Campus AI Framework / Pillar 4 — Risk
Download framework
← All domains
Domain 09 · Domains 8–9

Governance, Oversight & Continuous Review

The governance body, risk tiering, system inventory, agentic AI, incident response, and continuous review — the foundation established first.
Key AI risks
▹Ungoverned AI proliferation across the institution
▹Agentic systems acting autonomously without oversight
▹No shared risk-tiering standard or system inventory
▹Fragmented ownership leaving shared risks unassigned
Governed through the RMF Playbook
Each function pairs the outcome to reach for this domain (the Playbook's About) with the Playbook's suggested actions.
Govern
Establish the body, charter, and accountability that hold the whole AI-governance system together.
Playbook · suggested actions
Charter the governance body and the incident-response process.
Map
Maintain the shared risk-tiering standard and system inventory that let the institution see all of its AI.
Playbook · suggested actions
Maintain the risk-tiering standard and the AI system inventory.
Measure
Track risk, review policy, and assess whether governance capacity and resourcing are keeping pace.
Playbook · suggested actions
Keep a risk register and run annual policy and resourcing reviews.
Manage
Respond to incidents, govern autonomous systems, and coordinate the risks that cross domains.
Playbook · suggested actions
Respond to incidents and govern agentic and cross-domain risks.
Worked case studies · the RMF Playbook applied 10 scenarios
Each step is a Playbook suggested action for that function; the evidence line is the transparency & documentation you keep.
An agentic AI proposal reaches the governance body
AI Governance Body · agentic AI review

IT proposes an autonomous agent that can take actions directly inside the student information system.

Govern Apply the AI governance charter, the incident-response policy, and the agentic-AI standard.
Map The risk-tiering standard classifies the agent as consequential; log it in the AI system inventory.
Measure Add it to the risk register and run the annual review plus enablement and equity-resourcing checks.
Manage Require human-in-the-loop approval, hard action boundaries, an escalation path, and cost governance.
Outcome — The agent is approved with strict action boundaries and a kill-switch, and is tracked in the inventory.
Evidence: Risk-register entry + agentic-AI review record
Risk-tier examples
Consequential Agentic AI taking autonomous action — Domain 9 owns the risk-tiering and inventory standards that classify it.
Tools & artifacts
AI governance charter AI risk register Risk-tiering standard AI system inventory Incident-response plan
Key controls & instruments
AI governance charter Institutional AI risk-tiering standard AI system inventory standard Agentic AI governance standard & incident response
← 08 · AI Literacy & Role-Based Competency (Employees)