Organizational AI Governance Policy Template
Fill in the highlighted fields below to turn this template into your organization’s own AI governance policy draft. Everything you type is saved in this browser as you go.
1. Purpose and Scope
Purpose: The purpose of this policy is to establish clear, simple guardrails for using Artificial Intelligence (AI) at {{organization}}. We want to use modern tools to save time and work more efficiently without compromising constituent trust, confidentiality, privacy, or our organization’s reputation.
Scope: This policy applies to all employees, contractors, interns, and volunteers. It covers any AI tool used for organizational work, including free web-based tools and built-in AI features within our existing software.
2. Plain-English Definitions
To make sure everyone is on the same page, we define key concepts as follows:
- Generative AI: Tools that create new content, such as drafting text, generating social captions, creating images, or summarizing long documents.
- Predictive AI: Tools that analyze patterns in existing data to predict numbers, trends, or behaviors, such as donor propensity scores, churn risk, or program participation patterns.
- Personally Identifiable Information (PII): Private details that identify a specific individual. This includes donor names, home addresses, phone numbers, and private giving histories, as well as client, beneficiary, or program participant details (such as health status, legal histories, immigration details, or housing records).
3. Governance Roles & Responsibilities
Because we do not have a full-time IT or compliance department, AI oversight is shared across key organizational roles to ensure safety and accountability.
Executive Sponsor: {{sponsor_name}}
- Holds overall accountability for AI policy enforcement, ethical alignment, and board transparency.
- Reviews and approves high-risk (Tier 3) AI use cases alongside a completed written risk assessment.
- Receives annual AI usage reports and serves as the final escalation point for security incidents or policy breaches.
Policy Lead: {{lead_name}}
- Owns the day-to-day administration, vendor contract reviews, and annual updates of this policy.
- Maintains the Approved Tools Register and evaluates all software requests.
- Delivers mandatory AI policy training to all new hires within 30 days of start, and coordinates an annual refresher for all active staff, contractors, and volunteers.
Department Liaisons: {{liaison_names}}
- Monitor how their immediate teams use AI tools in day-to-day operations and service delivery.
- Ensure staff members follow human-in-the-loop review rules before publishing materials or acting on AI insights.
- Bring new AI use-case ideas, software requests, or grant compliance requirements to the Policy Lead.
All Staff, Contractors, and Volunteers:
- Read, sign, and adhere to this policy upon hire and during annual training cycles.
- Ensure no non-public donor, client, or financial data is entered into unapproved tools.
- Report potential data exposures, unvetted tool usage, or harmful AI outputs within 24 hours.
4. Approved Tools Register
Staff members may only use AI tools that have been formally reviewed and added to the official register below. Using unapproved consumer AI tools for organizational work is strictly prohibited.
| Software Name | Approved Use Case | Approved Data Domain | Tool Owner |
|---|---|---|---|
| {{tool_1_name}} | {{tool_1_use}} | {{tool_1_data}} | {{tool_1_owner}} |
| {{tool_2_name}} | {{tool_2_use}} | {{tool_2_data}} | {{tool_2_owner}} |
| {{tool_3_name}} | {{tool_3_use}} | {{tool_3_data}} | {{tool_3_owner}} |
Adding New Tools
To request approval for a new AI tool or feature, submit an AI Tool Request to {{policy_lead}} for security and privacy evaluation before signing up or testing with organizational data.
Organizational data inside approved AI tools belongs to {{organization}}. Staff are required to use organizational accounts rather than personal logins to access work-related AI tools.
5. Core Policy Rules
5.1 Centralized Vendor Vetting for Private Data
Staff members are strictly prohibited from typing or uploading non-public donor details, constituent PII, client case notes, or internal financial records into commonly-available Generative AI tools.
Only the Policy Lead may designate an AI tool as approved for handling private data, based on a documented review of the vendor’s data processing agreement (DPA) to confirm that data is not saved, shared, or used for model training. Staff should not independently attempt to evaluate vendor contract language.
5.2 All Outputs Are Drafts. Human Review Is Mandatory
Generative AI can be considered a helpful drafting assistant, but not an autonomous worker. No AI-generated content may be published, sent to constituents, or acted upon without direct human review.
- The “Edit Before Send” Rule: Staff members must review, edit, and manually approve any AI-assisted text.
- Fact-Checking Requirement: AI models can state incorrect facts convincingly. Staff must independently verify dates, financial figures, donor statistics, program outcome data, and research claims against primary sources before publishing.
5.3 No Fully Automated Critical Decisions
We do not allow AI to make autonomous decisions that impact people, client services, or finances. AI tools may provide predictive scores or suggest actions, but a human staff member must evaluate the underlying factors and make the final call. Predictive scores are directional guides, not absolute truths, and must be reviewed to ensure they do not systematically exclude or bias specific demographics.
5.4 Transparency and Honest Communication
We protect community trust through transparency.
- Internal Labeling: Keep clear notes or labels on working drafts so team members know when AI was used to assist a document.
- External Disclosures: If an AI tool materially creates constituent-facing media (such as generating a stock illustration), include a simple disclosure statement.
5.5 Intellectual Property and Copyright Respect
Respect third-party intellectual property. Do not upload copyrighted books, paid market research, or proprietary software code into any AI tool. Because pure AI outputs are not protected by copyright law, all AI-generated content must undergo significant human revision to ensure originality, accuracy, and brand alignment.
5.6 Ethical Use of Visual and Audio AI
Staff must not use generative AI to create deceptive media, deepfakes, or synthetic representations of any real person. If AI images are used to illustrate generic concepts, they must never exploit, misrepresent, or dehumanize the communities we serve.
5.7 AI in Service Delivery, Case Management, and Grant Compliance
- Program Triage & Intake: AI tools may not be used as the sole deciding factor in client intake triage, eligibility screening, or program service allocation. Any AI assistance in service delivery must serve strictly as an administrative aid subject to case manager review.
- Grant Applications & Funder Reporting: Before using generative AI to draft grant proposals, progress reports, or evaluation data, staff must check funder guidelines. If a funder requires disclosure of AI assistance in application materials or reported metrics, staff must provide explicit, honest documentation.
6. AI Risk Tiers With Human Input Requirements
Before using an AI tool or feature for a task, categorize it using this simple risk framework:
| Risk Tier | What the AI Does | Staff Approval Requirement |
|---|---|---|
| Tier 1: Low Risk (Assisted) | AI Suggests: Writing first drafts of social posts, outlining event agendas, summarizing public documents. | Standard peer or supervisor review before publishing. |
| Tier 2: Medium Risk (Augmented) | AI Analyzes: Reviewing donor engagement scores, analyzing program feedback trends, or predicting donor churn. | Staff must compare scores and predictions against known data and recent activity before acting, and investigate any result that contradicts them. |
| Tier 3: High Risk (Autonomous) | AI Acts: Auto-sending donor emails, altering financial records, or automating client service eligibility decisions. | Prohibited without a written risk assessment, logged in the Approved Tools Register, and signed off by the Executive Sponsor before launch. |
7. Acceptable vs. Prohibited Uses
Acceptable Uses:
- Drafting initial outlines for appeal letters, grant sections, social posts, or blog ideas.
- Brainstorming event themes or writing alternative email subject lines.
- Summarizing lengthy internal meeting notes, public sector reports, or research papers.
- Formatting raw, non-sensitive notes into bullet points or tables.
Prohibited Uses:
- Copying and pasting donor names, client case details, sensitive beneficiary history, or contact information into public AI chats.
- Relying on individual judgment to read vendor legal terms instead of routing software requests through the Policy Lead.
- Using AI to generate false claims, fake impact statistics, or fabricated research.
- Generating content intended to impersonate a specific real person.
- Allowing AI tools to automatically send unedited communications to donors, clients, or grantmakers.
8. Incident Reporting, Oversight, and Policy Violations
Incident Escalation Timelines
If you accidentally paste sensitive constituent or client data into an unauthorized AI tool, or if an AI feature produces inaccurate output that reaches the public:
- Notify the Policy Lead within 24 hours of discovering the exposure.
- The Policy Lead and Executive Sponsor will assess the incident within 5 business days to determine if state breach-notification laws, funder contracts, or board disclosures are triggered.
- Prompt reporting allows us to secure our systems and protect our community. Unreported, intentional violations of this policy may lead to disciplinary action.
Governance Oversight & Board Reporting
To maintain meaningful oversight, the Policy Lead will deliver an annual AI Governance & Usage Summary to the Executive Sponsor and the Board of Directors. This report will detail active tools in the register, any Tier 3 approvals, staff training completion rates, and any logged incidents.
Employee Acknowledgment
I have read, understood, and agree to follow the {{organization}} AI Governance Policy. I understand that I am required to renew this acknowledgment during annual policy training cycles.
Staff Name: ___________________________
Signature: ____________________________
Date: _________________________________
This document template is provided by Neon One for informational and educational purposes only and does not constitute formal legal advice. AI laws, data privacy regulations, and compliance standards vary significantly by jurisdiction and change rapidly. Your organization should consult with a qualified legal professional to review, customize, and finalize any internal policies to ensure full compliance with applicable local, state, and federal laws.
