MODULE 04 · FDE ACADEMY
Govern
This module is issue-spotting to support the customer’s own review. It is not legal advice, and neither is anything you will write after completing it — the standing disclaimer on every compliance surface of this site applies to your work too.
- Lessons
- 5
- Module
- 04 of 5
What a forward-deployed engineer owes a customer is different from what their counsel owes them. Counsel decides what the rules require. You identify, early and specifically, which questions this architecture raises, what evidence exists to answer them, and where the honest gaps are. Doing that well is the difference between a two-week security review and a six-month one.
Every lesson works against pages that already carry their sources: the jurisdiction pages, the compliance assessments and the recipes’ compliance notes. Read the instrument, not a summary of it.
- Covers
- privacysecuritydata residencyvendor assessmentAI governance
Free and self-paced. No certification is offered.
Lessons
5 lessons
Each one ends with a task carried out somewhere on this site.
- 01Personal data and confidential material are different dutiesTwo obligations that overlap without being the same, why the confidential one is usually binding for professional-services firms, and the copies an AI deployment creates that nobody’s retention schedule covers.About two hours with a real scenario in front of you.compliance-governance5 steps
- 02Residency, transfer, and the questions that followWhere data rests, where it is processed, and where the logs are. Two jurisdictions treated side by side, because the transfer question has a different shape in each.About ninety minutes of reading and note-taking.compliance-governancesecurity-hardening5 steps
- 03Vendor assessment: published, promised, verifiedThree different things that get written down as one. How to read a vendor’s documents for what they commit to, and how to record what you could not establish.Two hours per vendor the first time; forty minutes once you have the question set.compliance-governanceapi-integration5 steps
- 04Security of an AI deploymentThe ordinary hardening every system needs, plus the three problems that are specific here: over-broad retrieval, prompt leakage, and where your model weights came from.Half a day, including a deliberate attempt to retrieve something you should not.security-hardeningidentity-ssorag5 steps
- 05Governance: oversight, transparency, and the policy nobody wroteWho checks the output, who is told the system exists, what people may type into it, and the register that lets an organisation answer “what AI are we running?” in one page.About three hours to draft, and one meeting to get it owned.compliance-governancechange-management5 steps