Governance Question Guide
A structured diagnostic across the Nine AI Governance Domains for Higher Education. Mark each question Yes, Partial, or No to surface where governance exists, where the gaps are, and where governance exists but can't be found.
Agnostic by design. This guide defines what each domain must govern, not which standard you use to do it. Expand any domain to see established frameworks (NIST AI RMF, ISO/IEC 42001, HECVAT, and others) you can adopt to operationalize it. Pick what fits your institution; the guide gives each a place in the whole.
The most common thing heard across campuses is not “we have bad AI governance.” It is “we do not have AI governance” — or “I do not even know how it works here” — sometimes from someone who is, technically, part of the governance team. The gap is between the governance that exists and the awareness of it. Policies can exist, a body can be doing real work, and the people it serves still cannot find it. That is not a governance failure in the traditional sense. It is a communication and coordination problem — and that is solvable once it is named.
Start here: seven questions that cut through the fog
Ask these out loud, with people from different parts of the institution, and listen for whether the answers are consistent.- 1Can people find it?If a faculty member, staff member, or student wanted the institution's AI policies right now, could they find them in five minutes — in one visible, maintained place, not a PDF on a committee SharePoint?
- 2Do people know who to ask?Is there a named body or individual accountable for AI governance, and does the campus community know who that is — or do questions route through informal channels until someone guesses an office?
- 3Is governance keeping pace with adoption?AI tools are being adopted right now. Is governance ahead of that adoption, alongside it, or behind — are there domains where tools are in use but no policy exists?
- 4Is it enabling or only restricting?Do people experience governance as something that helps them use AI responsibly — approved-tool lists, sandboxes, training, clear guidance — or only as a list of what they cannot do?
- 5Is it calibrated to risk?Does an AI writing assistant get the same scrutiny as a predictive system affecting financial-aid decisions? Tier by assistive, operational, and consequential so oversight matches actual risk.
- 6Who is not in the room?Are students, frontline staff, and faculty really represented? Are equity considerations — who is most affected by algorithmic decisions, who has least access, who bears the most workforce disruption — part of the design?
- 7Is anyone measuring whether it works?Not whether policies exist, but whether they are known, understood, followed, and producing the outcomes they were designed for.
If the answers are consistent, governance is working and the task is refinement. If they conflict ("we have a policy," "I have never seen it," "I thought someone else was handling that") the institution doesn't have a governance problem so much as a communication and coordination problem. The per-domain diagnostic below makes those gaps visible and nameable.
Academic Core & Student Outcomes
Domains 1–4Teaching, Learning & Assessment
Course-level instructional practice, academic integrity, assessment, and AI use in the classroom.
Open diagnosticResearch & Scholarship
AI in research, intellectual property, disclosure, funder compliance, and research integrity.
Open diagnosticInstitutional Algorithmic Decision-Making & Student Services
AI wherever it makes or informs consequential decisions about people, students, employees, donors, alumni, and community members.
Open diagnosticStudent AI Literacy, Career Readiness & Workforce Preparation
Institution- and program-level student outcomes for AI literacy, employability, and career readiness. Distinct from Domain 1, which governs individual courses.
Open diagnosticInfrastructure, Risk & Vendors
Domains 5–7Data, Security, Privacy & AI-Enabled Systems
Institutional data practices, security posture, privacy compliance, shadow AI, application development, and campus-operations AI.
Open diagnosticFairness, Transparency, Accountability & Algorithmic Oversight
Impact assessments, bias audits, ethics, explainability, and accountability for AI-assisted decisions.
Open diagnosticProcurement, Vendors & Legal
Vendor risk, contracts, compliance, rapid pilots, open-source AI, and IP provisions.
Open diagnosticPeople & Governance
Domains 8–9AI Literacy & Role-Based Competency (Employees)
Employee acceptable use, role-based competency, professional development, and AI in performance management.
Open diagnosticGovernance, Oversight & Continuous Review
Governance charter, risk tiering, system inventory, agentic AI, incident response, review cycles, and financial sustainability.
Open diagnosticCross-Domain Coordination
Shared concernsCross-domain coordination is where governance most commonly breaks down. Shadow AI, algorithmic bias, vendor data security, and agentic AI do not belong to any single office. Without explicit ownership, these concerns remain unmanaged.
Next: test whether it works. This guide asks whether governance exists and can be found. The Self-Audit & Assurance tool takes the next step, testing each control for design and operating effectiveness and producing findings and an assurance opinion. Where this guide surfaces gaps, the self-audit tells you whether what you have actually holds up. Open it →