AI Governance Framework for Institutional Advancement
Risk classification, policy templates, vendor evaluation, and compliance mapping for advancement offices running operational governance programs.
About this framework
Four sections cover the operational surface: risk assessment and classification, regulatory compliance by jurisdiction, vendor and supply chain evaluation, and operations from acceptable use through incident response.
The structure draws from the NIST AI Risk Management Framework and ISO/IEC 42001, adapted for the data types, risk profiles, and regulatory exposure specific to fundraising operations.
Risk Assessment
Governance structure, AI system inventory, four-factor risk classification matrix, and data governance controls.
Governance structure · System inventory · Risk classification · Data governance Read sectionRegulatory Compliance
FERPA, HIPAA, NY SHIELD Act, state AI laws, and EU AI Act obligations mapped to advancement use cases. Interactive state law coverage map.
Federal regulations · State AI laws · International · Donor privacy standards Read sectionVendor Assessment
Evaluation criteria for AI vendors and embedded platform features. Covers model transparency, bias testing, security, contract terms, and embedded feature governance.
Model and data · Transparency · Bias and fairness · Security · Contract terms Read sectionOperations
Acceptable use policy, monitoring and audit procedures, incident response, training requirements, and a 90-day implementation roadmap.
Acceptable use policy · Monitoring · Incident response · Training · Implementation Read sectionDownloadable Templates
Standalone templates for your governance program. Acceptable use policy, system inventory worksheet, vendor assessment checklist, committee charter, and contract addendum.
5 templates · Word downloads · Fill-in-the-blank Browse templatesSources and standards crosswalk
The guidance across this framework reflects our interpretation and application of these standards to fundraising-specific use cases, data types, and regulatory exposure. The crosswalk serves institutions that need to demonstrate conformance with a specific standard or document governance framework provenance for procurement.
Framework crosswalk
| Framework section | NIST AI RMF | ISO 42001 | EU AI Act |
|---|---|---|---|
| Governance structure | GV-1 (policies), GV-2 (accountability), GV-3 (workforce diversity), GV-4 (culture) | Clause 5 (Leadership), A.3.2 (Roles) | Art. 17 (Quality management) |
| System inventory | MP-1 (context), MP-2 (categorization) | Clause 8.1 (Operational planning), A.4.2 (Resources) | Art. 49 (EU database registration) |
| Risk classification | MP-3 (benefits/costs), MP-5 (impact characterization) | Clause 6.1.2 (Risk assessment), A.5.2 (Impact assessment process) | Art. 6 (Classification), Annex III |
| Data governance | MG-3 (third-party risk), MS-2.5 (valid/reliable) | A.7.2–A.7.6 (Data controls) | Art. 10 (Data governance) |
| Vendor assessment | GV-6 (third-party policies), MG-3 (third-party management) | A.10.2–A.10.4 (Third-party relationships) | Art. 25 (Deployer obligations) |
| Acceptable use | GV-1.1 (organizational policies) | A.2.2 (AI policy), A.9.2 (Responsible use) | Art. 4 (AI literacy) |
| Compliance | GV-1.6 (legal compliance), MP-4 (third-party risks) | Clause 4.1 (Context), A.2.3 (Policy alignment) | Art. 5 (Prohibitions), Art. 50 (Transparency) |
| Monitoring and audit | MS-1 (measurement approach), MS-2 (trustworthiness evaluation), MS-3 (risk tracking) | Clause 9 (Performance evaluation), A.6.2.6 (Monitoring) | Art. 9 (Risk management), Art. 12 (Logging) |
| Incident response | MG-4 (post-deployment response) | Clause 10.2 (Corrective action), A.8.4 (Incident communication) | Art. 62 (Reporting), Art. 73 (Serious incidents) |
| Training | GV-4 (culture and competency) | Clause 7.2 (Competence), 7.3 (Awareness) | Art. 4 (AI literacy) |
Further reading
- NIST AI 100-1: AI Risk Management Framework 1.0 (January 2023)
- NIST AI 600-1: Generative AI Profile (July 2024)
- NIST AI RMF Playbook: suggested actions per subcategory (airc.nist.gov)
- ISO/IEC 42001:2023: AI Management System standard
- EU AI Act: Regulation (EU) 2024/1689 (entered into force August 1, 2024)
- EDUCAUSE HECVAT 4: Higher Education Community Vendor Assessment Toolkit, including AI/ML module (February 2025)
- APRA Ethics in AI for Fundraising Toolkit (aprahome.org)
- Fundraising.AI Framework toward Responsible and Beneficial AI for Fundraising (revised November 2025)
- NY SHIELD Act: Stop Hacks and Improve Electronic Data Security Act (GBL §§ 899-aa, 899-bb)
- IAPP US State Privacy Legislation Tracker (iapp.org)