Campus AI Framework · Governance, Risk & Compliance
AI is already shaping decisions on your campus. The question is whether it's governed.
AI is shaping decisions about real people across your campus — admissions, advising, research, vendor systems — often with no review and no owner. This is the practical guide to governing it: a structured method applied to the nine areas where the risk actually lives, sized so oversight matches the stakes.
The exposure you already own
Ungoverned AI isn't a neutral pause — discrimination claims, privacy breaches, unreviewed contracts, and eroded trust accrue quietly. Doing nothing is the higher-risk option no one consciously chose.
9
governance domains
4
NIST RMF functions
3
risk tiers
Built on NIST AI RMF 1.0
However you arrive, there's a lane for you
01
The risk you own →
02
How it scales →
03
Find your domain →
The decision-maker
You fund & greenlight it
The case in one screen: the exposure you carry, and the one thing only leadership can do — name owners and charter oversight.
The strategist
You set the direction
How it sequences and scales — a small first phase covering the biggest exposures, growing from one unit to the whole system.
The practitioner
You run an actual AI use
Find your domain, tier it, then follow a worked path — risks, RMF actions, a case study, controls — to a defensible decision.