Human accountability
AI may assist, but accountable people and units retain responsibility for decisions, communications, evaluations, and outcomes.
A registry is not built in one release. This is a staged path from a published governance map to an integrated operating model — with the success measures that tell you it is working and the design principles that keep it honest along the way.
Each phase delivers standalone value while laying track for the next — so governance is useful in the first quarter, not only after full integration.
Publish a governance map, baseline principles, appropriate-use guidance, governance roles, an intake template, a small set of context profiles, and sample linked records. Establish a preliminary taxonomy, decision statuses, and minimum data fields.
Pilot selected use cases across teaching & learning, research, and administration. Test the decision tree, review workflow, record templates, local-contact model, and approval-condition language — and build a searchable prototype registry.
Adopt an AI Tool Approval Standard; align intake with procurement and security; formalize central and local registers; establish reporting; launch reviewer training; and implement reauthorization workflows.
Integrate with service management, procurement, enterprise architecture, vendor management, records, privacy, security, and risk systems. Publish transparent dashboards, collect feedback, analyze patterns, and update policies and profiles based on evidence.
Measure whether governance is enabling responsible adoption — not merely counting approvals. Each measure ties back to a promise the framework makes.
| What to measure | Why it matters |
|---|---|
| Share of known AI services and material use cases represented in the registry. | Coverage — the registry only reflects reality if it is reasonably complete. |
| Share of AI-related procurements reviewed before purchase, renewal, integration, or expansion. | The procurement control is actually catching tools before they land. |
| Median time from intake to decision, segmented by risk tier and route. | Proportionality — low-risk requests move fast; scrutiny concentrates where stakes are high. |
| Share of approved records with current owners, conditions, review dates, and monitoring plans. | Records stay live, not stale after approval. |
| Number and type of local approvals synchronized to the central registry. | Federated review is visible centrally rather than drifting into shadow governance. |
| Share of high-impact uses with documented oversight, accessibility review, equity assessment, and evaluation evidence. | The heaviest-consequence uses carry the strongest evidence. |
| Reauthorization completion rate and on-time material-change reviews. | Approval is treated as time-bound and conditional, not permanent. |
| Incident, complaint, suspension, remediation, and retirement trends. | The institution can see and act on where things go wrong. |
| User experience: clarity of guidance, ease of intake, confidence in pathways, perceived fairness of review. | Governance is a service people trust, not a gate they route around. |
| Institutional learning: repeated issues, common denial reasons, reusable mitigations, policy improvements. | The registry compounds into institutional memory and better decisions over time. |
Eight principles run through the framework's content, workflows, and technical design — the test any decision the registry supports should be able to pass.
AI may assist, but accountable people and units retain responsibility for decisions, communications, evaluations, and outcomes.
Apply more rigorous review to uses with more sensitive data, greater scale, higher stakes, more automation, or greater potential for harm.
Distinguish teaching, research, administration, student support, and employment rather than applying a generic rule set.
Make governance pathways, decision criteria, and appropriate records visible while protecting security-sensitive and confidential information.
Evaluate foreseeable disparate impacts, language implications, digital-exclusion risks, and accessibility barriers from intake through monitoring.
Treat approval as time-bound and conditional; reassess when technology, data, context, performance, or risk changes.
Support local expertise and academic autonomy while retaining a common taxonomy, core controls, oversight, and institutional visibility.
Preserve decisions, conditions, declines, incidents, and lessons so the institution becomes more consistent and capable over time.
Done well, the framework pairs a transparent approval-and-accountability operating model with a linked-record registry architecture. Its strongest contribution is not another list of approved products — it is a structured institutional memory of how AI is proposed, assessed, approved, constrained, monitored, changed, and retired.
Start from the operating model to see how decisions get made, then adapt the templates to your institution.
Take the whole framework as a whitepaper, or start filling in the four core documents.