Certificate in AI Governance Professional · 40 hours · 10 sessions

Governance you practise, not just study.

Ten sessions from the executive lens to the boardroom capstone — each anchored by a simulation where governance decisions carry consequences. Aligned to the IAPP AIGP Body of Knowledge v2.1, and delivered with the Diploma in AI Governance from SUNY Potsdam.

Sign in to the Sim LabSee the 10-session mapRuns in the browser · no install · enrolled participants only
40
Contact hours
across 10 sessions
4
Core simulations
plus five rapid drills
3
Jurisdictions modelled
EU · US · India
AIGP v2.1
IAPP Body of Knowledge
mapped domain by domain

The Sim Lab

Four simulations, one continuing story.

A Markstrat-style serious-game suite built for the programme. Everything runs client-side in the browser — nothing to install, and a refresh resets the run, so teams can replay a round as often as the debrief demands. Open to enrolled participants; sign in with your programme email to play.

New · Timed triage game

Cascade — three alarms, one team

Four waves, and each one lands an Analytical, a GenAI and an Agentic incident at once against a countdown. Dispatch them in the right order and answer each class on its own terms: analytical failures punish haste, generative ones punish deliberation, agentic ones punish negotiation. One reflex applied to all three is how organisations lose.

4 waves · 75–120s eachSequencing + response scored~15 min · replayable

Try it first

Play GovernSim now, no sign-up.

The flagship simulation, first two rounds, running in your browser. No account, no email, nothing stored — close the tab and it is as if you were never here.

Free preview · no sign-in

Run Veritas Digital for two rounds

You take over a mid-size fintech with four AI systems ready to ship and no governance programme. $12M a round, three rivals, and every dollar you spend on compliance is one you didn’t spend on growth. Round 2 is where that starts to show.

  • Rounds 1–2 of 5
  • About 10 minutes
  • Nothing saved, nothing tracked
Start the preview →

The full five rounds, the Risk Lab, the Decision Game, the Crisis Room and the drill decks are part of the programme.

Programme map

One session. One simulation. Every day.

Ten four-hour sessions following the CAIGP syllabus. Each row links straight into the activity that anchors that session.

01
M1 · 4 hrs

The Executive Lens on AI

AI taxonomy · seven categories of AI harm · why traditional governance fails · board-grade KPIs

Activity → The Failure Files

Diagnose six real AI failures — Air Canada, Amazon, the Dutch scandal, Apple Card, deepfake scams, escaping agents — and name the guardrail that failed first.

02
M2 · 4 hrs

Building the Governance Backbone

Decision rights from board to model owner · cross-functional alignment · AI literacy · the developer–deployer–user accountability chain

Activity → The Decision Game

Play the newly appointed Head of AI Governance: a biased hiring model, a hostile CHRO, and no charter. Every choice moves four dials.

03
M3 · 4 hrs

Future-Proofing Enterprise Policy

Meaningful human oversight · policy gaps AI exploits · third-party and vendor AI risk · cross-border data flows across ASEAN, GCC, India and the EU

Activity → Vendor Red-Line

Eight clauses from an AI vendor contract, one read-through before signature. Sign or red-line — and learn which clause caused Day 10’s crisis.

04
M4 · 4 hrs

The Privacy & Data Protection Battleground

Notice, consent and purpose limitation when models repurpose data · Privacy by Design · controller/processor obligations · special-category and inference data

Activity → The Privacy Battleground

Eight scenarios across DPDP, GDPR and Malaysia’s PDPA. Decide what the law actually requires when AI meets personal data.

05
M5 · 4 hrs

Sectoral Crossfire

The IP minefield across training data, models, outputs and prompts · algorithmic discrimination · consumer protection and synthetic media · product liability when the product learns

Activity → Sectoral Crossfire

One AI product, five bodies of old law. Identify the primary legal exposure in six scenarios — AI usually breaks the ordinary law you forgot applied.

06
M6 · 4 hrs

Decoding the EU AI Act

Risk-tier framework · conformity obligations and technical documentation · GPAI obligations · penalties up to €35M / 7% · the Brussels Effect

Activity → Risk Classification Lab

Fourteen real-world AI systems. Classify each under the EU AI Act tiers — with the legal reasoning, the exam traps, and NIST/ISO mappings.

07
M7 · 4 hrs

Anchoring to Global Standards

OECD Principles · NIST AI RMF · ISO/IEC 42001, 42005 and 22989 · Singapore MAIGF and AI Verify · ASEAN Guide · UAE AI Charter · SDAIA · India MeitY and DPDP

Activity → Standards Mapper

Eight situations, one alphabet soup. Pick the instrument that answers each need — and learn which regimes bite, which certify, and which merely signal.

08
M8 · 4 hrs

Governing the AI Lifecycle, End to End

Design with intention · data governance and training integrity · deployment gates, monitoring and drift · assurance, audit and incident response · responsible retirement

Activity → GovernSim — Rounds 1–3

Teams take over Veritas Digital and run the first three rounds: build the program, classify and comply, govern development. Instructor debrief between rounds.

09
S9 · 4 hrs

Applied Workshop & Regional Deep-Dive

Participants apply the full framework stack to their own organisation’s AI inventory and exposure, in a facilitated working session

Activity → GovernSim — Rounds 4–5

Deploy at scale, then survive the audit sweep. Final league table and debrief — then teams map the same levers onto their own organisation’s AI inventory.

10
S10 · 4 hrs

Capstone Build & Board Simulation

Charter drafting · roadmap prioritisation · board-level presentation simulation

Activity → The Crisis Room

The FinBuddy Meltdown: five timed injects from viral thread to emergency board session. Teams present their governance verdict to the class as the board.

How the days connect

The activities are one continuing story. The vendor clause you red-line on Day 3 is the clause that detonates in Day 10’s crisis. The purpose-limitation rule from Day 4 is why GovernSim fines you in Round 2. The ISO/IEC 42001 standard you map on Day 7 is the certification your team buys — or skips — on Day 8. By Day 10, every failure in the boardroom has a name the class already knows.

Coverage

The instruments that actually bite.

Participants leave able to tell which regimes carry penalties, which offer certification, and which merely signal intent.

Binding regulation
  • EU AI ActRisk tiers, GPAI duties, penalties to €35M / 7%
  • GDPRLawful basis, purpose limitation, automated decisions
  • India DPDP ActConsent, notice, data-fiduciary obligations
  • Malaysia PDPAAmendments and sectoral guidelines
Standards & assurance
  • ISO/IEC 42001AI management systems — certifiable
  • ISO/IEC 42005 · 22989Impact assessment, concepts and terminology
  • NIST AI RMFGovern, Map, Measure, Manage
  • AI VerifySingapore’s testing toolkit
Principles & regional
  • OECD AI PrinciplesThe reference vocabulary most regimes borrow
  • Singapore MAIGFModel AI Governance Framework
  • ASEAN GuideRegional guidance on AI governance and ethics
  • UAE AI Charter · SDAIAGulf-region instruments

Bring the Sim Lab to your leadership team.

The programme runs as a cohort for enterprises and as an open certification track. The simulations are part of the programme: enrolled participants sign in with their programme email and can replay every activity as often as they like.

See our AI strategy practiceDelivered with 360DigiTMG.