2-Day Executive Certification

Vision: The GRC Officer Certification

An intensive professional curriculum integrating Governance, Risk & Compliance with Cybersecurity, IT Governance, and AI Resilience — designed for GRC Officers, CISOs and IT Audit Leaders navigating GDPR, the EU AI Act, and modern cyber-risks.

Day 1 – Foundations and Quantitative Risk in Technology GRC Click to expand or collapse

Part 1 – Governance Foundations for Technology, AI, and Cybersecurity

  • Scope and objectives
    • Align governance with digital strategy, AI adoption, and cyber risk
    • Create enforceable accountability with minimal bureaucracy
    • Translate ISO principles into operating models
  • Core standards and references
    • ISO 31000, ISO 37301, ISO 27001, ISO 22301
    • OECD AI Principles, NIST AI RMF (contextual reference)
  • Key concepts and components
    • Governance vs management vs operations
    • Three lines model in tech-heavy organizations
    • Board, executive, and product-level governance
  • RACI and accountability design
    • Build RACI for AI systems, data assets, and cyber controls
    • Distinguish accountability vs execution
    • Avoid shared accountability traps
    • Map RACI to job descriptions and incentives
  • Practices and workshops
    • Build a RACI for an AI-powered product
    • Rewrite a weak policy into an enforceable one
    • Design a governance calendar for a global tech firm

Part 2 – Quantitative Risk Management and Cyber Risk Modeling

  • Scope and objectives
    • Move from qualitative to quantitative risk
    • Support investment, sourcing, and security decisions
  • Quantification fundamentals
    • Loss distributions vs point estimates
    • Frequency and severity separation
    • Correlation and dependency concepts
  • Monte Carlo simulation
    • When and why to use it
    • Inputs, assumptions, and pitfalls
    • Interpreting outputs for executives
Day 2 – Compliance, Technology Controls, Audit, and Optimization Click to expand or collapse

Part 3 – Compliance Management in Global and Digital Contexts

  • Scope and objectives
    • Systematize compliance across jurisdictions
    • Reduce noise and focus on material obligations
  • Practices and workshops
    • Build a compliance obligation register
    • Extract controls from a regulation clause
    • Design a third-party due diligence flow

Part 4 – Technology, AI, Audit, and Process Optimization

  • Scope and objectives
    • Embed controls into technology and operations
    • Enable continuous assurance and efficiency
  • Responsible AI governance
    • Model inventory and classification
    • Controls across training, deployment, and monitoring
    • Human oversight and accountability

2nd-3rd March 2026 at 9:00 AM (CET) to 4:40 PM CET