Campus AI Framework / Pillar 4 — Risk
Download framework
About this website · what it is and how to read it

A working reference for governing AI risk in higher education

This site is the risk companion to the Campus AI Framework — its Pillar 4, Governance, Risk & Compliance. It takes one well-established method — the NIST AI Risk Management Framework and its Playbook — and applies it to the nine domains where AI actually shows up in a university. Not a reading assignment but an operating reference: find the domain your situation lives in, see the risks it carries, and follow a worked path from concern to a proportionate, defensible decision.

Abstract

Every institutional use of AI is treated as a concrete use that lives in one of nine governance domains, carries a subset of failure modes, and threatens specific harms. Each use is run through the four RMF functions — Govern, Map, Measure, Manage — and sized against three risk tiers so that oversight is proportional to the stakes. The nine domains answer who owns a risk; five board-level categories answer what kind of risk it is; and cross-domain concerns are given a single explicit owner. The result is one shared vocabulary that connects a classroom decision to a board report.

Who it is for
▹Provosts, CIOs, CISOs and general counsel setting institution-wide AI policy
▹Deans, department chairs and program leads making domain-level decisions
▹AI governance committees, IRBs, and audit & risk committees
▹Faculty and staff piloting a specific AI use who need a defensible path
How to read it
▹Read top to bottom the first time — each page builds on the last
▹Use the left Contents panel to jump; open The nine domains to reach any single domain
▹Each domain page carries its risks, RMF actions, worked case studies, tier examples, tools and controls
▹Return here anytime — this page is the map of everything else
How it is organized · eight sections
00 Overview The framing — what the risk companion covers and why proportionate governance matters. 01 First principles What makes higher-ed AI different, and the durable commitments every decision is measured against. 02 Operating model The two instruments in play: the NIST RMF as method, the nine domains as territory. 03 The method The method itself — Govern, Map, Measure, Manage — and how the four functions interlock. 04 The nine domains The nine domains where AI risk lives, each with its own detail page of risks and worked cases. 05 Five risk categories The board lens — five categories that name what kind of risk a system poses. 06 Risk tiers Three risk tiers that set how much rigor and who must be at the table. 07 Cross-domain risk Risks that fall between offices, each assigned one explicit owner. 08 The people affected The students, faculty, and staff on the receiving end — their right to notice, explanation, and appeal. 09 Maturity model A five-stage self-assessment: locate where your institution is today and the next move. 10 Roadmap A phased adoption path — the minimum viable governance stack first, full framework second. 11 Governance body Who to convene and how they work — the committee roster and the process for prioritizing risks.
What it rests on

The vocabulary is deliberately borrowed, not invented. Method and language come from the NIST AI Risk Management Framework (AI 100-1) and its Playbook; the nine domains and their three bands come from The Nine AI Governance Domains, Pillar 4 of the Campus AI Framework. Nothing here asks an institution to adopt a new standard — only to apply a recognized one consistently.

What it is not

This is general guidance, not legal advice, and not a compliance certification. The case studies are illustrative, not prescriptive. Your institution's own counsel, privacy office, policies and local rules govern any real decision.

Status Concept & content by Joe Sabado · Version 1.0, March 2026 · Licensed CC BY-NC-SA 4.0 · Developed with AI assistance.
← Governance body