Skip to content

An Integrated Governance Model for University AI: Extending ISO/IEC 27001 for Higher Education

2026 · AHFE International · 0 citations

Abstract

Generative Artificial Intelligence has become part of everyday practice in higher education. It supports learning and teaching, but it also enables new forms of academic misconduct, as students can use large language models to bypass assessment rules and to produce outputs that are difficult to attribute to individual performance. In parallel, universities face AI-related information security risks such as sensitive data disclosure and intellectual-property leakage. ISO/IEC 27001:2022 provides a well-established baseline for governing confidentiality, integrity, and availability, but it does not explicitly address AI-specific risk sources such as training-data dependencies, prompt-based attacks, non-deterministic outputs, model drift, and limited explainability. This paper develops an integrated AI governance model for higher education using Design Science Research (DSR). The artefact extends an ISO/IEC 27001-based ISMS by integrating AI lifecycle risk perspectives from ISO/IEC 23894 and AI management system integration concepts from ISO/IEC 42001, AI TRiSM and the NIST AI Risk Management Framework. Because AI systems and misuse patterns evolve rapidly, the model is using an Observe–Orient–Decide–Act (OODA) loop to ensure the possibility of short, evidence-based adaptation. The proposed model is evaluated qualitatively through the conformance to the standards and real-world academic use cases that illustrate AI-enabled misconduct in artefacts.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.