Where the Risk Actually Sits

Every sector treats AI governance differently — what counts as a real risk, who signs off on it, and which frameworks actually get referenced in a Board conversation. The breakdown below isn't generic: it reflects how AI governance plays out specifically for organizations in Higher Education, from the challenges that show up first to the people who typically need to be in the room.

  • Faculty and student AI use has outpaced institutional policy almost everywhere
  • Academic integrity concerns compete with legitimate pedagogical AI use cases
  • Procurement of AI tools is decentralized across departments with no central governance
  • IT departments frequently lack the mandate to govern AI tool procurement happening informally within academic departments
  • Institutions with strong research programs face additional AI governance questions specific to research ethics and data use
  • Institution-wide AI literacy and faculty development (building on prior EdTech AI-governance experience)
  • AI-enabled research computing governance
  • Student-facing AI tools within an academic-integrity-compatible framework
Provincial privacy legislation covering student dataInstitutional academic integrity policy requirementsResearch ethics board considerations for AI in research
ISO42001
ISO/IEC 42001:2023

Artificial intelligence management systems — organizational accountability, AI policies, lifecycle governance, risk management and continuous improvement.

NISTAIRMF
NIST AI Risk Management Framework

The Govern, Map, Measure and Manage approach for identifying and controlling risks arising from AI systems.

PIPEDA
PIPEDA

Canadian federal privacy law governing the collection, use, disclosure and safeguarding of personal information.

View the full Frameworks Registry →

The stakeholders typically at the table for an engagement in this sector.

Provost / VP AcademicChief Information OfficerDean of the relevant FacultyAcademic Integrity OfficeFaculty Senate / Curriculum Committee