Free assessments
Short, free online assessments. Pass and get a certificate of completion you can print, verify, and share on LinkedIn.
EU AI Act
Test your understanding of the EU AI Act (Regulation (EU) 2024/1689) — risk classification, prohibited practices, high-risk obligations, and key deadlines.
Deployer obligations, transparency duties, GPAI systemic risk, and fundamental rights impact assessments under the AI Act.
Complex AI Act scenarios: prohibited practice edge cases, conformity assessment routes, GPAI systemic-risk thresholds, and enforcement.
GDPR
Test your understanding of the GDPR (Regulation (EU) 2016/679) — lawful bases, data subject rights, breach notification, and accountability.
Applying GDPR in practice: transparency notices, automated decision-making, design obligations, and cross-border transfers.
Deep GDPR scenarios covering joint controllership, international transfers, enforcement mechanics, and complex data subject rights.
AI Act / ISO 42001 / NIST AI RMF
CCPA
The California Consumer Privacy Act (as amended by the CPRA): core consumer rights and business obligations.
Applying CCPA/CPRA in practice: verifiable requests, service provider contracts, and notice obligations.
Complex CCPA/CPRA scenarios: enforcement risk, cross-border considerations, and interaction with other US privacy laws.
CRA
The Cyber Resilience Act: essential cybersecurity requirements, scope, and key definitions for products with digital elements.
Applying the CRA in practice: the 24h/72h/14-day reporting chain, SBOM requirements, technical documentation, and manufacturer due diligence.
Complex CRA scenarios: penalty tiers, the actively-exploited-vulnerability/incident reporting chain, and interaction with the EU AI Act.
DORA
The Digital Operational Resilience Act: ICT risk management, incident reporting, and third-party oversight for EU financial entities.
Implementing DORA in practice: incident classification thresholds, third-party contracts, and resilience testing programmes.
Complex DORA scenarios: Oversight Framework mechanics, cross-border ICT concentration risk, and TLPT programme design.
GDPR / UK GDPR
ISO 23894
AI risk management guidance: applying ISO 31000 risk principles specifically to artificial intelligence.
Applying structured AI risk management in practice: sources of risk, stakeholder communication, and recording/reporting.
Complex AI risk management scenarios: cascading risk, third-party model risk, and integrating 23894 guidance across a risk-management ecosystem.
ISO 27001
The fundamentals of the leading information security management system (ISMS) standard.
Implementing an ISMS in practice: risk treatment, the Statement of Applicability, and continual improvement.
Complex ISMS scenarios: multi-site scoping, integrating ISO 27001 with other frameworks, and mature risk governance.
ISO 42001
The fundamentals of the world's first AI management system (AIMS) standard.
Implementing an AI management system in practice: risk assessment, objectives, and operational controls.
Complex AIMS scenarios: multi-framework integration, third-party AI supply chains, and mature AI governance.
NIS2
The Network and Information Security Directive 2: scope, governance duties, and incident reporting for essential and important entities.
Applying NIS2 governance, risk-management, and incident-reporting duties in practice, including supply chain security.
Complex NIS2 scenarios: cross-border supervision, scope edge cases, and integrating NIS2 with DORA and ISO 27001 programmes.
NIST AI RMF
The NIST AI Risk Management Framework's four core functions: Govern, Map, Measure, and Manage.
Applying the Govern-Map-Measure-Manage functions in practice, including the AI RMF Playbook's practical suggestions.
Complex NIST AI RMF scenarios: generative AI profile considerations, cross-framework mapping, and organisational maturity.
UK GDPR
How the UK GDPR and Data Protection Act 2018 work post-Brexit: lawful bases, principles, and the ICO's role.
Divergence between UK GDPR and EU GDPR, ICO guidance, and practical compliance for UK-facing organisations.
Complex UK data protection scenarios: adequacy risk, ICO enforcement powers, and cross-border programme design.