Article Authors
AI is not something nonprofits should be afraid of.
In fact, for many organizations, it may be one of the more practical tools available to help stretched teams gain capacity. Nonprofits are constantly being asked to do more with less: write more grants, communicate with more stakeholders, analyze more data, report to more funders, and respond to more community needs. AI can help with that.
It can help draft donor communications, summarize board materials, organize grant narratives, analyze trends, create first drafts of policies, translate content, and reduce time spent on routine administrative work. For finance and operations teams, AI may also help with variance explanations, forecasting support, contract summaries, documentation, and internal process improvement. That is the opportunity. But the opportunity needs structure.
The real issue is not whether nonprofits should use AI. Many already are. The better question is whether the organization has any governance around how it is being used. Because unmanaged AI use is where the risk starts.
AI Is Already in the Organization
A lot of organizations are treating AI as a future policy issue. That is probably a mistake.
In many nonprofits, staff are already experimenting with AI tools. Some may be using them for harmless first drafts or brainstorming. Others may be using them with donor information, employee data, grant reports, board materials, financial information, or program-related content.
Leadership may not have a full picture of what is happening, and that uncertainty carries risk.
From an audit and governance perspective, this starts to look like a control environment issue. If a tool is being used to support work that affects financial reporting, grant compliance, donor communications, program decisions, or board materials, then management should understand how that tool is being used, what information is being entered, and who is reviewing the output.
That does not mean AI use should be discouraged. It means the organization needs basic guardrails. Good policy does not slow down innovation. It makes innovation safer and more repeatable.
The Policy Should Be Practical
An AI governance policy does not need to be complicated. In fact, if the first version is too long, too technical, or too restrictive, people may ignore it.
The policy should be clear enough that staff understand what is allowed, what is not allowed, and when they need to ask for approval.
At a minimum, a nonprofit AI policy should answer a few basic questions:
- Who is allowed to use AI tools?
- Which tools are approved?
- What information should never be entered into an AI platform?
- When is human review required?
- Can AI-assisted content be used in grant reporting, financial reporting, board materials, donor communications, or program materials?
- Who owns the final output?
At their core, those are governance questions. The most important principle is simple: AI can assist the work, but it should not own the conclusion. Management still owns the output. The organization still owns the communication. The board still relies on leadership’s judgment. A policy should make that clear.
Where Nonprofits Should Be Careful
Nonprofits have a few risk areas that deserve special attention.
The first is confidential information. Many nonprofits hold donor data, employee records, beneficiary information, grant agreements, board materials, and sensitive financial information. Staff should not be entering that information into public AI tools without clear approval and an understanding of how the data may be used or retained.
The second is grant and compliance reporting. AI can be helpful in organizing information or drafting narrative language. But grant reports still need to be accurate, supported, and consistent with the award terms. AI should not replace management review of compliance requirements.
The third is financial analysis. AI-generated explanations can sound polished even when they are incomplete or wrong. If AI is used to help prepare variance explanations, forecasts, dashboards, or board commentary, someone still needs to verify the data, assumptions, and conclusions.
The fourth is program decision-making. If AI is used to help evaluate applications, prioritize services, assess needs, or allocate resources, the organization needs to think carefully about fairness, bias, transparency, and accountability.
The right response is not avoidance but proportionate review, matched to the level of risk. Using AI to clean up a paragraph is different from using AI to support a compliance conclusion. Using AI to brainstorm fundraising language is different from uploading donor lists or relying on AI to summarize grant requirements.
A good policy helps people understand the difference.
The Audit Undertone: Trust, Review, and Evidence
For CPAs, auditors, and finance leaders, the concepts here should feel familiar.
AI governance is really about authorization, review, documentation, accountability, and evidence. Those are not new ideas.
If AI is being used in low-risk ways, the process can be simple. If it is being used in higher-risk areas, the expectations should be stronger.
For example, if AI helps draft a board financial summary, the organization should still be able to show that the underlying numbers were reviewed and the final commentary was approved by management. If AI helps summarize a grant agreement, someone still needs to compare the summary back to the actual agreement. If AI helps draft a policy, management still needs to determine whether the policy fits the organization.
The real question isn’t whether AI touched the work. It’s whether the organization reviewed and owned the final product.
The Board’s Role
- Board members aren’t expected to become AI experts, or to approve every tool or use case. They are expected to ask smart governance questions: How is AI being used today?
- What information is prohibited from being entered into AI tools?
- Who approves new tools?
- How does management review AI-assisted work?
- Are there higher-risk uses that require special approval?
- Does the policy align with the organization’s privacy, cybersecurity, grant compliance, and ethical obligations?
These questions are not meant to create fear. They are meant to create visibility=, which is what good governance does.
Start With an Inventory
For many nonprofits, the best first step is not drafting the perfect policy. It is understanding current use.
- What tools are staff using?
- For what purposes?
- With what data?
- In what departments?
- Are those tools free, paid, public, private, or vendor-provided?
That inventory gives leadership a practical starting point. From there, the organization can decide what to allow, what to prohibit, what needs approval, and what requires documentation. The policy can evolve as the organization’s AI use matures. The worst approach is to wait until there is a problem.
The Takeaway
AI can be a real advantage for nonprofits. It can save time, expand capacity, and help teams move faster. For organizations dealing with limited resources, that matters.
But AI should not operate outside the organization’s governance structure.
The goal is not to make AI scary. The goal is to make AI usable, controlled, and aligned with the organization’s mission.
Nonprofits should be asking a practical question:
How do we use AI in a way that helps our people work better while still protecting data, judgment, accountability, and trust?
This is a governance question, not just an IT one, and it deserves a policy before it becomes a problem.
How HBK Can Help
HBK can assist nonprofits in developing practical AI governance policies that fit their operations, control environment, and compliance responsibilities. This can include helping leadership identify current AI use, evaluate higher-risk areas, define acceptable-use guidelines, and develop a policy that supports innovation while protecting the organization.
"*" indicates required fields

