Campus AI Framework · Pillar 4 deep-dive

The Nine AI Governance Domains for Higher Education

A comprehensive architecture covering the full scope of institutional AI governance — nine domains, three supercategories, each with its own policy instruments, delegation logic, and coordination mechanisms.

This expands Pillar 4 — Governance, Risk, Compliance & Data Governance of the Campus AI Framework, Joe Sabado's practitioner's playbook of eight pillars and four application domains for AI in higher education.

The nine at a glance
Academic Core · 1–4 Infrastructure & Risk · 5–7 People & Governance · 8–9

The whole framework on one screen. Click any domain to open it.

The gap this closes

Most institutions are deep in one area and shallow everywhere else.

Nearly every institution began its AI governance journey in the same place: teaching and academic integrity. That made sense — it is where the urgency was most visible. But it is also where most institutions have stopped.

Research, student services, data security, procurement, employee competency, campus operations, and institutional oversight remain largely ungoverned — even as AI tools proliferate across every one of those functions.

The problem was not a lack of effort. It was a lack of a complete picture.

How it is organized

Three supercategories that mirror how universities work

The nine domains group into three families, reflecting the provost, the CIO and VP of Research, and the people-and-governance side of the institution.

What it is not
  • Not a compliance checklist.
  • Not a single-institution case study.
  • Not a principles document.
What it is

An operating design. Architecture an institution can adopt in phases, adapt to its own mission, and sustain over time as both AI and regulation continue to evolve.

If you already have data governance

AI governance sits alongside data governance — it doesn't replace it.

If your campus already runs a data-governance program, you have most of the infrastructure this framework needs: a governance body, a system inventory, data classification and risk tiering, named stewards, and a review cycle. AI governance points that same apparatus at a new object — models and their decisions — rather than duplicating it.

The seam is Domain 5: AI is built on governed data, so a mature data-governance program is a prerequisite, not a competitor. Most institutions run the two as one coordinated program under a shared body.

Where they map
{{ m.dg }} {{ m.dom }}
Where AI goes further

Bias, explainability, and the right to a human decision; teaching, research, and assessment; and agentic AI that takes autonomous action — none of which data governance covers.

Six cross-cutting lenses

On top of the six components sit six cross-cutting lenses — threads that run through all nine domains. Three carry the work AI adds (Lifecycle, Assurance & Accreditation, Culture & Readiness); three check the system from outside (Transparency & Trust, Global & Jurisdictional, Participatory Co-Governance). See all six in detail →

Each component, at work across lifecycle, assurance & culture

This is the matrix that ties it together: the six building blocks your data-governance program already runs on, each shown doing real work across Lifecycle, Assurance, and Culture — extended, not rebuilt. Click a domain to see where the component anchors.

{{ p.p }}

{{ p.reuse }}

Lifecycle {{ p.lifecycle }}
Assurance {{ p.assurance }}
Culture {{ p.culture }}
For leadership · The case

Why AI governance, and why now

Every consequential thing AI now touches — who we admit, how we advise, what we automate, what we tell accreditors — runs on systems few people fully govern. This is the two-minute case for a president, provost, CFO, or CIO who needs the why.

The cost of doing nothing

{{ c.t }}

{{ c.d }}

What governance delivers

{{ c.t }}

{{ c.d }}

What we ask leadership for
{{ a.n }}
{{ a.t }}

{{ a.d }}

Why now

Generative and agentic AI are entering every function at once — while accreditors and regulators move in.

Governance is far cheaper to build deliberately now than to retrofit after an incident, a failed audit, or an AI misstep. The cost of waiting compounds.

The system

Nine domains, one system

The domains are not nine separate policies. They interlock — a foundation that carries all of them, a standards layer they all apply, a build layer where they all become real, and a coordination map for the risks that belong to no single office. This is the leadership view.

How the nine fit together
{{ grp.label }}
every domain rests on ↓
Build layer (D5) — where every domain’s requirements become real technology. Standards layer (D6) — owns the standards every domain applies. Foundation (D9) — governance under everything.
Coverage posture

Deep in one area, shallow everywhere else

The typical institutional starting point — the pattern this framework exists to correct. Map your own campus against it.

Established Partial Gap / foundation
What a chancellor should ask

Six questions that reveal real posture

{{ q }}

Cross-domain coordination map

The concerns that belong to no single domain

Every shared risk gets one explicit owner, so nothing falls between offices. This map is the connective tissue that keeps nine domains coherent instead of siloed.

{{ c.name }}

{{ c.desc }}

Coordinated by
{{ c.owner }}
Where risk concentrates

Consequential AI clusters in a few domains — govern those first

Proportionality means the most attention goes where the stakes are highest. High-risk systems that make or inform decisions about people tend to live here — with Domain 6 providing the oversight that governs them all.

The governance committee

The body that keeps the system coherent

One standing group owns the connective work — the charter, the inventory, and the coordination map — so the nine domains operate as a single system, not nine silos. Its standing responsibilities cross every domain:

{{ d }}

Orientation

How the framework fits together

The framework has three layers. They aren't competing lists — they stack. One tells you where governance happens, one gives each place its infrastructure, and a set of six cross-cutting lenses runs through every domain — the work AI performs and the audiences the whole system answers to. Read top to bottom.

6 Cross-cutting lenses · run through every domain ↓
{{ ln.name }}
{{ ln.reach }}
6 Components · the infrastructure inside every domain
{{ cp.name }}
↓ operate within every one of ↓
9 Domains · where governance happens
{{ dm.num2 }}
{{ dm.short }}

Read it bottom-up: pick a domain → inside it sit all six components (the infrastructure) → and six cross-cutting lenses run through every domain — three describe the work AI adds (lifecycle, assurance, culture & readiness), three the outside audiences it answers to (transparency, jurisdiction, participation).

{{ L.count }} Layer {{ L.n }}

{{ L.name }}

{{ L.kind }}

{{ L.desc }}

{{ L.role }}
How the layers interlock

One sentence connects all three.

In any domain, the six components supply the infrastructure, and six cross-cutting lenses run through every one — carrying the work AI performs and holding the result accountable to the outside world.

Components are universal

All six appear in all nine domains — only the object changes (a syllabus tool in Domain 1, a model in Domain 5, a contract in Domain 7).

Lenses run through everything

All six cross-cutting lenses touch all nine domains at varying intensity. Three carry the work AI adds — Lifecycle in the build domains, Assurance in oversight and risk, Culture in the people domains. Three check the system from outside — against accreditors, the public, regulators, and the affected community.

Domain 9 holds it together

The governing core — charter, inventory, risk-tiering standard, review cycle — is where the components are first established and the whole system is kept coherent.

See each layer in the tool
Executive front door · A simpler entry point

The Five-Domain View

Most institutions govern only fragments of AI — usually teaching and academic integrity — while gaps open everywhere else. This is a mission-aligned, five-part structure that folds the complete nine-domain architecture into a front door leaders can actually hold in their head.

The Five-Domain view is the accessible executive summary; the original Nine-Domain architecture remains the complete reference for detailed policy work. Every domain below maps directly onto it.

Who should use this Presidents · Provosts · CIOs / CAIOs · Faculty leaders · Student affairs · Research offices · Procurement · HR · Shared governance
The five domains
{{ fd.num2 }} {{ fd.phase }}

{{ fd.title }}

{{ fd.desc }}

{{ fd.scope }}

Maps to nine-domain reference
Cross-cutting principles

Four principles apply across every domain wherever an AI system is consequential.

{{ p.name }}
{{ p.desc }}
Implementation

A phased path, not a big bang

{{ ph.tag }}

{{ ph.title }}

{{ ph.body }}

{{ pn }}
Our purpose

{{ fivePurpose }}

The five domains are the way in. The nine domains remain the complete reference architecture for detailed policy work.

The framework

The nine domains

Each domain has its own policy instruments, delegation logic, and coordination mechanisms. Select a domain to read its full scope.

The nine as one system

The same components run through every domain

All six shared components — governance body, inventory, classification & risk tiering, stewards & owners, policies & standards, and review & monitoring — operate in every domain, applied to a different object. The three cross-cutting functions concentrate where each domain does its work. ● primary · ○ present · · minimal

Domain
{{ sf.name }}

Read a row: every domain carries all six components; the dots show which functions it leans on. Culture leads the people domains, Assurance the oversight and risk domains, Lifecycle the build domains.

What makes it different

Five design decisions

These choices distinguish the framework from principles documents and compliance checklists — and make it something an institution can actually run.

{{ dec.n }} {{ dec.short }}
{{ dec.n }}

{{ dec.title }}

{{ dec.body }}

{{ it.k }} · {{ it.v }}
Proportionality & risk tiering

Apply governance in proportion to context

Governance intensity should scale to the actual stakes — not applied uniformly, and not driven by fear. The same weight should never fall on a faculty member using a writing assistant and on a system determining financial-aid eligibility. Proportionality weighs several factors together:

Consequence & risk
Who is affected, and how severely if the system errs.
Decision context
Whether AI advises a human or determines the outcome.
Capability & autonomy
From assistive tools to autonomous, agentic systems.
Institutional capacity
The institution’s size, resources, and mission.
The three tiers
{{ t.risk }}
{{ t.label }}

{{ t.desc }}

Phased implementation sequence

Adopt in two phases, not all at once

Establish a minimum viable governance stack first, then extend to the full framework once the infrastructure is operational.

{{ p.tag }}

{{ p.title }}

{{ p.desc }}

{{ pd.num2 }} {{ pd.title }}

Domain 9 — Governance, Oversight, and Continuous Review — should be the first established, not the last.

The framework · Case studies

Governance in action

A ladder of illustrative scenarios per domain, ordered from the simplest single-office situation to the most systemic institution-wide one. Pick a domain, then read down the ladder. The institutions are composite and hypothetical; the mechanics are the ones the framework prescribes.

Domain {{ caseHead.num2 }} · {{ caseHead.catLabel }}

{{ caseHead.short }}

{{ caseHead.detail }}

Foundational · 1–3 Operational · 4–7 Systemic · 8+
{{ c.levelText }}

{{ c.title }}

{{ c.setting }}
{{ c.bandLabel }}
Situation

{{ c.situation }}

Governance response

{{ c.response }}

Outcome

{{ c.outcome }}

Read full case →

Scenarios are illustrative composites for orientation — not case reports of specific institutions.

Domain {{ modal.domNum }} · Case {{ modal.levelText }} / {{ modal.total }} {{ modal.bandLabel }}

{{ modal.title }}

{{ modal.setting }} · {{ modal.domShort }}
Components engaged
{{ pt.name }}
Cross-cutting lenses · operating threads
{{ ft.name }}{{ ft.sub }}
The scenario

{{ modal.scenario }}

What's at risk
{{ r }}
Governance response, step by step
{{ s.t }} {{ s.d }}
Who's accountable
{{ ro }}
Outcome & evidence

{{ modal.outcome }}

Artifact: {{ modal.evidence }}

Signals it's working
{{ sg }}
Framework elements touched
Cross-cutting lenses

Six lenses across the nine domains

Six lenses cut across the architecture. Three carry the work AI adds — lifecycle, assurance, and readiness; three keep the system responsive to accreditors, regulators, and the people it affects. Every lens runs through all nine domains. What differs is intensity: some are near-universal, others sharpen only where a specific obligation applies. The domain tags below mark where each lens becomes a concrete, named practice — not the limit of where it belongs.

Universal — applies everywhere Broad — most domains Selective — specific obligations
{{ L.kicker }}

{{ L.title }}

{{ L.reach }} reach
Most active in {{ c.label }}

{{ L.lead }}

Reach: {{ L.reachNote }}

{{ m.d }}

{{ m.text }}

Standards & sources {{ s.label }} ↗
Operating model

What it takes to run it

A framework is only adoptable if it names the concrete pieces. These are the artifacts to produce, the processes to run, the roles that own them, and the structure that holds it together.

{{ g.kicker }}

{{ g.title }}

{{ g.desc }}

{{ it.name }} {{ it.meta }}

{{ it.desc }}

Operating & evidence · Metrics

How do we know it’s working?

Governance earns its keep when it changes outcomes. Track a small, balanced set across five pillars — each with a leading indicator (effort, early signal) and a lagging indicator (realized result). Start with one of each.

{{ m.n }}

{{ m.name }}

{{ m.q }}

Leading

{{ m.leading }}

Lagging

{{ m.lagging }}

A metric without a baseline and a target is just a number. Set targets per institution; review leading indicators monthly with owners, lagging indicators quarterly with the governance committee.

Operating & evidence · Crosswalk

Mapped to the standards

The framework is a higher-ed-specific synthesis, not an invention. This crosswalk shows roughly where each area aligns with recognized standards — so when an accreditor or CIO asks “what is this based on?”, you can point to established references.

{{ r.area }}

{{ mp.s }} {{ mp.m }}

These are high-level associations, not certified mappings — a starting point for your own review, not a claim of equivalence or compliance.

Adoption · Myths & objections

The pushback you’ll hear — answered

Every AI governance effort meets the same handful of objections. Most contain a grain of truth about programs done badly. Here is the honest answer to each — the version you can say in a meeting.

The objection

“{{ m.o }}”

The reality

{{ m.r }}

The pattern behind the pushback

Nearly every objection assumes governance means control — more rules, more gatekeeping, more delay. Reframe it as clarity about who decides, sized to the risk, and each objection answers itself. That reframing is the whole strategy of this framework.

CAGMA · The maturity model

Campus AI Governance Maturity Assessment

The framework tells you what to govern. CAGMA tells you how far along you are — a companion instrument that measures maturity and reach across all nine domains, so an institution can benchmark itself, track progress, and set priorities.

The problem it solves
{{ p.n }}

{{ p.t }}

{{ p.d }}

Two independent dimensions

Every element is scored on two axes, then multiplied — so a strong policy that reaches almost no one scores as low as a weak one deployed everywhere.

Maturity · Levels 1–5

How sophisticated, formalized, and effective are governance processes?

Measures the quality and depth of what exists.

Coverage · Tiers 1–5

How broadly are governance processes deployed across the institution?

Measures the reach of what exists.

Governance Effectiveness Score  =  Maturity  ×  Coverage
Three-layer architecture

Each layer answers a different question

{{ l.tag }} · {{ l.meta }}

{{ l.name }}

“{{ l.q }}”

{{ l.body }}

Layer 1 · The eight pillars

Institutional AI capability infrastructure.

{{ p.id }} {{ p.name }}
Layer 2 · The strategic compass

Five criteria for evaluating any AI initiative.

{{ c.id }} {{ c.name }}

{{ c.d }}

Six-step decision flow
{{ s.name }}

Lessons from Reflect feed back into Screen, Score, and Plan.

Three composite indices
{{ i.abbr }}
{{ i.name }}
{{ i.meta }}

{{ i.d }}

IAMC  =  Average of PCI + CCI + IAGI
CAGMA · Scoring & levels

The scoring scales

Five maturity levels (adapted from CMMI) and five coverage tiers combine into a single Governance Effectiveness Score from 1 to 25.

Maturity · five levels
{{ l.n }} {{ l.name }}

{{ l.d }}

Coverage · five tiers
{{ t.n }}
{{ t.name }}

{{ t.d }}

GES  =  Maturity (1–5)  ×  Coverage (1–5)  =  1 to 25
{{ b.range }} {{ b.name }} {{ b.d }}
What each level looks like

Worked example — D1 Teaching, Learning & Assessment

The same domain reads very differently at each maturity level. This is the ladder an institution climbs.

{{ e.lv }} {{ e.name }}

{{ e.d }}

CAGMA · Self-assessment

Score your institution

Rate each domain on Maturity and Coverage (1–5). The tool computes each Governance Effectiveness Score, assigns a band, and averages them into your IAGI — the Institutional AI Governance Index. Your entries are saved on this device only.

How the numbers work
Maturity 1–5

How sophisticated and formalized the governance is. 1 = ad hoc, 5 = optimized and continuously improving.

Coverage 1–5

How broadly it is deployed across applicable units. 1 = under 10%, 5 = 75–100% (enterprise-wide).

GES Maturity × Coverage · 1–25

The big number on each row. Multiplying rewards depth and reach — high scores need both.

IAGI 0–25

Institutional AI Governance Index — your single headline number, the average GES across all scored domains. It answers “how mature is our AI governance overall?”

{{ b.name }}
GES {{ b.range }}
IAGI · Institutional AI Governance Index
{{ iagiText }} {{ iagiBandLabel }}

Average GES across scored domains · {{ assessComplete }} domains scored

Floor domains · GES < 5

{{ floorText }}

All nine domains scored — ready to share with your governance committee.

{{ r.num2 }} {{ r.label }}
Maturity
Coverage
{{ r.gesText }}
{{ r.bandLabel }}

A self-assessment is a conversation starter, not an audit. Score it with a cross-functional team, and revisit quarterly to track movement.

Three-index diagnostic profile

What the shape of your scores reveals

PCI, CCI, and IAGI form a diagnostic triangle. The relationship between them — not any single number — tells you where to act next.

{{ p.name }}

{{ p.d }}

Applicability across institution types

{{ a.type }}

{{ a.d }}

Companion instruments

{{ c.name }}

“{{ c.q }}”

{{ c.d }}

Scorecard ▶ Readiness Guide ▶ CAGMA
Intellectual lineage
{{ l.name }}
{{ l.d }}
{{ l.org }}

CAGMA’s contribution: domain-specific maturity + a coverage dimension + a higher-ed governance taxonomy.

Next steps

{{ s }}

Where it stands

Compared to the field

Few frameworks match the breadth, depth, and higher-ed specificity of the Nine Domains. Most alternatives are narrower, more general, or higher-level.

Aspect Nine Domains LearnWise Jisc UC Approach
{{ r.aspect }} {{ r.nine }} {{ r.learnwise }} {{ r.jisc }} {{ r.uc }}

The closest comparables

{{ c.name }}

{{ c.meta }}

{{ c.body }}

About · This website

About this website

This is an interactive reference for The Nine AI Governance Domains for Higher Education — an expansion of Pillar 4 of the Campus AI Framework. It covers the full scope of institutional AI governance and is organized around a single idea: that this work becomes manageable when it is broken into nine domains, grouped into three supercategories, each with its own policy instruments, delegation logic, and coordination mechanisms.

The underlying model

Every domain shares one internal structure — six components (from policy instrument to review cadence), a delegation logic that says who decides, and coordination links to the domains it touches. The nine sit in three bands: Academic Core (1–4), Infrastructure & Risk (5–7), and People & Governance (8–9). Cross-cutting lenses — lifecycle, assurance, culture, transparency — run through all of them, and a maturity model (CAGMA) lets an institution locate where it stands and what to do next.

Academic Core · 1–4 Infrastructure & Risk · 5–7 People & Governance · 8–9
Who it's for
  • Senior leaders — provosts, CIOs, CISOs, chief data and academic officers
  • AI governance committees and shared-governance bodies
  • IT, risk, compliance, privacy, and legal officers building the operating layer
  • Faculty and academic leaders weighing AI in teaching and research
  • Consultants, accreditors, and peer institutions looking for a reference model
How to read it
  • New here? Start with Overview, or the Five-Domain View for a lighter entry.
  • The Nine Domains is the core reference — open any domain for its full detail.
  • Use the Maturity Model and Self-Assessment to place your own institution.
  • Reach for the Standards Crosswalk when someone asks what it's based on.
  • It's non-linear — jump anywhere from the sidebar; nothing requires reading in order.
How it's organized

Every top-level section, mirrored from the sidebar. Click any to open it.

{{ grp.groupLabel }}
What it rests on
  • +Scholarly research, regulatory analysis, and firsthand institutional practice across many institution types
  • +Aligned with recognized standards — NIST AI RMF, ISO/IEC 42001, the EU AI Act, and EDUCAUSE
  • +Built as Pillar 4 of the Campus AI Framework, a practitioner's playbook for AI in higher education
What it is not
  • Not legal advice — confirm applicability with your own counsel, privacy office, and leadership
  • Not a certified compliance mapping; the crosswalk shows association, not equivalence
  • Not vendor- or product-specific, and not a substitute for local policy
  • Not a synthesis of existing frameworks — the architecture is an original contribution
Status
Author
Joe Sabado · CampusAIExchange.com
Version
Version 1.0 · March 2026
Part of
Campus AI Framework · Pillar 4
License
CC BY-NC-SA 4.0
Developed with AI assistance. General guidance — not legal advice; your institution's local rules govern.
About the framework

Joe Sabado

Founder of CampusAIExchange.com, writing on responsible AI adoption, governance, and workforce transformation in higher education.

The Nine Domains framework grew out of AI governance work begun in 2023 — as a practitioner inside an institution, as a consultant engaging other campuses and systems, and as a scholar researching the evolving governance landscape.

That work has spanned a university system, a national higher-education technology community, and direct engagement with community colleges, research universities, private universities, a health-sciences institution, an accreditation agency, and industry associations.

In every one of those contexts, the same pattern appeared: institutions working hard on AI governance, but working on pieces of it. The architecture is an original contribution — tested against scholarly research, regulatory analysis, and institutional practice — not a synthesis of existing frameworks.

Download the full framework document

All nine domains with their complete policy instruments, delegation logic, cross-domain coordination map, risk-tiering examples, implementation sequence, and institution-type applicability matrix.

{{ dd.catLabel }}
{{ dd.num2 }}

{{ dd.title }}

Scope

{{ dd.detail }}

In practice

{{ dd.practice }}

Key elements
{{ tag }}
Cross-cutting lenses
{{ ad.name }}

{{ ad.text }}

How the model shows up here

The six shared components, and which cross-cutting functions this domain leans on.

{{ mp.name }} {{ mp.here }}
{{ mf.name }} {{ mf.leadLabel }}

{{ mf.note }}