Phase 7: Responsible AI, Governance & Risk · 140 min · Python · EU AI Act · NIST AI RMF
Project: Responsible AI Review
Four lessons, one feature, one document a launch review would actually accept.
Hiring signal: A complete, coherent responsible AI review — consequence-scan, disclosure plan, regulatory triage, incident readiness, and guardrail decisions for one real feature — is precisely the artifact research identifies as the highest-leverage AI PM portfolio piece: it demonstrates technical fluency, judgment under uncertainty, and the ability to ship consequential features responsibly, all against a concrete example rather than in the abstract. This project also feeds directly into the Phase 9 capstone case study.
What you will learn
- Assemble a consequence-scan, ethical KPIs, and a product-facing system card for the same feature carried through Projects 1-3
- Classify that feature under the EU AI Act and map it to NIST AI RMF actions, translating the result into PRD-ready requirements
- Write an incident-readiness plan and a guardrail decision set for the feature's most plausible failure and abuse scenarios
- Produce a single, complete responsible AI review document a real launch review would accept as sufficient
- Explicitly connect this review's findings back to the opportunity assessment, PRD, and eval plan from Projects 1-3
The Problem
Picture the launch review you'd actually sit in for the feature you've been carrying through this course. The opportunity assessment from Phase 2 said this was worth building. The PRD from Phase 4 said exactly what it should do, including its guardrails and cost model. The evaluation plan from Phase 5 said how you'd know if it's working. Now someone at the table — legal, a skeptical VP, a trust-and-safety lead who has seen a feature like this go wrong before — asks the question none of those three documents fully answers: if this goes wrong, what happens, and are we ready?
That question doesn't get a good answer from four separate documents stapled together. It gets a good answer from one responsible AI review that pulls the actual analysis from this phase's five lessons — consequence-scan, disclosure plan, regulatory classification, incident readiness, guardrail decisions — and applies every one of them to the same feature you've been developing since Phase 2. This project is that document. It's also, not incidentally, the fourth of four project artifacts the Phase 9 capstone will assemble into a single portfolio case study, so the discipline of writing this cleanly now pays off twice: once in this phase, and again when you're building the artifact a hiring manager actually reads.
What This Project Assembles
Rather than introducing new frameworks, this project is deliberately an assembly exercise — the hard thinking already happened in Lessons 1-5. Your job is to apply five completed frameworks to one real feature and make them cohere into a single narrative, not five disconnected exercises:
- Consequence-scan and ethical KPIs (Lesson 1) — who is affected if your feature's AI component is wrong, and what fairness metric with what threshold would catch it
- Product-facing disclosure (Lesson 2) — what a user or affected person needs to know about this specific feature, distinct from any internal model documentation
- Regulatory classification (Lesson 3) — the feature's EU AI Act tier and the NIST AI RMF actions that follow from it, turned into requirements a PRD could actually contain
- Incident readiness (Lesson 4) — the single most plausible way this feature fails publicly, and whether your team could actually execute the first-hour/first-day response if it happened tomorrow
- Guardrail decisions (Lesson 5) — the two or three most plausible abuse cases for this specific feature, each with an allow/deflect/escalate/refuse decision and a stated friction tradeoff
Continuity is the point, not a formality
If your Phase 2 opportunity assessment picked "AI-assisted loan pre-approval" and your Phase 4 PRD specified how it works, this review has to be about that feature — not a generic loan-AI risk essay. A reviewer (and, later, an interviewer looking at your portfolio) can tell immediately when a "risk assessment" was written in isolation versus written against a real PRD's actual design decisions. Reuse your own specifics: the affected groups you already named, the guardrails you already specified, the cost/latency tradeoffs that already constrain what containment options are realistic.
Unlock the full lesson
You've read the first 2 sections. The rest of this lesson covers Why This Order, and Why It's Not Five Separate Documents, What Makes This Review Launch-Ready, Not Just Complete, Build It, What to Practice — plus a hands-on lab, quiz, and project artifact.
Create a free account to unlock Phase 0 and Phase 1 of every course — no credit card.
Browse all courses · View pricing · DeVenture Academy