The Nine AI Governance Domains for Higher Education
A comprehensive architecture covering the full scope of institutional AI governance — nine domains, three supercategories, each with its own policy instruments, delegation logic, and coordination mechanisms.
This expands Pillar 4 — Governance, Risk, Compliance & Data Governance of the Campus AI Framework, Joe Sabado's practitioner's playbook of eight pillars and four application domains for AI in higher education.
Most institutions are deep in one area and shallow everywhere else.
Nearly every institution began its AI governance journey in the same place: teaching and academic integrity. That made sense — it is where the urgency was most visible. But it is also where most institutions have stopped.
Research, student services, data security, procurement, employee competency, campus operations, and institutional oversight remain largely ungoverned — even as AI tools proliferate across every one of those functions.
The problem was not a lack of effort. It was a lack of a complete picture.
Three supercategories that mirror how universities work
The nine domains group into three families, reflecting the provost, the CIO and VP of Research, and the people-and-governance side of the institution.
- ✕ Not a compliance checklist.
- ✕ Not a single-institution case study.
- ✕ Not a principles document.
An operating design. Architecture an institution can adopt in phases, adapt to its own mission, and sustain over time as both AI and regulation continue to evolve.
AI governance sits alongside data governance — it doesn't replace it.
If your campus already runs a data-governance program, you have most of the infrastructure this framework needs: a governance body, a system inventory, data classification and risk tiering, named stewards, and a review cycle. AI governance points that same apparatus at a new object — models and their decisions — rather than duplicating it.
The seam is Domain 5: AI is built on governed data, so a mature data-governance program is a prerequisite, not a competitor. Most institutions run the two as one coordinated program under a shared body.
Bias, explainability, and the right to a human decision; teaching, research, and assessment; and agentic AI that takes autonomous action — none of which data governance covers.
Why AI governance, and why now
Every consequential thing AI now touches — who we admit, how we advise, what we automate, what we tell accreditors — runs on systems few people fully govern. This is the two-minute case for a president, provost, CFO, or CIO who needs the why.
{{ c.t }}
{{ c.d }}
{{ c.t }}
{{ c.d }}
{{ a.d }}
Generative and agentic AI are entering every function at once — while accreditors and regulators move in.
Governance is far cheaper to build deliberately now than to retrofit after an incident, a failed audit, or an AI misstep. The cost of waiting compounds.
Nine domains, one system
The domains are not nine separate policies. They interlock — a foundation that carries all of them, a standards layer they all apply, a build layer where they all become real, and a coordination map for the risks that belong to no single office. This is the leadership view.
Six shared components run inside every domain
A domain says where governance happens; the six components are how it happens. The same six operate in all nine — only the object they govern changes (a syllabus tool in Domain 1, a model in Domain 5, a contract in Domain 7).
Deep in one area, shallow everywhere else
The typical institutional starting point — the pattern this framework exists to correct. Map your own campus against it.
Six questions that reveal real posture
{{ q }}
The concerns that belong to no single domain
Every shared risk gets one explicit owner, so nothing falls between offices. This map is the connective tissue that keeps nine domains coherent instead of siloed.
{{ c.desc }}
Consequential AI clusters in a few domains — govern those first
Proportionality means the most attention goes where the stakes are highest. High-risk systems that make or inform decisions about people tend to live here — with Domain 6 providing the oversight that governs them all.
The body that keeps the system coherent
One standing group owns the connective work — the charter, the inventory, and the coordination map — so the nine domains operate as a single system, not nine silos. Its standing responsibilities cross every domain:
{{ d }}
The Five-Domain View
Most institutions govern only fragments of AI — usually teaching and academic integrity — while gaps open everywhere else. This is a mission-aligned, five-part structure that folds the complete nine-domain architecture into a front door leaders can actually hold in their head.
The Five-Domain view is the accessible executive summary; the original Nine-Domain architecture remains the complete reference for detailed policy work. Every domain below maps directly onto it.
{{ fd.title }}
{{ fd.desc }}
{{ fd.scope }}
Four principles apply across every domain wherever an AI system is consequential.
A phased path, not a big bang
{{ ph.title }}
{{ ph.body }}
{{ fivePurpose }}
The five domains are the way in. The nine domains remain the complete reference architecture for detailed policy work.
The nine domains
Each domain has its own policy instruments, delegation logic, and coordination mechanisms. Select a domain to read its full scope.
Five design decisions
Most AI guidance is either a list of principles or a compliance checklist. Five deliberate choices make this something an institution can actually operate. Each solves a specific failure of the usual approaches.
{{ dec.title }}
{{ dec.body }}
{{ dec.why }}
Apply governance in proportion to context
Governance intensity should scale to the actual stakes — not applied uniformly, and not driven by fear. The same weight should never fall on a faculty member using a writing assistant and on a system determining financial-aid eligibility. Proportionality weighs several factors together:
Adopt in two phases, not all at once
Establish a minimum viable governance stack first, then extend to the full framework once the infrastructure is operational.
{{ p.title }}
{{ p.desc }}
Domain 9 — Governance, Oversight, and Continuous Review — should be the first established, not the last.
Governance in action
A ladder of illustrative scenarios per domain, ordered from the simplest single-office situation to the most systemic institution-wide one. Pick a domain, then read down the ladder. The institutions are composite and hypothetical; the mechanics are the ones the framework prescribes.
{{ caseHead.short }}
{{ caseHead.detail }}
{{ c.title }}
{{ c.situation }}
{{ c.response }}
{{ c.outcome }}
Scenarios are illustrative composites for orientation — not case reports of specific institutions.
What it takes to run it
A framework is only adoptable if it names the concrete pieces. These are the artifacts to produce, the processes to run, the roles that own them, and the structure that holds it together.
{{ g.title }}
{{ g.desc }}
{{ it.desc }}
How do we know it’s working?
Governance earns its keep when it changes outcomes. Track a small, balanced set across five pillars — each with a leading indicator (effort, early signal) and a lagging indicator (realized result). Start with one of each.
{{ m.name }}
{{ m.q }}
{{ m.leading }}
{{ m.lagging }}
A metric without a baseline and a target is just a number. Set targets per institution; review leading indicators monthly with owners, lagging indicators quarterly with the governance committee.
Mapped to the standards
The framework is a higher-ed-specific synthesis, not an invention. This crosswalk shows roughly where each area aligns with recognized standards — so when an accreditor or CIO asks “what is this based on?”, you can point to established references.
{{ r.area }}
These are high-level associations, not certified mappings — a starting point for your own review, not a claim of equivalence or compliance.
The pushback you’ll hear — answered
Every AI governance effort meets the same handful of objections. Most contain a grain of truth about programs done badly. Here is the honest answer to each — the version you can say in a meeting.
“{{ m.o }}”
{{ m.r }}
Nearly every objection assumes governance means control — more rules, more gatekeeping, more delay. Reframe it as clarity about who decides, sized to the risk, and each objection answers itself. That reframing is the whole strategy of this framework.
Campus AI Governance Maturity Assessment
The framework tells you what to govern. CAGMA tells you how far along you are — a companion instrument that measures maturity and reach across all nine domains, so an institution can benchmark itself, track progress, and set priorities.
{{ p.t }}
{{ p.d }}
Every element is scored on two axes, then multiplied — so a strong policy that reaches almost no one scores as low as a weak one deployed everywhere.
How sophisticated, formalized, and effective are governance processes?
Measures the quality and depth of what exists.
How broadly are governance processes deployed across the institution?
Measures the reach of what exists.
Each layer answers a different question
{{ l.name }}
“{{ l.q }}”
{{ l.body }}
Institutional AI capability infrastructure.
Five criteria for evaluating any AI initiative.
{{ c.d }}
Lessons from Reflect feed back into Screen, Score, and Plan.
The scoring scales
Five maturity levels (adapted from CMMI) and five coverage tiers combine into a single Governance Effectiveness Score from 1 to 25.
{{ t.d }}
What each level looks like
One domain, shown at all five levels, to make the scale concrete. Every domain climbs the same ladder — switch domains to compare.
{{ e.d }}
Score your institution
A quick way to see where your institution stands. You rate each of the nine domains on two simple 1–5 scales, and the tool turns that into a single headline score with suggested next steps. Takes about ten minutes; your answers stay on this device.
For all nine domains, pick a Maturity (how formal) and Coverage (how widespread) from 1 to 5.
Each domain gets a color-coded band, and everything rolls up into one headline number for the whole institution.
The lowest-scoring domains surface as priorities, with concrete next steps to bring to your committee.
You only enter the first two — Maturity and Coverage. The tool derives the rest.
How sophisticated and formalized the governance is. 1 = ad hoc, 5 = optimized and continuously improving.
How broadly it is deployed across applicable units. 1 = under 10%, 5 = 75–100% (enterprise-wide).
The big number on each row. Multiplying rewards depth and reach — high scores need both.
Institutional AI Governance Index — your single headline number, the average GES across all scored domains. It answers “how mature is our AI governance overall?”
Average GES across scored domains · {{ assessComplete }} domains scored
{{ floorText }}
All nine domains scored — ready to share with your governance committee.
A self-assessment is a conversation starter, not an audit. Score it with a cross-functional team, and revisit quarterly to track movement.
{{ a.type }}
{{ a.d }}
{{ c.name }}
{{ c.d }}
CAGMA’s contribution: domain-specific maturity + a coverage dimension + a higher-ed governance taxonomy.
{{ s }}
Compared to the field
Few frameworks match the breadth, depth, and higher-ed specificity of the Nine Domains. Most alternatives are narrower, more general, or higher-level.
| Aspect | Nine Domains | LearnWise | Jisc | UC Approach |
|---|---|---|---|---|
| {{ r.aspect }} | {{ r.nine }} | {{ r.learnwise }} | {{ r.jisc }} | {{ r.uc }} |
The closest comparables
{{ c.name }}
{{ c.meta }}{{ c.body }}
About this website
This is an interactive reference for The Nine AI Governance Domains for Higher Education — an expansion of Pillar 4 of the Campus AI Framework. It covers the full scope of institutional AI governance and is organized around a single idea: that this work becomes manageable when it is broken into nine domains, grouped into three supercategories, each with its own policy instruments, delegation logic, and coordination mechanisms.
Whether or not you agree with these specific domains as I've drawn them, that's not really the point. The point is that AI on campus is not one problem in one place. There are many domains to consider — not just what happens inside the classroom. AI touches teaching, research, data, infrastructure, security, procurement, hiring, accessibility, and governance itself, and a decision in any one of them ripples into the others.
That's why a campus needs integrated, coordinated AI governance and operations rather than a patchwork of disconnected efforts. When each office solves its own slice in isolation, the gaps and contradictions between them become the real risk. Treating the domains as one connected system — with shared instruments, clear ownership, and links across boundaries — is what makes the whole thing governable.
Every domain shares one internal structure — six components (from policy instrument to review cadence), a delegation logic that says who decides, and coordination links to the domains it touches. The nine sit in three bands: Academic Core (1–4), Infrastructure & Risk (5–7), and People & Governance (8–9). A maturity model (CAGMA) lets an institution locate where it stands and what to do next.
- Senior leaders — provosts, CIOs, CISOs, chief data and academic officers
- AI governance committees and shared-governance bodies
- IT, risk, compliance, privacy, and legal officers building the operating layer
- Faculty and academic leaders weighing AI in teaching and research
- Consultants, accreditors, and peer institutions looking for a reference model
- New here? Start with Overview, or the Five-Domain View for a lighter entry.
- The Nine Domains is the core reference — open any domain for its full detail.
- Use the Maturity Model and Self-Assessment to place your own institution.
- Reach for the Standards Crosswalk when someone asks what it's based on.
- It's non-linear — jump anywhere from the sidebar; nothing requires reading in order.
Every top-level section, mirrored from the sidebar. Click any to open it.
- +Scholarly research, regulatory analysis, and firsthand institutional practice across many institution types
- +Aligned with recognized standards — NIST AI RMF, ISO/IEC 42001, the EU AI Act, and UNESCO
- +Built as Pillar 4 of the Campus AI Framework, a practitioner's playbook for AI in higher education
- –Not legal advice — confirm applicability with your own counsel, privacy office, and leadership
- –Not a certified compliance mapping; the crosswalk shows association, not equivalence
- –Not vendor- or product-specific, and not a substitute for local policy
- –Not a synthesis of existing frameworks — the architecture is an original contribution
Joe Sabado
Founder of CampusAIExchange.com, writing on responsible AI adoption, governance, and workforce transformation in higher education.
The Nine Domains framework grew out of AI governance work begun in 2023 — as a practitioner inside an institution, as a consultant engaging other campuses and systems, and as a scholar researching the evolving governance landscape.
That work has spanned a university system, a national higher-education technology community, and direct engagement with community colleges, research universities, private universities, a health-sciences institution, an accreditation agency, and industry associations.
In every one of those contexts, the same pattern appeared: institutions working hard on AI governance, but working on pieces of it. The architecture is an original contribution — tested against scholarly research, regulatory analysis, and institutional practice — not a synthesis of existing frameworks.
{{ dd.title }}
{{ dd.detail }}
{{ dd.practice }}
The six shared components, and how each shows up in this domain.