Agentic AI Governance for GRC & Cybersecurity

François B. Arthanas

Agentic AI Governance Educator | Founder

Govern AI agents with controls you can test and decisions you can defend.

A six-week live program for GRC and cybersecurity professionals who want to assess agentic risk, design meaningful human oversight, test controls, and support enterprise deployment decisions.

Read what our students say →

🚨 Early Enrollment Discount - Save $500 - CYB500 applied:

September Day · Ends Sept 25

October Night · Ends Oct 23

Your enrollment includes:

  • 12 live classes + weekly office hours.

  • 10 connected hands-on labs + editable governance templates.

  • A VerifyWise workspace to organize risks, controls, and evidence.

  • Lifetime access to recordings and course materials.

  • One year of The Agent Vault Premium ($497 value).

Learn to answer:

  • What should this agent be allowed to do and how do we enforce the limit?

  • When does a human need to approve, and what should happen if nobody responds?

  • How do we test for prompt injection, tool misuse, and unauthorized actions?

  • What evidence supports release, and which gaps should stop it?

  • Who can shut the agent down, and how does the business keep operating?

Apply NIST AI RMF, ISO 42001, EU AI Act, AIUC-1, and OWASP Agentic Top 10.

Leave with a governance portfolio and a release recommendation you can defend.

📚 Click here to view the syllabus

No coding required.

What you’ll learn

By the end of this course, you will take one AI agent from discovery to an evidence-backed governance decision.

  • Discover approved, embedded, vendor-provided, and shadow agents and separate true agents from AI features and plain automation

  • Build an enterprise inventory and map the agent’s tools, data flows, dependencies, and trust boundaries.

  • Assess whether the use case needs an agent and prioritize risks by impact, autonomy, access, and reversibility.

  • Specify what the agent may read, change, send, or spend and which actions are prohibited.

  • Apply least privilege to identities, tools, data, credentials, and delegated permissions.

  • Test whether permission boundaries and approval thresholds actually block unauthorized actions.

  • Assign decision rights across business, engineering, security, privacy, and external vendors.

  • Design approval checkpoints and packets that give a reviewer the information needed to decide.

  • Define what happens when approval is delayed, rejected, or unavailable, and how to measure oversight effectiveness.

  • Map attack paths using MITRE ATLAS and the OWASP Top 10 for Agentic Applications.

  • Run guided tests for prompt injection, memory poisoning, tool misuse, and data leakage.

  • Capture failures, prioritize fixes, and retest controls with evidence another reviewer can inspect.

  • Define rollout conditions, monitoring signals, intervention thresholds, and shutdown authority.

  • Investigate a simulated incident and govern changes to the agent’s permissions or behavior.

  • Rehearse a human fallback and prepare guidance for the people operating or interacting with the agent.

  • Crosswalk one control set to AIUC-1, NIST AI RMF, ISO 42001, and the EU AI Act and reuse the evidence

  • Use your learnings to build a real-world enterprise capstone that that can be shared on LinkedIn and GitHub

  • Present your final project to the class

Learn directly from François

François B. Arthanas

François B. Arthanas

I help you become the professional teams trust to govern AI agents.

Cyber Pros Training
Centene
ISACA
Trenton Health Team
Western Governors University
See all products from François B. Arthanas

Who this course is for

  • GRC, risk, audit, privacy, and compliance professionals who need to assess AI agents and defend deployment decisions.

  • Cybersecurity professionals who need to test agent permissions, identify security gaps, and verify controls.

  • Anyone interested in AI governance who wants hands-on skills to assess agent risks, test controls, and make informed decisions.

Prerequisites

  • The Only Prerequisite

    A willingness to learn how to Govern AI Agents. Basic familiarity with GRC, cybersecurity, audit, privacy or risk work would be nice to have

  • No coding or prior AI experience required

    Session 1 covers how LLMs and agents actually work, in plain language. You build the AI foundation in week 1

What's included

François B. Arthanas

Live sessions

Learn directly from François B. Arthanas in a real-time, interactive format.

10+ Hands-On Labs on a Working AI Agent

You don't study governance you do it. Govern SupportFlow, a live refund agent that reads records, drafts replies, and moves money. You can "Bring Your Own Agent" (BYOA).

Office Hours & Community

Optional 60-minute sessions for questions, artifact feedback, and discussion of workplace challenges.

Your VerifyWise AI Governance Workspace

Connect agent records, risks, owners, vendors, policies, findings, and evidence in one working platform during the cohort.

Lifetime access to course learning materials

Return to instructional recordings, slides, lab guides, templates, and self-paced course materials when you need them.

One year of The Agent Vault Premium

Twelve months of Premium access are included with your enrollment.

Capstone preparation, live defense, and feedback

Every artifact compounds into one portfolio piece the evidence pack that shows you can take an agent from unknown to approved. Defend your capstone in a final presentation.

Certificate of Completion

Share your new skills with your employer or on LinkedIn. The portfolio behind it is what proves the work. This can be used for 18 CPE that can be used to renew your other Certifications from ISACA, ISC2, CompTIA, AIPP.

Maven Guarantee

Your purchase is backed by the Maven Guarantee.

Course syllabus

17 live sessions • 37 lessons • 10 projects

Week 1

Sep 30—Oct 4

    PREP | See the Agentic AI System Before You Govern It

    1 item

    Sep

    30

    LIVE 01 | Foundations of AI, Agentic AI, and Governance

    Wed 9/301:00 PM—2:30 PM (UTC)

    CASE STUDY | OpenClaw

    1 item

    LAB 1 | Build the Enterprise AI Inventory & Agent Registry

    2 items

    Oct

    1

    OPTIONAL | Office Hours NOT 🔴 RECORDED

    Thu 10/11:00 PM—2:00 PM (UTC)

    Oct

    2

    LIVE 02 | Define and Map the Agentic System

    Fri 10/21:00 PM—2:30 PM (UTC)

    LAB 2 | Map the Agent Architecture & Trust Boundaries

    2 items

    OPTIONAL | Deep Dives & FAQs

    2 items

Week 2

Oct 5—Oct 11

    PREP | Assess and Bound the Risks Upfront

    1 item

    Oct

    7

    LIVE 03 | Assess the Use Case and Tier the Risk

    Wed 10/71:00 PM—2:30 PM (UTC)

    LAB 3 | Assess the Use Case & Build the Risk Register

    2 items

    CASE STUDY | Tiering and Bounding Agentic IT Actions

    1 item

    Oct

    8

    OPTIONAL | Office Hours NOT 🔴 RECORDED

    Thu 10/81:00 PM—2:00 PM (UTC)

    Oct

    9

    LIVE 04 | Bound Authority, Identity, Data, and Permissions

    Fri 10/91:00 PM—2:30 PM (UTC)

    CASE STUDY | Bounding Autonomy in Source-of-Wealth Analysis

    1 item

    LAB 4 | Enforce Agent Permissions & Data Protection

    2 items

    OPTIONAL | Deep Dives & FAQs

    2 items

Free resource

Field Notes LIVE: Who Can Shut It Down? cover image

Field Notes LIVE: Who Can Shut It Down?

What Actually Happened

We will unpack the Hugging Face and Anthropic incidents in plain language and discuss what made them different.

Where the Controls Broke Down

Was this a model problem, a security failure, an evaluation failure, a governance failure or a combination of all four?

Who Can Shut Down the Agent

Who should have the authority to pause or stop an AI agent, and what should trigger that decision?

By continuing, you agree to Maven's Terms and Privacy Policy.

Schedule

Live sessions

3 hrs / week

Designed for working professionals

    • Wed, Sep 30

      1:00 PM—2:30 PM (UTC)

    • Thu, Oct 1

      1:00 PM—2:00 PM (UTC)

    • Fri, Oct 2

      1:00 PM—2:30 PM (UTC)

Hands-On Lab Work

1-2 hrs / week

Optional Office Hours

1 hr / week

Hands-On Agentic AI Governance That Goes Beyond Theory - in Their Own Words💬

More here: https://testimonial.to/agentic-ai-governance/all

Frequently asked questions

Leave with an agent-governance portfolio you can present.

Build the skills to govern AI agents. Join my next live Cohort

Your capstone brings the work together: the system you assessed, the risks you identified, the authority you defined, the controls you tested, and the conditions you recommended.

Present your decision in a five-minute live defense. Your instructor and peers challenge it from auditor, security-leader, and business-owner perspectives.

Use the completed training project to demonstrate your approach in professional development discussions, interviews, or client conversations.

Build the evidence behind your next AI-agent review.

Click on the Enroll Button and I'll see you in the Live Cohort or the Self-Paced Course.

Covered by Maven’s Satisfaction Guarantee.

Maven for Teams

Reimbursement

Get your company to pay

Everything L&D needs: email template, receipts, and certificate of completion.

Get reimbursed

Team discount

Learn with your teammates

Save 20%+ when 2 or more teammates enroll in the same cohort.

Save 20%+ with a team

Private cohort

Run a cohort for your org

A dedicated cohort with a custom schedule and curriculum, tailored to your team.

Book a private cohort

$2,500

USD

·
Sep 30Nov 7
·

2 cohorts