Microsoft

Governance and Compliance Management

Microsoft

Governance and Compliance Management

 Microsoft

Instructor: Microsoft

Included with Coursera PlusLearn more

Ask Coursera

Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

9 hours to complete
Flexible schedule
Learn at your own pace
Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

9 hours to complete
Flexible schedule
Learn at your own pace

What you'll learn

  • Assign AI governance responsibilities using a RACI matrix and circulate for executive sign-off.

  • Analyze policy gaps against Microsoft’s Responsible AI Standard v2 and manage a remediation backlog.

  • Map ISO/IEC 42001 controls to AI systems and evaluate SOC 2 audit readiness.

  • Draft AI security policy sections and evaluate policy compliance exception requests.

Details to know

Shareable certificate

Add to your LinkedIn profile

Recently updated!

July 2026

Assessments

26 assignments¹

AI Graded see disclaimer
Taught in English

See how employees at top companies are mastering in-demand skills

 logos of Petrobras, TATA, Danone, Capgemini, P&G and L'Oreal

Build your Security expertise

This course is part of the Microsoft Enterprise AI Governance, Ethics & Security Professional Certificate
When you enroll in this course, you'll also be enrolled in this Professional Certificate.
  • Learn new concepts from industry experts
  • Gain a foundational understanding of a subject or tool
  • Develop job-relevant skills with hands-on projects
  • Earn a shareable career certificate from Microsoft

There are 11 modules in this course

This module introduces the AI Governance RACI matrix as a practical accountability tool, walking learners through how to assign and validate roles across executive leadership, model owners, and audit functions in the context of an Large Language Model (LLM) rollout—and how to prepare the completed matrix for stakeholder sign-off.

What's included

2 videos1 reading3 assignments

This module guides learners through a structured AI governance gap analysis process. Using the Microsoft Responsible AI Standard v2 as the benchmark, learners evaluate existing information security policies, identify misalignments or deficiencies, and translate findings into a prioritized remediation backlog. The resulting backlog serves as a governance artifact used to support audit readiness and policy alignment across AI systems.

What's included

2 videos2 readings2 assignments

This module develops learners' ability to interpret AI governance program health through KPI dashboards and translate quantitative trends into actionable charter or operating model recommendations—a critical skill for communicating governance status to senior leadership and program steering committees.

What's included

1 video2 readings3 assignments

This module introduces the ISO/IEC 42001 AI management system standard and demonstrates how governance teams translate its control requirements into operational compliance documentation. Learners will map relevant ISO 42001 controls to a specific AI system by identifying where each control applies across the system's lifecycle, assessing the current implementation status (implemented, partially implemented, or not implemented), and documenting the results within a compliance control matrix. The resulting matrix becomes a core governance artifact used to track control coverage, identify compliance gaps, and support internal assurance reviews and external certification audits. By the end of the module, learners will understand how structured control mapping transforms ISO requirements into actionable governance documentation that supports both AI system oversight and audit readiness.

What's included

3 videos2 readings3 assignments

This module develops learners' ability to evaluate the quality, completeness, and traceability of audit evidence and map it to SOC 2 Security and Confidentiality Trust Services Criteria. Learners will assess whether provided evidence sufficiently supports control operation, identify gaps or insufficiencies, and determine whether controls can be considered effectively implemented in preparation for an external audit. By the end of the module, learners will be able to inspect audit artifacts and flag evidence deficiencies before formal auditor review, reducing the risk of late-stage audit findings.

What's included

2 videos1 reading2 assignments

This module builds applied evaluation skills for SOC 2 audit readiness. Learners interpret compliance drift findings — where previously effective controls have degraded due to process, system, or ownership changes — and assess their impact on audit readiness. Learners then translate these findings into an executive briefing that supports a clear pass/fail (go/no-go) recommendation for an upcoming SOC 2 audit. The focus is on converting technical audit findings into clear, decision-oriented leadership communication.

What's included

1 video2 readings3 assignments

This module builds the foundational understanding needed to draft an AI security policy section. Learners explore how AI security policy differs from traditional IT security policy, how ISO/IEC 42001 clauses—along with EU AI Act Article 15 obligations and OWASP LLM Top 10 2025 risk categories—inform policy structure, and how corporate policy templates are organized to support CISO-level review and governance approval. The focus is on understanding policy structure, standards alignment, and template design patterns that enable consistent and audit-ready AI governance documentation in later applied modules.

What's included

2 videos2 readings1 assignment

This module transitions learners from foundational understanding to applied policy development. Learners use a structured corporate policy template to draft an AI Model Security and Monitoring policy section, ensuring alignment with ISO/IEC 42001 clauses, EU AI Act Article 15 cybersecurity obligations, and OWASP LLM Top 10 2025 risk categories and enterprise governance requirements. Learners then self-check the draft against these frameworks before submission. The resulting artifact must be suitable for CISO submission, meaning it is structured, enforceable, and traceable to recognized AI governance standards.

What's included

2 readings3 assignments

This module introduces the policy exception review framework—covering what exception requests are, how risk is assessed against policy requirements, and what a well-structured ServiceNow exception ticket looks like before a reviewer makes an approve or deny decision.

What's included

1 video2 readings1 assignment

This module applies the policy exception review framework in a realistic governance workflow. Learners evaluate two ServiceNow-based policy exception requests submitted by product teams, assess each request using structured risk criteria, and determine whether to approve, deny, or escalate the exception. For each case, learners must document a clear and defensible rationale that reflects governance standards for risk evaluation, compensating control assessment, and alignment with policy compliance. The final output simulates real-world exception decision records used in security and AI governance programs.

What's included

2 readings3 assignments

In this capstone project, learners produce a portfolio-ready AI Governance and Compliance artifact—a consolidated governance deliverable that integrates accountability, compliance mapping, policy development, and exception management work. The final artifact reflects the type of governance documentation package an AI program lead or security governance manager would assemble when establishing or maturing an organizational AI governance program. Learners will synthesize governance role definitions, compliance control mapping, policy documentation, and exception review frameworks into a single structured deliverable aligned with recognized governance standards such as ISO/IEC 42001 and audit frameworks such as SOC 2. The completed portfolio piece demonstrates the learner's ability to translate governance principles into operational documentation suitable for internal leadership review, audit readiness, and program implementation.

What's included

1 video2 readings2 assignments

Earn a career certificate

Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.

Instructor

 Microsoft
404 Courses2,735,638 learners

Offered by

Microsoft

Explore more from Security

Why people choose Coursera for their career

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."

Frequently asked questions

¹ Some assignments in this course are AI-graded. For these assignments, your data will be used in accordance with Coursera's Privacy Notice.