Confidential — internal only
Back to web view
Meridian State UniversityPrivacy & Information Security Offices
Confidential
Privacy & Security Review · Risk Evidence

Admissions CRM AI — Review & Risk Register

Document typeReview + Risk-register entryRef.RR-AI-0117
Prepared byPrivacy + ISOReviewed byAI Governance Committee
ScopeCRM AI over applicant PIIVisibilityConfidential
Assessed2026-04-08Re-assess by2026-07-08

1. Review scope

Assessment of AI features in the admissions CRM against privacy (FERPA), security, and the Student Engagement RMF profile, focused on the processing of prospective-student PII.

2. Findings summary

Critical0High1 (remediated)
Medium2 (remediated)Low1 (accepted)

3. Risk-register entry

Primary risk
Exposure or misuse of applicant PII via AI features.
Inherent rating
High (likelihood: medium · impact: severe).
Mitigations
Field-level restrictions, least privilege, in-CRM processing, audit logging, human review.
Residual rating
Low — accepted by the data owner and Privacy Office.

4. High finding & remediation

An over-broad role could view restricted fields. Remediated 2026-04-09 by tightening role scopes; re-tested by the ISO. No evidence of exposure.

5. Conditions of approval

  • No automated decisions about applicants
  • Quarterly access recertification
  • Re-review on any new data field or integration

6. Decision

Outcome: Approved to operate over Confidential applicant data, subject to the conditions above and re-assessment by the date shown.

Review & approval
Chief Privacy Officer
Chief Information Security Officer
Data owner — Enrollment Management
Date approved

Fictional example document for demonstration. In practice a Confidential document like this is not published — it is shown here only to illustrate the format.