Campus AI Framework / Pillar 4 — Risk
Download framework
Campus AI Framework · Governance, Risk & Compliance

AI is already shaping decisions on your campus. The question is whether it's governed.

AI is shaping decisions about real people across your campus — admissions, advising, research, vendor systems — often with no review and no owner. This is the practical guide to governing it: a structured method applied to the nine areas where the risk actually lives, sized so oversight matches the stakes.

The exposure you already own
Ungoverned AI isn't a neutral pause — discrimination claims, privacy breaches, unreviewed contracts, and eroded trust accrue quietly. Doing nothing is the higher-risk option no one consciously chose.
9 governance domains
4 NIST RMF functions
3 risk tiers
Built on NIST AI RMF 1.0
First principles · before the mechanics

A university is not a company. Its AI governance shouldn't pretend to be.

Why higher education is different

Corporate AI governance optimizes for the shareholder. A university answers to students it holds in trust, to a mission of truth-seeking, and to shared governance and academic freedom. Those commitments change what "responsible AI" means here — and generic frameworks ignore them.

Students are a vulnerable population
They can't opt out of the systems that grade, flag, and route them. The institution holds a duty of care a customer relationship never carries.
Truth-seeking is the product
AI that fabricates, flatters, or erodes critical thinking attacks the university's core purpose — not just its efficiency.
Authority is shared, not top-down
Faculty governance and academic freedom mean policy must be legitimate, not just issued. Governance that ignores this won't hold.
Why this matters Principles are the constant the mechanics serve. When a domain, tier, or vendor contract raises a hard call, these six commitments are what you decide against — and what makes the decision defensible to a board, a faculty senate, or a student.
Six durable commitments
{{ p.n }} {{ p.name }}
{{ p.body }}
The operating model

Two instruments, applied to the risk in every domain

The NIST AI Risk Management Framework defines the outcomes; its companion Playbook turns each one into concrete suggested actions and documentation. Together they are applied to the specific AI risks in each of the nine domains of the Campus AI Framework.

Why this matters You don't have to invent a standard or defend a homegrown one. A recognized, publicly documented method is easier to explain to a board or auditor, and gives you a consistent basis to point to if a decision is challenged.
01 · The framework
NIST AI Risk Management Framework

A widely recognized framework for AI risk. Its four functions define the outcomes an institution must reach across the AI lifecycle — the culture, context, assessment, and treatment of risk.

Govern Map Measure Manage
NIST AI 100-1 · 7 trustworthy characteristics ↗
02 · The playbook
NIST AI RMF Playbook

The companion Playbook translates every outcome into suggested actions, transparency & documentation questions, and references — the how-to for achieving the framework's outcomes.

Suggested actions Documentation References
Open the Playbook ↗
03 · The application
The nine domains' risks

Playbook and method meet the ground truth — the specific AI risks in each domain, governed in proportion to each system's stakes through the three risk tiers.

9 domains 3 tiers
Explore the nine domains →
NIST AI RMF + NIST RMF Playbook AI risk, governed across nine domains
The method · NIST AI RMF 1.0

The nine domains say where risk lives. NIST says how to govern it.

The framework maps the full territory of institutional AI — teaching, research, decisions about people, data and systems, vendors, and oversight. The NIST AI RMF supplies the repeatable practice applied inside each domain.

Its four functions are not a linear checklist. Govern is the culture that wraps everything; Map, Measure, and Manage run continuously across the AI lifecycle.

Why this matters This is the practice your teams run for any AI use — the same four steps whether it's a chatbot or an admissions model. One method everyone follows is what makes oversight consistent instead of ad hoc.
How the four functions relate
Govern The culture, policy & accountability that wraps and runs through the other three
Map
Establish context & identify risk
Measure
Analyze, assess & monitor
Manage
Prioritize, respond & recover
Map · Measure · Manage run continuously across the AI lifecycle — not a one-time checklist
Govern
Cultivate a culture of AI risk management — the cross-cutting foundation
Policies, accountability structures, and review cycles that inform and run through Map, Measure, and Manage across the entire lifecycle. Here Govern is owned by Domain 9 and shared by every other domain.
Map
Establish context & identify risk

Categorize the AI system, its purpose, and who it affects. In practice: risk tiering, the system inventory, and impact assessments before deployment.

Measure
Analyze, assess & monitor

Assess risk with quantitative and qualitative methods. In practice: bias audits, explainability standards, validation, audit trails and logging.

Manage
Prioritize, respond & recover

Act on risk in proportion to impact. In practice: human-review pathways, appeals and redress, incident response, and vendor remediation.

How the Playbook works
New to NIST? For every outcome in the framework, the NIST AI RMF Playbook hands you four practical things — the same structure behind each domain's worked case study.
About
A plain-language explanation of the risk each outcome addresses.
Suggested actions
Concrete steps a team can take to reach the outcome.
Transparency & documentation
Questions to answer and record as evidence of your work.
References
Standards and sources to draw on for each action.
The bar each domain is measured against · 7 characteristics of trustworthy AI
Valid & reliable Safe Secure & resilient Accountable & transparent Explainable & interpretable Privacy-enhanced Fair — with harmful bias managed
Where risk lives · the nine domains

Nine domains, each governed through the RMF

Each domain is a container of risks, and all four RMF functions apply to every one. Filter by area, then open a domain for its risks, RMF mapping, a worked case study, tiers, and tools.

Why this matters These nine areas are how you assign clear ownership — every AI use on campus has a named owner, so nothing runs unwatched. Start with the one domain your situation sits in.
Filter {{ count }} shown
{{ g.range }} {{ g.label }}
The board lens · five categories of risk

What kind of risk is this?

The nine domains answer who owns a risk; a board also needs the other lens — what kind of exposure it is. Every category spans all nine domains; what differs is where each concentrates. Each card names the domains where the exposure is most acute and how it's captured, documented, and escalated.

Why this matters This is the view for a board or risk committee: the same exposures they already govern — legal, financial, reputational — now applied to AI, in language they recognize and can act on.
01Strategic
Mission & position

Falling behind on AI capability, misaligned investment, or graduating students unready for an AI workforce — risk to the institution's long-term competitiveness and mission.

Concentrates in
Institutional risk register → board / cabinet review
02Ethical
Fairness & integrity

Bias and disparate impact, opacity in consequential decisions, and erosion of academic integrity — risk to how AI treats people and knowledge.

Concentrates in
Impact assessment + bias audit → human oversight & appeals
03Operational
Reliability & security

Model drift, security exposure, shadow AI, and agentic systems acting unsupervised — risk to the continuity and safety of AI-enabled operations.

Concentrates in
Audit logging + shadow-AI discovery → incident response
04Regulatory
Law & compliance

FERPA and privacy, IP and training-data terms, export control, and funder rules — risk of breaching the law, contracts, or sponsor conditions.

Concentrates in
Legal review + contract controls → compliance monitoring
05Reputational
Trust & standing

Public backlash when AI use becomes visible — in admissions, proctoring, or communications — and the loss of community trust that follows.

Concentrates in
Disclosure & comms review → governance-body escalation
Category × domain — where each exposure concentrates
Every category touches all nine domains; the marked cells show where it bites hardest. A filled cell means the domain owns that category's standard.
D1
D2
D3
D4
D5
D6
D7
D8
D9
Strategic
Ethical
Operational
Regulatory
Reputational
Concentrates here
Owns the standard

These categories are a reporting lens, not a parallel process. A single AI system usually carries several at once — a retention model is ethical, operational, and reputational simultaneously. Its domain still owns it and the RMF still governs it; the category simply tells the board why it matters and routes it to the right committee.

Proportionality · risk tiering applied through the NIST RMF

Govern each system in proportion to its stakes

These three tiers are this framework's own, applied through the NIST AI RMF: Map categorizes each system, Measure assesses its risk, and Manage treats it. Domain 9 owns the standard; every domain applies it. The tier rates how much a system decides, not how much an office matters — a critical department can run entirely on Assistive tools, and that's the goal.

Why this matters Not every AI use needs the same scrutiny. Tiering lets low-stakes tools move fast while high-stakes ones get real review — oversight that's proportionate, not bureaucratic.
Oversight scales with stakes more at stake → more scrutiny
1 RMF function
Assistive
Tier 1 · Low
3 functions
Operational
Tier 2 · Moderate
4 functions
+ impact assessment
Consequential
Tier 3 · High
Tier 1 · Low
Assistive

Tools that support a person who stays fully in control, with no decision authority. Where most systems should stay — keeping a human in charge is the win, not a limitation.

RMF Govern
Acceptable-use compliance + approved tool list
Tier 2 · Moderate
Operational

Systems that inform work or decisions with meaningful human review in the loop.

RMF Govern Map Measure
Data-governance review + departmental approval
Tier 3 · High
Consequential

Systems that make or inform decisions materially affecting people's lives and rights.

RMF Map Measure Manage
Impact assessment · bias audit · human oversight · notification & appeals · evidence package · inventory
Map + Measure
The assessment behind the tier: a NIST-aligned algorithmic impact assessment

Before any consequential system deploys, Domain 6 requires an algorithmic impact assessment aligned to the RMF's Map and Measure functions — drawing on the Playbook's suggested actions and transparency & documentation questions to establish context, test for bias, and record the evidence that sets the system's tier.

Coordination · risks that belong to no single office

Shared risks get one explicit owner

The concerns most likely to fall between offices get an owner and coordinating domains — the connective tissue that keeps nine domains coherent instead of siloed.

Why this matters The risks that cause the worst surprises are the ones no single office thought it owned. Naming one owner for each prevents the “we assumed someone else had it” failure.
Shadow AI

Ungoverned AI use — including by student orgs and co-curricular programs — on institutional data or infrastructure.

D5 discovery → D7 vendor remediation → D9 escalation
Algorithmic bias

Disparate impact in consequential systems affecting admissions, aid, retention, hiring, and public communications.

D6 owns standard → applied by D3, D5, D7
Agentic AI

Autonomous systems taking actions, with human-in-the-loop requirements and agent-to-agent controls.

D9 owns standard → D5 build, D7 vendor, D3 decisions
Data security in vendor relationships

Training-data terms, data-use restrictions, and audit rights that outpace legal and security review.

D5 defines → D7 enforces in contracts → D9 monitors
Where consequential risk concentrates
High-risk systems cluster in decisions about people — govern those first

Domain 3 (decisions about people), Domain 5 (data, security & operational AI), and Domain 8 (employment) hold most consequential systems — with Domain 6 supplying the oversight that governs them all.

03 05 08 06
The people affected · governance from the other side of the decision

Protect the institution — and the person the AI decides about.

Every risk on this site ultimately lands on a person — a student who was flagged, an applicant screened out, a faculty member whose work was scored. Governance that only asks "what's our exposure?" tells half the story. The measure of a system is whether the person on the receiving end has any recourse.

Why this matters Contestability is both an equity commitment and a risk control. A system people can question surfaces its own errors — the appeals are your early-warning signal for bias and failure, long before a lawsuit or a headline.
{{ r.icon }}
{{ r.title }}
{{ r.body }}
What it looks like in practice · a student flagged by an early-alert model
Without contestability

A retention model flags a student as "high risk." Advising quietly reroutes them to a remedial track. The student is never told, can't see why, and has no way to say the model misread a medical leave. The error compounds silently.

With contestability

The student is notified a model informed the outreach, gets a plain explanation of the top factors, can appeal to a named advisor, and their correction feeds back — redress — improving the model for everyone.

Maturity model · where is your institution now?

You can't plan the path until you know where you're standing.

Before the roadmap, locate yourself. Institutions are often further back than leadership assumes — and the honest answer sets your next move. Find the stage that sounds like today.

Why this matters A shared, honest read of your current stage aligns leadership on the size of the gap and prevents skipping steps. You can't buy your way to "Managed" — each stage is the foundation the next stands on.
{{ s.n }}
{{ s.name }}
{{ s.who }}
Signs: {{ s.signs }}
Next move {{ s.next }}
Implementation · adopt in phases

A minimum viable governance stack first

Why this matters You don't need a finished program to start. A small first phase — a policy, an owner, a tiering rule — covers the biggest exposures now and scales from one unit to the whole institution without a reboot.
Phase 1 · Minimum viable stack
Stand up governance and the most urgent risk domains
09Governance, oversight & continuous review — established first
05Data, security, privacy & AI-enabled systems
01Teaching, learning & assessment
03Institutional algorithmic decision-making & student services
07Procurement, vendors & legal
Phase 2 · Full framework
Extend once infrastructure is operational
02Research & scholarship
04Student AI literacy, career readiness & workforce
06Fairness, transparency, accountability & oversight
08AI literacy & role-based competency (employees)
Standing up your governance body · who & how

Someone has to own this. Here's who, and how they work.

The framework assumes a body that charters oversight and prioritizes risk. Here's how to convene it: a cross-functional committee, a repeatable process from "we should look at AI" to a ranked list of risks with owners, and the one structural choice that decides whether it lasts.

Why this matters AI governance often stalls because no group owns it. Chartering a standing body — with the right offices at the table — is the one move only leadership can make, and what turns this framework from a document into a practice.
Who's at the table
A cross-functional committee — because AI risk crosses every office

No single office can see the whole picture — the risks that cause the worst surprises are the ones each office assumed another owned. Each seat below maps to the domains it's closest to.

{{ c.role }}
{{ c.why }}
Scale to fit: a department or single college can combine seats into three or four people; a whole system charters the full committee with subteams. The functions matter more than the headcount.
How they work · from "we should look at AI" to a ranked list with owners
A five-step convening process
{{ p.n }} {{ p.title }} {{ p.body }}
The one choice that decides if it lasts
A standing committee, not a task force

AI risk is continuous, not a one-time project. A task force disbands the moment its report is filed — right when new tools, vendors, and regulations start arriving. Charter a permanent body with a standing mandate to review, or the work evaporates and you rebuild it under pressure a year later.

What a charter should name
Mandate — examine AI risk, prioritize it, recommend mitigations, protect data, operations, and the community
Sponsor — a named senior executive (finance, provost, or CIO) who convenes it and receives its reports
Cadence — a standing review rhythm, plus a path to escalate high-tier risks between meetings
Authority — what it can approve, what it must escalate, and how its decisions bind procurement and units
Your move, by role
Decision-maker
Charter a standing committee and name its sponsor. That single act is what only you can do.
Strategist
Right-size the roster to your unit today, with a clear path to expand to subteams as adoption grows.
Practitioner
Run the five-step process on your own AI uses and bring the ranked list to the committee.
Committee model and convening process adapted from published higher-ed practice (e.g. RIT's AI Safety & Security Advisory Committee), mapped onto this framework's domains and tiers.
About this website · what it is and how to read it

A working reference for governing AI risk in higher education

This site is the risk companion to the Campus AI Framework — its Pillar 4, Governance, Risk & Compliance. It takes one well-established method — the NIST AI Risk Management Framework and its Playbook — and applies it to the nine domains where AI actually shows up in a university. Not a reading assignment but an operating reference: find the domain your situation lives in, see the risks it carries, and follow a worked path from concern to a proportionate, defensible decision.

Abstract

Every institutional use of AI is treated as a concrete use that lives in one of nine governance domains, carries a subset of failure modes, and threatens specific harms. Each use is run through the four RMF functions — Govern, Map, Measure, Manage — and sized against three risk tiers so that oversight is proportional to the stakes. The nine domains answer who owns a risk; five board-level categories answer what kind of risk it is; and cross-domain concerns are given a single explicit owner. The result is one shared vocabulary that connects a classroom decision to a board report.

Who it is for
Provosts, CIOs, CISOs and general counsel setting institution-wide AI policy
Deans, department chairs and program leads making domain-level decisions
AI governance committees, IRBs, and audit & risk committees
Faculty and staff piloting a specific AI use who need a defensible path
How to read it
Read top to bottom the first time — each page builds on the last
Use the left Contents panel to jump; open The nine domains to reach any single domain
Each domain page carries its risks, RMF actions, worked case studies, tier examples, tools and controls
Return here anytime — this page is the map of everything else
How it is organized · eight sections
What it rests on

The vocabulary is deliberately borrowed, not invented. Method and language come from the NIST AI Risk Management Framework (AI 100-1) and its Playbook; the nine domains and their three bands come from The Nine AI Governance Domains, Pillar 4 of the Campus AI Framework. Nothing here asks an institution to adopt a new standard — only to apply a recognized one consistently.

What it is not

This is general guidance, not legal advice, and not a compliance certification. The case studies are illustrative, not prescriptive. Your institution's own counsel, privacy office, policies and local rules govern any real decision.

Status Concept & content by Joe Sabado · Version 1.0, March 2026 · Licensed CC BY-NC-SA 4.0 · Developed with AI assistance.
← All domains
Domain {{ selectedDomain.num2 }} · {{ selectedDomain.catRange }}

{{ selectedDomain.title }}

{{ selectedDomain.scope }}
Key AI risks
{{ r }}
Governed through the RMF Playbook
Each function pairs the outcome to reach for this domain (the Playbook's About) with the Playbook's suggested actions.
{{ b.key }}
{{ b.text }}
Playbook · suggested actions
{{ b.actions }}
Worked case studies · the RMF Playbook applied {{ selectedDomain.caseCount }} scenarios
Each step is a Playbook suggested action for that function; the evidence line is the transparency & documentation you keep.
{{ selectedDomain.activeCase.title }}
{{ selectedDomain.activeCase.setting }}

{{ selectedDomain.activeCase.scenario }}

{{ s.fn }} {{ s.text }}
Outcome — {{ selectedDomain.activeCase.outcome }}
Evidence: {{ selectedDomain.activeCase.evidence }}
Risk-tier examples
{{ t.tier }} {{ t.example }}
Tools & artifacts
{{ t }}
Key controls & instruments
{{ c }}
{{ selectedDomain.prevLabel }} {{ selectedDomain.nextLabel }}