A working reference for governing AI risk in higher education
This site is the risk companion to the Campus AI Framework — its Pillar 4, Governance, Risk & Compliance. It takes one well-established method — the NIST AI Risk Management Framework and its Playbook — and applies it to the nine domains where AI actually shows up in a university. Not a reading assignment but an operating reference: find the domain your situation lives in, see the risks it carries, and follow a worked path from concern to a proportionate, defensible decision.
Every institutional use of AI is treated as a concrete use that lives in one of nine governance domains, carries a subset of failure modes, and threatens specific harms. Each use is run through the four RMF functions — Govern, Map, Measure, Manage — and sized against three risk tiers so that oversight is proportional to the stakes. The nine domains answer who owns a risk; five board-level categories answer what kind of risk it is; and cross-domain concerns are given a single explicit owner. The result is one shared vocabulary that connects a classroom decision to a board report.
The vocabulary is deliberately borrowed, not invented. Method and language come from the NIST AI Risk Management Framework (AI 100-1) and its Playbook; the nine domains and their three bands come from The Nine AI Governance Domains, Pillar 4 of the Campus AI Framework. Nothing here asks an institution to adopt a new standard — only to apply a recognized one consistently.
This is general guidance, not legal advice, and not a compliance certification. The case studies are illustrative, not prescriptive. Your institution's own counsel, privacy office, policies and local rules govern any real decision.