Maturity framework

K-12 AI Governance Readiness Assessment

A readiness assessment should reveal the next operating decisions a district needs to make. This eight-domain framework evaluates both direct AI use and backend application AI without producing a false compliance score.

Audience
District cabinet, technology, curriculum, privacy, security, accessibility, and school leaders
Read time
10 min read
Published
Reviewed
Review
TrueMadeAI Engineering

Current status: This is a planning framework, not a compliance audit, certification, or diagnostic guarantee.

AI governance readiness is a district’s capacity to make and carry out repeatable AI decisions. It includes leadership, inventory, review, data boundaries, instructional practice, technical and procedural controls, evidence, and continuous improvement across both direct AI use and backend application AI. This assessment produces a maturity profile and an action plan. It does not produce a legal conclusion or guarantee that an AI system is safe.

Download the AI governance readiness CSV

The four maturity levels

Score each domain using current evidence, not intention.

Level Name Evidence standard
0 Unaddressed No owner or repeatable practice is evident
1 Emerging Informal work exists, but scope, ownership, or evidence is inconsistent
2 Defined Roles and processes are documented and used for priority cases
3 Operational The process is used across scope, measured, reviewed, and improved

Do not let a total score conceal a serious gap. A district with strong training but no inventory or data-boundary review still has an urgent governance problem.

Domain 1: leadership and decision rights

Question: Can the district identify who is accountable and who may approve each class of AI use?

  • 0: No designated executive sponsor or decision path.
  • 1: An informal committee discusses AI, but authority and escalation are unclear.
  • 2: An executive sponsor, cross-functional group, decision matrix, and exception path are documented.
  • 3: Decisions are made within service targets, conflicts are escalated, and leadership reviews program outcomes and open risks.

Evidence can include a charter, RACI, board or cabinet direction, meeting cadence, decision records, and exception procedure.

Domain 2: inventory and ownership

Question: Does the district know where AI is used and who owns each use?

  • 0: No inventory.
  • 1: A partial list of prominent tools exists.
  • 2: The register covers direct-use products, embedded features, district applications, vendor applications, pilots, owners, purposes, deployments, and review dates.
  • 3: Procurement, identity, application, cloud, and departmental processes keep the register current, and unowned or expired uses are resolved.

Use the AI application register template for backend uses and link related direct-use approvals.

Domain 3: risk-tiered vetting and approval

Question: Can the district make consistent, documented approval decisions proportional to risk?

  • 0: Uses begin without review.
  • 1: Reviews occur reactively or depend on individual reviewers.
  • 2: Common intake, risk tiers, evidence requirements, statuses, conditions, and expiry rules are documented.
  • 3: Review quality, turnaround, exceptions, and material changes are measured and used to improve the process.

Evidence can include the AI tool vetting template, completed decisions, pilot criteria, and material-change records.

Domain 4: privacy and data governance

Question: Can the district state which data a use may access, why, where it goes, and how long it remains?

  • 0: Approval relies on broad labels such as “student data” or vendor assurances.
  • 1: Privacy review occurs for selected procurements, but field-level scope, retention, or deployment details are inconsistent.
  • 2: Purpose, source system, data class, fields or documents, recipient, retention, training use, legal model, contract, and deletion are documented.
  • 3: Least-privilege access, review of material changes, deletion verification, and data-flow evidence operate across the inventory.

Federal resources provide important requirements and practices, but districts must evaluate their exact facts and applicable state and local rules. Use K-12 AI data boundaries to structure the record.

Domain 5: instructional quality, accessibility, and human responsibility

Question: Does the district connect AI use to learning goals, equitable access, accessibility, and accountable human decisions?

  • 0: No instructional or accessibility guidance.
  • 1: General principles exist, but assignment-level expectations and support vary widely.
  • 2: Guidance defines acceptable assistance, disclosure, source checking, educator review, alternatives, accessibility testing, and prohibited consequential uses.
  • 3: Educator feedback, student experience, accessibility findings, and learning evidence are used to revise guidance and approvals.

Evidence can include assignment guidance, professional learning, accessible alternatives, test records, and a documented process for individualized educational decisions.

Domain 6: technical and procedural controls across both planes

Question: Can the district carry policy into the actual place where AI is used?

  • 0: Policy relies mainly on user memory.
  • 1: Destination-level access or isolated controls cover some direct-use tools.
  • 2: Supported direct-use surfaces have managed guardrails, and backend applications have registered identities, approved routes, and procedural controls.
  • 3: Control coverage is tested, exceptions expire, failure behavior is known, and support matrices are kept current.

Tenet Edge addresses direct use on supported managed-device surfaces. Tenet Gateway is a founding-district program for backend authorization. Read The Two Planes of District AI before selecting controls.

Domain 7: evidence, transparency, and response

Question: Can the district explain approvals, policy decisions, exceptions, and incidents without collecting unnecessary content?

  • 0: No consistent record or response path.
  • 1: Logs or reports exist, but access, meaning, retention, and ownership are unclear.
  • 2: The district defines bounded evidence, district-owned destinations, access, retention, notices, incident routing, and review responsibilities.
  • 3: Evidence quality, low-volume privacy risk, response timeliness, stakeholder feedback, and corrective action are reviewed.

Evidence can include an event dictionary, retention schedule, access list, notice, incident playbook, review log, and closure record.

Domain 8: lifecycle and continuous improvement

Question: Does the district revisit AI uses when the context changes?

  • 0: Approval has no expiry or review.
  • 1: Renewal happens mainly at contract dates.
  • 2: Scheduled reviews and material-change triggers cover purpose, users, data, model deployment, terms, controls, and outcomes.
  • 3: Changes are detected through operating processes, approvals are updated or revoked, and program measures inform priorities.

Evidence can include review calendars, change notices, retired-use records, control tests, program measures, and leadership reports.

How to run a useful assessment

1. Convene the right people

Include an executive sponsor plus technology, curriculum, privacy, security, accessibility, procurement, student services, school leadership, and educator perspectives. Add legal review as appropriate. A technology-only assessment will miss key educational and rights-based decisions.

2. Score with evidence

For each domain, link to the document, system, completed record, or observed practice that supports the score. If the group cannot produce evidence, use the lower level and record the gap.

3. Capture disagreement

If one team scores a domain differently, record why. Disagreement often reveals that a process exists on paper but is not visible or consistently used.

4. Choose priority actions

Select no more than three to five actions for the next cycle. Each needs an owner, due date, dependency, and completion evidence.

5. Reassess at a defined cadence

Repeat after major policy or platform changes and at least on the district’s chosen annual or semester cadence. Use the same evidence standard so progress is meaningful.

Suggested priority rules

Address these conditions before chasing a higher total score:

  1. No accountable executive or decision authority.
  2. High-consequence or high-data uses with no owner.
  3. AI use involving education records with no documented data boundary or legal review.
  4. AI output used for consequential decisions without required human responsibility and review.
  5. Student use with no age, accessibility, instructional, or family communication process.
  6. Backend applications with shared credentials and no application-level registration.
  7. Approvals with no disable path, expiry, or material-change trigger.

Example action plan

Gap Next action Owner Completion evidence
Partial inventory Reconcile procurement, identity, cloud, and department lists CIO designee Register with owner, purpose, deployment, and status for each known use
Inconsistent privacy review Adopt a data-boundary record and routing rule Privacy lead Completed records for all medium- and high-risk uses
Policy cannot reach direct use Define supported surfaces and managed controls Technology lead Tested compatibility matrix and exception procedure
Backend apps share one undifferentiated route Register application identities and approved purposes Architecture lead Application register and per-app authorization design

Frequently asked questions

What does AI governance readiness mean for a school district?

It means the district has enough ownership, inventory, decision process, data discipline, instructional guidance, controls, evidence, and review capacity to manage AI uses consistently.

Is the readiness assessment a compliance score?

No. It is a planning rubric. It does not establish compliance, certify a product, or predict that incidents will not occur.

Should a district add the eight domain scores together?

A total can help track broad progress, but the domain profile is more useful. A low score in data governance or decision ownership should not be hidden by high scores elsewhere.

Who should complete the assessment?

A cross-functional group should complete it with evidence. Include leadership, technology, curriculum, privacy, security, accessibility, procurement, student services, educators, and other roles required by district policy.

What should happen after the assessment?

Select a small number of priority gaps, assign owners and dates, define evidence of completion, and reassess after material program changes or on a regular cadence.

Sources

This assessment is educational information. It is not a compliance audit, legal opinion, certification, or guarantee of risk reduction.

Choose your Tenet path

Start with one district baseline. Add context when you need it.

Tenet Basic is free. Tenet District adds roster, classroom, teacher, grade, and schedule context.