Courses that leave you with real work done.

Each course is built around a task you do at work, like running a SOC 2, answering a breach, or putting AI to use safely. You finish with a working deliverable built on your own organization, whether you are a team of five or five thousand, and a certificate anyone can verify.

Concepts you hear but never learned

Sixteen ten-minute lessons, free to every member. 0.25 ALC each, 4 ALCs toward the Foundations Certificate.

Free

Open the series to read every term in full.

Bridge letter

A bridge letter, sometimes called a gap letter, is a short statement from a service organization covering the period between the end of its most recent SOC report and the…

TPR · 10 minutes

CUEC

Complementary user entity controls are the controls a SOC report assumes you, the customer, operate. Every service organization's control objectives depend on some things…

TPR · 10 minutes

Subservice organisation and carve-out

A subservice organization is a vendor of your vendor whose controls matter to the service you receive: the cloud provider the software runs on, the data centre, the…

TPR · 10 minutes

Global Privacy Control (GPC)

Global Privacy Control is a browser signal. When it is switched on, the browser sends a header and exposes a flag on every request saying that the user opts out of the…

PRV · 10 minutes

TCF and consent strings

The Transparency and Consent Framework is an industry standard, maintained by the IAB in Europe, for passing a user's consent choices through the advertising supply…

PRV · 10 minutes

SBOM and VEX

A software bill of materials is a parts list for software: every component, library and dependency in a build, with versions, expressed in a machine-readable format such…

CYB · 10 minutes

Statement of Applicability

The Statement of Applicability is the ISO 27001 document that lists every control in the standard's Annex A, states whether each applies to your organization, gives the…

GRC · 10 minutes

ITGC

IT general controls are the controls over the technology environment that financial and other application controls depend on. Auditors group them into four areas…

AUD · 10 minutes

Legitimate interest and the balancing test

Legitimate interests is one of the six lawful bases for processing personal data under GDPR. It allows processing that is necessary for a genuine interest of the…

PRV · 10 minutes

Article 28 processor terms

Article 28 of GDPR sets the mandatory terms of any contract between a controller and a processor. The contract has to bind the processor to act only on the controller's…

PRV · 10 minutes

Business associate agreement

A business associate agreement is the contract that HIPAA requires between a covered entity, such as a healthcare provider or health plan, and any organization that…

PRV · 10 minutes

Risk acceptance and expiry

Risk acceptance is a decision by someone with the authority to make it that a known risk will not be treated further for now. It is a legitimate outcome of risk…

RSK · 10 minutes

Type I versus Type II

A SOC 2 Type I report describes a service organization's controls and gives an auditor's opinion on whether they are suitably designed at a single point in time. A Type…

TPR · 10 minutes

Data processing agreement versus data protection addendum

Both are abbreviated DPA, and both deal with how a vendor handles personal data, which is why they are confused. A data processing agreement is a standalone contract, or…

PRV · 10 minutes

Suppression list

A suppression list is the set of contacts an organization must not market to: people who unsubscribed, objected, opted out of sale, asked by phone not to be called, or…

PRV · 10 minutes

Population and sample

When an auditor tests a control, they start by defining the population: the complete set of instances in which the control should have operated during the period. Every…

AUD · 10 minutes

Privacy & Data Protection

AIW-301

AI in Privacy Operations: Requests, Records and Notices

Access requests, records of processing and privacy notices are slow, repetitive work. Let AI speed them up while your team keeps the decisions and the deadlines.

4.00 ALCs Practitioner Wave 3
PRV-201

GDPR in Practice: From Articles to an Operating Program

GDPR has 99 articles, but running a program comes down to a handful of decisions. Make them, and leave with a working plan for the next 12 months.

4.00 ALCs $190 with membership Wave 1
PRV-202

US State Privacy Laws in Practice: CCPA/CPRA and the Rest

More US states have their own privacy law every year. Work out which apply to you and handle opt-outs, GPC and sensitive data with one standard.

3.00 ALCs Free $145 with membership Wave 1
PRV-203

HIPAA in Practice for HealthTech and Business Associates

Business associates carry real HIPAA duties, and most learn that in an audit. Know what applies, what your BAA should say and how to apply minimum necessary in product design.

3.00 ALCs $145 with membership Wave 1
PRV-210

Data Subject Rights Operations: GDPR, CCPA and HIPAA Access

Access and deletion requests have deadlines, and they arrive in bursts. Handle them across GDPR, CCPA and HIPAA from intake to evidence file.

4.00 ALCs $190 with membership Wave 1
PRV-220

Building a Record of Processing and Data Inventory That Survives Audit

Records of processing are usually wrong within months. Build one from real systems and keep it current after the project ends.

3.00 ALCs $145 with membership Wave 1
PRV-230

Consent and Cookie Management Platforms in Practice

Cookie banners are one of the most enforced areas of privacy law. Configure your consent platform so the banner, the tags and the policy all match.

3.00 ALCs $145 with membership Wave 1
PRV-240

Privacy in Marketing: Consent, Lists and Campaign Compliance

Marketing lists are where privacy complaints start. Run campaigns with clean consent, working suppression and lists you can defend.

3.00 ALCs Free Free Wave 1
PRV-250

DPIA and PIA: Running One That Changes a Decision

Most impact assessments are paperwork done after the decision. Run a DPIA that actually changes the design.

3.00 ALCs $145 with membership Wave 2
PRV-260

Breach Notification Decisions Under Pressure

You may have 72 hours or less to decide whether to notify. Make breach notification calls under GDPR, HIPAA and US state laws while the clock runs.

3.00 ALCs $145 with membership Wave 1
PRV-270

Retention and Deletion That Actually Deletes

Deletion schedules that nobody runs are worse than none. Set retention, handle legal holds and prove data is deleted, including in backups and SaaS.

2.00 ALCs $95 with membership Wave 2
PRV-280

International Transfers: SCCs, Transfer Assessments and the DPF

Sending personal data out of the EU needs a mechanism for every flow. Map your transfers, choose SCCs or the DPF and complete a transfer impact assessment.

2.00 ALCs $95 with membership Wave 2

Governance, Risk & Compliance

AIW-305

AI in Compliance Mapping: Crosswalks and Gap Analysis

Mapping controls across SOC 2, ISO 27001, NIST and the rest takes weeks. Let AI draft the crosswalk, and keep it accurate enough to show an auditor.

4.00 ALCs Practitioner Wave 3
GRC-201

SOC 2 From the Inside: Scoping, Ownership, Evidence and the Auditor

SOC 2 goes smoothly when scoping and ownership are right from day one. This course takes you through an engagement from the inside, including what the auditor will really ask.

4.00 ALCs $190 with membership Wave 1
GRC-202

ISO 27001 Implementation, Not Interpretation

Most ISO 27001 projects stall in interpretation. Implement the standard and reach Stage 1 with documents that reflect how you really work.

4.00 ALCs $190 with membership Wave 2
GRC-203

Control Mapping and Evidence Reuse Across SOC 2, ISO, NIST CSF and HITRUST

Running SOC 2, ISO, NIST CSF and HITRUST separately doubles the work. Map one control set across them and reuse evidence without overclaiming.

3.00 ALCs $145 with membership Wave 1
GRC-210

Policies People Read: Writing, Versioning, Acknowledgement and Training Binding

Nobody reads a 40-page policy. Write policies people follow, keep versions straight, and tie acknowledgements and training to the right version.

3.00 ALCs $145 with membership Wave 1
GRC-220

Evidence Management and Audit Readiness

Audit readiness is a habit, not a sprint. Manage evidence year-round so audits feel routine.

3.00 ALCs $145 with membership Wave 1
GRC-230

Internal Controls and SOX for Practitioners

SOX control failures often come from IT general controls nobody owns. Scope your ITGCs, run quarterly certifications and handle deficiencies before the auditors do.

3.00 ALCs $145 with membership Wave 2
GRC-240

PCI DSS in Practice: Scoping, SAQs and Compensating Controls

PCI DSS gets expensive when scope grows unchecked. Shrink the cardholder data environment, pick the right SAQ and document compensating controls that hold up.

2.00 ALCs $95 with membership Wave 2
GRC-250

HITRUST for HealthTech: Self-Assessment to Validated

HITRUST is often a customer requirement in healthcare. Move from self-assessment to validated, inheriting controls from your cloud provider along the way.

2.00 ALCs $95 with membership Wave 3
GRC-260

Running a Security Awareness Program Auditors Accept

Auditors look for training evidence mapped to controls, not attendance counts. Run security awareness that satisfies them and actually changes behavior.

2.00 ALCs $95 with membership Wave 2

Audit & Assurance Operations

AIW-303

AI in Audit and Assurance: Sampling, Evidence and Workpapers

AI can test whole populations and draft workpapers in minutes. Use it and still meet professional standards for evidence, sampling and independence.

4.00 ALCs Executive Practitioner Wave 3
AUD-201

Owning a Control: Accountability, Delegation and Follow-Through

Controls fail when everyone thinks someone else owns them. Give every control one accountable owner, delegate the work, and follow it through to evidence.

3.00 ALCs $145 with membership Wave 3
AUD-210

Populations, Completeness and Sampling

Auditors start by asking how you know the list is complete. Have the answer ready, along with samples they'll accept without redoing them.

3.00 ALCs $145 with membership Wave 3
AUD-220

Evidence That Holds: Collection, Freshness and Reuse

Most audit pain is evidence collected late, stale or twice. Run an evidence calendar so the right proof is ready before anyone asks.

3.00 ALCs $145 with membership Wave 3
AUD-230

Automated Audit Tests and Continuous Control Monitoring

Automated tests can check controls every day instead of once a year. Decide what to automate, what each test must prove and what happens when it fails.

3.00 ALCs $145 with membership Wave 3
AUD-240

Working With Auditors: Walkthroughs, Questions and Findings

A walkthrough can win or lose an audit. Walk in prepared, answer consistently, and respond to findings without a fight.

2.50 ALCs $120 with membership Wave 3
AUD-250

Framework Scope as a Guardrail, Not a Burden

Scope decisions made in a hurry come back as findings. Set framework scope on purpose and write down why each exclusion is safe.

2.50 ALCs $120 with membership Wave 3
AUD-260

Control Maturity and Status Reporting

Red, amber and green don't tell a board anything. Define control maturity and report status in a way that shows real movement.

2.50 ALCs $120 with membership Wave 3

Cybersecurity & Threat

AIW-304

AI in Security Operations: Triage and Detection

AI can triage alerts and write detections, and attackers can target the AI itself. Get faster without ever letting a model close a real incident.

4.00 ALCs Practitioner Wave 3
AIW-306

AI-Assisted Vulnerability Remediation: SAST, Secrets and SCA

Security scanners bury developers in findings. Use AI to triage SAST, secrets and dependency alerts and write fixes developers trust, without auto-suppressing real problems.

6.00 ALCs Practitioner Wave 3
CYB-201

Software Supply Chain: SBOMs, VEX and Component Monitoring in Practice

Customers and regulators are starting to ask for SBOMs. Generate them, ingest your vendors', and use VEX to know what's really exposed.

3.00 ALCs $145 with membership Wave 1
CYB-210

Threat Intelligence for Risk Decisions

Threat intelligence is useless if it doesn't change a decision. Turn breach and vulnerability news into risk register changes and vendor actions.

3.00 ALCs $145 with membership Wave 2
CYB-220

Vulnerability Management Governance: SLAs, Exceptions and Evidence

Vulnerability SLAs only work if exceptions expire. Set remediation deadlines engineering can meet, manage exceptions, and have the evidence ready when auditors ask.

2.00 ALCs $95 with membership Wave 2
CYB-230

Incident and Breach Readiness: Tabletop to Regulator

The first hours of an incident decide how the regulator sees you. This course takes you from a tabletop exercise to the decisions, logs and notices a real incident demands.

3.00 ALCs $145 with membership Wave 1
CYB-240

Access Reviews That Pass Audit

Access reviews fail audits for the same few reasons every year. Get the population right, collect real reviewer decisions and prove revoked access is gone.

2.00 ALCs $95 with membership Wave 2
CYB-250

Cyber Insurance Applications and Attestations

Cyber insurance applications ask yes-or-no questions with big consequences. Answer them honestly with evidence, and find the gaps before the insurer does.

1.50 ALCs $70 with membership Wave 3

Third-Party & Supply Chain Risk

AIW-302

AI in Third-Party Risk: Questionnaires and Evidence

Vendor reviews pile up because questionnaires and SOC reports take hours to read. Let AI do the reading while your team makes the risk calls.

4.00 ALCs Practitioner Wave 3
TPR-201

Building a Third-Party Risk Program: From Zero and At Scale

You can't review every vendor the same way. Build a third-party risk program, from scratch or at scale, with tiering that puts effort where the risk is.

4.00 ALCs $190 with membership Wave 1
TPR-210

Reading a SOC 2 Report: Opinion, Scope, Exceptions, CUECs and Subservice Organisations

A SOC 2 report can look clean while missing exactly what you rely on. Read the opinion, scope, exceptions, CUECs and carve-outs like an auditor.

3.00 ALCs $145 with membership Wave 1
TPR-215

Handling CUECs: Turning Complementary User Entity Controls Into Your Own Obligations

Every SOC report hands you controls you're expected to run. Turn complementary user entity controls into your own obligations, with owners and evidence.

2.00 ALCs $95 with membership Wave 1
TPR-220

Vendor Due Diligence Questionnaires: SIG, CAIQ, Custom and Scoring

Long questionnaires waste everyone's time and still miss the risk. Build tiered questionnaires, score them with partial credit and ask only for evidence that matters.

3.00 ALCs $145 with membership Wave 1
TPR-230

Contracting for Risk: DPAs, BAAs, Security Schedules and Right to Audit

Contracts are the only leverage you have after signature. Know which clauses matter in DPAs, BAAs and security schedules, and how hard to push by vendor tier.

3.00 ALCs $145 with membership Wave 2
TPR-240

Continuous Vendor Monitoring: Breach Intelligence, Attestation Expiry and Recertification

Vendor risk changes between annual reviews. Monitor vendors continuously, catch expiring reports and DPAs, and offboard cleanly.

3.00 ALCs $145 with membership Wave 2
TPR-250

Fourth-Party and Concentration Risk

Your vendors' vendors can take you down. Map subprocessors and spot concentration risk in the services you depend on most.

2.00 ALCs $95 with membership Wave 3
TPR-260

Answering Customer Security Questionnaires: The Other Side of the Table

Security questionnaires from customers can stall deals for weeks. Answer them fast and accurately, and use a trust center to cut the volume.

3.00 ALCs $145 with membership Wave 1
TPR-270

Regulated Outsourcing: DORA, OCC and FCA Registers in Practice

Regulators now expect registers of your ICT third parties and exit plans that would work. Meet DORA, OCC and FCA outsourcing requirements in practice.

3.00 ALCs $145 with membership Wave 3

AI Governance

AIG-201

AI Inventory and Use-Case Intake in Practice

You can't govern AI you don't know about. Find every AI system in use and set up an intake form product teams will actually fill in.

3.00 ALCs Free Free Wave 1
AIG-210

AI Risk and Impact Assessment: NIST AI RMF and EU AI Act Tiers Applied

Before an AI system goes live, someone has to decide how risky it is and what that means. This course walks you through an impact assessment and an EU AI Act tiering decision you can defend.

4.00 ALCs $190 with membership Wave 2
AIG-220

Third-Party AI and Model Vendor Governance

Most of your AI risk arrives through vendors. Learn what to ask AI suppliers, which contract terms matter, and how to approve tools without grinding the business to a halt.

3.00 ALCs $145 with membership Wave 2
AIG-230

AI Acceptable Use and Policy That Engineers Follow

Most AI policies are ignored because they're vague. Write one engineers and staff will follow, with approval tiers and monitoring that fit how they work.

2.00 ALCs $95 with membership Wave 2
AIG-240

Running an AI Management System to ISO/IEC 42001

ISO/IEC 42001 gives you a way to manage AI that certifiers and customers recognize. Stand up an AI management system and run it, not just write it down.

4.00 ALCs Executive Practitioner Wave 3
AIG-250

EU AI Act Obligations by Role

The EU AI Act puts different duties on providers, deployers and others. Work out which role you hold for each AI system and exactly what it requires, with the dates as amended in 2026.

4.00 ALCs Executive Practitioner Wave 3
AIG-260

AI Documentation That Holds Up: Model Cards and Impact Assessments

Regulators, customers and auditors all want AI documentation, each for different reasons. Write model cards and impact assessments once, and keep them true as the system changes.

4.00 ALCs Executive Practitioner Wave 3
AIG-270

Testing and Red-Teaming AI Systems

Testing AI isn't like testing code. Set acceptance criteria before you test, red-team generative systems and make a release decision you can defend.

4.00 ALCs Executive Practitioner Wave 3
AIG-280

Monitoring AI in Production

AI systems change after launch as data drifts and vendors update models. Know what to watch, when to act, and who has the authority to switch a system off.

4.00 ALCs Executive Practitioner Wave 3
AIG-290

Governing Agentic AI: Permissions, Tools and Oversight

AI agents don't just answer, they act. Decide what an agent may do, control its tools and permissions, and stop it safely when something goes wrong.

4.00 ALCs Executive Practitioner Wave 3
AIG-300

Securing LLM Applications

Prompt injection will succeed eventually, so design for it. Threat model an LLM application and build controls that hold even when the model is fooled.

4.00 ALCs Executive Practitioner Wave 3

Applied AI at Work

AIW-201

Practical Application of AI in Marketing

Your team is already using AI for copy, campaigns and research. This course turns scattered experiments into a playbook that makes the work faster and better, without a claims, privacy or brand problem landing on your desk.

3.00 ALCs Practitioner Wave 3
AIW-202

Practical Application of AI in Sales

AI can research accounts, draft outreach and prep calls in minutes. Use it to build more pipeline without sending claims you can't back up or breaking contact rules.

4.00 ALCs Practitioner Wave 3
AIW-203

Practical Application of AI in Accounting

AI can match invoices, draft reconciliations and research accounting questions. Learn where it's safe to use in the close, and how to keep your controls and your auditors comfortable.

4.00 ALCs Practitioner Wave 3
AIW-204

Practical Application of AI in Finance

Forecasts, variance commentary and board packs can come together in hours instead of days. Get there with AI and still defend every number.

4.00 ALCs Practitioner Wave 3
AIW-205

Practical Application of AI in HR

AI screening, interview tools and HR chatbots come with real legal exposure. Get the time savings and stay on the right side of discrimination, privacy and employment law.

4.00 ALCs Practitioner Wave 3
AIW-206

Practical Application of AI in Legal and Compliance

AI can draft, review and research in a fraction of the time. Use it without citing cases that don't exist, waiving privilege or leaking client data.

4.00 ALCs Practitioner Wave 3
AIW-207

Practical Application of AI in Procurement and Supply Chain

AI can analyze spend, screen suppliers and prep negotiations. Put it to work well, and know what to insist on when you're the one buying AI.

4.00 ALCs Practitioner Wave 3
AIW-208

Practical Application of AI in IT and Security

IT and security teams are both using AI and defending against it. This course covers the service desk, scripting, access reviews and company-wide AI use, plus the attacks AI now makes convincing.

4.00 ALCs Practitioner Wave 3
AIW-209

Practical Application of AI in Operations and Project Delivery

Status reports, plans, meeting notes and procedures are ideal AI work. Hand them over without losing accuracy or accountability.

4.00 ALCs Practitioner Wave 3
AIW-210

Practical Application of AI in Customer Service and Support

Chatbots and agent-assist tools can cut wait times, or promise refunds you never approved. Deploy AI that answers from policy and hands off to a person at the right moment.

4.00 ALCs Practitioner Wave 3
AIW-211

Practical Application of AI for Executives and Boards

Boards are being asked what their AI strategy is and how they oversee it. This course gives directors and executives a clear answer, and the reporting to back it up.

3.00 ALCs Executive Practitioner Wave 3