Founder | Agentic AI Governance Advisor

Framework knowledge alone does not answer the question leadership actually asks: “Can we deploy this AI agent?” Legal wants classification. Risk wants failure scenarios. Security wants controls. Audit wants evidence. Leadership wants a decision.
In this live one-day workshop, you will govern one realistic recruiting agent from initial review to deployment decision. I will show you how to use NIST AI RMF 1.0 to identify its highest-priority risks, the EU AI Act to determine role and classification, ISO/IEC 42001 to connect the agent to organizational governance, and AIUC-1 to select agent-specific safeguards and evidence.
Then you will connect the work:
Agent → Risk → Requirement → Control → Evidence → Decision
You will leave with a reusable Four-Framework Agent Governance Map and a one-page recommendation to approve, conditionally approve, restrict, pilot, or pause the agent.
Built for GRC, cybersecurity, risk, compliance, audit, and AI governance professionals. No coding or prior framework expertise required.
Become the practitioner who can apply four AI governance frameworks to one agent and defend an evidence-backed deployment decision.
Map the agent’s purpose, users, data, tools, memory, third parties, human oversight, and affected people.
Separate recommendations from actions to see what the agent can read, write, decide, communicate, or execute.
Complete a focused Agent Context and Authority Profile using the provided enterprise case.
Apply Govern, Map, Measure, and Manage directly to the agent’s context, risks, evidence, and treatment decisions.
Write three cause–event–impact risks covering people, business operations, security, and compliance.
Document the owner, current safeguard, and treatment decision for each priority risk.
Work through prohibited-practice, high-risk, and transparency screens using a guided decision tree.
Define the monitoring signals you'd require before this agent goes live.
Identify priority duties for data governance, logging, human oversight, robustness, security, and monitoring.
Connect the agent to ISO/IEC 42001 processes for accountability, impact assessment, suppliers, change, monitoring, and improvement.
Select AIUC-1 safeguards across data and privacy, security, safety, reliability, accountability, and society.
Name the policy, configuration, log, test result, approval, or vendor record that can serve as evidence.
Map the same risk and control across all four frameworks without treating similar language as equivalent.
Identify direct, partial, supporting, and non-applicable relationships and expose the remaining control gaps.
Leave with a reusable governance map and a recommendation to approve, restrict, pilot, pause, or reject the agent.
Meet TalentFlow, the fictional recruiting agent you’ll govern all day. Examine its access, influence, and failure modes - then make an initial approve, restrict, or pause decision.
Apply Govern, Map, Measure, and Manage. Document TalentFlow’s three priority risks, existing safeguards, risk owners, and initial treatment decisions.
Drink something!
Determine whether the Act applies, your organization’s provider or deployer role, and TalentFlow’s likely classification. Identify the priority obligations that follow.
Follow one risk from a NIST risk statement to an EU AI Act obligation and shared control objective. Then complete the same connection for one of your priority risks.
Go eat something!
Move from requirements to the processes that sustain governance. Connect TalentFlow to accountability, impact assessment, supplier and change management, monitoring, and corrective action.
Translate priority risks into practical safeguards. Select controls across AIUC-1’s six domains and identify the evidence that proves each safeguard exists and operates.
Map three control themes across all four frameworks: human oversight, candidate data and fairness, and security, reliability, and monitoring. Find alignment, partial coverage, and missing evidence.
Revisit your 9:00 AM decision. Recommend approve, approve with conditions, pilot, pause, or reject and document the conditions, accountable owner, and reassessment trigger.

Founder of CyberProsAI | Agentic AI Governance Advisor | CISSP, CISA, AAIA™



GRC, cybersecurity, compliance, audit, privacy, and vendor-risk professionals responsible for reviewing or approving enterprise AI agents.
AI governance and Responsible AI professionals who need to apply four major frameworks to one agent and produce defensible evidence.
Consultants, advisors, and emerging practitioners seeking a repeatable method to assess AI agents and recommend approval or remediation.
No coding, machine-learning, legal training, or prior experience with all four frameworks is required. You will follow a guided case.
You only need enough professional context to participate in governance decisions and follow the guided framework walkthroughs.

Live sessions
Learn directly from François B. Arthanas in a real-time, interactive format.
Lifetime access
Go back to course content and recordings whenever you need to.
Community of peers
Stay accountable and share insights with like-minded professionals.
Certificate of completion
Share your new skills with your employer or on LinkedIn.
Maven Guarantee
Your purchase is backed by the Maven Guarantee.
Maven for Teams
Reimbursement
Get your company to pay
Everything L&D needs: email template, receipts, and certificate of completion.
Get reimbursedTeam discount
Learn with your teammates
Save 20%+ when 2 or more teammates enroll in the same cohort.
Save 20%+ with a teamPrivate cohort
Run a cohort for your org
A dedicated cohort with a custom schedule and curriculum, tailored to your team.
Book a private cohort$297
USD
11am–5pm EDT