FC Fundraising Commons Team avatar Fundraising Commons Team 4 min read

AI governance for donor data: a starter policy any shop can adopt

ai governance privacy
AI governance for donor data: a starter policy any shop can adopt

Governing AI on donor data doesn’t require a legal department, a consultant, or a 40-page framework. It requires a one-page policy that answers a handful of concrete questions before you point any AI (a chatbot, an agent, a vendor feature) at donor records. This post is that starter policy: copy it, fill in your answers, and you have governance that’s real because it’s written and enforceable, not aspirational.

How do nonprofits govern AI on donor data?

By deciding, in advance and in writing, what AI is allowed to do with which data, who signs off, and what it must never do. Governance isn’t a technology; it’s a set of answered questions. The trap is treating it as a big project, so you never start. A single page, adopted today, covers the cases that actually matter.

Governance is policy, written down: before the agent, not after the incident. One enforceable page beats a perfect framework that never ships.

The one-page starter policy

Six sections. Answer each in a sentence or two for your shop:

1. Scope: what data may AI touch?

Name the data AI tools are permitted to use, and what’s off-limits. Example: “AI may use giving history and engagement; it may not use protected notes, health information, or anything flagged confidential.”

2. Approval: who signs off before AI acts?

Define the human-in-the-loop. Example: “Donor-facing output (emails, asks) requires staff approval before sending. Internal analysis does not.”

3. Guardrails: what must it never do?

The never-do list, in plain language. Example: “Never contact anyone who opted out. Never state an ask amount above $X without review. Never fabricate a fact about a donor.”

Tie use back to permission. Example: “AI only acts on records with a lawful basis for contact; retention rules apply to AI outputs as to any record.”

5. Audit: can you see what it did?

Require a trail. Example: “Every AI-generated action affecting a donor record is logged with input, output, and approver.”

6. Review: who owns this, and when is it revisited?

Name an owner and a cadence. Example: “Owned by the data lead; reviewed every six months or when a new AI tool is adopted.”

Copy this, then fill it in

Those six headings are the policy. A shop of any size can answer them in an afternoon, circulate one page, and have governance that holds up, far better than waiting for a framework you’ll never finish. Start with something enforceable and expand it later.

Why a page beats a framework

A 40-page policy nobody reads governs nothing. A one-page policy everyone has seen, that names what’s forbidden and who approves, actually changes behavior. Start with the page; let it grow only where you hit a real gap. Governance earns trust by being used, the same way the rest of your data operation does.

Governance sits on top of the other three

A policy can only govern data the system can actually distinguish. “Don’t contact opt-outs” requires opt-out to be a real, reliable field; “don’t act on a mis-credited gift” requires credit to be resolved. That’s why governed is the top of the AI-readiness checklist, because it rests on clean, defined, connected data beneath it. Without those, a policy is a wish; with them, it’s enforceable.

1 page
the whole starter policy
6
questions it answers
1
named owner and review cadence

And it’s the difference between AI that amplifies good work and AI that industrializes a bad record. The glossary terms behind these choices (guardrails, human-in-the-loop, autonomy) are unpacked in the agentic-AI glossary for leaders.

What you get

Governance you can actually point to when a board member, a donor, or a regulator asks “how do you control what AI does with our data?”: adopted in an afternoon, enforceable because it’s specific, and a foundation you can build on as your AI use grows. Start the page today; it’s the cheapest risk reduction available.


For the leadership view on adopting AI safely, see Future-Proofing & AI and How It Works.

This is a general starting template, not legal advice. Examples use synthetic data; the standard is open and early; treat current releases as drafts.