AI for Nonprofits

Writing an AI Policy for a Small Nonprofit Board

By HeartBridge Team · · 8 min read

Small nonprofit board members reviewing documents at a meeting table
Photo by Christina Morillo on Pexels

Key takeaways

  • An ai policy nonprofit board approves should be short, clear, and tied to real workflows.
  • Start with approved uses, prohibited uses, review steps, and a named policy owner.
  • Protect donor, financial, personnel, and board information from being entered into public tools.
  • Require human review for anything external, especially donor-facing content.
  • Review the policy at least once a year or whenever your AI use changes.

What should an AI policy nonprofit board actually cover?

A small nonprofit board does not need a long technology manual. It needs a clear, usable policy that tells staff and volunteers when AI can be used, what needs review, and who is accountable when something goes wrong.

The goal is not to ban tools. The goal is to protect your mission, your donor relationships, and your board’s oversight role while giving people enough room to work efficiently.

If your team is already using AI for draft emails, campaign ideas, grant drafting, or thank-you notes, you are already making policy decisions, even if they are informal. A written policy turns those habits into something the board can approve, revisit, and enforce.

Start with the board’s job

Board members are responsible for oversight, not day-to-day prompting. A good policy should make that distinction clear, so staff know where they can experiment and where they need approval.

For a small nonprofit, the board can focus on five questions: What tasks may AI help with? What data should never be entered? Who reviews outputs? How are mistakes corrected? When should the board be told about new uses?

What risks should the policy address?

The biggest risk is not that AI exists. The bigger risk is using it without guardrails. For a nonprofit, that can mean inaccurate donor communications, accidental disclosure of sensitive information, or content that sounds polished but does not reflect the organization’s values.

It also helps to remember that nonprofit governance already expects careful recordkeeping and honest communications. The IRS explains the importance of sound records and internal controls for organizations that want to stay compliant and accountable, which is a useful lens for AI policy planning. irs.gov/charities-non-profits

A practical policy should name the risks in plain language. That makes it easier for volunteers and board members to follow the rules without needing a legal background.

Policy areaWhat to decideSimple board-friendly rule
Approved usesWhich tasks AI can help withAI may draft, brainstorm, or summarize, but a person approves the final version
Restricted dataWhat cannot be pasted into toolsNo donor, payment, or confidential personnel information
Review processWho checks outputsStaff owner reviews all externally shared content
EscalationWhen to ask for helpAny legal, HR, donor privacy, or financial use gets extra review
TrainingHow people learn the rulesNew users read the policy before they use AI

How do you draft the policy without making it too complicated?

Keep it short enough that people will actually read it. One to two pages is often enough for a small organization, as long as it covers the essentials.

Use language that names real tasks your team does now. For example, you might allow AI to help draft campaign subject lines, summarize meeting notes, or suggest thank-you note language, while requiring human review before anything is sent.

You can also tie the policy to existing systems the board already understands. If your organization already uses a donor CRM, hosted pages, forms, or smart emails, the policy can say that AI may support content creation, but it does not replace staff judgment or approved workflows. If you are still building out your fundraising stack, it may help to review your tools alongside your policy, including HeartBridge features and HeartBridge pricing.

Use a simple structure

  1. Purpose: explain why the policy exists.
  2. Scope: say who must follow it, including staff, contractors, and volunteers.
  3. Approved uses: list tasks AI can assist with.
  4. Prohibited uses: list sensitive data and high-risk decisions.
  5. Review and approval: define who signs off on external content.
  6. Training and updates: say how often the policy will be reviewed.

That structure is enough for most small nonprofits. It keeps the policy readable while still giving the board something concrete to adopt.

What should be prohibited or tightly controlled?

Some AI uses should be off-limits unless the board approves a more specific process. The safest approach is to prohibit anything involving sensitive personal data, legal judgment, employment decisions, or financial authorization.

  • Do not enter donor payment details, bank information, or other financial credentials into AI tools.
  • Do not use AI to make final decisions about hiring, discipline, termination, or volunteer removal.
  • Do not use AI to write legal, tax, or compliance advice as if it were expert guidance.
  • Do not let AI send donor-facing messages without human review.
  • Do not allow staff to paste confidential board or personnel information into public tools.

These guardrails are especially important if your team is using AI to speed up fundraising work. For example, if you are testing AI for grant drafts, a dedicated review process is wise. HeartBridge already includes AI features such as campaign builder, donor engagement suggestions, grant writer, thank-you notes, and impact reports, so a policy can define who may use them and for what purpose.

How do you keep the policy practical for a small team?

Make the policy match your capacity. A volunteer treasurer and a part-time executive director do not need a complex approval matrix. They need a few clear rules and a short review cycle.

One useful approach is to assign a single staff owner, even if that person is not the one using AI every day. That owner can keep track of approved tools, review concerns, and bring issues to the board when needed.

If your nonprofit is also evaluating fundraising platforms, it can help to compare how AI fits into the broader workflow. For example, if you are considering a switch from another platform, you may want to review HeartBridge switch support or compare options like HeartBridge as a Flipcause alternative.

Do this this week

  • List the AI tools your team already uses, even informally.
  • Decide which tasks AI may help with and which tasks require human-only judgment.
  • Write a one-page draft policy with approved uses, prohibited uses, and review steps.
  • Ask one board member and one staff member to test the draft for clarity.
  • Put a date on the calendar for a board review and annual update.

What should the board minutes say?

When the board adopts the policy, the minutes should show that directors reviewed it, asked questions, and approved it. That does not need to be elaborate. It just needs to document that the board took the policy seriously.

A simple minutes note could say the board reviewed the AI policy, discussed acceptable uses and data protection, and approved the policy effective immediately. If the board wants a later revision, note that too.

For small nonprofits, documentation matters because it helps future leaders understand why decisions were made. It also makes it easier to train new board members and volunteers.

How often should you revisit the policy?

Review the policy at least once a year, and sooner if your team starts using AI in a new way. That could include donor communications, event workflows, or grant support.

If your organization is changing systems, the policy should be reviewed alongside the change. That is especially important when the board is comparing software options or moving fundraising operations into a new platform. A related guide like what happened to Flipcause can help board members think about vendor risk, data access, and continuity when they evaluate tools.

As you update the policy, ask three questions: What changed? What new risk appeared? What training do people need now?

Could a board adopt a simple template?

Yes. In fact, a template is often the best starting point. Use it to make decisions faster, then adapt it to your actual workflows.

Policy starter language: “The organization may use AI tools to assist with drafting, summarizing, brainstorming, and internal productivity tasks. AI may not be used to make final decisions about people, finances, legal matters, or donor communications without human review and approval.”

That kind of language is short, understandable, and easy to enforce. It also gives staff enough flexibility to use AI responsibly without guessing what the board expects.

Key takeaways

  • An ai policy nonprofit board approves should be short, clear, and tied to real workflows.
  • Start with approved uses, prohibited uses, review steps, and a named policy owner.
  • Protect donor, financial, personnel, and board information from being entered into public tools.
  • Require human review for anything external, especially donor-facing content.
  • Review the policy at least once a year or whenever your AI use changes.

FAQ

Do small nonprofits really need an AI policy?Yes. Even a simple policy helps the board set expectations, protect sensitive information, and avoid confusion about who approves AI use.

Should the policy ban AI completely?Usually no. A better approach is to allow low-risk uses and restrict high-risk ones, with human review before anything is shared externally.

Who should write the first draft?A staff member, executive director, or board officer can draft it, then the board can review and approve it. The draft should reflect how the organization actually works.

What is the biggest mistake to avoid?Treating AI as a shortcut for judgment. AI can help draft or organize, but people still need to review accuracy, tone, and compliance.

Should volunteers follow the same policy as staff?Yes, if they use organizational tools or handle organizational information. The policy should apply to anyone acting on behalf of the nonprofit.

Where does this fit with our fundraising tools?The policy should cover how AI is used inside your fundraising workflow, including donor communications, campaign content, and any platform features that generate text or suggestions. If you are registering a new account or preparing to start, register here.

For more on nonprofit governance and recordkeeping, see the IRS nonprofit resources at irs.gov/charities-non-profits. For board education and practical governance ideas, the Council of Nonprofits is also a helpful reference at councilofnonprofits.org.

Frequently asked questions

Yes. Even a simple policy helps the board set expectations, protect sensitive information, and avoid confusion about who approves AI use.

Usually no. A better approach is to allow low-risk uses and restrict high-risk ones, with human review before anything is shared externally.

A staff member, executive director, or board officer can draft it, then the board can review and approve it. The draft should reflect how the organization actually works.

Treating AI as a shortcut for judgment. AI can help draft or organize, but people still need to review accuracy, tone, and compliance.

Yes, if they use organizational tools or handle organizational information. The policy should apply to anyone acting on behalf of the nonprofit.

The policy should cover how AI is used inside your fundraising workflow, including donor communications, campaign content, and any platform features that generate text or suggestions. If you are registering a new account or preparing to start, register here.

Sources

IRS Charities and Nonprofits · Council of Nonprofits · Candid

Start free on HeartBridge

No credit card required. Run your fundraising on your own Stripe account, with AI built in.

Start free on HeartBridge

Share this post

LinkedIn Facebook X

Related posts