Agentic AI Governance for GRC & Cybersecurity

François B. Arthanas

Ph.D. Scholar, CISSP, CISA, AAIA™, CDPSE

Everyone builds AI agents. Few can GOVERN what they do. Become the one who can.

🚨 Save $500 with code CYB500 applied automatically:

September Day CohortEnroll here · code expires Aug 31

October Night CohortEnroll here · code expires Oct 10

A chatbot that fails gives a wrong answer. An AI agent that fails takes a wrong action it approves the refund, emails the customer, and updates the CRM before any human looks.

That's what you are being asked to govern, with controls built for software that never acts on its own.

In this live 8-week cohort for GRC, risk, audit, privacy, and cybersecurity professionals. 16 live sessions. 10+ hands-on labs. You will govern SupportFlow, a working refund agent that reads records, drafts replies, and moves money and leave with a complete governance portfolio: registry, threat model, test results, decision memo that you can defend live.

Built on AIUC-1 (https://www.aiuc-1.com/). Mapped to NIST AI RMF, ISO/IEC 42001, the EU AI Act, the OWASP Agentic Top 10, MITRE ATLAS, and CSA MAESTRO.

16 live sessions · 10+ hands-on labs · Rated 5.0 by students

Take one AI agent from discovery to an evidence-backed governance decision.

What you’ll learn

By the end of this course, you will take one AI agent from discovery to an evidence-backed governance decision.

  • Discover approved, embedded, vendor-provided, and shadow agents and separate true agents from AI features and plain automation

  • Build an Enterprise AI Inventory and Agent Registry with owners, risk flags, and material-change triggers

  • Work in VerifyWise, the live AI Governance workspace platform you set up in Lab 0 and use all course

  • Map architecture, data flows, and trust boundaries into a one-page Boundary Board

  • Write an Agent Authority Matrix read, draft, send, spend, or delete with approval gates and a defensible risk tier

  • Apply least privilege to agent identities, data, tools, credentials, and MCP connections

  • Apply the OWASP Agentic Top 10, MITRE ATLAS, and CSA MAESTRO to a working agent

  • Test prompt injection, memory poisoning, tool misuse, and data exfiltration

  • Turn results into reproducible evidence and a remediation backlog

  • Build a Harm Assessment and Safety Requirements Register for foreseeable misuse

  • Evaluate accuracy, tool-call correctness, and safe refusal then set release thresholds

  • Run golden tests, edge cases, and cascading-failure scenarios

  • Design approval gates, kill switches, rollback, and escalation with a governance RACI

  • Stand up logging, drift monitoring, and an agent incident-response runbook

  • Vet vendors, models, and subagents with an AI Bill of Materials and due-diligence assessment

  • Crosswalk one control set to AIUC-1, NIST AI RMF, ISO 42001, and the EU AI Act and reuse the evidence

  • Use your learnings to build a real-world enterprise capstone that that can be shared on LinkedIn and GitHub

  • Present your final project to the class

Learn directly from François

François B. Arthanas

François B. Arthanas

Founder of CyberProsAI | Agentic AI Governance Advisor | CISSP, CISA, AAIA™

Cyber Pros Training
Centene
ISACA
Trenton Health Team
Western Governors University
See all products from François B. Arthanas

Who this course is for

  • GRC, risk, and AI governance leads told to “Own AI Governance” as agents enter scope you need an operating model, not another policy

  • Cybersecurity architects and engineers asked to sign off on agents that touch identity, credentials, MCP servers, and production systems

  • Auditors, privacy pros, and DPOs and anyone who knows agents are coming and wants to be the person trusted to evaluate them

Prerequisites

  • The Only Prerequisite

    A willingness to learn how to Govern AI Agents. Basic familiarity with GRC, cybersecurity, audit, privacy or risk work would be nice to have

  • No AI/ML and Coding Background Required

    Session 1 covers how LLMs and agents actually work, in plain language. You build the AI foundation in week 1 - skepticism welcome

What's included

François B. Arthanas

Live sessions

Learn directly from François B. Arthanas in a real-time, interactive format.

10+ Hands-On Labs on a Working AI Agent

You don't study governance you do it. Govern SupportFlow, a live refund agent that reads records, drafts replies, and moves money.

Reusable Templates for Every Artifact

Registry, authority matrix, threat model, test plan, decision memo take each template back to work and run it on your own agents.

Your Governance Workspace in VerifyWise

Set up in Lab 0, used all course. You leave knowing how to run agent governance in a real GRC tool, not a slide deck.

Recordings of Every Session

Miss a session, catch up the same day. Recordings, slides, and lab guides are there when work gets in the way.

Office Hours & Community

Once a week for 60 minutes. Bring your deliverable drafts, your career questions, your workplace challenges and get personalized coaching. We also have a dedicate private community for ongoing discussions, updated templates, job opportunities, peer networking, and direct access to the instructor.

Access to curated Agentic AI Governance Resources

We have curated a large collection of Agentic AI Governance Practitioner approved free resources for you to continue your learning journey.

The complete Agent Governance Portfolio & Capstone

Every artifact compounds into one portfolio piece the evidence pack that shows you can take an agent from unknown to approved. Defend your capstone against security, legal, privacy, and business challenges.

Certificate of Completion

Share your new skills with your employer or on LinkedIn.T he portfolio behind it is what proves the work. This can be used for 20 CPE that can be used to renew your other Certifications from ISACA, ISC2, CompTIA, AIPP.

Maven Guarantee

Your purchase is backed by the Maven Guarantee.

Course syllabus

16 lessons • 8 projects

Week 1

Sep 15—Sep 20

    Introduction & Our Favorite Agentic AI Governance Tools

    4 items

    [Lab 0] VerifyWise Setup and The SupportFlow Agent

    1 item

    [Lab 1]: Map the Agent: Scope, Authority, and Risk Tiering

    1 item

    FAQs, Links & Additional Resources

    2 items

Week 2

Sep 21—Sep 27

    [Lab 2] Follow the Data: Privacy, PII, and Leakage Evidence

    1 item

    FAQs, Links & Additional Resources

    2 items

Free resource

Field Notes LIVE: Who Can Shut It Down? cover image

Field Notes LIVE: Who Can Shut It Down?

What Actually Happened

We will unpack the Hugging Face and Anthropic incidents in plain language and discuss what made them different.

Where the Controls Broke Down

Was this a model problem, a security failure, an evaluation failure, a governance failure or a combination of all four?

Who Can Shut Down the Agent

Who should have the authority to pause or stop an AI agent, and what should trigger that decision?

Schedule

Live sessions

3-5 hrs / week

Designed for working professionals

Projects

2-3 hrs / week

AI is no longer only producing content. It is taking action.

Build the skills to govern AI agents. Join our next LIVE Agentic AI Governance Cohort

Why this course is different? You May Ask.

Simple: One agent, governed end-to-end. Most AI governance training is a framework tour - you leave knowing what NIST says and not knowing what to do. - NOT - in this course, Here, every session moves the same agent one step closer to an approval decision. By week 8, you've done the whole job once. That's what makes it repeatable.

One spine. Every major framework mapped to it. AIUC-1 is the backbone. NIST AI RMF, ISO/IEC 42001, the EU AI Act, WEF ACAP, Singapore's agentic AI framework, the OWASP Agentic Top 10, MITRE ATLAS, and CSA MAESTRO are mapped against it as you work. You do the work once and reuse the evidence everywhere instead of running eight parallel checklists.

Built for agents, not adapted from chatbot guidance. Agent authority tiers. Non-human identity. MCP and tool security. Memory poisoning. Agent-to-agent trust. Kill switches and recoverability. These aren't add-on slides they're the curriculum.

Live cohort, real pressure. You get feedback on your actual artifacts, not a quiz score. And the course ends the way real governance ends: defending your decision in front of real people that ask questions.

Frequently asked questions

Maven for Teams

Reimbursement

Get your company to pay

Everything L&D needs: email template, receipts, and certificate of completion.

Get reimbursed

Team discount

Learn with your teammates

Save 20%+ when 2 or more teammates enroll in the same cohort.

Save 20%+ with a team

Private cohort

Run a cohort for your org

A dedicated cohort with a custom schedule and curriculum, tailored to your team.

Book a private cohort

$2,497

USD

Sep 15Nov 7
·

1 more cohort