Campus AI Framework / Pillar 4 — Risk
Download framework
Standing up your governance body · who & how

Someone has to own this. Here's who, and how they work.

The framework assumes a body that charters oversight and prioritizes risk. Here's how to convene it: a cross-functional committee, a repeatable process from "we should look at AI" to a ranked list of risks with owners, and the one structural choice that decides whether it lasts.

Why this matters AI governance often stalls because no group owns it. Chartering a standing body — with the right offices at the table — is the one move only leadership can make, and what turns this framework from a document into a practice.
Who's at the table
A cross-functional committee — because AI risk crosses every office

No single office can see the whole picture — the risks that cause the worst surprises are the ones each office assumed another owned. Each seat below maps to the domains it's closest to.

Information Security / CISO
Owns data security and unauthorized-access risk — the technical exposures under Domain 5.
IT / Enterprise Systems
Knows where AI is already embedded in vendor and enterprise systems.
Legal Affairs & Privacy Officer
Covers regulatory, contractual, and privacy obligations — Domains 5 and 7.
Procurement
Gates vendor AI before it enters the institution — the Domain 7 chokepoint.
Provost / Academic Affairs
Represents teaching, assessment, and research uses — Domains 1 and 2.
Student Affairs
Speaks for algorithmic decisions that touch students directly — Domain 3.
Finance & Administration
Owns fraud, deepfake, and financial-operations exposure — often the sponsor.
Audit, Compliance & Ethics
Ensures decisions are documented, defensible, and independently reviewable.
Faculty / Practitioner reps
Ground the committee in real AI uses and surface over-reliance risk.
Scale to fit: a department or single college can combine seats into three or four people; a whole system charters the full committee with subteams. The functions matter more than the headcount.
How they work · from "we should look at AI" to a ranked list with owners
A five-step convening process
1 Establish a shared baseline Get the whole committee to a common understanding of what GenAI is, where it already operates on campus, and the trustworthy-AI characteristics at stake — before debating risks.
2 Surface an initial risk list As a full committee, brainstorm candidate risks across all nine domains. Breadth first — the goal is to leave nothing unnamed, not yet to rank.
3 Split into subteams by domain Assign clusters of risk to small subteams aligned to the domains and the offices that own them, so detailed work happens where the expertise is.
4 Prioritize and tier Each subteam scores its risks against the three tiers — likelihood and impact — and returns a short list of the highest-tier concerns rather than an exhaustive catalog.
5 Recommend owners and mitigations Consolidate the top risks, assign each a single named owner, attach a proportionate mitigation and RMF actions, and report to the sponsor.
The one choice that decides if it lasts
A standing committee, not a task force

AI risk is continuous, not a one-time project. A task force disbands the moment its report is filed — right when new tools, vendors, and regulations start arriving. Charter a permanent body with a standing mandate to review, or the work evaporates and you rebuild it under pressure a year later.

What a charter should name
▹Mandate — examine AI risk, prioritize it, recommend mitigations, protect data, operations, and the community
▹Sponsor — a named senior executive (finance, provost, or CIO) who convenes it and receives its reports
▹Cadence — a standing review rhythm, plus a path to escalate high-tier risks between meetings
▹Authority — what it can approve, what it must escalate, and how its decisions bind procurement and units
Your move, by role
Decision-maker
Charter a standing committee and name its sponsor. That single act is what only you can do.
Strategist
Right-size the roster to your unit today, with a clear path to expand to subteams as adoption grows.
Practitioner
Run the five-step process on your own AI uses and bring the ranked list to the committee.
Committee model and convening process adapted from published higher-ed practice (e.g. RIT's AI Safety & Security Advisory Committee), mapped onto this framework's domains and tiers.
← Roadmap
About this website →