Skip to content

Free planning tool

Your board will ask about AI. Answer with a policy.

Answer a short set of questions about your organization, your data, and who approves what. Get a tailored draft AI use policy for your board, plus the ten questions directors ask about AI in fundraising.

A nonprofit AI policy sets which work AI may assist, which data it may use, who approves each tool, and who reviews anything that reaches a donor.

  • Free to build, no email needed
  • Editable Word document by email
  • Plain language, not legal advice

Your answers stay in your browser unless you ask for the document. We record anonymous usage (which step you reached and the oversight posture you chose, never names), and nothing else is sent.

What is in the template

What the nonprofit AI policy template includes.

A policy a board can read in one sitting: eleven short sections, two appendices, and a one-page set of board questions. Every section is written in plain language from your answers, and every section is editable. For the thinking behind each section, readhow to write a nonprofit AI policy your board will adopt.

  1. Section 1

    Purpose and scope

    Who and what the policy covers, and which rule wins when policies overlap.

  2. Section 2

    Principles

    Mission first, human-led, proportionate, transparent, secure, accountable.

  3. Section 3

    Approved uses

    The work AI may assist, the limit on each, and the uses that are never permitted.

  4. Section 4

    Data AI may use

    Permitted and excluded categories, the sensitive-data rule, and the rule on personal chatbot accounts.

  5. Section 5

    Human oversight

    What waits for a person, who reviews drafts to donors and funders, and how output is checked.

  6. Section 6

    Approving tools and uses

    The approval steps, the register entry, and when approval is withdrawn.

  7. Section 7

    Vendor requirements

    What every AI vendor confirms in writing before approval.

  8. Section 8

    Disclosure

    When recipients are told AI was involved, and the rule that a name means a person reviewed it.

  9. Section 9

    Roles and responsibilities

    Board, policy owner, executive, data owners, and everyone else.

  10. Section 10

    Training, incidents, exceptions

    Annual training, what counts as an incident, and how exceptions are granted.

  11. Section 11

    Review and reporting

    The review cadence, the standing board report, and the questions left for the board.

  12. Appendix A

    AI tool register

    The one-table record of every approved tool and what it may do.

  13. Appendix B

    Draft board resolution

    Resolution language the board can adopt with the policy.

  14. One-pager

    Questions your board will ask

    Why directors ask each one, and how to answer from your draft.

The one-pager

Questions your board will ask about AI in fundraising.

The same ten questions come up at almost every board when an AI policy reaches the agenda. Build the draft above and each one gets an answer written from your own choices, ready to take into the room.

Build the draft
  1. 1. What are we using AI for today, and who decided?

    Boards worry about tools arriving through the side door: a free trial here, a feature switched on there.

  2. 2. What donor data can the AI see?

    Donor trust is the asset. Directors want to know the boundary, not the feature list.

  3. 3. Is our data training somebody else’s model?

    This is the question directors have read about, and the one a vendor answer tends to blur.

  4. 4. Can the AI send something to a donor without a person seeing it?

    One wrong acknowledgement to a major donor is the failure directors picture first.

  5. 5. Who is accountable when it gets something wrong?

    Directors are asking about themselves as much as about staff.

  6. 6. Will donors know when AI was involved?

    Disclosure is where values become visible, and where a board can be embarrassed.

  7. 7. What happens to our data if we leave the vendor?

    Lock-in is a governance risk, and the board owns the organization’s continuity.

  8. 8. How is this different from staff using a chatbot on their own?

    Directors know this is already happening. They want to know the organization has noticed.

  9. 9. Does this mean fewer staff?

    Some directors hope so; more of them fear it. Both need a straight answer.

  10. 10. How will we know it is working, and when do we revisit this?

    A policy with no review date is a document, not governance.

How Ignite answers section 7

Hold every vendor to the same list. Here is our page.

Your draft asks vendors to confirm things in writing. These are our answers, drawn from our trust page, so you can compare any platform against the same questions. The controls themselves live in Ignite Intelligence.

Named model providers and data location

Ignite runs AI through Microsoft Foundry on Azure-hosted endpoints, with Anthropic Claude models hosted on Azure. AI processing stays in the U.S. Data Zone.

Our data is not training material

Prompts and outputs are not used to train foundation models by default, and we will walk your reviewer through the data flow.

What AI can do on its own

Agents start with read access. Write capability is granted per agent and per action, never assumed.

Human approval controls

Writes use the gates your team configures, and you can see what will change before approving one.

A record of AI actions and approvals

Every agent action lands in an audit trail: what was proposed, who approved it, and what changed.

An independent audit

StratusLIVE maintains a current SOC 2 Type II report, refreshed at least annually, shared under NDA where one is needed.

A data processing agreement and subprocessors

The data processing agreement and the current subprocessor list are published on this site, with advance notice before the list changes.

LegalSubprocessors

Your security questionnaire

In an active evaluation, your questionnaire goes to the team that owns each control. Bring it to your working session.

Read the full security review

Questions about the nonprofit AI policy template.

Does a nonprofit need a written AI policy?

If anyone on staff uses an AI tool on the organization’s behalf, the organization already has an AI practice; the policy is what makes it deliberate. A written policy tells the board which work AI may assist, keeps donor and client data inside approved systems, names who approves each tool, and gives staff a rule for the consumer chatbots they may already be using. Funders, auditors, and IT reviewers increasingly ask to see one.

What should a nonprofit AI policy include?

Purpose and scope, principles, the approved uses and the uses that are never permitted, the data AI may and may not touch, human oversight rules (what waits for a person, who reviews drafts to donors and funders), how new tools are approved, what vendors must confirm in writing, disclosure, roles and responsibilities, training and incident handling, and a review cadence with a standing board report. The template covers all eleven, plus an AI tool register and a draft board resolution.

Is the Nonprofit AI Policy Template legal advice?

No. It is a structured starting point for a board conversation, written in plain language from your own answers. Review the draft with counsel before adoption, especially where health, education, employment, or financial regulations apply to your organization. The document says this on its first page.

Do I need to enter my email to build the policy?

No. Answer the questions and the tailored outline and the ten board questions appear on this page. You give an email only if you want the editable Word document, sent as a link with a printable version.

What is in the document?

Eleven policy sections (purpose, principles, approved uses, data, human oversight, approving tools, vendor requirements, disclosure, roles, training and incidents, review and reporting), an AI tool register, a draft board resolution, and a one-page set of questions your board will ask about AI in fundraising, each with a suggested answer drawn from your draft.

Does the policy mention StratusLIVE or Ignite?

No. The policy body names no vendor and no product, because a board policy should outlive any tool. This page separately shows how Ignite answers the vendor questions in section 7, drawn from our trust page, so you can compare any vendor against the same list.

How governed AI works in practice

How is the draft tailored to my organization?

Every section is built from your answers by fixed rules: your data choices set section 4, your oversight choice sets section 5, your approver appears wherever a decision is made, and anything you leave undecided becomes an explicit question for the board in section 11. No AI writes the draft, nothing is inferred about your organization, and the same answers always produce the same document.

What happens to my answers?

Your answers stay in your browser while you build the draft. If you request the document, they are stored with your contact record in our CRM so the document link keeps working, and we record anonymous usage of the tool. We never send anything else unless you check the follow-up box. Our data privacy policy describes the rest.

Read the data privacy policy

Is this only for fundraising?

It covers the whole organization. The fundraising and finance workflows are the most detailed because that is where donor data, money, and outbound communication meet, and where boards ask the hardest questions.

Take the draft to a working session.

Bring your directors’ questions. We show how governed AI works inside Ignite, and what stays human.