A nonprofit AI policy for real decisions.
Download Gratona's provider-neutral Word template. Set a clear boundary for AI use, data, human review, fundraising, vendors, connected actions, incidents, and accountable adoption.
No email gate · Editable .docx file · Provider-neutral · Published August 25, 2026
Explore Gratona by fundraising goal
19
policy sections
4
risk tiers
1
use-case record
0
email forms
A policy needs more than a tool list
A usable policy names the purpose, people, data, systems, actions, reviewers, prohibited use, incident path, and owner. It tells staff when AI may assist and when a person must stop the work.
AI may assist with work. A person owns the consequence.
The template keeps decisions, permissions, promises, relationships, payments, safeguarding duties, and external actions with accountable people. It also gives reviewers a practical standard for rejecting unsafe work.
The rules around the output matter
Risk tiers and approval
Classify low, moderate, high, and prohibited use. Match each tier to a real review and decision path.
Data protection and privacy
Set rules for approved systems, sensitive data, access, model training, retention, deletion, and testing.
Human review and external actions
Name what a reviewer must check before AI-assisted work reaches a person, record, payment, or system.
Fundraising and constituent trust
Protect donor intent, communication preferences, beneficiary dignity, authentic voice, consent, and appeal.
Vendors and connected systems
Review providers, subprocessors, contracts, security, logs, data use, model changes, exit, and action scope.
Incidents, records, and monitoring
Create a stop path, evidence record, use-case inventory, monitoring thresholds, owners, and review cadence.
Match the approval to the actual consequence
Sensitive data, connected actions, vulnerable populations, material decisions, or uncertainty move a use case to the higher tier.
Low
Public or approved internal information, no sensitive data, and no direct effect on a person.
A trained staff member may approve use in an approved tool.
Moderate
Internal or constituent information used for drafting, translation, analysis, or recommendations.
The use-case owner, data owner, and qualified reviewer document the controls.
High
A material decision, sensitive population, connected action, or consequential inference.
Use stays blocked until formal review, testing, logging, monitoring, and written approval are complete.
Prohibited
Deception, coercion, unauthorized sensitive data, discrimination, impersonation, or bypass of permissions.
Do not use.
Make the policy fit the organization you run
Inventory actual use
Include free tools, embedded AI features, meeting assistants, translation, analytics, APIs, and connected agents.
Adapt the boundary
Align the template with your programs, data classifications, contracts, insurance, safeguarding duties, and applicable law.
Name accountable owners
Assign a policy owner, executive sponsor, system and data owners, use-case owners, and qualified reviewers.
Test difficult cases
Use synthetic or appropriately de-identified data to test denial, conflict, unsafe action, bias, outage, incident, and deletion.
Train, adopt, and revisit
Pair the policy with approved-tool guidance, a use-case register, incident reporting, training, and a dated review cycle.
Trace the rules to current nonprofit and risk guidance
The template draws on official risk-management guidance and nonprofit policy resources. Use the sources to review the rationale, then adapt the policy to your organization.
NIST AI Risk Management Framework for governance, mapping, measurement, and management of AI risk.
NIST Generative AI Profile for generative-AI risk, provenance, testing, incident disclosure, and monitoring.
NTEN and ANB Advisory AI Policy Template for nonprofit policy structure, cross-functional ownership, and organizational tailoring.
Fundraising.AI Responsible AI Framework for fundraising privacy, consent, dignity, accountability, human review, and public trust.
GlobalGiving responsible AI use policy guidance for nonprofit privacy, bias, human oversight, vendor review, training, and consent.
Candid responsible AI policy guidance for nonprofit trust, privacy, factual error, bias, and staff overconfidence.
TechSoup generative AI use policy guidance for scope, permitted and prohibited use, data rules, human review, and policy alignment.
Policy sets the boundary
The Word template gives your organization a common rulebook for AI use, data, decisions, actions, incidents, and owners.
Download the policy templateReview proves the workflow
Use the separate Excel workbook to review 51 controls, run 18 hard-path tests, collect evidence, resolve blockers, and record a use-case decision.
Get the review checklistNonprofit AI policy template FAQ
Is the nonprofit AI policy template free?
Yes. The editable Word document is a direct, ungated download. You can adapt it for your organization and use it with Gratona or any other provider.
What does the template include?
It includes 19 policy sections, four risk tiers, permitted and prohibited use, data and privacy rules, human review, fundraising and constituent safeguards, vendor review, incident response, roles, training, adoption checks, sources, and an AI use-case record.
Is this legal or compliance advice?
No. It is an educational starting point. Your organization remains responsible for its final policy, applicable law, contracts, insurance, privacy, security, employment, fundraising, and safeguarding duties.
Who should own a nonprofit AI policy?
Name one accountable policy owner and an executive sponsor. Build the policy with people who understand programs, fundraising, operations, data or technology, privacy or legal needs, and the communities affected by the rules.
How often should the policy be reviewed?
Review it at least annually and sooner after a material incident or change to law, risk, program, data, vendor, model, feature, integration, audience, or external-action scope.
Does this replace an AI use-case review?
No. The policy sets the organization-wide boundary. Each moderate- or high-risk workflow still needs its own documented review, testing, evidence, owner, approval, monitoring, and stop conditions.
Give your team a policy they can follow
Download the editable Word document, replace the bracketed fields, align it with your existing rules, and put accountable owners behind the final policy.
Educational resource, not legal or compliance advice.