Skip to main content

Phase 3: Governance, Risk & Contracts

Goal: Make AI safe to sell and safe to buy β€” embedding governance, risk controls, and AI-aware contract terms into enterprise deals across North America, LATAM, and Europe.

AttributeDetail
Duration7 weeks
Time commitment5-8 hours/week
Cost$0 (frameworks are public standards)
Capstone deliverableAI Contract Clause Library + a one-page AI Governance & Escalation Policy
Career signal"Can navigate AI risk and regulation in commercial deals" β€” rare and board-critical

Why This Phase Matters (Market Alignment)​

AI governance has moved from theory to enforceable law. The EU AI Act (Regulation (EU) 2024/1689) is phasing in, ISO/IEC 42001 is now the certifiable AI-management standard, and NIST's framework is the US reference. Executives who can hold a governance conversation with legal, security, and the board β€” while still closing deals β€” are exactly who capital-intensive firms need. This maps to Chief Commercial Officer, VP Strategy, AI Governance Lead, and Risk-aware Growth roles.


Learning Objectives​

  1. Apply NIST AI RMF, ISO/IEC 42001, and the EU AI Act at a working (not academic) level
  2. Identify AI/data/IP risk in customer-facing AI usage
  3. Draft and negotiate AI-specific contract terms (liability, IP, confidentiality, auditability)
  4. Recognize jurisdictional risk patterns across your key regions
  5. Build an escalation model so business, legal, and technical teams move fast without cutting corners

Week-by-Week Structure​

Week 15 β€” Responsible AI, From Principles to Controls​

  • Learn: NIST AI RMF β€” deep read of Govern/Map/Measure/Manage + the Playbook
  • Do: Translate the four functions into 8-10 concrete controls for a commercial AI use case

Week 16 β€” ISO/IEC 42001 (AI Management Systems)​

Week 17 β€” The EU AI Act & Global Regulation​

Week 18 β€” Data Governance for Commercial AI​

  • Do: Define rules for what customer/pipeline data may enter AI tools (PII, confidentiality, data residency)
  • Do: Draft an approved-use / prohibited-use policy for your commercial team

Week 19 β€” AI Contract Terms (Build the Clause Library)​

  • Do: Draft negotiable clauses for: IP ownership of AI outputs, liability for AI errors, confidentiality of training data, audit/explainability rights, and model-change notification
  • Reference: align each clause to a NIST/ISO/EU AI Act control

Week 20 β€” Jurisdictional Risk & Cross-Border Deals​

  • Do: Create a comparison table of AI/data obligations across your top 3 jurisdictions
  • Do: Add jurisdiction flags to your Phase 2 Negotiation Prep Copilot

Week 21 β€” Escalation Model + Capstone​

  • Do: Build the AI Governance & Escalation Policy and finalize the Clause Library (see below)

Capstone Deliverables​

1. AI Contract Clause Library​

A reusable set of negotiable clauses covering:

  • IP ownership of AI-generated outputs
  • Liability and indemnity for AI errors/hallucinations
  • Confidentiality and data-use restrictions
  • Auditability, explainability, and reporting rights
  • Model-change and deprecation notification

Each clause is mapped to a governance control (NIST / ISO 42001 / EU AI Act).

2. AI Governance & Escalation Policy (1 page)​

  • Approved vs. prohibited AI use cases for the commercial team
  • Data-handling rules (PII, confidentiality, residency)
  • Escalation matrix: who decides, at what risk threshold, how fast

Skills β†’ Market Keywords​

AI Governance Β· Responsible AI (NIST AI RMF) Β· ISO/IEC 42001 Β· EU AI Act Compliance Β· AI Contract Negotiation Β· Data Governance Β· AI Risk Management


Phase 3 Checkpoint (Gate to Phase 4)​

  • Can explain the EU AI Act risk tiers and ISO 42001's purpose in plain language
  • Completed a working AI Contract Clause Library
  • One-page Governance & Escalation Policy ready to circulate
  • Jurisdictional heatmap for your active regions

All frameworks are cited with primary-source links in Sources & Verification.