Role-Based Programme
RB0928

Hugging Face for Risk & Internal Audit

AI Model Due Diligence, Risk Review & Governance Awareness

IMAGE REQUIRED
Duration
4 Hours
Level
Awareness
Delivery
Instructor-Led
Format
Awareness Session

Programme Objectives

  • Understand how Hugging Face models, datasets, repositories, and documentation can be reviewed from a risk and internal-audit perspective.
  • Explore Model Cards and Dataset Cards to identify intended use, limitations, evaluation evidence, data characteristics, and documentation gaps.
  • Recognise licensing, security, access, provenance, bias, and third-party AI risks associated with model adoption.
  • Experience a structured due-diligence workflow for reviewing AI assets before enterprise use.
  • Understand where specialist validation and professional audit judgement remain essential.

Tools covered

Hugging Face HubModel CardsDataset CardsModel & Dataset RepositoriesLicensesGated ModelsSecurity ScanningRepository Metadata

Who should attend

  • Internal Auditors
  • IT Auditors
  • Technology Risk Professionals
  • Enterprise Risk Management Professionals
  • AI Risk & Governance Professionals
  • Model Risk Professionals
  • Information Security Risk Professionals
  • Compliance Professionals
  • Internal Control Professionals
  • Risk Assurance Professionals
  • Third-Party Risk Professionals
  • Audit Managers

Prerequisites & Participant Readiness

  • Basic understanding of risk, controls, compliance, or internal audit
  • Basic awareness of Artificial Intelligence and Machine Learning is helpful
  • Familiarity with technology or third-party risk is beneficial
  • No programming or model-development knowledge required
  • No previous Hugging Face experience required

TOC Modules

Concepts
  • Understanding Hugging Face and the role of the Hugging Face Hub
  • Understanding models, datasets, repositories, and AI assets
  • Identifying risk areas across sourcing, data, security, licensing, and usage
  • Understanding public, private, and gated AI resources
Practical activities
  • Navigating the Hugging Face Hub from an auditor's perspective
  • Locating key model, dataset, ownership, and repository information

Scenarios

Third-Party AI Model Due Diligence

Proposed Model → Model Card → Dataset Information → License → Security Indicators → Identified Risks → Follow-Up Questions → Review Recommendation

Participants review a Hugging Face model proposed for organisational use and identify documentation, data, licensing, security, and governance issues requiring further assessment.

AI Asset Risk Screening

Model Repository → Ownership & Documentation → Data Provenance → Usage Conditions → Security Review → Risk Classification

Participants perform an initial risk screening of an external AI asset and prepare a structured summary showing potential risks, evidence gaps, and areas requiring specialist validation.

Continue with programmes from the same capability area.

Take the next step

Ready to make this programme work for your team?

Customise modules, duration and business scenarios for your team.

Instructor-ledVirtualHybrid

Designed around your roles, tools and real workflows.