Courses that leave you with real work done.
Each course is built around a task you do at work, like running a SOC 2, answering a breach, or putting AI to use safely. You finish with a working deliverable built on your own organization, whether you are a team of five or five thousand, and a certificate anyone can verify.
87 courses across 12 domains. Jump to one:
Concepts you hear but never learned
Sixteen ten-minute lessons, free to every member. 0.25 ALC each, 4 ALCs toward the Foundations Certificate.
Open the series to read every term in full.
Bridge letter
A bridge letter, sometimes called a gap letter, is a short statement from a service organization covering the period between the end of its most recent SOC report and the…
CUEC
Complementary user entity controls are the controls a SOC report assumes you, the customer, operate. Every service organization's control objectives depend on some things…
Subservice organisation and carve-out
A subservice organization is a vendor of your vendor whose controls matter to the service you receive: the cloud provider the software runs on, the data centre, the…
Global Privacy Control (GPC)
Global Privacy Control is a browser signal. When it is switched on, the browser sends a header and exposes a flag on every request saying that the user opts out of the…
TCF and consent strings
The Transparency and Consent Framework is an industry standard, maintained by the IAB in Europe, for passing a user's consent choices through the advertising supply…
SBOM and VEX
A software bill of materials is a parts list for software: every component, library and dependency in a build, with versions, expressed in a machine-readable format such…
Statement of Applicability
The Statement of Applicability is the ISO 27001 document that lists every control in the standard's Annex A, states whether each applies to your organization, gives the…
ITGC
IT general controls are the controls over the technology environment that financial and other application controls depend on. Auditors group them into four areas…
Legitimate interest and the balancing test
Legitimate interests is one of the six lawful bases for processing personal data under GDPR. It allows processing that is necessary for a genuine interest of the…
Article 28 processor terms
Article 28 of GDPR sets the mandatory terms of any contract between a controller and a processor. The contract has to bind the processor to act only on the controller's…
Business associate agreement
A business associate agreement is the contract that HIPAA requires between a covered entity, such as a healthcare provider or health plan, and any organization that…
Risk acceptance and expiry
Risk acceptance is a decision by someone with the authority to make it that a known risk will not be treated further for now. It is a legitimate outcome of risk…
Type I versus Type II
A SOC 2 Type I report describes a service organization's controls and gives an auditor's opinion on whether they are suitably designed at a single point in time. A Type…
Data processing agreement versus data protection addendum
Both are abbreviated DPA, and both deal with how a vendor handles personal data, which is why they are confused. A data processing agreement is a standalone contract, or…
Suppression list
A suppression list is the set of contacts an organization must not market to: people who unsubscribed, objected, opted out of sale, asked by phone not to be called, or…
Population and sample
When an auditor tests a control, they start by defining the population: the complete set of instances in which the control should have operated during the period. Every…
Digital Trust Foundations
What Digital Trust Means in Your Job
Trust, privacy and security obligations land on every job, not just the security team's. Find out exactly which ones your role carries and how to prove you meet them.
Ethics and Judgement Calls for Practitioners
Sooner or later someone will ask you to sign something you're not sure is true. This course prepares you for the judgment calls that come with trust work.
Reading a Regulation Without a Lawyer
You don't need a law degree to work out what a regulation asks of you. Turn articles into obligations, owners and evidence you can act on.
Privacy & Data Protection
AI in Privacy Operations: Requests, Records and Notices
Access requests, records of processing and privacy notices are slow, repetitive work. Let AI speed them up while your team keeps the decisions and the deadlines.
GDPR in Practice: From Articles to an Operating Program
GDPR has 99 articles, but running a program comes down to a handful of decisions. Make them, and leave with a working plan for the next 12 months.
US State Privacy Laws in Practice: CCPA/CPRA and the Rest
More US states have their own privacy law every year. Work out which apply to you and handle opt-outs, GPC and sensitive data with one standard.
HIPAA in Practice for HealthTech and Business Associates
Business associates carry real HIPAA duties, and most learn that in an audit. Know what applies, what your BAA should say and how to apply minimum necessary in product design.
Data Subject Rights Operations: GDPR, CCPA and HIPAA Access
Access and deletion requests have deadlines, and they arrive in bursts. Handle them across GDPR, CCPA and HIPAA from intake to evidence file.
Building a Record of Processing and Data Inventory That Survives Audit
Records of processing are usually wrong within months. Build one from real systems and keep it current after the project ends.
Consent and Cookie Management Platforms in Practice
Cookie banners are one of the most enforced areas of privacy law. Configure your consent platform so the banner, the tags and the policy all match.
Privacy in Marketing: Consent, Lists and Campaign Compliance
Marketing lists are where privacy complaints start. Run campaigns with clean consent, working suppression and lists you can defend.
DPIA and PIA: Running One That Changes a Decision
Most impact assessments are paperwork done after the decision. Run a DPIA that actually changes the design.
Breach Notification Decisions Under Pressure
You may have 72 hours or less to decide whether to notify. Make breach notification calls under GDPR, HIPAA and US state laws while the clock runs.
Retention and Deletion That Actually Deletes
Deletion schedules that nobody runs are worse than none. Set retention, handle legal holds and prove data is deleted, including in backups and SaaS.
International Transfers: SCCs, Transfer Assessments and the DPF
Sending personal data out of the EU needs a mechanism for every flow. Map your transfers, choose SCCs or the DPF and complete a transfer impact assessment.
Data Governance
Data Classification and Handling Rules People Follow
Classification schemes fail when they're too clever. Build three levels people understand, with handling rules your tools actually enforce.
Data Mapping and Discovery: Connectors, Owners and Drift
Your data inventory starts going stale the day you finish it. Use discovery tools and clear ownership to keep it accurate as systems change.
Secure Data Sharing: Data Rooms, Remanence and What People Miss
Data rooms, shared links and file transfers leave copies behind. Share sensitive data safely, and make sure it's really gone when the deal or project ends.
Governance, Risk & Compliance
AI in Compliance Mapping: Crosswalks and Gap Analysis
Mapping controls across SOC 2, ISO 27001, NIST and the rest takes weeks. Let AI draft the crosswalk, and keep it accurate enough to show an auditor.
SOC 2 From the Inside: Scoping, Ownership, Evidence and the Auditor
SOC 2 goes smoothly when scoping and ownership are right from day one. This course takes you through an engagement from the inside, including what the auditor will really ask.
ISO 27001 Implementation, Not Interpretation
Most ISO 27001 projects stall in interpretation. Implement the standard and reach Stage 1 with documents that reflect how you really work.
Control Mapping and Evidence Reuse Across SOC 2, ISO, NIST CSF and HITRUST
Running SOC 2, ISO, NIST CSF and HITRUST separately doubles the work. Map one control set across them and reuse evidence without overclaiming.
Policies People Read: Writing, Versioning, Acknowledgement and Training Binding
Nobody reads a 40-page policy. Write policies people follow, keep versions straight, and tie acknowledgements and training to the right version.
Evidence Management and Audit Readiness
Audit readiness is a habit, not a sprint. Manage evidence year-round so audits feel routine.
Internal Controls and SOX for Practitioners
SOX control failures often come from IT general controls nobody owns. Scope your ITGCs, run quarterly certifications and handle deficiencies before the auditors do.
PCI DSS in Practice: Scoping, SAQs and Compensating Controls
PCI DSS gets expensive when scope grows unchecked. Shrink the cardholder data environment, pick the right SAQ and document compensating controls that hold up.
HITRUST for HealthTech: Self-Assessment to Validated
HITRUST is often a customer requirement in healthcare. Move from self-assessment to validated, inheriting controls from your cloud provider along the way.
Running a Security Awareness Program Auditors Accept
Auditors look for training evidence mapped to controls, not attendance counts. Run security awareness that satisfies them and actually changes behavior.
Risk Management
Risk Assessment as a Craft: Scoping, Scenarios and Judgement
Good risk assessment is judgment, not a spreadsheet. Scope an assessment, build realistic scenarios and write down assumptions others can challenge.
Quantifying Risk: From Heat Maps to Money
Heat maps can't tell you whether a control is worth the money. Estimate risk in dollars, with ranges you can defend.
Treatment, Acceptance and Exceptions That Expire
Accepted risks that never expire become permanent holes. Make every acceptance name an owner, a compensating control and an end date.
Risk Appetite, KRIs and the Board Conversation
Most appetite statements are too vague to guide a decision. Tie appetite to indicators and thresholds, and have a sharper risk conversation with the board.
Audit & Assurance Operations
AI in Audit and Assurance: Sampling, Evidence and Workpapers
AI can test whole populations and draft workpapers in minutes. Use it and still meet professional standards for evidence, sampling and independence.
Owning a Control: Accountability, Delegation and Follow-Through
Controls fail when everyone thinks someone else owns them. Give every control one accountable owner, delegate the work, and follow it through to evidence.
Populations, Completeness and Sampling
Auditors start by asking how you know the list is complete. Have the answer ready, along with samples they'll accept without redoing them.
Evidence That Holds: Collection, Freshness and Reuse
Most audit pain is evidence collected late, stale or twice. Run an evidence calendar so the right proof is ready before anyone asks.
Automated Audit Tests and Continuous Control Monitoring
Automated tests can check controls every day instead of once a year. Decide what to automate, what each test must prove and what happens when it fails.
Working With Auditors: Walkthroughs, Questions and Findings
A walkthrough can win or lose an audit. Walk in prepared, answer consistently, and respond to findings without a fight.
Framework Scope as a Guardrail, Not a Burden
Scope decisions made in a hurry come back as findings. Set framework scope on purpose and write down why each exclusion is safe.
Control Maturity and Status Reporting
Red, amber and green don't tell a board anything. Define control maturity and report status in a way that shows real movement.
Cybersecurity & Threat
AI in Security Operations: Triage and Detection
AI can triage alerts and write detections, and attackers can target the AI itself. Get faster without ever letting a model close a real incident.
AI-Assisted Vulnerability Remediation: SAST, Secrets and SCA
Security scanners bury developers in findings. Use AI to triage SAST, secrets and dependency alerts and write fixes developers trust, without auto-suppressing real problems.
Software Supply Chain: SBOMs, VEX and Component Monitoring in Practice
Customers and regulators are starting to ask for SBOMs. Generate them, ingest your vendors', and use VEX to know what's really exposed.
Threat Intelligence for Risk Decisions
Threat intelligence is useless if it doesn't change a decision. Turn breach and vulnerability news into risk register changes and vendor actions.
Vulnerability Management Governance: SLAs, Exceptions and Evidence
Vulnerability SLAs only work if exceptions expire. Set remediation deadlines engineering can meet, manage exceptions, and have the evidence ready when auditors ask.
Incident and Breach Readiness: Tabletop to Regulator
The first hours of an incident decide how the regulator sees you. This course takes you from a tabletop exercise to the decisions, logs and notices a real incident demands.
Access Reviews That Pass Audit
Access reviews fail audits for the same few reasons every year. Get the population right, collect real reviewer decisions and prove revoked access is gone.
Cyber Insurance Applications and Attestations
Cyber insurance applications ask yes-or-no questions with big consequences. Answer them honestly with evidence, and find the gaps before the insurer does.
Third-Party & Supply Chain Risk
AI in Third-Party Risk: Questionnaires and Evidence
Vendor reviews pile up because questionnaires and SOC reports take hours to read. Let AI do the reading while your team makes the risk calls.
Building a Third-Party Risk Program: From Zero and At Scale
You can't review every vendor the same way. Build a third-party risk program, from scratch or at scale, with tiering that puts effort where the risk is.
Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations
A SOC 2 report can look clean while missing exactly what you rely on. Read the opinion, scope, exceptions, CUECs and carve-outs like an auditor.
Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations
Every SOC report hands you controls you're expected to run. Turn complementary user entity controls into your own obligations, with owners and evidence.
Vendor Due Diligence Questionnaires: SIG, CAIQ, Custom and Scoring
Long questionnaires waste everyone's time and still miss the risk. Build tiered questionnaires, score them with partial credit and ask only for evidence that matters.
Contracting for Risk: DPAs, BAAs, Security Schedules and Right to Audit
Contracts are the only leverage you have after signature. Know which clauses matter in DPAs, BAAs and security schedules, and how hard to push by vendor tier.
Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification
Vendor risk changes between annual reviews. Monitor vendors continuously, catch expiring reports and DPAs, and offboard cleanly.
Fourth-Party and Concentration Risk
Your vendors' vendors can take you down. Map subprocessors and spot concentration risk in the services you depend on most.
Answering Customer Security Questionnaires: The Other Side of the Table
Security questionnaires from customers can stall deals for weeks. Answer them fast and accurately, and use a trust center to cut the volume.
Regulated Outsourcing: DORA, OCC and FCA Registers in Practice
Regulators now expect registers of your ICT third parties and exit plans that would work. Meet DORA, OCC and FCA outsourcing requirements in practice.
AI Governance
AI Inventory and Use-Case Intake in Practice
You can't govern AI you don't know about. Find every AI system in use and set up an intake form product teams will actually fill in.
AI Risk and Impact Assessment: NIST AI RMF and EU AI Act Tiers Applied
Before an AI system goes live, someone has to decide how risky it is and what that means. This course walks you through an impact assessment and an EU AI Act tiering decision you can defend.
Third-Party AI and Model Vendor Governance
Most of your AI risk arrives through vendors. Learn what to ask AI suppliers, which contract terms matter, and how to approve tools without grinding the business to a halt.
AI Acceptable Use and Policy That Engineers Follow
Most AI policies are ignored because they're vague. Write one engineers and staff will follow, with approval tiers and monitoring that fit how they work.
Running an AI Management System to ISO/IEC 42001
ISO/IEC 42001 gives you a way to manage AI that certifiers and customers recognize. Stand up an AI management system and run it, not just write it down.
EU AI Act Obligations by Role
The EU AI Act puts different duties on providers, deployers and others. Work out which role you hold for each AI system and exactly what it requires, with the dates as amended in 2026.
AI Documentation That Holds Up: Model Cards and Impact Assessments
Regulators, customers and auditors all want AI documentation, each for different reasons. Write model cards and impact assessments once, and keep them true as the system changes.
Testing and Red-Teaming AI Systems
Testing AI isn't like testing code. Set acceptance criteria before you test, red-team generative systems and make a release decision you can defend.
Monitoring AI in Production
AI systems change after launch as data drifts and vendors update models. Know what to watch, when to act, and who has the authority to switch a system off.
Governing Agentic AI: Permissions, Tools and Oversight
AI agents don't just answer, they act. Decide what an agent may do, control its tools and permissions, and stop it safely when something goes wrong.
Securing LLM Applications
Prompt injection will succeed eventually, so design for it. Threat model an LLM application and build controls that hold even when the model is fooled.
Trust & Assurance
Building and Running a Trust Center
A good trust center answers buyers' questions before they ask. Decide what to publish, what to gate and how to keep it current.
Program Attestations and Certificates of Diligence for Buyers, Insurers and Regulators
Buyers, insurers and regulators want proof of diligence, not promises. Know what you can honestly claim and back it with evidence that stays current.
M&A Cyber Diligence: Buy Side and Sell Side
Cyber problems found after an acquisition become the buyer's problems. Run cyber diligence on either side of a deal.
Practitioner Methods
A Risk Register Executives Use
Executives stop reading risk registers that never lead to a decision. Build one they use, with scoring, appetite and indicators that trigger action.
Findings That Get Fixed: Task, Remediation and Evidence Management
Findings pile up when nobody owns them. Run remediation so every finding has an owner, a deadline and proof it was fixed.
Digital Trust Metrics and Board Reporting
Boards want to know whether the organization is safer than last quarter. Choose the metrics that answer that and fit them on one page they'll actually read.
Capstone: Build a 90-Day Trust Program for a Real Organisation
Put everything together. This capstone has you build a 90-day trust program for a real organization, from obligations and controls to vendors, privacy and board reporting.
Applied AI at Work
Practical Application of AI in Marketing
Your team is already using AI for copy, campaigns and research. This course turns scattered experiments into a playbook that makes the work faster and better, without a claims, privacy or brand problem landing on your desk.
Practical Application of AI in Sales
AI can research accounts, draft outreach and prep calls in minutes. Use it to build more pipeline without sending claims you can't back up or breaking contact rules.
Practical Application of AI in Accounting
AI can match invoices, draft reconciliations and research accounting questions. Learn where it's safe to use in the close, and how to keep your controls and your auditors comfortable.
Practical Application of AI in Finance
Forecasts, variance commentary and board packs can come together in hours instead of days. Get there with AI and still defend every number.
Practical Application of AI in HR
AI screening, interview tools and HR chatbots come with real legal exposure. Get the time savings and stay on the right side of discrimination, privacy and employment law.
Practical Application of AI in Legal and Compliance
AI can draft, review and research in a fraction of the time. Use it without citing cases that don't exist, waiving privilege or leaking client data.
Practical Application of AI in Procurement and Supply Chain
AI can analyze spend, screen suppliers and prep negotiations. Put it to work well, and know what to insist on when you're the one buying AI.
Practical Application of AI in IT and Security
IT and security teams are both using AI and defending against it. This course covers the service desk, scripting, access reviews and company-wide AI use, plus the attacks AI now makes convincing.
Practical Application of AI in Operations and Project Delivery
Status reports, plans, meeting notes and procedures are ideal AI work. Hand them over without losing accuracy or accountability.
Practical Application of AI in Customer Service and Support
Chatbots and agent-assist tools can cut wait times, or promise refunds you never approved. Deploy AI that answers from policy and hands off to a person at the right moment.
Practical Application of AI for Executives and Boards
Boards are being asked what their AI strategy is and how they oversee it. This course gives directors and executives a clear answer, and the reporting to back it up.