top of page

FOR STATE AND LOCAL GOVERNMENT AND HIGHER EDUCATION
Before someone asks you to explain your AI posture, know where you stand.
Most public sector and higher ed organizations are already running AI nobody approved, in unvetted vendor products and everyday staff workflows. The exposure is real, and it's not just a compliance issue. Regimes like FERPA, CJIS, HIPAA, and CMMC are only the start — the rest is data leakage, security gaps, and eroded public trust.
20 minutes with Paul Ashe, Securance's founder and president — 30 years spent finding what's broken in enterprise IT security, not what looks broken on paper. No pitch — just a working conversation, followed by a free AI usage analysis of your organization.
The gap no one is owning
No one owns the decision.
Ask "who decides whether staff can use a new AI tool?" and the honest answer in most organizations is "it depends." Committees can draft policy, but nobody can approve, restrict, or revoke the use of a tool. The most common AI governance gap isn't a missing policy — it's a missing owner.
AI is already in your stack.
Microsoft 365, your ERP, your permitting system, your student information system — all added AI features in the last 18 months, most enabled by default, none run through procurement. Vendors aren't required to warn you. Contracts signed before 2023 almost never anticipated it.
Well-meaning staff create real exposure.
A caseworker pastes resident records into a consumer AI tool; a registrar does the same with student data. FERPA or state privacy law almost certainly applies — and almost certainly isn't satisfied. The same holds for CJIS, HIPAA, GLBA, PCI, and CMMC. The intent is good; the exposure is the same.
The public moment is coming.
Your council, board, faculty senate, or an accreditor will eventually ask you to explain your AI posture. Organizations that worked it out in advance answer from strength. The rest answer reactively, after something has gone wrong.
AI GOVERNANCE BENCHMARK
Where do public sector and higher ed peers actually stand? Average score: 11.8 / 100.
We assessed eight organizations against The Securance 11. Every one landed "at risk" or "early," and five of the 11 domains scored a flat zero across all assessed organizations. Wherever you land, the benchmark gives you a baseline — so you know where your peers stand.
SECURANCE 11
The AI governance standard for government and higher education
Sector-agnostic AI frameworks like the NIST AI Risk Management Framework and ISO/IEC 42001 tell you what to govern. They don't tell a city manager or a provost what to do Monday morning, and they don't deal directly with FERPA, CJIS, FOIA, CMMC, sponsored research, faculty governance, or the political accountability that comes with serving the public.
The Securance 11 covers the 11 governance domains that matter for government and higher ed — and turns them into a single 90-day action sequence, built for leaders who are already stretched thin. It draws directly on the work our advisory team does with public sector and higher ed clients.

01
GOVERNANCE AND OWNERSHIP

02
ACCEPTABLE USE AND WORKFORCE POLICY

03
DATA PROTECTION AND INFORMATION GOVERNANCE

04
EMBEDDED AI IN VENDOR PRODUCTS

05
RISK AND COMPLIANCE POSTURE

06
BUILD VS. BUY VS. EMBED

07
SECURITY IMPLICATIONS

08
INTELLECTUAL PROPERTY

09
WORKFORCE AND CHANGE MANAGEMENT

10
MEASUREMENT AND VALUE REALIZATION

11
ETHICS AND EXTERNAL POSITIONING
11 GOVERNANCE DOMAINS
bottom of page
.png)
.png)