AEES Executive Certificate in Digital sovereignty and risk

Judge a dependency, a cloud and a jurisdiction risk. This AEES certification attests digital sovereignty and risk.

  • AssessmentProfessional assessment
  • Attempts2
  • PreparationIncluded
  • France
  • Canada
Description

Digital sovereignty and risk

A vague familiarity with “Digital sovereignty and risk” is no longer enough. This belongs with Cybersecurity and sovereignty. You hold cyber risk, the information system, privacy and continuity. People are hired to decide, not just to name the topic. This AEES certification is for professionals, managers and leaders who want to judge a digital dependency, decide hosting and limit lock-in. No diploma is required. What is required is a working command of written French, and the will to show the subject on a real file, in a company, a public body or a partner organisation.

You are not joining a long degree. You take “Digital sovereignty and risk” seriously enough to use it, and seriously enough for someone else to read it on a file. Everything happens online, around a job you already have. You prepare if you need to, then you sit a professional assessment. The AEES Executive Certificate, if it is issued, is proof in your name, and it can be checked. It holds in a CV, a move or a cooperation. It is a short specialisation, issued by a higher-education institution. You see at once what you are buying: a targeted title, not a course catalogue.

Afterwards you can carry “Digital sovereignty and risk” into a team, a file or a new responsibility, and explain your choices to a manager, a funder or a partner institution. Others will see that you can judge a digital dependency, decide hosting and limit lock-in, including outside your own organisation. If you succeed, AEES issues an AEES Executive Certificate in your name, with a unique serial number that can be checked in the public register. The award stays in your workspace. It shows a professional judgement you have demonstrated, useful for a CV, a new post or work in common.

Skills

What this certificate attests

The capabilities the assessment attests if you pass.

  • Judge a digital dependency
  • Decide hosting
  • Limit lock-in
  • Require exit, portability and audit
  • See the subcontractors the vendor did not name
  • Decide what you do if the vendor disappears
ESCO classification — European Skills, Competences, Qualifications and Occupations

ESCO, the European skills vocabulary

This is the European Commission’s classification of skills, competences, qualifications and occupations. This certificate is linked to it through the skills below. Each link opens the official record.

Preparation included

To prepare for the assessment

After purchase, a preparatory course is available: 6 written modules, without an instructor, at your own pace. You are not required to follow it before opening the assessment. Each module sets out the notions, a commented case, the points to keep and a FAQ. It covers Dependency, Jurisdiction, Hosting and Contract.

When you are ready, you enter the assessment: a file already open, incomplete facts, conflicting views. You move through successive decisions. This is not a full taught programme with pedagogical supervision.

Structured written course

Notions, objectives and concrete examples, organised progressively.

Applied case

A commented professional situation to anchor the theory.

FAQ and preparation

Frequent doubts, then questions to go further on your own.

  1. AEES Executive Certificate (Digital Sovereignty and Risk) Module 1: Dependency Digital sovereignty begins with a clear view of who can interrupt your operations. Dependency is not only about a cloud provider. It is the sum of technical, legal, financial, and operational levers that others hold over your essential processes, data, and users. This module gives you a method to surface those levers, compare options, and act before a forced interruption leaves you without a plan. Real world dependency lives in the details. It hides in subscription terms, identity integrations, domain registrars, payment gateways, continuous integration tools, software update channels, and the sub processors your main vendor quietly relies on. You will learn to map these layers quickly, ask for the right contractual protections, set technical conditions for portability, and decide what to do if the vendor disappears or refuses cooperation.
  2. Module 2, Jurisdiction: Know where the data actually lives Jurisdiction is not only about which country a server sits in. It is a combination of place, actors and law. The country of the data center, the company that runs the service, the parent company that controls it, and the locations from which administrators log in can all bring different laws to the same dataset. If you assume physical location alone decides your legal risk, you will miss important exposure. Cloud services complicate matters further. Data is replicated, cached and backed up across regions. Support staff connect from different time zones. Subcontractors operate parts of the stack. Your contract might promise a region, but the provider’s security tools or analytics pipeline may move fragments elsewhere unless you ask and verify. This module shows how to discover the real geography of your data and the legal hooks that follow.
  3. Hosting Hosting is not only a location on a map. It is a set of decisions about who can operate your systems, who can reach your data, which control plane runs your service, and how easily you can move away. In this module you will judge cloud hosting using verifiable controls and traceable risks instead of slogans. A hosting decision sits at the intersection of law, architecture, and operations. A provider can keep your data physically in your chosen region while still being able to access it through support channels, telemetry, or managed services. A vendor can be regionally certified yet still depend on foreign software supply chains or a global control plane. You will learn to map these paths and test what truly limits access.
  4. Contract: Exit, Portability and Audit Sovereignty is not a slogan in a contract. It is a set of enforceable obligations that let you leave a service, take your data with you and look into how the service protects your interests. Without clear clauses, dependencies solidify, switching costs rise and audit becomes a favor rather than a right. This module translates those risks into concrete contract terms. You will learn how to specify exit timelines and deliverables, require usable export formats, cap egress costs, obtain practical transition assistance and formalize audit and assurance. You will also frame what happens to your data and logs at the end, and how the vendor discloses and controls its subcontracting chain.
  5. Module 5, Chain: Seeing the Unnamed Subcontractors You rarely contract a single entity when you buy a digital service. You contract a visible vendor, and you also inherit a hidden chain of hosting providers, content delivery networks, analytics firms, support desks, managed security services, payment gateways, messaging platforms, and niche microservices. This chain can cross borders, insert new jurisdictions, and concentrate risk in entities you never negotiated with. If you cannot see the chain, you cannot govern it. Subcontractors can shift data location, introduce additional logging, add their own incident response practices, or create a single point of failure that your business continuity plan does not cover. Visibility is the first control. With visibility, you can ask better questions, define boundaries, and make credible decisions on acceptance, mitigation, or exit.
  6. Plan B: What to Do If the Vendor Disappears In most organizations, digital operations run on a mesh of vendors you do not control. A vendor can fail for many reasons: insolvency, acquisition followed by product retirement, sanctions, catastrophic outages, legal injunctions, or a security incident that compels a shutdown. When it happens, you need a Plan B you can execute in days, not in board cycles. Your goal is not to predict the specific incident but to pre-commit to a credible, resourced, and tested exit path. This module gives you a method to produce that plan for a real dossier. You will learn how to define triggers, pre-position the assets and access you must retain, choose among exit patterns, and set decision criteria that let you act under pressure. You will see how to align the plan with business continuity targets, how to contract for it, and how to verify that what you wrote is actually doable.