Certificate in AI Governance Professional · 40 hours · 10 sessions
Governance you practise, not just study.
Ten sessions from the executive lens to the boardroom capstone — each anchored by a simulation where governance decisions carry consequences. Aligned to the IAPP AIGP Body of Knowledge v2.1, and delivered with the Diploma in AI Governance from SUNY Potsdam.
across 10 sessions
plus five rapid drills
EU · US · India
mapped domain by domain
The Sim Lab
Four simulations, one continuing story.
A Markstrat-style serious-game suite built for the programme. Everything runs client-side in the browser — nothing to install, and a refresh resets the run, so teams can replay a round as often as the debrief demands. Open to enrolled participants; sign in with your programme email to play.
GovernSim
/simulation/#/company-sim
A five-round, Markstrat-style company simulation against three AI competitors. Teams allocate budget across product launches, marketing, and six governance levers; the engine then computes revenue, incidents via a hazard-rate model, regulatory risk per jurisdiction, audits, and fines.
Risk Classification Lab
/simulation/#/risk-lab
Fourteen real-world AI systems, each classified against the EU AI Act risk tiers. Every card carries the legal reasoning, the exam traps that catch candidates out, and the corresponding NIST AI RMF and ISO/IEC 42001 mappings.
The Decision Game
/simulation/#/scenario
Branching role-play as a newly appointed Head of AI Governance: a biased hiring model, a hostile CHRO, a GPAI vendor contract, and a DPDP consent mess — with no charter to fall back on. Every choice moves four dials.
The Crisis Room
/simulation/#/crisis
An instructor-led, timed tabletop — “The FinBuddy Meltdown.” Five injects carry the room from a viral thread to an emergency board session, with countdown timers, hidden facilitator notes, and an after-action checklist.
New · Timed triage game
Cascade — three alarms, one team
Four waves, and each one lands an Analytical, a GenAI and an Agentic incident at once against a countdown. Dispatch them in the right order and answer each class on its own terms: analytical failures punish haste, generative ones punish deliberation, agentic ones punish negotiation. One reflex applied to all three is how organisations lose.
Try it first
Play GovernSim now, no sign-up.
The flagship simulation, first two rounds, running in your browser. No account, no email, nothing stored — close the tab and it is as if you were never here.
Free preview · no sign-in
Run Veritas Digital for two rounds
You take over a mid-size fintech with four AI systems ready to ship and no governance programme. $12M a round, three rivals, and every dollar you spend on compliance is one you didn’t spend on growth. Round 2 is where that starts to show.
- Rounds 1–2 of 5
- About 10 minutes
- Nothing saved, nothing tracked
The full five rounds, the Risk Lab, the Decision Game, the Crisis Room and the drill decks are part of the programme.
Programme map
One session. One simulation. Every day.
Ten four-hour sessions following the CAIGP syllabus. Each row links straight into the activity that anchors that session.
The Executive Lens on AI
AI taxonomy · seven categories of AI harm · why traditional governance fails · board-grade KPIs
Diagnose six real AI failures — Air Canada, Amazon, the Dutch scandal, Apple Card, deepfake scams, escaping agents — and name the guardrail that failed first.
Building the Governance Backbone
Decision rights from board to model owner · cross-functional alignment · AI literacy · the developer–deployer–user accountability chain
Play the newly appointed Head of AI Governance: a biased hiring model, a hostile CHRO, and no charter. Every choice moves four dials.
Future-Proofing Enterprise Policy
Meaningful human oversight · policy gaps AI exploits · third-party and vendor AI risk · cross-border data flows across ASEAN, GCC, India and the EU
Eight clauses from an AI vendor contract, one read-through before signature. Sign or red-line — and learn which clause caused Day 10’s crisis.
The Privacy & Data Protection Battleground
Notice, consent and purpose limitation when models repurpose data · Privacy by Design · controller/processor obligations · special-category and inference data
Eight scenarios across DPDP, GDPR and Malaysia’s PDPA. Decide what the law actually requires when AI meets personal data.
Sectoral Crossfire
The IP minefield across training data, models, outputs and prompts · algorithmic discrimination · consumer protection and synthetic media · product liability when the product learns
One AI product, five bodies of old law. Identify the primary legal exposure in six scenarios — AI usually breaks the ordinary law you forgot applied.
Decoding the EU AI Act
Risk-tier framework · conformity obligations and technical documentation · GPAI obligations · penalties up to €35M / 7% · the Brussels Effect
Fourteen real-world AI systems. Classify each under the EU AI Act tiers — with the legal reasoning, the exam traps, and NIST/ISO mappings.
Anchoring to Global Standards
OECD Principles · NIST AI RMF · ISO/IEC 42001, 42005 and 22989 · Singapore MAIGF and AI Verify · ASEAN Guide · UAE AI Charter · SDAIA · India MeitY and DPDP
Eight situations, one alphabet soup. Pick the instrument that answers each need — and learn which regimes bite, which certify, and which merely signal.
Governing the AI Lifecycle, End to End
Design with intention · data governance and training integrity · deployment gates, monitoring and drift · assurance, audit and incident response · responsible retirement
Teams take over Veritas Digital and run the first three rounds: build the program, classify and comply, govern development. Instructor debrief between rounds.
Applied Workshop & Regional Deep-Dive
Participants apply the full framework stack to their own organisation’s AI inventory and exposure, in a facilitated working session
Deploy at scale, then survive the audit sweep. Final league table and debrief — then teams map the same levers onto their own organisation’s AI inventory.
Capstone Build & Board Simulation
Charter drafting · roadmap prioritisation · board-level presentation simulation
The FinBuddy Meltdown: five timed injects from viral thread to emergency board session. Teams present their governance verdict to the class as the board.
How the days connect
The activities are one continuing story. The vendor clause you red-line on Day 3 is the clause that detonates in Day 10’s crisis. The purpose-limitation rule from Day 4 is why GovernSim fines you in Round 2. The ISO/IEC 42001 standard you map on Day 7 is the certification your team buys — or skips — on Day 8. By Day 10, every failure in the boardroom has a name the class already knows.
Coverage
The instruments that actually bite.
Participants leave able to tell which regimes carry penalties, which offer certification, and which merely signal intent.
- EU AI ActRisk tiers, GPAI duties, penalties to €35M / 7%
- GDPRLawful basis, purpose limitation, automated decisions
- India DPDP ActConsent, notice, data-fiduciary obligations
- Malaysia PDPAAmendments and sectoral guidelines
- ISO/IEC 42001AI management systems — certifiable
- ISO/IEC 42005 · 22989Impact assessment, concepts and terminology
- NIST AI RMFGovern, Map, Measure, Manage
- AI VerifySingapore’s testing toolkit
- OECD AI PrinciplesThe reference vocabulary most regimes borrow
- Singapore MAIGFModel AI Governance Framework
- ASEAN GuideRegional guidance on AI governance and ethics
- UAE AI Charter · SDAIAGulf-region instruments
Bring the Sim Lab to your leadership team.
The programme runs as a cohort for enterprises and as an open certification track. The simulations are part of the programme: enrolled participants sign in with their programme email and can replay every activity as often as they like.