A phased rollout

Each phase delivers standalone value while laying track for the next — so governance is useful in the first quarter, not only after full integration.

1

Foundation

0–90 days

Publish a governance map, baseline principles, appropriate-use guidance, governance roles, an intake template, a small set of context profiles, and sample linked records. Establish a preliminary taxonomy, decision statuses, and minimum data fields.

2

Pilot

3–6 months

Pilot selected use cases across teaching & learning, research, and administration. Test the decision tree, review workflow, record templates, local-contact model, and approval-condition language — and build a searchable prototype registry.

3

Operationalize

6–12 months

Adopt an AI Tool Approval Standard; align intake with procurement and security; formalize central and local registers; establish reporting; launch reviewer training; and implement reauthorization workflows.

4

Scale & improve

12+ months

Integrate with service management, procurement, enterprise architecture, vendor management, records, privacy, security, and risk systems. Publish transparent dashboards, collect feedback, analyze patterns, and update policies and profiles based on evidence.

Success measures

Measure whether governance is enabling responsible adoption — not merely counting approvals. Each measure ties back to a promise the framework makes.

What to measureWhy it matters
Share of known AI services and material use cases represented in the registry.Coverage — the registry only reflects reality if it is reasonably complete.
Share of AI-related procurements reviewed before purchase, renewal, integration, or expansion.The procurement control is actually catching tools before they land.
Median time from intake to decision, segmented by risk tier and route.Proportionality — low-risk requests move fast; scrutiny concentrates where stakes are high.
Share of approved records with current owners, conditions, review dates, and monitoring plans.Records stay live, not stale after approval.
Number and type of local approvals synchronized to the central registry.Federated review is visible centrally rather than drifting into shadow governance.
Share of high-impact uses with documented oversight, accessibility review, equity assessment, and evaluation evidence.The heaviest-consequence uses carry the strongest evidence.
Reauthorization completion rate and on-time material-change reviews.Approval is treated as time-bound and conditional, not permanent.
Incident, complaint, suspension, remediation, and retirement trends.The institution can see and act on where things go wrong.
User experience: clarity of guidance, ease of intake, confidence in pathways, perceived fairness of review.Governance is a service people trust, not a gate they route around.
Institutional learning: repeated issues, common denial reasons, reusable mitigations, policy improvements.The registry compounds into institutional memory and better decisions over time.

Design principles

Eight principles run through the framework's content, workflows, and technical design — the test any decision the registry supports should be able to pass.

Human accountability

AI may assist, but accountable people and units retain responsibility for decisions, communications, evaluations, and outcomes.

Risk proportionality

Apply more rigorous review to uses with more sensitive data, greater scale, higher stakes, more automation, or greater potential for harm.

Context sensitivity

Distinguish teaching, research, administration, student support, and employment rather than applying a generic rule set.

Transparency with safeguards

Make governance pathways, decision criteria, and appropriate records visible while protecting security-sensitive and confidential information.

Equity & accessibility by design

Evaluate foreseeable disparate impacts, language implications, digital-exclusion risks, and accessibility barriers from intake through monitoring.

Lifecycle accountability

Treat approval as time-bound and conditional; reassess when technology, data, context, performance, or risk changes.

Federated governance

Support local expertise and academic autonomy while retaining a common taxonomy, core controls, oversight, and institutional visibility.

Learning orientation

Preserve decisions, conditions, declines, incidents, and lessons so the institution becomes more consistent and capable over time.

Where it lands

Done well, the framework pairs a transparent approval-and-accountability operating model with a linked-record registry architecture. Its strongest contribution is not another list of approved products — it is a structured institutional memory of how AI is proposed, assessed, approved, constrained, monitored, changed, and retired.

Start from the operating model to see how decisions get made, then adapt the templates to your institution.

Ready to stand it up?

Take the whole framework as a whitepaper, or start filling in the four core documents.