

Stress-test GenAI, agency, optimisation and capability-control risks before deployment or continuation decisions

Translate assessment findings into treatment, usage conditions, deployment gates and residual-risk decisions

Separate deployer monitoring, provider post-market information needs, reassessment triggers and assurance evidence

Maintain assessment practice as AI law, standards, guidance, incident patterns and model capabilities evolve

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of AI Risk Management is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About AI Risk Management · HAM-AI-S-02

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About AI Risk Management · HAM-AI-S-02

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.