Admissions screening, advising nudges, research tools, vendor systems grading and flagging students — AI is shaping decisions about real people across your institution, often with no review and no owner. This is the practical guide to governing it: a proven federal method applied to the nine areas of campus where the risk actually lives, sized so oversight matches the stakes.
The case in one screen: the exposure you already carry, and the one thing only leadership can do — name owners and charter oversight.
How it fits, sequences, and scales — a small first phase that covers the biggest exposures now and grows from one unit to the whole system.
Find the domain your situation lives in, tier it, then follow a worked path — risks, RMF actions, a real case study, controls — to a defensible decision.
Corporate AI governance optimizes for the shareholder. A university answers to students it holds in trust, to a mission of truth-seeking, and to a tradition of shared governance and academic freedom. Those commitments change what "responsible AI" means here — and generic frameworks quietly ignore them.
The NIST AI Risk Management Framework defines the outcomes; its companion Playbook turns each one into concrete suggested actions and documentation. Together they are applied to the specific AI risks in each of the nine domains of the Campus AI Framework.
The recognized framework for AI risk. Its four functions define the outcomes an institution must reach across the AI lifecycle — the culture, context, assessment, and treatment of risk.
The companion Playbook translates every outcome into suggested actions, transparency & documentation questions, and references — the how-to for achieving the framework's outcomes.
Playbook and method meet the ground truth — the specific AI risks in each domain, governed in proportion to each system's stakes through the three risk tiers.
The framework maps the full territory of institutional AI — teaching, research, decisions about people, data and systems, vendors, people, and oversight. The NIST AI RMF supplies the repeatable practice applied inside each of those domains.
Its four functions are not a linear checklist. Govern is the culture that wraps everything; Map, Measure, and Manage run continuously across the AI lifecycle.
Categorize the AI system, its purpose, and who it affects. In practice: risk tiering, the system inventory, and impact assessments before deployment.
Assess risk with quantitative and qualitative methods. In practice: bias audits, explainability standards, validation, audit trails and logging.
Act on risk in proportion to impact. In practice: human-review pathways, appeals and redress, incident response, and vendor remediation.
Each domain is a container of risks, and all four RMF functions — Govern, Map, Measure, Manage — apply to every one. Filter by area, then open a domain for its risks, full RMF mapping, a worked case study, tiers, and tools.
The nine domains answer who owns a risk. Governance and audit committees also need the other lens — what kind of exposure it is. Every category applies to all nine domains — any AI system can carry all five at once. What differs is where each concentrates. Mapping AI onto the risk language the board already uses keeps anything consequential from falling between the domain headings. Each card names the domains where the exposure is most acute and how it is captured, documented, and escalated.
Falling behind on AI capability, misaligned investment, or graduating students unready for an AI workforce — risk to the institution's long-term competitiveness and mission.
Bias and disparate impact, opacity in consequential decisions, and erosion of academic integrity — risk to how AI treats people and knowledge.
Model drift, security exposure, shadow AI, and agentic systems acting unsupervised — risk to the continuity and safety of AI-enabled operations.
FERPA and privacy, IP and training-data terms, export control, and funder rules — risk of breaching the law, contracts, or sponsor conditions.
Public backlash when AI use becomes visible — in admissions, proctoring, or communications — and the loss of community trust that follows.
These categories are a reporting lens, not a parallel process. A single AI system usually carries several at once — a retention model is ethical, operational, and reputational simultaneously. Its domain still owns it and the RMF still governs it; the category simply tells the board why it matters and routes it to the right committee.
Risk assessment and tiering follow the NIST AI RMF: Map categorizes each system and its context, Measure assesses its risk, and Manage treats it — with the Playbook's suggested actions supplying the concrete steps at each tier. Domain 9 owns the three-tier standard; every domain applies it.
Tools that support a person who stays fully in control, with no decision authority.
Systems that inform work or decisions with meaningful human review in the loop.
Systems that make or inform decisions materially affecting people's lives and rights.
Before any consequential system deploys, Domain 6 requires an algorithmic impact assessment aligned to the RMF's Map and Measure functions — drawing on the Playbook's suggested actions and transparency & documentation questions to establish context, test for bias, and record the evidence that sets the system's tier.
The concerns most likely to fall between offices are assigned an owner and coordinating domains — the connective tissue that keeps nine domains coherent instead of siloed.
Ungoverned AI use — including by student orgs and co-curricular programs — on institutional data or infrastructure.
Disparate impact in consequential systems affecting admissions, aid, retention, hiring, and public communications.
Autonomous systems taking actions, with human-in-the-loop requirements and agent-to-agent controls.
Training-data terms, data-use restrictions, and audit rights that outpace legal and security review.
Domain 3 (decisions about people), Domain 5 (data, security & operational AI), and Domain 8 (employment) hold most consequential systems — with Domain 6 supplying the oversight that governs them all.
Every risk on this site ultimately lands on a human being — a student who was flagged, an applicant who was screened out, a faculty member whose work was scored. Governance that only asks "what's our exposure?" misses half the picture. The measure of a system is whether the person on the receiving end has any recourse.
A retention model flags a student as "high risk." Advising quietly reroutes them to a remedial track. The student is never told, can't see why, and has no way to say the model misread a medical leave. The error compounds silently.
The student is notified a model informed the outreach, gets a plain explanation of the top factors, can appeal to a named advisor, and their correction feeds back — redress — improving the model for everyone.
Before the roadmap, locate yourself. Most institutions are further back than their leadership assumes — and the honest answer determines your very next move. Find the stage that sounds like today.
The framework assumes a body that charters oversight and prioritizes risk. This is how to convene it: a cross-functional committee, a repeatable process to get from "we should look at AI" to a ranked list of risks with owners, and the one structural choice that decides whether it lasts.
No single office can see the whole picture — the risks that cause the worst surprises are the ones each office assumed another owned. Each seat below maps to the domains it's closest to.
AI risk is continuous, not a one-time project. A task force disbands the moment its report is filed — right when new tools, vendors, and regulations start arriving. Charter a permanent body with a standing mandate to review, or the work evaporates and you rebuild it under pressure a year later.
This site is the risk companion to the Campus AI Framework — its Pillar 4, Governance, Risk & Compliance. It takes a single, well-established method — the NIST AI Risk Management Framework and its Playbook — and applies it to the nine domains where AI actually shows up in a university. The aim is not a reading assignment but an operating reference: a leader can find the domain their situation lives in, see the risks it carries, and follow a worked path from concern to a proportionate, defensible decision.
Every institutional use of AI is treated as a concrete use that lives in one of nine governance domains, carries a subset of failure modes, and threatens specific harms. Each use is run through the four RMF functions — Govern, Map, Measure, Manage — and sized against three risk tiers so that oversight is proportional to the stakes. The nine domains answer who owns a risk; five board-level categories answer what kind of risk it is; and cross-domain concerns are given a single explicit owner. The result is one shared vocabulary that connects a classroom decision to a board report.
The vocabulary is deliberately borrowed, not invented. Method and language come from the NIST AI Risk Management Framework (AI 100-1) and its Playbook; the domain map and tiering come from the Campus AI Framework. Nothing here asks an institution to adopt a new standard — only to apply a recognized one consistently.
This is general guidance, not legal advice, and not a compliance certification. The case studies are illustrative, not prescriptive. Your institution's own counsel, privacy office, policies and local rules govern any real decision.
{{ selectedDomain.activeCase.scenario }}