Chittagong University of Engineering and Technology, Chattogram 4349, BD
Abstract
The rapid adoption of AI-driven adaptive learning platforms, intelligent tutoring systems, automated grading tools, and generative-AI tutoring assistants has introduced a category of institutional risk that extends beyond conventional cloud and data security: algorithmic bias, model opacity, autonomous or semi-autonomous decision-making about students, and the regulatory scrutiny now attached to AI systems used for admissions, assessment, and monitoring. This paper argues that Enterprise Risk Management (ERM), and specifically the baseline cloud-security requirements and governance principles developed for general enterprise cloud deployments, provide a transferable risk-management foundation for AI-driven educational platforms, but require a dedicated AI-specific risk layer that the enterprise baseline alone does not anticipate. Drawing on enterprise-sector research on baseline cloud-security requirements within an ERM framework, on the strategies, challenges, and organizational-success factors of ERM implementation, on the education-sector AI-ethics literature, on international AI-governance standards (the NIST AI Risk Management Framework and ISO/IEC 42001), and on the risk-tier classifications introduced by the European Union's Artificial Intelligence Act (Regulation (EU) 2024/1689, Annex III), this paper proposes a framework comprising an AI-specific risk register mapped to ERM controls, a four-tier AI risk classification scheme for educational use cases, a human-oversight-and-explainability layer, a quantitative risk-scoring model, and an institutional governance structure. The framework is demonstrated through an illustrative twelve-month institutional pilot scenario, following design-science research (DSR) evaluation conventions, and is contextualized against recently reported survey evidence on rising faculty and administrator concern about AI bias and data-privacy risk in higher education, an illustrative risk-register heat-map, and an illustrative cost-versus-risk-reduction analysis. The paper concludes with adoption barriers, a positioning of the framework against the EU AI Act, the NIST AI RMF, and ISO/IEC 42001, and recommendations for institutions deploying AI-driven learning technologies.
Keywords
Artificial Intelligence in EducationEnterprise Risk ManagementAI GovernanceAlgorithmic BiasEducational Information SystemsAdaptive Learning PlatformsData Privacy
Article Information
- Published
- September 8, 2026
- Journal
- US Journal of New Insights in Tech & Education
- Volume / Issue
- 6 / 1
- Article No.
- USJNITE-2602
- Year
- 2026