Key AI risks
▹Bias going undetected without audits
▹Unexplained, un-appealable automated decisions
▹No clear accountability when AI causes harm
▹Inequitable deployment across student and employee populations
Governed through the RMF Playbook
Each function pairs the outcome to reach for this domain (the Playbook's About) with the Playbook's suggested actions.
Govern
Require human oversight, transparency, and clearly assigned accountability for any AI that affects people.
Playbook · suggested actions
Require oversight, transparency, and named accountability for consequential AI.
Map
Assess the impact of a consequential system before it deploys — who it affects and how it could go wrong.
Playbook · suggested actions
Run an algorithmic impact assessment before any consequential deployment.
Measure
Audit for bias, demand explainability, and review equity impact on a defined schedule.
Playbook · suggested actions
Schedule bias audits and require explainability and equity review.
Manage
Provide redress when harm occurs and hold named owners accountable for the outcomes.
Playbook · suggested actions
Provide appeals and redress and assign responsibility when AI causes harm.
Worked case studies · the RMF Playbook applied
10 scenarios
Each step is a Playbook suggested action for that function; the evidence line is the transparency & documentation you keep.
Standing up the impact-assessment process
AI Governance Body · oversight
The institution has consequential AI in several offices but no consistent way to assess its risk.
Govern
Adopt human-oversight and transparency policies plus institutional AI ethics principles.
Map
Establish the NIST-aligned impact-assessment standard — every consequential system files one first.
Measure
Set a bias-audit schedule, an explainability standard, and an equity-impact review.
Manage
Run appeals and redress, assign accountability, and audit on an annual cycle.
Outcome — Consequential systems across the institution produce consistent, comparable risk evidence.
Evidence: Impact-assessment repository + bias-audit calendar
Bias audit of an admissions model
Oversight · admissions AI
An admissions scoring model must be audited for disparate impact before renewal.
Govern
The bias-audit standard requires scheduled audits of consequential systems.
Map
Identify protected groups and the decisions the model influences.
Measure
Run the bias-audit protocol and quantify disparate impact.
Manage
Require remediation or retirement where disparities appear.
Outcome — Disparities are surfaced and remediated before the model continues.
Evidence: Bias-audit report + remediation plan
Explainability for an aid-eligibility system
Oversight · financial aid
Students denied aid by an AI-informed system deserve an understandable reason.
Govern
The transparency policy requires explainable consequential decisions.
Map
Identify what must be explained and to whom.
Measure
Test whether explanations are accurate and understandable.
Manage
Provide reasons and a route to human review.
Outcome — Affected students receive clear, accurate reasons they can act on.
Evidence: Explainability standard + sample decision notices
Equity review before a campus-ops AI deploys
Oversight · operations
A campus-operations AI could affect individual rights and triggers Domain 6 review.
Govern
Oversight is required for operational AI affecting people.
Map
Assess who is affected and how before deployment.
Measure
Run an equity-impact review and check for harm.
Manage
Set conditions, mitigations, and a review date.
Outcome — The system deploys only with equity safeguards in place.
Evidence: Equity-impact review + deployment conditions
Assigning accountability when AI errs
Oversight · accountability
A consequential system caused harm and no one is clearly responsible.
Govern
The accountability framework names responsible owners for each system.
Map
Identify the decision chain and where responsibility sits.
Measure
Review the incident against the accountability assignment.
Manage
Assign ownership, remediate, and update the framework.
Outcome — Every consequential system has a named, accountable owner.
Evidence: Accountability RACI + incident review
Community input on surveillance AI
Oversight · civil liberties
A proposed surveillance system needs community review before deployment.
Govern
Community engagement is required for surveillance and security AI.
Map
Identify the affected community and civil-liberties concerns.
Measure
Assess proportionality, bias, and retention.
Manage
Hold consultation and set limits before any go-ahead.
Outcome — Deployment reflects community input and clear limits.
Evidence: Consultation record + civil-liberties assessment
Transparency disclosure on a public chatbot
Oversight · public communications
A public-facing chatbot must disclose that people are interacting with AI.
Govern
The transparency-disclosure policy requires clear AI disclosure.
Map
Identify where disclosure and a human path are needed.
Measure
Verify the disclosure and escalation actually work.
Manage
Publish the disclosure and monitor for accuracy.
Outcome — The public knows when it is talking to AI and how to reach a person.
Evidence: Disclosure copy + escalation test
Auditing a vendor model for bias
Oversight · vendor systems
A vendor product classified as consequential must show bias documentation.
Govern
High-risk vendor products must supply impact and bias documentation.
Map
Identify the model’s decisions and affected groups.
Measure
Review the vendor’s bias evidence and independently spot-check.
Manage
Require fixes or reject the product where evidence is weak.
Outcome — Only vendor models with credible fairness evidence are used.
Evidence: Vendor bias documentation + independent check
Redress for a wrongly flagged student
Oversight · appeals
A student was wrongly flagged by a consequential system and needs recourse.
Govern
The redress process guarantees appeals for AI-affected individuals.
Map
Identify the decision and the harm to the student.
Measure
Review the case and the system’s error.
Manage
Reverse the outcome, remediate, and log the error for the audit.
Outcome — The student is made whole and the error feeds the next audit.
Evidence: Appeal resolution + error log
Periodic re-audit and drift monitoring
Oversight · monitoring
A previously cleared model may have drifted and needs re-checking.
Govern
The review cycle requires periodic re-audit of consequential systems.
Map
Identify systems due for re-audit and what may have changed.
Measure
Re-run bias and performance checks and compare to baseline.
Manage
Remediate drift or retire the system.
Outcome — Models are kept fair and accurate over time, not just at launch.
Evidence: Re-audit report + drift comparison
Risk-tier examples
Consequential
Any consequential system requiring an impact assessment, bias audit, and human oversight.
Tools & artifacts
Algorithmic impact assessment template
Bias-audit protocol
Explainability / decision-log standard
Accountability RACI
Key controls & instruments
Algorithmic impact assessment standard (NIST-aligned)
Bias-audit requirements & schedules
Explainability standards
Accountability assignment framework