AEES Executive Certificate in AI regulation and compliance

Classify a use, hold the duties and decide what you document. This AEES certification attests AI regulation and compliance.

  • AssessmentProfessional assessment
  • Attempts2
  • PreparationIncluded
  • France
  • Canada
Description

AI regulation and compliance

A vague familiarity with “AI regulation and compliance” is no longer enough. This belongs with AI, data and digital. You lead AI, you govern data and you frame a digital change. People are hired to decide, not just to name the topic. This AEES certification is for professionals, managers and leaders who want to classify an AI use, decide what you document and judge a forbidden use. No diploma is required. What is required is a working command of written French, and the will to show the subject on a real file, in a company, a public body or a partner organisation.

You are not joining a long degree. You take “AI regulation and compliance” seriously enough to use it, and seriously enough for someone else to read it on a file. Everything happens online, around a job you already have. You prepare if you need to, then you sit a professional assessment. The AEES Executive Certificate, if it is issued, is proof in your name, and it can be checked. It holds in a CV, a move or a cooperation. It is a short specialisation, issued by a higher-education institution. You see at once what you are buying: a targeted title, not a course catalogue.

Afterwards you can carry “AI regulation and compliance” into a team, a file or a new responsibility, and explain your choices to a manager, a funder or a partner institution. Others will see that you can classify an AI use, decide what you document and judge a forbidden use, including outside your own organisation. If you succeed, AEES issues an AEES Executive Certificate in your name, with a unique serial number that can be checked in the public register. The award stays in your workspace. It shows a professional judgement you have demonstrated, useful for a CV, a new post or work in common.

Skills

What this certificate attests

The capabilities the assessment attests if you pass.

  • Classify an AI use
  • Decide what you document
  • Judge a forbidden use
  • Decide what you require from a third party before plugging the tool in
  • Refuse a use the organisation is not allowed to hold
  • Check afterwards, not only at purchase
ESCO classification — European Skills, Competences, Qualifications and Occupations

ESCO, the European skills vocabulary

This is the European Commission’s classification of skills, competences, qualifications and occupations. This certificate is linked to it through the skills below. Each link opens the official record.

Knowledge & research

Related scientific readings

Scientific readings related to this certificate.

Preparation included

To prepare for the assessment

After purchase, a preparatory course is available: 6 written modules, without an instructor, at your own pace. You are not required to follow it before opening the assessment. Each module sets out the notions, a commented case, the points to keep and a FAQ. It covers Classification, Duties, Documentation and Vendor.

When you are ready, you enter the assessment: a file already open, incomplete facts, conflicting views. You move through successive decisions. This is not a full taught programme with pedagogical supervision.

Structured written course

Notions, objectives and concrete examples, organised progressively.

Applied case

A commented professional situation to anchor the theory.

FAQ and preparation

Frequent doubts, then questions to go further on your own.

  1. AEES Executive Certificate in AI Regulation and Compliance, Module 1: Classification Classification is the first decision in AI governance. It tells you whether a use can proceed as ordinary software, whether it must be framed with transparency and documentation, whether it triggers a full risk and compliance program, or whether it must be refused. This module gives you practical steps to read a use case, place it on a recognised risk ladder, and record the decision so that the next modules can build on it. Global guidance converges on a risk-based approach. The European Union’s Artificial Intelligence Act sets out prohibited practices, high-risk systems, and lower risk categories that still require transparency. NIST’s AI Risk Management Framework and the OECD AI Principles encourage context-based, impact-first thinking. You will use these shared ideas to reach fast, defensible classifications, even when a vendor markets a tool in vague terms.
  2. Module 2: Duties This module focuses on what you must actually do. You will translate high level principles into operational duties that attach to specific AI uses. You will map who you are in law for each system, what that role triggers, and how to prove you did it. The goal is to leave with an actionable duty register that you can keep current over time. The core references are the EU Artificial Intelligence Act and the GDPR for uses that touch the EU, sector regulations where your system falls under product or service regimes, and widely used risk management frameworks that regulators expect to see. We also cover guidance from supervisory authorities that shape enforcement. When sources diverge, you will learn to apply the stricter or more specific duty for your situation.
  3. Module 3: Documentation Documentation in AI regulation and compliance is not a cosmetic file. It is a living set of evidence that shows what you run, why you run it, what it can and cannot do, and how you keep it under control over time. When done well, documentation compresses many hours of interviews and system digging into a concise, reviewable record. It tells a regulator, an internal auditor, a buyer, or a board member that the organisation knows what it is doing and can prove it. Different frameworks point in the same direction. Data protection laws expect records of processing activities and risk assessments. The EU AI Act requires providers of high-risk AI systems to prepare technical documentation, keep logs, and implement risk management and human oversight. NIST’s AI Risk Management Framework and ISO management system standards give structure to evidence, roles, and continuous improvement. You do not need a second library to satisfy all of them. You need a disciplined way to decide what to keep, where to keep it, how to keep it current, and how to retrieve it fast.
  4. Module 4, Vendor: What to require from third parties before integration Most AI capability arrives in organisations through vendors. The quality of your vendor requirements determines your legal exposure, your operational risk, and your ability to prove compliance later. This module shows you what to ask for before you plug in any external AI tool, how to judge the answers, and how to lock those expectations into binding commitments and practical controls. You will build a short, reusable method to screen vendors, align internal stakeholders, and translate risk into clear clauses and checkpoints. The method is jurisdiction‑aware without pretending there is a single global rulebook. Where the law is specific, we anchor the requirement to that source. Where practice leads the law, we state the professional principle and show how to justify it in audit terms.
  5. Module 5/6, Forbidden: Refusing AI Uses Your Organisation Cannot Hold This module focuses on a practical, high‑stakes skill: saying no to an AI use your organisation cannot lawfully or ethically hold. You will learn how to spot hard prohibitions, apply a clear decision path, and record a refusal that is defensible to business leaders, auditors, and regulators. The emphasis is on translating abstract legal and policy bans into concrete, timely go/no‑go outcomes. Prohibitions arise from multiple places. Some practices are banned outright by law in certain jurisdictions. Others are blocked by sectoral rules, contractual restrictions, or internal policies. You also need to account for the operational reality of working across borders with suppliers who may host or process data elsewhere. A robust refusal process prevents unlawful deployment, avoids costly rollbacks, and protects people from harm.
  6. Module 6: Control Buying or building an AI solution is only half the job. Real risk starts when the tool meets production data, real users, and changing business conditions. Models drift, vendors push silent updates, and a harmless edge case can become a recurring failure. This module gives you a simple way to keep control after deployment. Regulators expect continuous oversight. The EU Artificial Intelligence Act requires post-market monitoring for high-risk systems and incident reporting to authorities. Data protection regulators expect ongoing risk management, not a one-off assessment. Even if your use is not high-risk, control is a basic professional duty: you must know how the tool actually behaves, not how it behaved during procurement.