Current status: This is a planning framework, not a compliance audit, certification, or diagnostic guarantee.
AI governance readiness is a district’s capacity to make and carry out repeatable AI decisions. It includes leadership, inventory, review, data boundaries, instructional practice, technical and procedural controls, evidence, and continuous improvement across both direct AI use and backend application AI. This assessment produces a maturity profile and an action plan. It does not produce a legal conclusion or guarantee that an AI system is safe.
Download the AI governance readiness CSV
The four maturity levels
Score each domain using current evidence, not intention.
| Level | Name | Evidence standard |
|---|---|---|
| 0 | Unaddressed | No owner or repeatable practice is evident |
| 1 | Emerging | Informal work exists, but scope, ownership, or evidence is inconsistent |
| 2 | Defined | Roles and processes are documented and used for priority cases |
| 3 | Operational | The process is used across scope, measured, reviewed, and improved |
Do not let a total score conceal a serious gap. A district with strong training but no inventory or data-boundary review still has an urgent governance problem.
Domain 1: leadership and decision rights
Question: Can the district identify who is accountable and who may approve each class of AI use?
- 0: No designated executive sponsor or decision path.
- 1: An informal committee discusses AI, but authority and escalation are unclear.
- 2: An executive sponsor, cross-functional group, decision matrix, and exception path are documented.
- 3: Decisions are made within service targets, conflicts are escalated, and leadership reviews program outcomes and open risks.
Evidence can include a charter, RACI, board or cabinet direction, meeting cadence, decision records, and exception procedure.
Domain 2: inventory and ownership
Question: Does the district know where AI is used and who owns each use?
- 0: No inventory.
- 1: A partial list of prominent tools exists.
- 2: The register covers direct-use products, embedded features, district applications, vendor applications, pilots, owners, purposes, deployments, and review dates.
- 3: Procurement, identity, application, cloud, and departmental processes keep the register current, and unowned or expired uses are resolved.
Use the AI application register template for backend uses and link related direct-use approvals.
Domain 3: risk-tiered vetting and approval
Question: Can the district make consistent, documented approval decisions proportional to risk?
- 0: Uses begin without review.
- 1: Reviews occur reactively or depend on individual reviewers.
- 2: Common intake, risk tiers, evidence requirements, statuses, conditions, and expiry rules are documented.
- 3: Review quality, turnaround, exceptions, and material changes are measured and used to improve the process.
Evidence can include the AI tool vetting template, completed decisions, pilot criteria, and material-change records.
Domain 4: privacy and data governance
Question: Can the district state which data a use may access, why, where it goes, and how long it remains?
- 0: Approval relies on broad labels such as “student data” or vendor assurances.
- 1: Privacy review occurs for selected procurements, but field-level scope, retention, or deployment details are inconsistent.
- 2: Purpose, source system, data class, fields or documents, recipient, retention, training use, legal model, contract, and deletion are documented.
- 3: Least-privilege access, review of material changes, deletion verification, and data-flow evidence operate across the inventory.
Federal resources provide important requirements and practices, but districts must evaluate their exact facts and applicable state and local rules. Use K-12 AI data boundaries to structure the record.
Domain 5: instructional quality, accessibility, and human responsibility
Question: Does the district connect AI use to learning goals, equitable access, accessibility, and accountable human decisions?
- 0: No instructional or accessibility guidance.
- 1: General principles exist, but assignment-level expectations and support vary widely.
- 2: Guidance defines acceptable assistance, disclosure, source checking, educator review, alternatives, accessibility testing, and prohibited consequential uses.
- 3: Educator feedback, student experience, accessibility findings, and learning evidence are used to revise guidance and approvals.
Evidence can include assignment guidance, professional learning, accessible alternatives, test records, and a documented process for individualized educational decisions.
Domain 6: technical and procedural controls across both planes
Question: Can the district carry policy into the actual place where AI is used?
- 0: Policy relies mainly on user memory.
- 1: Destination-level access or isolated controls cover some direct-use tools.
- 2: Supported direct-use surfaces have managed guardrails, and backend applications have registered identities, approved routes, and procedural controls.
- 3: Control coverage is tested, exceptions expire, failure behavior is known, and support matrices are kept current.
Tenet Edge addresses direct use on supported managed-device surfaces. Tenet Gateway is a founding-district program for backend authorization. Read The Two Planes of District AI before selecting controls.
Domain 7: evidence, transparency, and response
Question: Can the district explain approvals, policy decisions, exceptions, and incidents without collecting unnecessary content?
- 0: No consistent record or response path.
- 1: Logs or reports exist, but access, meaning, retention, and ownership are unclear.
- 2: The district defines bounded evidence, district-owned destinations, access, retention, notices, incident routing, and review responsibilities.
- 3: Evidence quality, low-volume privacy risk, response timeliness, stakeholder feedback, and corrective action are reviewed.
Evidence can include an event dictionary, retention schedule, access list, notice, incident playbook, review log, and closure record.
Domain 8: lifecycle and continuous improvement
Question: Does the district revisit AI uses when the context changes?
- 0: Approval has no expiry or review.
- 1: Renewal happens mainly at contract dates.
- 2: Scheduled reviews and material-change triggers cover purpose, users, data, model deployment, terms, controls, and outcomes.
- 3: Changes are detected through operating processes, approvals are updated or revoked, and program measures inform priorities.
Evidence can include review calendars, change notices, retired-use records, control tests, program measures, and leadership reports.
How to run a useful assessment
1. Convene the right people
Include an executive sponsor plus technology, curriculum, privacy, security, accessibility, procurement, student services, school leadership, and educator perspectives. Add legal review as appropriate. A technology-only assessment will miss key educational and rights-based decisions.
2. Score with evidence
For each domain, link to the document, system, completed record, or observed practice that supports the score. If the group cannot produce evidence, use the lower level and record the gap.
3. Capture disagreement
If one team scores a domain differently, record why. Disagreement often reveals that a process exists on paper but is not visible or consistently used.
4. Choose priority actions
Select no more than three to five actions for the next cycle. Each needs an owner, due date, dependency, and completion evidence.
5. Reassess at a defined cadence
Repeat after major policy or platform changes and at least on the district’s chosen annual or semester cadence. Use the same evidence standard so progress is meaningful.
Suggested priority rules
Address these conditions before chasing a higher total score:
- No accountable executive or decision authority.
- High-consequence or high-data uses with no owner.
- AI use involving education records with no documented data boundary or legal review.
- AI output used for consequential decisions without required human responsibility and review.
- Student use with no age, accessibility, instructional, or family communication process.
- Backend applications with shared credentials and no application-level registration.
- Approvals with no disable path, expiry, or material-change trigger.
Example action plan
| Gap | Next action | Owner | Completion evidence |
|---|---|---|---|
| Partial inventory | Reconcile procurement, identity, cloud, and department lists | CIO designee | Register with owner, purpose, deployment, and status for each known use |
| Inconsistent privacy review | Adopt a data-boundary record and routing rule | Privacy lead | Completed records for all medium- and high-risk uses |
| Policy cannot reach direct use | Define supported surfaces and managed controls | Technology lead | Tested compatibility matrix and exception procedure |
| Backend apps share one undifferentiated route | Register application identities and approved purposes | Architecture lead | Application register and per-app authorization design |
Frequently asked questions
What does AI governance readiness mean for a school district?
It means the district has enough ownership, inventory, decision process, data discipline, instructional guidance, controls, evidence, and review capacity to manage AI uses consistently.
Is the readiness assessment a compliance score?
No. It is a planning rubric. It does not establish compliance, certify a product, or predict that incidents will not occur.
Should a district add the eight domain scores together?
A total can help track broad progress, but the domain profile is more useful. A low score in data governance or decision ownership should not be hidden by high scores elsewhere.
Who should complete the assessment?
A cross-functional group should complete it with evidence. Include leadership, technology, curriculum, privacy, security, accessibility, procurement, student services, educators, and other roles required by district policy.
What should happen after the assessment?
Select a small number of priority gaps, assign owners and dates, define evidence of completion, and reassess after material program changes or on a regular cadence.
Sources
- AI Risk Management Framework Core, NIST
- NIST AI RMF Playbook
- Checklist: Data Governance, U.S. Department of Education
- Artificial Intelligence and the Future of Teaching and Learning, U.S. Department of Education
This assessment is educational information. It is not a compliance audit, legal opinion, certification, or guarantee of risk reduction.