Agentic AI Governance for GRC & Cybersecurity

François B. Arthanas

Agentic AI Governance Educator | Founder

Assess agent risks, test controls, and defend a deployment decision.

Your team wants to put an AI agent to work. It can access records, send messages, issue refunds, or change systems. Someone has to decide what it may do and whether the evidence supports letting it do it.

⭐ Read what our students say →

In six weeks, practice making that decision from start to finish.

You will register agents and assign owners, assess risks and applicable obligations, set authority limits, test human approvals, challenge vendor claims, and investigate a simulated incident.

Each lab includes step-by-step instructions, a solution walkthrough video, and a submission with feedback.

For your individual capstone, choose an agent scenario or bring an approved workplace use case. Build the evidence, write your recommendation, and defend a Go, Conditional Go, or No-Go decision at Demo Day.

📚 Click here to view the syllabus

12 live classes. 6 office hours. A governance portfolio you can explain and adapt to your work. 24 CPE, subject to completion and attendance requirements.

No coding or prior AI experience required.

What you’ll learn

By the end of the course, you’ll be able to assess an AI agent, test its controls, and defend a deployment recommendation with evidence.

  • Build an agent inventory in VerifyWise showing what each agent does, what it can access, and who owns it.

  • Create an AI policy with testable requirements for authority limits, human approval, and shutdown.

  • Apply ISO/IEC 42001 to define who approves deployment, accepts risk, and can stop an agent.

  • Map an agent’s tools, data, dependencies, and trust boundaries to identify where it could cause harm.

  • Use the EU AI Act to assess classification and obligations, and NIST AI RMF to prioritize risk treatment.

  • Build a threat model with MITRE ATLAS and turn findings into risk treatments with named owners.

  • Define what an agent may read, change, send, or spend and which actions require human approval.

  • Configure authority limits and an approval gate in Dify, then test whether unauthorized actions are blocked.

  • Inspect traces in Opik to verify control behavior and identify where human oversight can fail.

  • Assess supplier claims and identify evidence gaps that could affect your deployment recommendation.

  • Run agent evaluations, compare automated judgments with human review, and investigate disagreements.

  • Explain what test results demonstrate, what they miss, and whether the evidence supports release.

  • Define rollout conditions, monitoring thresholds, and who must act when an agent exceeds its limits.

  • Test a model or workflow change and use regression results to decide whether it should proceed.

  • Investigate a simulated compromise, document containment, and set conditions for safe recovery.

  • Choose an agent scenario or bring an approved workplace use case for your individual capstone.

  • Assemble risks, controls, test evidence, and operating conditions into a reusable governance package.

  • Present your Go, Conditional Go, or No-Go recommendation at Demo Day and defend it with evidence.

Learn directly from François

François B. Arthanas

François B. Arthanas

I help you become the professional teams trust to govern AI agents.

Cyber Pros Training
Centene
ISACA
Trenton Health Team
Western Governors University
See all products from François B. Arthanas

Who this course is for

  • GRC, risk, audit, privacy, and compliance professionals who need to assess AI agents and defend deployment decisions.

  • Cybersecurity professionals who need to test agent permissions, investigate failures, and verify controls before and after deployment.

  • Anyone interested in AI governance who wants hands-on skills to assess agent risks, test controls, and make informed decisions.

Prerequisites

  • The Only Prerequisite

    A willingness to learn how to Govern AI Agents. Basic familiarity with GRC, cybersecurity, audit, privacy or risk work would be nice to have

  • No coding or prior AI experience required

    Session 1 explains how AI agents work, what makes them different from other automation, and where governance fits.

What's included

François B. Arthanas

Live sessions

Learn directly from François B. Arthanas in a real-time, interactive format.

12 live, interactive classes

Two 90-minute classes each week, with demonstrations, practical scenarios, breakout discussions, and time to work through governance decisions.

6 office hours and capstone support

A weekly 60-minute session for questions and feedback. Week 5 includes the Capstone Brainstorming Workshop; Week 6 includes a final clinic before Demo Day.

Hands-on labs with walkthroughs

Each lab includes step-by-step instructions, a chaptered solution walkthrough video, and a submission with feedback. Practice the work, compare your approach, and improve your reasoning.

Lifetime access to course learning materials

Return to instructional recordings, slides, lab guides, templates, and self-paced course materials when you need them.

Your VerifyWise Agentic AI Governance Workspace

Use your own workspace during the cohort to connect agent records, owners, risks, controls, suppliers, and evidence.

One year of The Agent Vault Premium

Your enrollment includes 12 months of Agent Vault Premium access.

Capstone preparation, live defense, and feedback

Every artifact compounds into one portfolio piece the evidence pack that shows you can take an agent from unknown to approved. Defend your capstone in a final presentation.

Certificate of Completion and 24 CPE with eligible participation

Earn your certificate by completing the labs, passing the capstone, and meeting participation requirements. The course provides 24 CPE; that can be used to renew your other Certifications from ISACA, ISC2, CompTIA, AIPP.

Maven Guarantee

Your purchase is backed by the Maven Guarantee.

Course syllabus

17 lessons • 5 projects

Week 1

Oct 27—Nov 1

    Lab 1.1 | Stand Up Your AI Governance Workspace

    3 items

    Frequently Asked Questions (FAQs)

    1 item

Week 2

Nov 2—Nov 8

    Lab 2.1 | Map, Classify and Threat-Model an Agent

    3 items

    Frequently Asked Questions (FAQs)

    1 item

Free resources

Schedule

Live sessions

3 hrs / week

Designed for working professionals

Hands-On Lab Work

1-2 hrs / week

Complete one lab each week in Weeks 1–5. Each lab is divided into parts you can work through after the relevant class. Begin shaping your capstone in Week 4 and complete it in Week 6. Plan additional time outside the live sessions for this work.

Optional Office Hours

1 hr / week

Hands-On Agentic AI Governance That Goes Beyond Theory - in Their Own Words💬

More here: https://testimonial.to/agentic-ai-governance/all

Frequently asked questions

Leave with an agent-governance portfolio you can present.

Build the skills to govern AI agents. Join my next live Cohort

Show the evidence behind your decision.

Your portfolio grows from the work you complete in the five guided labs. For the capstone, reuse and adapt relevant evidence for your chosen agent, then assemble it into one indexed governance package. Templates and platform records give you a starting point throughout the course.

What goes in your portfolio:

→ Agent profile and system map: what the agent does, what it can access, and who owns it.

→ Obligations, impacts, and risks: the requirements you identified and the risks you prioritized.

→ Authority and oversight: permitted actions, approval boundaries, and accountable people.

→ Supplier and test evidence: what you reviewed, what you tested, and what remains uncertain.

→ Operational requirements: release conditions, monitoring, change control, and incident recovery.

→ Decision memo: your Go, Conditional Go, or No-Go recommendation, with conditions and reasons.

Choose a capstone that fits your work

Choose a refund, hiring, invoice-payment, IT-helpdesk, coding, or patient-scheduling agent. You can also assess shadow agents and embedded vendor features, or bring an approved workplace scenario using sanitized information.

Sign up in Week 4. Shape your approach in the Week 5 workshop. Present at Demo Day and submit your final package in Week 6.

This is individual work, with peer and instructor feedback along the way.

Build the evidence behind your next AI-agent review.

Click on the Enroll Button and I'll see you in the Live Cohort or the Self-Paced Course.

Covered by Maven’s Satisfaction Guarantee.

Maven for Teams

Reimbursement

Get your company to pay

Everything L&D needs: email template, receipts, and certificate of completion.

Get reimbursed

Team discount

Learn with your teammates

Save 20%+ when 2 or more teammates enroll in the same cohort.

Save 20%+ with a team

Private cohort

Run a cohort for your org

A dedicated cohort with a custom schedule and curriculum, tailored to your team.

Book a private cohort

$2,500

USD

·
Oct 27—Dec 5
Enroll