The Nine AI Governance Domains for Higher Education
A comprehensive architecture covering the full scope of institutional AI governance — nine domains, three supercategories, each with its own policy instruments, delegation logic, and coordination mechanisms.
This expands Pillar 4 — Governance, Risk, Compliance & Data Governance of the Campus AI Framework, Joe Sabado's practitioner's playbook of eight pillars and four application domains for AI in higher education.
The whole framework on one screen. Click any domain to open it.
Most institutions are deep in one area and shallow everywhere else.
Nearly every institution began its AI governance journey in the same place: teaching and academic integrity. That made sense — it is where the urgency was most visible. But it is also where most institutions have stopped.
Research, student services, data security, procurement, employee competency, campus operations, and institutional oversight remain largely ungoverned — even as AI tools proliferate across every one of those functions.
The problem was not a lack of effort. It was a lack of a complete picture.
Three supercategories that mirror how universities work
The nine domains group into three families, reflecting the provost, the CIO and VP of Research, and the people-and-governance side of the institution.
- ✕ Not a compliance checklist.
- ✕ Not a single-institution case study.
- ✕ Not a principles document.
An operating design. Architecture an institution can adopt in phases, adapt to its own mission, and sustain over time as both AI and regulation continue to evolve.
AI governance sits alongside data governance — it doesn't replace it.
If your campus already runs a data-governance program, you have most of the infrastructure this framework needs: a governance body, a system inventory, data classification and risk tiering, named stewards, and a review cycle. AI governance points that same apparatus at a new object — models and their decisions — rather than duplicating it.
The seam is Domain 5: AI is built on governed data, so a mature data-governance program is a prerequisite, not a competitor. Most institutions run the two as one coordinated program under a shared body.
Bias, explainability, and the right to a human decision; teaching, research, and assessment; and agentic AI that takes autonomous action — none of which data governance covers.
On top of the six components sit six cross-cutting lenses — threads that run through all nine domains. Three carry the work AI adds (Lifecycle, Assurance & Accreditation, Culture & Readiness); three check the system from outside (Transparency & Trust, Global & Jurisdictional, Participatory Co-Governance). See all six in detail →
This is the matrix that ties it together: the six building blocks your data-governance program already runs on, each shown doing real work across Lifecycle, Assurance, and Culture — extended, not rebuilt. Click a domain to see where the component anchors.
{{ p.p }}
{{ p.reuse }}
Why AI governance, and why now
Every consequential thing AI now touches — who we admit, how we advise, what we automate, what we tell accreditors — runs on systems few people fully govern. This is the two-minute case for a president, provost, CFO, or CIO who needs the why.
{{ c.t }}
{{ c.d }}
{{ c.t }}
{{ c.d }}
{{ a.d }}
Generative and agentic AI are entering every function at once — while accreditors and regulators move in.
Governance is far cheaper to build deliberately now than to retrofit after an incident, a failed audit, or an AI misstep. The cost of waiting compounds.
Nine domains, one system
The domains are not nine separate policies. They interlock — a foundation that carries all of them, a standards layer they all apply, a build layer where they all become real, and a coordination map for the risks that belong to no single office. This is the leadership view.
Deep in one area, shallow everywhere else
The typical institutional starting point — the pattern this framework exists to correct. Map your own campus against it.
Six questions that reveal real posture
{{ q }}
The concerns that belong to no single domain
Every shared risk gets one explicit owner, so nothing falls between offices. This map is the connective tissue that keeps nine domains coherent instead of siloed.
{{ c.desc }}
Consequential AI clusters in a few domains — govern those first
Proportionality means the most attention goes where the stakes are highest. High-risk systems that make or inform decisions about people tend to live here — with Domain 6 providing the oversight that governs them all.
The body that keeps the system coherent
One standing group owns the connective work — the charter, the inventory, and the coordination map — so the nine domains operate as a single system, not nine silos. Its standing responsibilities cross every domain:
{{ d }}
How the framework fits together
The framework has three layers. They aren't competing lists — they stack. One tells you where governance happens, one gives each place its infrastructure, and a set of six cross-cutting lenses runs through every domain — the work AI performs and the audiences the whole system answers to. Read top to bottom.
Read it bottom-up: pick a domain → inside it sit all six components (the infrastructure) → and six cross-cutting lenses run through every domain — three describe the work AI adds (lifecycle, assurance, culture & readiness), three the outside audiences it answers to (transparency, jurisdiction, participation).
{{ L.name }}
{{ L.kind }}{{ L.desc }}
One sentence connects all three.
In any domain, the six components supply the infrastructure, and six cross-cutting lenses run through every one — carrying the work AI performs and holding the result accountable to the outside world.
All six appear in all nine domains — only the object changes (a syllabus tool in Domain 1, a model in Domain 5, a contract in Domain 7).
All six cross-cutting lenses touch all nine domains at varying intensity. Three carry the work AI adds — Lifecycle in the build domains, Assurance in oversight and risk, Culture in the people domains. Three check the system from outside — against accreditors, the public, regulators, and the affected community.
The governing core — charter, inventory, risk-tiering standard, review cycle — is where the components are first established and the whole system is kept coherent.
The Five-Domain View
Most institutions govern only fragments of AI — usually teaching and academic integrity — while gaps open everywhere else. This is a mission-aligned, five-part structure that folds the complete nine-domain architecture into a front door leaders can actually hold in their head.
The Five-Domain view is the accessible executive summary; the original Nine-Domain architecture remains the complete reference for detailed policy work. Every domain below maps directly onto it.
{{ fd.title }}
{{ fd.desc }}
{{ fd.scope }}
Four principles apply across every domain wherever an AI system is consequential.
A phased path, not a big bang
{{ ph.title }}
{{ ph.body }}
{{ fivePurpose }}
The five domains are the way in. The nine domains remain the complete reference architecture for detailed policy work.
The nine domains
Each domain has its own policy instruments, delegation logic, and coordination mechanisms. Select a domain to read its full scope.
The same components run through every domain
All six shared components — governance body, inventory, classification & risk tiering, stewards & owners, policies & standards, and review & monitoring — operate in every domain, applied to a different object. The three cross-cutting functions concentrate where each domain does its work. ● primary · ○ present · · minimal
Read a row: every domain carries all six components; the dots show which functions it leans on. Culture leads the people domains, Assurance the oversight and risk domains, Lifecycle the build domains.
Five design decisions
These choices distinguish the framework from principles documents and compliance checklists — and make it something an institution can actually run.
{{ dec.title }}
{{ dec.body }}
Apply governance in proportion to context
Governance intensity should scale to the actual stakes — not applied uniformly, and not driven by fear. The same weight should never fall on a faculty member using a writing assistant and on a system determining financial-aid eligibility. Proportionality weighs several factors together:
Adopt in two phases, not all at once
Establish a minimum viable governance stack first, then extend to the full framework once the infrastructure is operational.
{{ p.title }}
{{ p.desc }}
Domain 9 — Governance, Oversight, and Continuous Review — should be the first established, not the last.
Governance in action
A ladder of illustrative scenarios per domain, ordered from the simplest single-office situation to the most systemic institution-wide one. Pick a domain, then read down the ladder. The institutions are composite and hypothetical; the mechanics are the ones the framework prescribes.
{{ caseHead.short }}
{{ caseHead.detail }}
{{ c.title }}
{{ c.situation }}
{{ c.response }}
{{ c.outcome }}
Scenarios are illustrative composites for orientation — not case reports of specific institutions.
Six lenses across the nine domains
Six lenses cut across the architecture. Three carry the work AI adds — lifecycle, assurance, and readiness; three keep the system responsive to accreditors, regulators, and the people it affects. Every lens runs through all nine domains. What differs is intensity: some are near-universal, others sharpen only where a specific obligation applies. The domain tags below mark where each lens becomes a concrete, named practice — not the limit of where it belongs.
{{ L.title }}
{{ L.lead }}
Reach: {{ L.reachNote }}
{{ m.text }}
What it takes to run it
A framework is only adoptable if it names the concrete pieces. These are the artifacts to produce, the processes to run, the roles that own them, and the structure that holds it together.
{{ g.title }}
{{ g.desc }}
{{ it.desc }}
How do we know it’s working?
Governance earns its keep when it changes outcomes. Track a small, balanced set across five pillars — each with a leading indicator (effort, early signal) and a lagging indicator (realized result). Start with one of each.
{{ m.name }}
{{ m.q }}
{{ m.leading }}
{{ m.lagging }}
A metric without a baseline and a target is just a number. Set targets per institution; review leading indicators monthly with owners, lagging indicators quarterly with the governance committee.
Mapped to the standards
The framework is a higher-ed-specific synthesis, not an invention. This crosswalk shows roughly where each area aligns with recognized standards — so when an accreditor or CIO asks “what is this based on?”, you can point to established references.
{{ r.area }}
These are high-level associations, not certified mappings — a starting point for your own review, not a claim of equivalence or compliance.
The pushback you’ll hear — answered
Every AI governance effort meets the same handful of objections. Most contain a grain of truth about programs done badly. Here is the honest answer to each — the version you can say in a meeting.
“{{ m.o }}”
{{ m.r }}
Nearly every objection assumes governance means control — more rules, more gatekeeping, more delay. Reframe it as clarity about who decides, sized to the risk, and each objection answers itself. That reframing is the whole strategy of this framework.
Campus AI Governance Maturity Assessment
The framework tells you what to govern. CAGMA tells you how far along you are — a companion instrument that measures maturity and reach across all nine domains, so an institution can benchmark itself, track progress, and set priorities.
{{ p.t }}
{{ p.d }}
Every element is scored on two axes, then multiplied — so a strong policy that reaches almost no one scores as low as a weak one deployed everywhere.
How sophisticated, formalized, and effective are governance processes?
Measures the quality and depth of what exists.
How broadly are governance processes deployed across the institution?
Measures the reach of what exists.
Each layer answers a different question
{{ l.name }}
“{{ l.q }}”
{{ l.body }}
Institutional AI capability infrastructure.
Five criteria for evaluating any AI initiative.
{{ c.d }}
Lessons from Reflect feed back into Screen, Score, and Plan.
{{ i.d }}
The scoring scales
Five maturity levels (adapted from CMMI) and five coverage tiers combine into a single Governance Effectiveness Score from 1 to 25.
{{ t.d }}
Worked example — D1 Teaching, Learning & Assessment
The same domain reads very differently at each maturity level. This is the ladder an institution climbs.
{{ e.d }}
Score your institution
Rate each domain on Maturity and Coverage (1–5). The tool computes each Governance Effectiveness Score, assigns a band, and averages them into your IAGI — the Institutional AI Governance Index. Your entries are saved on this device only.
How sophisticated and formalized the governance is. 1 = ad hoc, 5 = optimized and continuously improving.
How broadly it is deployed across applicable units. 1 = under 10%, 5 = 75–100% (enterprise-wide).
The big number on each row. Multiplying rewards depth and reach — high scores need both.
Institutional AI Governance Index — your single headline number, the average GES across all scored domains. It answers “how mature is our AI governance overall?”
Average GES across scored domains · {{ assessComplete }} domains scored
{{ floorText }}
All nine domains scored — ready to share with your governance committee.
A self-assessment is a conversation starter, not an audit. Score it with a cross-functional team, and revisit quarterly to track movement.
What the shape of your scores reveals
PCI, CCI, and IAGI form a diagnostic triangle. The relationship between them — not any single number — tells you where to act next.
{{ p.name }}
{{ p.d }}
{{ a.type }}
{{ a.d }}
{{ c.name }}
{{ c.d }}
CAGMA’s contribution: domain-specific maturity + a coverage dimension + a higher-ed governance taxonomy.
{{ s }}
Compared to the field
Few frameworks match the breadth, depth, and higher-ed specificity of the Nine Domains. Most alternatives are narrower, more general, or higher-level.
| Aspect | Nine Domains | LearnWise | Jisc | UC Approach |
|---|---|---|---|---|
| {{ r.aspect }} | {{ r.nine }} | {{ r.learnwise }} | {{ r.jisc }} | {{ r.uc }} |
The closest comparables
{{ c.name }}
{{ c.meta }}{{ c.body }}
About this website
This is an interactive reference for The Nine AI Governance Domains for Higher Education — an expansion of Pillar 4 of the Campus AI Framework. It covers the full scope of institutional AI governance and is organized around a single idea: that this work becomes manageable when it is broken into nine domains, grouped into three supercategories, each with its own policy instruments, delegation logic, and coordination mechanisms.
Every domain shares one internal structure — six components (from policy instrument to review cadence), a delegation logic that says who decides, and coordination links to the domains it touches. The nine sit in three bands: Academic Core (1–4), Infrastructure & Risk (5–7), and People & Governance (8–9). Cross-cutting lenses — lifecycle, assurance, culture, transparency — run through all of them, and a maturity model (CAGMA) lets an institution locate where it stands and what to do next.
- Senior leaders — provosts, CIOs, CISOs, chief data and academic officers
- AI governance committees and shared-governance bodies
- IT, risk, compliance, privacy, and legal officers building the operating layer
- Faculty and academic leaders weighing AI in teaching and research
- Consultants, accreditors, and peer institutions looking for a reference model
- New here? Start with Overview, or the Five-Domain View for a lighter entry.
- The Nine Domains is the core reference — open any domain for its full detail.
- Use the Maturity Model and Self-Assessment to place your own institution.
- Reach for the Standards Crosswalk when someone asks what it's based on.
- It's non-linear — jump anywhere from the sidebar; nothing requires reading in order.
Every top-level section, mirrored from the sidebar. Click any to open it.
- +Scholarly research, regulatory analysis, and firsthand institutional practice across many institution types
- +Aligned with recognized standards — NIST AI RMF, ISO/IEC 42001, the EU AI Act, and EDUCAUSE
- +Built as Pillar 4 of the Campus AI Framework, a practitioner's playbook for AI in higher education
- –Not legal advice — confirm applicability with your own counsel, privacy office, and leadership
- –Not a certified compliance mapping; the crosswalk shows association, not equivalence
- –Not vendor- or product-specific, and not a substitute for local policy
- –Not a synthesis of existing frameworks — the architecture is an original contribution
Joe Sabado
Founder of CampusAIExchange.com, writing on responsible AI adoption, governance, and workforce transformation in higher education.
The Nine Domains framework grew out of AI governance work begun in 2023 — as a practitioner inside an institution, as a consultant engaging other campuses and systems, and as a scholar researching the evolving governance landscape.
That work has spanned a university system, a national higher-education technology community, and direct engagement with community colleges, research universities, private universities, a health-sciences institution, an accreditation agency, and industry associations.
In every one of those contexts, the same pattern appeared: institutions working hard on AI governance, but working on pieces of it. The architecture is an original contribution — tested against scholarly research, regulatory analysis, and institutional practice — not a synthesis of existing frameworks.
Download the full framework document
All nine domains with their complete policy instruments, delegation logic, cross-domain coordination map, risk-tiering examples, implementation sequence, and institution-type applicability matrix.
{{ dd.title }}
{{ dd.detail }}
{{ dd.practice }}
{{ ad.text }}
The six shared components, and which cross-cutting functions this domain leans on.
{{ mf.note }}