Review AI before it reaches a donor.
Use Gratona's free, provider-neutral Excel workbook to set the boundary, review 51 controls, run 18 hard-path tests, collect evidence, resolve exceptions, and record an accountable AI fundraising decision.
No email gate · Editable .xlsx file · Provider-neutral · Reviewed 2026-08-18
Explore Gratona by fundraising goal
51
editable controls
10
control domains
18
workflow tests
0
email forms
Can your organization govern the whole workflow?
A good sample output does not prove that donor data stays protected, permissions hold, facts remain traceable, preferences are honored, approvals work, or incidents can be contained. The workbook reviews the operating system around the output—not just the output itself.
A promise and a verified control are not the same status
Each control separates the requirement, evidence, owner, exception, risk, and decision flag. A requested document remains unverified. A failed Must becomes a blocker. The decision summary updates from the evidence your team has actually accepted.
One review record from boundary to decision
Start Here
Define the use case, affected people, owners, prohibited actions, risk tolerance, decision, and next review date before reviewing features.
Controls
Review 51 editable controls across purpose, donor data, permissions, factuality, approval, dignity, security, vendors, and monitoring.
Workflow Tests
Run 18 repeatable scenarios with synthetic data, including permission denial, conflicting facts, unsafe action, bias, outage, and deletion.
Decision Summary
See blockers, unverified Musts, failed tests, weighted unresolved risk, evidence coverage, conditions, owners, and the current review state.
Sources
Trace the controls to current nonprofit, fundraising, AI risk, security, privacy, and ethical frameworks instead of relying on vendor rank.
Review what protects the relationship
The control library begins broad so a polished feature does not hide a weak data flow, missing approval, contract gap, or unsafe exit. Change the priorities and evidence requirements to match your use case.
Purpose and decision boundary
Donor data and privacy
Access and permissions
Source provenance and factuality
Human review and approval
Donor communications and consent
Fairness, equity, and dignity
Security and model risk
Vendor and contract diligence
Monitoring, incident response, and retirement
Prove the hard paths, not only the happy path
Every scenario includes synthetic input, the action to test, expected evidence, a risk owner, status, observed result, and follow-up. Use the same tests across products and material system changes.
Permission-bound context
Ask a lower-privilege user for two donor summaries and prove that denied records are neither revealed nor inferred.
Conflicting source records
Give the system two different gift amounts and require it to show the conflict instead of choosing a convenient answer.
Preference and consent
Request an appeal for a donor with a no-solicitation preference and verify that the workflow blocks or reroutes the action.
Prompt injection and agency
Place a hostile instruction inside a test document and verify that it cannot bypass policy, export data, or trigger an external action.
Dignity and sensitive inference
Test beneficiary-story handling, prohibited trait inference, and whether staff can question or correct a material output.
Outage, incident, and exit
Prove safe failure, access suspension, evidence preservation, export, deletion, and continuity when the service changes or stops.
Make the decision inspectable
- 1
Set the operating boundary
Name the purpose, intended users, affected groups, owners, data sources, prohibited actions, success measures, and stop conditions.
- 2
Review every Must with evidence
Use an observed workflow, current configuration, contract, test result, or audit artifact. Keep a request or promise marked unverified.
- 3
Run the hard paths with synthetic data
Test denial, conflict, stale context, unsafe action, bias, outage, incident, and deletion—not only the polished happy path.
- 4
Resolve exceptions before averages
Investigate blockers, unverified Musts, failed tests, privacy gaps, and owner objections before treating an aggregate score as approval.
- 5
Record conditions and re-review triggers
Name the decision owner, accepted exceptions, mitigations, monitoring thresholds, and changes that force a new review.
Keep real donor data out of the review
Use synthetic or appropriately de-identified records. Do not place donor, beneficiary, payment, health, safeguarding, authentication, or other sensitive production data in the workbook or evaluation environment.
Recheck the current system and terms
Models, prompts, subprocessors, settings, capabilities, security evidence, data use, and contracts change. Re-run the review after a material change and put critical commitments into the written agreement.
This checklist supports structured diligence. It is not legal, privacy, security, tax, accessibility, fundraising, or other professional advice, and it does not certify a provider.
Built from current primary sources
The workbook translates public nonprofit, fundraising, risk, privacy, and security frameworks into operational review prompts. The full source list and review notes are included inside the file.
- NIST AI Risk Management Framework
Used for lifecycle governance, trustworthiness, measurement, and risk treatment.
- NIST Generative AI Profile
Used for generative-AI risks and actions across governance, mapping, measurement, and management.
- NTEN Artificial Intelligence Resource Hub
Used for nonprofit AI governance, data practices, privacy, tool evaluation, and human-centered use.
- NTEN AI Framework for an Equitable World
Used for assessment, impact, intervention, equity, transparency, and policy development.
- Fundraising.AI Responsible AI Framework
Used for fundraising-specific responsibility, public trust, and shared accountability.
- AFP Code of Ethical Standards
Used for donor interests, truthful communication, privacy, preferences, intent, and stewardship.
- OWASP Top 10 for LLM Applications
Used for prompt injection, sensitive information disclosure, excessive agency, and connected-system risk.
- CISA and NCSC Secure AI Guidelines
Used for secure-by-design ownership, transparency, deployment, and operations.
- FTC Privacy and Security Guidance
Used for data minimization, appropriate security, accurate privacy promises, and service-provider oversight.
Source framework pages reviewed 2026-08-18.
Use the workbook without hiding uncertainty
Is the nonprofit AI fundraising review checklist free?+
Yes. The Excel workbook is a direct, ungated download. You can edit it for your organization and use it with Gratona or any other AI, fundraising, or CRM provider.
What does the workbook include?+
It includes 51 editable controls, 18 repeatable workflow tests, evidence and exception fields, data validation, formula-driven blockers and review status, an owner decision record, and source framework references.
Is this a vendor score or certification?+
No. It is a review structure, not a certification, legal opinion, security assessment, or universal pass score. Your organization remains responsible for scope, evidence, risk, applicable requirements, and the final decision.
Should we put real donor data in the workbook or tests?+
No. Use synthetic or appropriately de-identified records. Keep donor, beneficiary, payment, health, safeguarding, authentication, and other sensitive production data out of the workbook and evaluation environment.
What counts as evidence?+
Evidence can include an observed workflow, current configuration, documented architecture, contract language, test result, audit artifact, export, or incident procedure. A sales statement, roadmap slide, or requested document remains unverified until your team accepts the proof.
How often should an AI fundraising workflow be reviewed?+
Set a recurring cadence and trigger a new review when the model, prompt, data source, workflow, affected audience, permissions, policy, provider, subprocessor, contract, or external-action scope changes materially.
Bring the same review standard to every AI provider
Use the workbook with every system on your shortlist. If Gratona is included, bring the same controls, scenarios, and evidence rules to us. We will show the current workflow and make the implementation boundary explicit.
Want the category overview first? Read the AI fundraising CRM guide.