This pillar provides the structural foundation of the framework: the bodies, decision rights, risk processes, legal compliance, and data governance on which the other pillars depend. It is also subject to two opposing failures: insufficient oversight, in which AI spreads without governance, and excessive process, in which a heavyweight committee approves little and units bypass it. The objective is proportionate governance, greater scrutiny for higher-stakes and higher-sensitivity uses, and a lighter path for low-risk uses.
Because a general instruction to establish governance is difficult to act on, this pillar is defined by concrete structures: a standing AI governance body with a charter and defined decision rights; a risk-assessment process tiered by impact and data sensitivity; an explicit map of compliance obligations under FERPA, ADA, GDPR, and state law; and a data-governance baseline covering classification, access, retention, and vendor data terms, since AI deployed without data governance presents a significant breach risk. Each of these is an element the institution can establish and demonstrate.
Why it matters
Governance is what converts good intentions into reliable behavior, and data governance is the non-negotiable substrate: the fastest way to turn an AI initiative into an institutional crisis is to feed sensitive student data into a system nobody vetted. This pillar is where accountability becomes real, a named body, a documented decision, a defensible answer when a regulator or a journalist asks 'who approved this, and how?'
How you can tell
When it's working
A standing AI governance body exists with a charter, membership that includes faculty and student representation, and actual decision rights.
Risk assessment is tiered by impact and data sensitivity, with a fast lane for low-risk uses.
Compliance obligations (FERPA, ADA, GDPR, state law) are mapped and checked across the lifecycle.
Data is classified, access-controlled, retention-bound, and governed by vetted vendor terms.
When it's missing
No one owns AI oversight; approvals depend on who you happen to ask.
Every use gets the same scrutiny (or none), so governance is either a bottleneck or a fiction.
Compliance is discovered after deployment, in incident response rather than design.
Student data flows into AI tools under unread terms of service.
This is where the pillar stops being a principle and becomes work. Each practice below is something you can build, assign, and evidence, with a concrete first move, an owner, and what proof looks like. Move one practice up one level at a time.
1
AI governance body & charter
A cross-functional body with defined authority, a charter, and student representation.
Convene a cross-functional procurement review (legal, security, privacy, academic, library).
Create a fast lane for low-risk pilots with defined thresholds and expiration dates.
Who owns it
Procurement · Legal · CISO
Evidence it exists
Contract rider language
Review-team charter
Pilot-lane approvals log
Key governance artifacts
Two living records turn governance from intention into oversight. You can't govern (or right-size review for) what you can't see, so both are foundational, not paperwork.
AI Use Case Registry
The single source of truth for every AI system in use or proposed.
A living inventory of all AI initiatives across the institution, production systems, pilots, and proposals alike. It is the artifact that surfaces shadow AI, lets you apply proportionate review, and answers the question a board or regulator will eventually ask: “how many AI systems touch our students, and who owns them?” Without it, governance is guessing.
Why it mattersYou cannot govern what you cannot see. The registry is the substrate every other control depends on, risk assessment, proportionate review, incident response, and procurement all start from knowing the system exists.
Each entry captures
Use case ID & nameDescription & purposeApplication domainOwner & unitStatus (proposed / pilot / production / retired)Data sensitivity / classificationVendor or in-houseCompass risk tierDate added · last reviewedLinked risk-registry entries
The catalog of identified AI risks, each owned and being managed.
A central record of the risks AI introduces across the institution — bias, privacy, security, compliance, operational, reputational, academic integrity — each scored for likelihood and impact, assigned an owner, and paired with a mitigation. It converts vague anxiety into a tracked, prioritized, actionable list, and it is where 'we should look into that' becomes a task with a name on it.
Why it mattersRisks that aren't written down are rediscovered during incidents. A registry makes risk visible, ranked, and owned — so mitigation happens before harm, not after.
A university stands up an AI governance committee that insists on reviewing every use, including a faculty member using AI to draft discussion prompts on public material. Adoption stalls and units start going around it. Restructured under this pillar, the committee adopts a tiered model: low-risk, no-sensitive-data uses self-certify against a checklist; medium-risk uses get a short review; only high-stakes uses touching protected data get the full process. Throughput rises, shadow AI falls, and the committee's attention lands where the real risk is.
Watch for
One-size-fits-all review that treats a discussion-prompt helper like an admissions algorithm.
Standing up governance bodies without real decision rights, so they advise and are ignored.
Treating data governance as IT's separate problem rather than the foundation of AI risk.
Readiness & maturity questions
Readiness asks: are we prepared? Use these to surface blind spots before you build, honest “no” answers are where the work is. Representative prompts for reflection, not a scored test \u2014 for the scored version, use the Maturity Assessment.
Governance
Do we have a formal AI governance structure or body?
Are governance roles and responsibilities clearly assigned?
Is there executive-level sponsorship of AI governance?
Are academic, administrative, and student voices represented?
Are governance decisions documented and transparent?
Do committees have access to AI subject-matter expertise?
Are governance practices aligned with institutional mission?
Is there a process to escalate urgent AI-related issues?
Do we regularly review AI use across campus?
Is there coordination between AI governance and IT/data governance?
Risk
Have we defined AI-specific risk categories (e.g., reputational, bias, data)?
Do we use a risk-assessment checklist for AI projects?
Is there a risk scoring or classification framework?
Are high-risk AI uses (e.g., admissions, grading) flagged?
Are stakeholders trained on how to identify AI risks?
Is there a process to evaluate third-party AI vendor risks?
Are risks evaluated at multiple lifecycle stages (design, deployment, monitoring)?
Are there risk thresholds requiring executive or governance approval?
Is incident-response planning integrated with AI operations?
Are risks evaluated across technical, legal, and ethical dimensions?
Compliance
Do we have documented AI compliance requirements (e.g., FERPA, ADA)?
Are AI initiatives reviewed for regulatory alignment?
Are compliance officers involved in AI tool review or procurement?
Are legal and ethical compliance criteria part of project approval?
Are compliance standards built into system design (e.g., privacy by design)?
Are data access and audit controls in place for AI tools?
Are students aware of their rights in AI-mediated environments?
Do policies and terms of use cover AI system behavior and responsibilities?
Is AI-related training tied to compliance expectations?
Are external standards (e.g., EU AI Act, NIST RMF) referenced in planning?
Applicable legislation, policies & standards
Governance doesn't happen in a vacuum, it operationalizes obligations that already bind the institution. Applicability depends on your institution type, jurisdiction, and the data involved; always confirm with your own legal, privacy, and compliance offices.
Legislation & regulation
FERPAPrivacy of student education records, the central constraint on AI touching student data.
ADA & Section 508 / 504Accessibility of AI-enabled tools and digital content.
Title VI & Title IXNon-discrimination, bars AI from producing disparate impact in decisions about people.
GDPREU data protection, where you serve or process EU residents' data.
EU AI ActRisk-tiered obligations for higher-risk AI used in or with the EU.
State privacy laws (CCPA/CPRA & peers)Consumer/data-privacy rights varying by state.
HIPAAWhere AI touches protected health information (clinics, counseling, research).
COPPAWhere systems involve learners under 13 (dual-enrollment, pre-college).
Standards & frameworks
NIST AI RMFGovern · Map · Measure · Manage, the risk-management spine.
ISO/IEC 42001Certifiable AI management-system standard.
ISO/IEC 27001Information-security management.
NIST Cybersecurity & Privacy FrameworksSecurity and privacy control baselines.
HECVATHigher Education Community Vendor Assessment Toolkit, third-party/vendor risk.
OECD AI PrinciplesInternationally recognized trustworthy-AI values.
Institutional policies
Data classification & governance policyDefines sensitivity levels that gate AI data use.
Acceptable use policyWhat AI tools may be used, with what data, by whom.
Records retention & dispositionHow AI inputs, outputs, and logs are retained.
Procurement & vendor risk policyVetting, contracts, and data-processing terms for AI vendors.
IRB / human-subjects policyWhere AI is used in research involving people.