Role-Based Programme
RB0930

Hugging Face for Risk & Internal Audit

Assess AI Models, Data, Controls & Governance

IMAGE REQUIRED
Duration
16 Hours
Level
Intermediate
Delivery
Instructor-Led
Format
Capability Training

Programme Objectives

  • Develop functional proficiency in using Hugging Face to review AI models, datasets, repositories, and deployment information from a risk and audit perspective.
  • Evaluate model provenance, intended use, limitations, licences, datasets, security indicators, and supporting documentation.
  • Assess access governance, repository controls, authentication, deployment configurations, and evidence required for AI-control reviews.
  • Build reusable workflows for third-party AI due diligence, model-risk reviews, repository audits, and AI governance assessments.
  • Apply professional judgement to distinguish automated indicators from validated audit findings and risk conclusions.

Tools covered

Hugging Face HubModel CardsDataset CardsModel & Dataset RepositoriesEvaluation ResultsLicencesGated Models & DatasetsSecurity ScanningOrganizationsAccess ControlsResource GroupsAudit LogsInference Endpoints

Who should attend

  • Risk Managers
  • Internal Auditors
  • IT Auditors
  • Technology Risk Professionals
  • AI Risk & Governance Professionals
  • Model Risk Professionals
  • Information Security Auditors
  • Governance, Risk & Compliance Professionals
  • Operational Risk Professionals
  • Third-Party Risk Professionals
  • Compliance & Assurance Professionals
  • Technology Governance Teams
  • Internal Control Professionals

Prerequisites & Participant Readiness

  • Basic understanding of risk, audit, controls, or governance
  • Familiarity with technology or information-security risks is helpful
  • Basic awareness of AI and machine-learning concepts
  • Familiarity with control testing and evidence review is recommended
  • No advanced programming or data-science expertise required
  • No previous Hugging Face experience required

TOC Modules

Concepts
  • Understanding the Hugging Face ecosystem: models, datasets, repositories, Spaces, and deployment services
  • Understanding how AI assets move from development and sharing to deployment and business use
  • Identifying risk domains including model, data, security, licensing, access, and operational risks
  • Mapping Hugging Face artefacts to audit objectives and control evidence
Practical activities
  • Exploring representative model, dataset, and repository pages
  • Identifying audit-relevant information available within each artefact
  • Creating an initial AI Asset Risk Review checklist

Scenarios

Third-Party AI Model Due Diligence

Business Use Case → Hugging Face Model → Model Card → Dataset & Licence Review → Evaluation Evidence → Security Indicators → Risk Assessment → Approval Recommendation

Participants assess a proposed third-party Hugging Face model before enterprise adoption, identifying documentation, data, licensing, performance, security, and governance risks requiring remediation or approval.

Internal Hugging Face Repository & Access Audit

Organization → Models / Datasets → Users & Roles → Tokens → Access Controls → Audit Evidence → Exceptions → Corrective Actions

Participants conduct a structured review of an organization's Hugging Face environment, test repository and access controls, identify potential governance weaknesses, and produce evidence-backed audit observations and corrective-action recommendations.

Continue with programmes from the same capability area.

Take the next step

Ready to make this programme work for your team?

Customise modules, duration and business scenarios for your team.

Instructor-ledVirtualHybrid

Designed around your roles, tools and real workflows.