An Integrated Governance Model for University AI: Extending ISO/IEC 27001 for Higher Education
Abstract
Generative Artificial Intelligence has become part of everyday practice in higher education. It supports learning and teaching, but it also enables new forms of academic misconduct, as students can use large language models to bypass assessment rules and to produce outputs that are difficult to attribute to individual performance. In parallel, universities face AI-related information security risks such as sensitive data disclosure and intellectual-property leakage. ISO/IEC 27001:2022 provides a well-established baseline for governing confidentiality, integrity, and availability, but it does not explicitly address AI-specific risk sources such as training-data dependencies, prompt-based attacks, non-deterministic outputs, model drift, and limited explainability. This paper develops an integrated AI governance model for higher education using Design Science Research (DSR). The artefact extends an ISO/IEC 27001-based ISMS by integrating AI lifecycle risk perspectives from ISO/IEC 23894 and AI management system integration concepts from ISO/IEC 42001, AI TRiSM and the NIST AI Risk Management Framework. Because AI systems and misuse patterns evolve rapidly, the model is using an Observe–Orient–Decide–Act (OODA) loop to ensure the possibility of short, evidence-based adaptation. The proposed model is evaluated qualitatively through the conformance to the standards and real-world academic use cases that illustrate AI-enabled misconduct in artefacts.
Keywords: Higher education, AI governance, ISO/IEC 27001, academic misconduct, OODA loop
DOI: 10.54941/ahfe1008178
Cite this paper
More from this volume
- Designing an Online Rehabilitation Exercise Service for Frailty Prevention among Older Adults
- Perceived Helpfulness and Adoption Intentions for Real-Time Attendance Text Notifications: Insights from School Stakeholders
- Development of a design system for an AI call intake assistant - a user-centered reverse engineering approach
- Designing Adaptive Transparency User Interface for Pedestrian Safety in Mobile AR
- Systemic Design for Social License: Modelling Information and Communication Challenges in Mining Environmental Management through a Systemic CJM
- Development and Verification of a Testing Methodology for Driver Alcohol Intoxication Detection Systems
- Long-term One-year Stability of Discomfort Perception in Automated Driving and Personal Influencing Factors
- From Commuters to Explorers: Modal Inertia, Behavioral Commitment, and the Segmentation Logic of Flat-Rate Urban Mobility
- The Sunk Cost Dividend: Anticipatory Commitment, Willingness to Pay, and Behavioral Activation in Flat-Rate Urban Mobility
- Designing for the Operational Middle: A Sociotechnical Framework for Integrating Psychosocial Risk into Aviation Human Factors and Safety Management
- Designing Employee Experience through Culture: A Framework for Culture Shift in Organizations
- Financial Reporting Quality and Firm Value: Evidence from Saudi Arabia


AHFE Open Access