About this training
A 2-day advanced program for CIOs, CISOs, CROs, CCOs, and DPOs addressing AI governance, risk, security, and compliance disciplines end to end. Includes NIST AI RMF, ISO/IEC 42001, EU AI Act, KVKK Generative AI Guide, OWASP LLM Top 10, MITRE ATLAS, bias audit, vendor risk, and incident response.
This training is designed for: CIOs and Chief Technology Officers — responsible for AI infrastructure governance CISOs and Heads of Information Security — AI security, threat modeling, defense controls Chief Risk Officers (CRO) and Heads of Risk Management — enterprise AI risk management Chief Compliance Officers (CCO), Data Protection Officers (DPO) — KVKK, GDPR, EU AI Act compliance Heads of Internal Audit and audit committee members — AI Three Lines of Defense 3rd line Technology and risk leaders of sectors subject to BDDK, EPDK, SGK regulations
Why this course matters: Positioned as the only program specifically prepared for CIO/CISO responsibility with a focus on risk, security, compliance, and audit, clearly differentiated from the CEO/Executive AI Strategy training. Offers executive-level depth that carries global and local standards like NIST AI RMF, ISO/IEC 42001, EU AI Act, KVKK Generative AI guide into an implementation roadmap. Hands-on teaches security frameworks like OWASP LLM Top 10, MITRE ATLAS, STRIDE-AI, Microsoft AI Red Team within the CISO discipline. Comprehensively addresses audit and compliance topics such as bias audit (NYC Local Law 144), AIA, DPIA, model lifecycle governance (SR 11-7). Combines Turkey-specific KVKK Generative AI, Agentic AI, BDDK/EPDK/SGK sector regulations, and EU AI Act extraterritorial scope. Produces concrete board- and regulator-presentable outputs in the capstone by generating an AI Governance Charter and 18-month implementation roadmap for the company.
Learning outcomes by the end of the programme: Establish an AI Governance responsibility structure on the Three Lines of Defense model. Build your company's risk register with a 9-category AI risk taxonomy. Produce an integrated NIST AI RMF + ISO/IEC 42001 + GenAI Profile implementation roadmap. Correctly apply EU AI Act high-risk obligations and the KVKK Generative AI guide. Model the threat landscape with OWASP LLM Top 10 and MITRE ATLAS. Build defense controls and guardrail stacks against prompt injection, jailbreak, data poisoning. Perform model lifecycle governance and SR 11-7 framework adaptation. Apply bias audit (NYC Local Law 144), AIA, and DPIA methodologies. Conduct AI vendor risk management, certification evaluation, and DPA negotiation.
Prerequisites and recommended background: CIO, CISO, CTO, CRO, CCO, DPO, or Head of Risk/Security/Audit position Experience in information security, risk management, or compliance Familiarity with classic IT governance frameworks (COBIT, ITIL, ISO 27001) Basic experience in KVKK or GDPR compliance processes General knowledge of your company's existing AI initiatives or plans Tablet/laptop for the training since risk register / charter / playbook templates will be worked on
- Turkey's only comprehensive 2-day advanced program addressing AI Governance, risk, security, and compliance discipline end to end at the CIO/CISO level
- A structure that carries NIST AI RMF 1.0, GenAI Profile (AI 600-1), ISO/IEC 42001:2023 AIMS, ISO/IEC 23894 global standards into an implementation roadmap
- Turkey-specific compliance discipline with EU AI Act 4 risk categories + high-risk obligations and the KVKK Generative AI + Agentic AI guides
- CISO threat-landscape depth with OWASP LLM Top 10 (2025), MITRE ATLAS, STRIDE-AI threat modeling, and Microsoft AI Red Team methodology
- Hands-on coverage of defense controls against prompt injection, jailbreak, data poisoning, adversarial attacks (NeMo Guardrails, LLM Guard, Llama Guard)
- Integration of model lifecycle governance (SR 11-7), bias audit (NYC Local Law 144), AIA, DPIA, vendor risk management, and incident response playbook
Key Takeaways
- Establish an AI Governance responsibility structure on the Three Lines of Defense model.
- Build your company's risk register with a 9-category AI risk taxonomy.
- Produce an integrated NIST AI RMF + ISO/IEC 42001 + GenAI Profile implementation roadmap.
- Correctly apply EU AI Act high-risk obligations and the KVKK Generative AI guide.
- Model the threat landscape with OWASP LLM Top 10 and MITRE ATLAS.
- Build defense controls and guardrail stacks against prompt injection, jailbreak, data poisoning.
- Perform model lifecycle governance and SR 11-7 framework adaptation.
- Apply bias audit (NYC Local Law 144), AIA, and DPIA methodologies.
- Conduct AI vendor risk management, certification evaluation, and DPA negotiation.
AI Governance Training (for CIOs/CISOs)
A 2-day advanced program for CIOs, CISOs, CROs, CCOs, and DPOs addressing AI governance, risk, security, and compliance disciplines end to end. Includes NIST AI RMF, ISO/IEC 42001, EU AI Act, KVKK Generative AI Guide, OWASP LLM Top 10, MITRE ATLAS, bias audit, vendor risk, and incident response.
About This Course
This training is designed for senior technology and risk leaders in CIO, CISO, Chief Risk Officer (CRO), Chief Compliance Officer (CCO), Data Protection Officer (DPO), Head of Information Security, Head of Risk Management, and Head of Internal Audit positions who must end-to-end manage the risk, security, compliance, and audit dimensions of AI transformation while delivering its strategic opportunities to the company. At the heart of the program is the following approach: AI Governance is neither a 'barrier against AI' nor a 'compliance check-the-box exercise.' Real governance value comes from clearly establishing the responsibility and accountability structure on the Three Lines of Defense model; bringing global standards like NIST AI RMF, ISO/IEC 42001, and the EU AI Act into an implementation roadmap; modeling the threat landscape within the CISO discipline using OWASP LLM Top 10 and MITRE ATLAS; building layered defenses against AI-specific attacks like prompt injection, jailbreak, data poisoning; adapting the SR 11-7 Federal Reserve framework to AI with model lifecycle governance; conducting ethical and compliance assessments with bias audit, AIA, and DPIA; evaluating OpenAI / Anthropic / Google compliance postures through vendor risk management; and establishing crisis-management discipline in production through an AI incident response playbook.
Comprehensive training for senior technology and risk leaders in the scope of AI Governance is virtually nonexistent in Turkey; existing 'AI law' trainings exist but they do not comprehensively address topics within CIO/CISO responsibility such as technical risk taxonomy, security threat modeling, model lifecycle governance, and incident response. This training is designed to fill that gap as Turkey's most comprehensive AI Governance reference program for C-level technology leaders. It clearly differentiates from the CEO/Executive AI Strategy training: the CEO training focuses on strategy, ROI, and organizational transformation; this training focuses on risk, security, compliance, and audit. They form two complementary programs for two different C-level roles within the same company.
A strategic dimension of the program is placing AI governance responsibility into a clear RACI matrix. The boundaries and overlaps among CIO (technology backbone), CISO (security & risk), CTO (technical implementation), CRO (enterprise risk), CCO (compliance), DPO (privacy & data protection) are addressed. The Three Lines of Defense model is adapted to AI: 1st Line (AI product team, operations); 2nd Line (risk management, compliance, security); 3rd Line (internal audit). Board AI oversight structure and executive reporting cadence are addressed in detail. As case studies, the Air Canada chatbot legal enforcement case (2024), Samsung ChatGPT data leak, iTutor Group AI hiring discrimination (EEOC settlement), and KVKK enforcement examples from Turkey are presented.
The AI risk taxonomy module forms the foundational disciplinary backbone of the training. A comprehensive 9-category framework is addressed in detail: (1) Model risk (accuracy, drift, hallucination, robustness), (2) Data risk (quality, privacy, bias, poisoning), (3) Operational risk (downtime, capacity, performance), (4) Cybersecurity risk (adversarial attacks, model theft, prompt injection), (5) Compliance risk (KVKK, GDPR, EU AI Act, sector), (6) Ethical risk (bias, fairness, transparency, explainability), (7) Reputational risk (PR crisis, customer trust, brand damage), (8) Strategic risk (wrong technology investment, competitive disadvantage), (9) Third-party risk (vendor outage, supply chain compromise, lock-in). Risk register template, Likelihood × Impact 5x5 scoring matrix, risk appetite/tolerance threshold definition, heat maps, and executive reporting are shown hands-on.
The backbone of the program is formed by the global-standard implementation modules. On the NIST AI RMF 1.0 (January 2023) and GenAI Profile (NIST AI 600-1, 2024) side, the Govern (AI risk culture, policies, accountability), Map (context, classification, AI system characteristics), Measure (metrics, benchmarks, risk tracking), Manage (risk treatment, response, continuous improvement) functions are addressed hands-on. GenAI-specific risk categories like CBRN risks, confabulation, and dangerous content are addressed in detail. On the ISO/IEC 42001:2023 AI Management System (AIMS) side, 38 Annex A control objectives, integration with ISO 27001, certification process, and external-audit readiness are addressed comprehensively. ISO/IEC 23894 AI Risk Management standard is presented as a complementary framework.
The EU AI Act module covers in detail the obligations of Turkish companies under extraterritorial scope. The 4 risk categories (Unacceptable, High, Limited, Minimal Risk) and their contents; 9 high-risk categories in Annex III (credit scoring, recruitment, education, healthcare, justice); obligations for high-risk systems (Article 9 risk management, Article 10 data governance, technical documentation, human oversight, accuracy/robustness, conformity assessment, CE marking, post-market monitoring); GPAI (Foundation Model) obligations (Articles 51-55) and the 10^25 FLOPS systemic risk threshold; the 7% global turnover or €35M penalty structure are addressed comprehensively. The direct scope coverage of Turkish companies selling products/services to the EU market and the compliance roadmap are presented in detail.
The KVKK Generative AI and Agentic AI Guides module imparts the Turkey-specific compliance discipline. Application of the data controller vs data processor distinction to AI systems, AI training data and KVKK Article 5/6 legal-basis analysis, the personal-data status and responsibility of AI output, cross-border transfer (Article 9) and OpenAI/Anthropic compliance, the unique risk profile of Agentic AI (autonomous decision-making), the human-in-the-loop requirement, audit trail and decision-explainability obligation are addressed in detail. The AI extension of BDDK Information Systems Regulation, EPDK energy sector AI guidelines, and SGK health-data special-category data framework in AI projects are addressed sector-specifically.
The AI Security modules are the technical-depth dimension of the training. On the OWASP LLM Top 10 (2025) side, LLM01 Prompt Injection, LLM02 Insecure Output Handling, LLM03 Training Data Poisoning, LLM04 Model Denial of Service, LLM05 Supply Chain Vulnerabilities, LLM06 Sensitive Information Disclosure, LLM07 Insecure Plugin Design, LLM08 Excessive Agency, LLM09 Overreliance, LLM10 Model Theft are addressed in detail. On the MITRE ATLAS framework side, Reconnaissance, Resource Development, Initial Access, ML Model Access, Execution, Persistence, Defense Evasion, Discovery, Collection, Exfiltration, Impact tactics and TTPs are addressed. STRIDE-AI threat-modeling adaptation, Microsoft AI Red Team methodology, and Anthropic Responsible Scaling Policy are comprehensively addressed.
In the defense-controls module, direct and indirect prompt-injection attacks, jailbreak techniques (DAN, roleplay, multilingual, encoding-based, visual prompt injection), training data poisoning (backdoor, trigger attacks), adversarial examples, model extraction and inversion attacks, supply-chain risk (Hugging Face model trust, third-party library) are analyzed in detail. As defense controls, input sanitization, regex filtering, normalization; NeMo Guardrails, LLM Guard, Llama Guard guardrail frameworks; output filtering and LLM-as-judge post-process control; Anthropic constitutional AI and safe-completions are addressed hands-on.
The Model Governance module addresses model lifecycle management integrated with the MLOps discipline. Model registry (MLflow, Weights & Biases, Hugging Face Model Hub) and metadata management; Google Model Cards and Hugging Face standard model card discipline; lineage tracking; development → staging → production stage-gate criteria; Model Risk Council and approval matrix; SR 11-7 Federal Reserve model risk framework adaptation; data drift, concept drift, prediction drift detection; champion-challenger pattern and production A/B testing; deprecation procedures and rollback discipline are addressed in detail.
In the bias audit, AIA, and DPIA module, demographic parity, equal opportunity, equalized odds, calibration fairness metrics; disparate impact (80% rule) and EEOC framework; bias detection tools (AIF360, Fairlearn, Aequitas, What-If Tool); automated employment decision tool audit with NYC Local Law 144; Canada Directive and EU AI Act AIA frameworks; GDPR Article 35 DPIA and KVKK alignment; DPIA trigger criteria; pre-processing (data augmentation, reweighting), in-processing (adversarial debiasing), post-processing (threshold adjustment) mitigation strategies are addressed hands-on.
The third-party risk management module addresses AI vendor ecosystem compliance evaluation. Comparison of OpenAI, Anthropic, Google, Microsoft, AWS, Hugging Face compliance postures; SOC 2 Type II vs Type I, ISO 27001/27017/27018 cloud security, ISO 42001 AIMS certification evaluation; DPA negotiation (KVKK/GDPR-compliant clauses); data localization and sub-processor approval; vendor exit strategy and data portability are addressed comprehensively. An AI vendor risk assessment questionnaire containing 50+ controls is presented.
The incident response, audit trail, and continuous monitoring module represents the operational-discipline dimension of the training. Incident classification (model failure, data leak, prompt injection, bias); detect-contain-eradicate-recover-lessons-learned playbook; EU AI Act Article 73 serious-incident reporting (15 days); integration with KVKK's 72-hour data-breach notification; prompt-level audit (user, timestamp, input, output, cost); tamper-proof logging (WORM storage, blockchain-based); retention policy; data drift / concept drift / prediction drift detection (PSI, KL divergence, Wasserstein distance); SIEM (Splunk, Elastic, Sentinel) and SOAR integration are addressed in detail.
In the capstone project, each participant produces an end-to-end AI Governance Charter and an 18-month implementation roadmap for their own company: charter sections (scope, principles, roles, processes), AI Council charter template, 18-month quarterly milestones and KPI targets, NIST RMF + ISO 42001 + EU AI Act compliance integration, documentation at a quality presentable to the board and regulators. By the end of the training, participants reach a level of technical, regulatory, and strategic competence to manage AI Governance discipline in an integrated way at the CIO/CISO level, establish a risk register with a 9-category risk taxonomy, produce a NIST AI RMF and ISO/IEC 42001 implementation roadmap, ensure EU AI Act and KVKK Generative AI guide compliance, model the threat landscape with OWASP LLM Top 10 and MITRE ATLAS, build prompt injection / jailbreak / data-poisoning defense controls, adapt model lifecycle governance and the SR 11-7 framework, perform bias audit / AIA / DPIA, conduct AI vendor risk management, and establish production governance discipline with an AI incident response playbook. The training consists of 2 days, 12 modules, and over 70 executive technical lessons.
Training Methodology
Turkey's only comprehensive 2-day advanced program addressing AI Governance, risk, security, and compliance discipline end to end at the CIO/CISO level
A structure that carries NIST AI RMF 1.0, GenAI Profile (AI 600-1), ISO/IEC 42001:2023 AIMS, ISO/IEC 23894 global standards into an implementation roadmap
Turkey-specific compliance discipline with EU AI Act 4 risk categories + high-risk obligations and the KVKK Generative AI + Agentic AI guides
CISO threat-landscape depth with OWASP LLM Top 10 (2025), MITRE ATLAS, STRIDE-AI threat modeling, and Microsoft AI Red Team methodology
Hands-on coverage of defense controls against prompt injection, jailbreak, data poisoning, adversarial attacks (NeMo Guardrails, LLM Guard, Llama Guard)
Integration of model lifecycle governance (SR 11-7), bias audit (NYC Local Law 144), AIA, DPIA, vendor risk management, and incident response playbook
Who Is This For?
Why This Course?
Positioned as the only program specifically prepared for CIO/CISO responsibility with a focus on risk, security, compliance, and audit, clearly differentiated from the CEO/Executive AI Strategy training.
Offers executive-level depth that carries global and local standards like NIST AI RMF, ISO/IEC 42001, EU AI Act, KVKK Generative AI guide into an implementation roadmap.
Hands-on teaches security frameworks like OWASP LLM Top 10, MITRE ATLAS, STRIDE-AI, Microsoft AI Red Team within the CISO discipline.
Comprehensively addresses audit and compliance topics such as bias audit (NYC Local Law 144), AIA, DPIA, model lifecycle governance (SR 11-7).
Combines Turkey-specific KVKK Generative AI, Agentic AI, BDDK/EPDK/SGK sector regulations, and EU AI Act extraterritorial scope.
Produces concrete board- and regulator-presentable outputs in the capstone by generating an AI Governance Charter and 18-month implementation roadmap for the company.
Learning Outcomes
Requirements
Course Curriculum
126 LessonsInstructor

Şükrü Yusuf KAYA
AI Architect | Enterprise AI & LLM Training | Stanford University | Software & Technology Consultant
Şükrü Yusuf KAYA is an internationally experienced AI Consultant and Technology Strategist leading the integration of artificial intelligence technologies into the global business landscape. With operations spanning 6 different countries, he bridges the gap between the theoretical boundaries of technology and practical business needs, overseeing end-to-end AI projects in data-critical sectors such as banking, e-commerce, retail, and logistics. Deepening his technical expertise particularly in Generative AI and Large Language Models (LLMs), KAYA ensures that organizations build architectures that shape the future rather than relying on short-term solutions. His visionary approach to transforming complex algorithms and advanced systems into tangible business value aligned with corporate growth targets has positioned him as a sought-after solution partner in the industry. Distinguished by his role as an instructor alongside his consulting and project management career, Şükrü Yusuf KAYA is driven by the motto of "Making AI accessible and applicable for everyone." Through comprehensive training programs designed for a wide spectrum of professionals—from technical teams to C-level executives—he prioritizes increasing organizational AI literacy and establishing a sustainable culture of technological transformation.
Frequently Asked Questions
Apply for Training
Boutique training with limited seats.
Pre-register for Next Groups
Leave your info to be the first to know when the next batch opens.
1-on-1 Mentorship
Book a private session.
Related programs
Professional Software Development with Claude Code Training
A comprehensive, advanced 4-day training program for software professionals seeking enterprise-level mastery of Anthropic's agentic coding platform, Claude Code. Production-grade agent architecture with MCP integrations, Hooks, Sub-agents, Skills, and the Claude Agent SDK.
4 GünadvancedLLM Alignment Engineering with RLHF, DPO, and GRPO Training
A 3-day advanced Turkish LLM alignment training that covers the RLHF (PPO), DPO, KTO, IPO, SimPO, ORPO, and DeepSeek R1 GRPO algorithms at both math and code level; and teaches reward modeling, Constitutional AI, RLAIF, reasoning-model alignment, and the TRL/Axolotl/LLaMA-Factory/OpenRLHF/verl toolchain at production grade.
3 GünadvancedBuilding AI Agents with the Claude Agent SDK Training
A comprehensive, advanced 4-day program for software engineers who want to develop production-grade AI agents with Anthropic's Claude Agent SDK. Tool-use orchestration, MCP server development, multi-agent patterns, prompt caching, and evaluation engineering.
4 Günadvanced