AI Readiness & Safety Assessment
Is Your Nonprofit Ready for AI? Take This Quiz to Find Out
If you’re using AI in your nonprofit work, you’re not alone. A report from earlier this year found that 92% of nonprofits are already using AI in some form. An email draft here, a predictive score there. Maybe someone on your team has pasted donor notes into ChatGPT to summarize them for a board update. Maybe your fundraising team is testing an AI tool to draft appeal letters or testing out predictive scores to inform fundraising strategy.
On paper, it can feel like your team is moving fast and staying modern. But behind the scenes, nobody has actually stopped to ask: Are we doing any of this safely?
In the same research that we referenced above, nearly half of the respondents report having no formal AI policy. That’s a problem. If you’re using AI at your nonprofit without clear guidance and guardrails governing how you use it, you’re taking a big risk.
Using AI at your org without a real policy in place is not only a huge liability, but it also means that you and your team are not using or scaling these tools as effectively as you could be.
This implementation governance gap, with implementation outpacing governance at most organizations, is exactly what the Nonprofit AI Readiness & Safety Scorecard is built to address.
Why a Structured Scorecard Beats Guessing
Our Nonprofit AI Readiness & Safety Assessment uses 18 simple questions spanning six critical pillars (from governance and vendor vetting to data privacy, human review, transparency, and incident reporting) to produce a scorecard that gives you a clear risk score for your organization and recommendations tailored to your results.
Here is why this structured evaluation works:
- It replaces guessing with clear data. Most organizations sense they have risks somewhere. Our scorecard tells you exactly where those risks are.
- It is fast. It takes just 18 questions and a few minutes of your time.
- It gives you a blueprint to follow. You won’t just get a generic grade telling you that you need improvement. Every issue you uncover comes with specific, prioritized next steps to start fixing it.
Assess Your AI Risks Early Before They Lead to Public Incidents
Without the guardrails that our scorecard is designed to help you put in place, risks will take root and grow within your everyday operations.
When no single person owns AI decisions, that lack of accountability means nobody catches a problem until it becomes a public incident.
Staff members adopt unvetted personal accounts, completely unaware of how those platforms store or share organizational data. Sensitive donor or client details end up pasted into generative tools based on individual judgment calls rather than a firm rule.
Through it all, leadership and the board remain entirely blind to what is happening day to day.
The TL;DR here is simple: a lack of governance over AI use at your nonprofit means vulnerabilities, and those vulnerabilities can turn into real-world headaches fast. Let’s avoid that!
6 Pillars of Nonprofit AI Safety and Readiness
To turn your AI approach from reactive to proactive, we’ve built our Nonprofit AI Readiness & Safety Scorecard around six core pillars.
Here’s what each one measures and why it matters:
1. Governance Structure & Accountability
This pillar assesses the people power behind AI governance at your organization. Do you have named sponsors and policy leads? Who oversees staff AI use? Who are issues escalated to? Having designed governance roles for your team (including your board) ensures that someone actually reviews tools and handles questions.
2. Approved Tools & Vendor Vetting
This measures whether AI software enters your organization through a controlled vetting process. What are the approved tools at your organization? Is everyone using organizational accounts, not personal ones, to access AI tools? Is there a security review before new tools are adopted? Vetting matters because unapproved tools may put your organization’s data at risk.
3. Data Privacy Rules for Sensitive Information
This pillar checks whether protecting donor, staff, and client data is a strict rule rather than a personal judgment call. Do staff know what counts as personally identifiable information (PII)? Does your team know what information to keep out of public tools? Is there a staff member responsible for determining whether a tool is safe for private data? Inputting personally identifiable information into the wrong tool can trigger serious consequences. By putting proper rules in place, you’ll be protecting your org against them
4. Human Review & Risk Tiering
Here, we measure whether a human reviews every AI output before it goes public and whether high-stakes tasks get the attention that they require. Is AI-generated content required to be reviewed? Are you fact-checking AI-stated dates and figures? Are AI use cases sorted by risk level with clear processes in place for high-risk AI use? As we all should know by now, AI tools can make mistakes or hallucinate facts; this pillar makes sure human oversight remains a central element in your work to keep trust and your reputation intact.
5. Transparency, Ethics & Service Delivery
This evaluates whether your AI use stays honest with donors, funders, and the community you serve. Trust is your primary currency, and if stakeholders feel misled about how technology shapes your programs, that trust evaporates. Are you labeling AI materials? Are there safeguards to keep AI from making fake representations or biased decisions? Are you checking AI guidelines when producing grant applications or funder reports?
6. Incident Reporting & Board Oversight
Finally, this pillar measures whether leadership and the board have clear visibility into AI risks and a plan if something goes wrong. Who gets notified if sensitive data is accidentally exposed? What is the process to assess incidents and take appropriate action? How are you reporting on AI tools in use to your board and leadership?
How Your Scorecard Is Built
Once you complete the 18 questions, the assessment generates a customized scorecard for each pillar and lets you know exactly where you stand in each of them:
- High Risk: This pillar is largely unaddressed and should be treated as urgent—it’s the kind of oversight gap that leads to real incidents.
- Moderate Risk: Some practices exist, but they are inconsistent or undocumented. This is worth fixing soon, but it’s not urgent today.
- Strong: This pillar is in solid shape. Maintain it and revisit it periodically as tools and staff change.
And your results aren’t just a number and risk level. Your scorecard will also provide some immediate actions that you can take to remediate your largest areas of risk. High-risk pillars get three immediate steps to take. Moderate-risk pillars get one next step. Strong pillars are noted as solid for now.
For example, imagine an organization that scores well across data privacy, human review, transparency, and incident reporting, but comes up short on governance structure and vendor vetting. Their scorecard wouldn’t pile on tasks everywhere—it would zero in on those two weak pillars with specific, prioritized fixes, while confirming the rest of their AI usage is up to par.
From Score to Action
A score is only useful if it turns into a real fix. You get your immediate action items, and every vulnerability the scorecard identifies also maps directly to a section of our Nonprofit AI Governance Policy Template. If you score low on this assessment, or just want a more formalized way to document AI governance for your organization, that template and this guide are great next steps.
An AI readiness assessment is a structured set of questions that measures how prepared an organization is to use AI safely and responsibly, covering areas like governance, data privacy, and human oversight.
You’re ready when you have named accountability for AI decisions, a controlled process for approving new tools, clear data privacy rules, and a way for leadership to stay informed. The scorecard checks all four.
Your risk score on this AI scorecard reflects how exposed your organization is across six governance pillars: governance structure and accountability; approved tools and vendor vetting; data privacy rules; human review and risk tiering; transparency, ethics, and service delivery; and incident reporting and board oversight. A high-risk score in a pillar means that this area needs immediate attention; a strong score means you’re already covered there.
Yes! The assessment takes a few minutes to complete, and there’s no cost to take it or to receive your scorecard.
The assessment tells you where your vulnerabilities are. The policy is the document that fixes them. Most organizations take the assessment first, then use the results to build or refine their policy.
