
AI Policy for Small Charities: A Simple Staff and Volunteer Checklist
Why it matters: A practical, one-page AI policy and checklist for small charities and community teams using AI for drafting, summarising, planning, or admin support.
You'll explore:
- Quick answer: a small charity AI policy in plain English
- Do not enter sensitive records into AI tools
- Who this checklist is for and when to use it
- Plain-English working policy, not legal advice
- One-page AI use policy template for small charities
- Traffic-light checklist: allowed, needs approval, and not allowed
- No-sensitive-records warning and privacy checklist for AI use
- Staff and volunteer rules: roles, checks, records, and approvals
- Accuracy, bias, tone checks and escalation process
- Review schedule and copyable responsible AI checklist for staff and volunteers
- One-page AI use policy template
- Traffic-light AI use checklist
- Roles, approvals, and light-touch records
- Privacy checklist before using AI
- Accuracy, bias, tone, and confidentiality review checklist
- Copyable responsible AI checklist for staff and volunteers
- Do not enter sensitive records into AI tools
- Plain-English working policy, not legal advice
- Evidence note for this article
- Frequently asked questions
Quick answer: a small charity AI policy in plain English
A useful AI policy for small charities does not need to be long or legalistic. It should help staff, volunteers, coordinators, and trustees answer one practical question before using AI: is this task safe, non-sensitive, and reviewed by a human? Copyable short policy: We may use AI tools to support low-risk drafting, summarising, planning, and admin tasks. We must not enter sensitive, personal, confidential, safeguarding, HR, donor, service-user, casework, private, or identifiable information into AI tools. AI must not make final decisions for the charity. A human must check any AI-assisted output for accuracy, bias, tone, confidentiality, accessibility, consent, and fit with our values before it is used or shared. Higher-risk or public-facing use needs approval from the named coordinator, manager, or trustee group.
Do not enter sensitive records into AI tools
Do not send credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records to AI tools. This includes service-user details, safeguarding information, donor records, HR issues, private emails, case notes, financial access details, and anything that could identify a person, household, volunteer, donor, staff member, or beneficiary.

Who this checklist is for and when to use it
This checklist is for small charities, community organisations, informal project teams, trustees, coordinators, staff, and volunteers who are considering AI for everyday support. It is designed for practical tasks such as drafting a first version of a meeting agenda, summarising non-sensitive notes, planning a communications calendar, improving plain-English wording, or creating ideas for public event promotion. Use the checklist before a person puts information into an AI tool, before AI-assisted content is shared, and whenever a task moves from private drafting into public communication or decisions that could affect people. The aim is to create a lightweight working policy: clear enough for volunteers to follow, but not so heavy that it becomes a governance project.
- Use it before drafting, summarising, planning, or admin tasks with AI.
- Use it before sharing AI-assisted content with the public, partners, funders, volunteers, or service users.
- Use it when a volunteer asks whether they are allowed to use an AI tool for charity work.
- Use it when a trustee or coordinator needs to decide whether a task is green, amber, or red.
- Use it after a mistake, concern, or near miss so the policy can be improved.
Plain-English working policy, not legal advice
This article provides a practical starting point for a small charity AI policy. It is not legal advice and does not replace your organisation’s own safeguarding, data protection, HR, fundraising, communications, or volunteer policies. Adapt the wording to your responsibilities, your tools, and the people you support. If a task involves legal, safeguarding, HR, clinical, financial, or high-impact decisions, pause and seek appropriate advice rather than relying on AI.
One-page AI use policy template for small charities
The table below is the central copyable policy. You can paste it into a handbook, volunteer guide, shared document, induction pack, trustee paper, or internal wiki. Keep the wording short, name an owner, and make sure people know who to ask when they are unsure.
Traffic-light checklist: allowed, needs approval, and not allowed
A traffic-light approach is easier for a small team than a long approval process for every task. Green tasks are usually low-risk and non-sensitive. Amber tasks need approval because they involve public messaging, judgement, vulnerable groups, reputational risk, or information that could affect people. Red tasks are not allowed because the charity should not put sensitive records into AI tools or use AI as the final decision-maker.
No-sensitive-records warning and privacy checklist for AI use
Before using AI, strip the task back to non-sensitive information. If the task only works when you include names, contact details, case notes, donor history, HR issues, safeguarding details, private emails, screenshots, analytics exports, logins, passwords, or identifiable records, it is not suitable for a general AI tool under this simple policy. For safer prompts, use neutral examples. For example, instead of pasting a real service-user email, write: “Draft a kind reply to a community member asking whether our food project is open on bank holidays. Do not invent eligibility rules. Leave placeholders for details we must check.”
Staff and volunteer rules: roles, checks, records, and approvals
Small charities need clarity without creating a burdensome governance framework. The simplest rule is: the person using AI is responsible for what they put into the tool, the person sharing the output is responsible for checking it, and the named approver is responsible for amber uses. Volunteers can use AI only if the charity’s policy allows it, they understand the no-sensitive-records rule, and they know who reviews their work. AI should support a person; it should not replace safeguarding judgement, supervision, consent, accessibility checks, or trustee oversight where those are needed.
Accuracy, bias, tone checks and escalation process
AI-assisted text can sound confident even when it is wrong, unsuitable, or out of step with the charity’s voice. Treat AI output as a draft, not an answer. The reviewer should check facts against trusted internal records or original sources, remove anything the tool has invented, and edit the wording so it is accurate, kind, clear, accessible, and appropriate. Escalate instead of editing silently if the output includes confidential information, harmful or discriminatory wording, safeguarding concerns, legal or HR judgement, invented figures, false promises, or anything outside the reviewer’s knowledge. Escalation can be simple: stop using the output, save a brief note of the issue without sensitive detail, tell the named coordinator or trustee, and decide whether the policy or training needs updating.
Review schedule and copyable responsible AI checklist for staff and volunteers
Set a review date when the policy is adopted. A light review can ask: are people following the traffic-light rules, have any tools changed, have any mistakes or near misses been reported, are volunteers clear on the privacy boundary, and do trustees need to update the approval list? For a small team, the review can be a short agenda item rather than a large project. Keep a simple review log with the date, who attended, what changed, and what needs follow-up. If your team does not currently have capacity to review or support AI use properly, keep use narrow: low-risk drafting, planning, and admin only, with no sensitive records and human review every time. Capacity boundary: Chestnut Communities is not currently offering paid reviews, implementation, urgent support, or automatic AI replies. Use this article as a self-serve checklist and adapt it internally before adopting AI in day-to-day work.
One-page AI use policy template
| Policy section | Plain-English wording to copy | Who owns it |
|---|---|---|
| Purpose of AI use | We may use AI tools to support low-risk drafting, summarising, planning, and admin tasks. AI should help us prepare work; it should not replace human judgement. | Coordinator, manager, or named trustee |
| Core rule | Use AI only when the task is safe, non-sensitive, and reviewed by a human before it is used or shared. | Everyone using AI |
| Sensitive information boundary | Never enter credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records. This includes personal, confidential, safeguarding, HR, donor, service-user, casework, private email, financial access, or identifying details. | Everyone using AI |
| Human responsibility | AI must not be the final decision-maker for services, safeguarding, eligibility, complaints, HR, grants, finances, advice, or anything that could significantly affect a person. | Coordinator, manager, trustees, and relevant role holders |
| Output checks | All AI-assisted outputs must be checked for accuracy, bias, tone, confidentiality, accessibility, consent, and fit with our charity’s values before they are shared. | Person sharing the output and assigned reviewer |
| Approval for higher-risk use | Approval is needed before using AI for public-facing content, funding applications, policy wording, advice, volunteer management, work involving vulnerable groups, or any task where the impact is unclear. | Named approver, manager, coordinator, or trustee group |
Traffic-light AI use checklist
| Category | What it means | Example tasks | Action before use |
|---|---|---|---|
| Green: usually allowed | Low-risk, non-sensitive support tasks where the output will be checked by a human. | Drafting a meeting agenda; rewriting a public event description; brainstorming social media post ideas; creating a checklist for room setup; turning non-sensitive bullet points into a draft email. | Use AI, then check and edit before sharing. Do not include private or identifiable information. |
| Green: usually allowed | General learning or formatting support that does not require private charity records. | Asking for a plain-English explanation of a general term; turning public information into simpler wording; suggesting headings for a volunteer handbook section. | Use only public or generic information. Check that the wording fits your charity. |
| Amber: needs approval | Tasks involving public messaging, judgement, reputation, vulnerable groups, funding, policy wording, or information that could affect people. | Drafting a funding application outline; preparing a newsletter about service changes; creating volunteer guidance; summarising themes from anonymised feedback; drafting a response to a complaint without using private details. | Ask the named approver first. Use anonymised or generic information only. Record the approval and reviewer. |
| Amber: needs approval | Tasks where the team is unsure whether the information is sensitive or whether AI is appropriate. | Using AI to help plan a campaign about a sensitive topic; creating public wording about a difficult local issue; drafting content for people who may be distressed or vulnerable. | Pause and ask. Do not put the information into AI until approval is given. |
| Red: not allowed | Tasks that require sensitive, confidential, personal, safeguarding, HR, donor, casework, private, credential, screenshot, analytics export, or identifiable records to be entered into AI. | Pasting service-user case notes; uploading private emails; entering donor history; using safeguarding records; adding staff sickness or disciplinary details; sharing screenshots with names or contact details; entering passwords or access tokens. | Do not use AI for this task. Use normal secure charity processes instead. |
| Red: not allowed | Tasks where AI would make or appear to make a final decision affecting people, rights, access, safety, employment, eligibility, grants, advice, or complaints. | Deciding who receives support; assessing safeguarding risk; selecting beneficiaries; deciding disciplinary action; giving legal, clinical, financial, or immigration advice; approving or rejecting a complaint. | Do not use AI as the decision-maker. Escalate to the responsible person, manager, trustee, or qualified adviser. |

Roles, approvals, and light-touch records
| Role or situation | Responsibility | Minimum record |
|---|---|---|
| Staff member or volunteer using AI | Follow the traffic-light checklist, remove sensitive information, use only approved task types, and check the output before passing it on. | For green tasks, no record may be needed unless the output becomes substantial public-facing content. |
| Person publishing or sending AI-assisted content | Check accuracy, bias, tone, confidentiality, accessibility, consent, and fit with the charity’s voice and values. | Note that AI helped create substantial public-facing content if your policy requires it. |
| Coordinator or manager | Approve amber uses, decide who reviews outputs, and make sure volunteers understand the policy. | Record approval, purpose, tool or method if useful, reviewer, and date. Do not record sensitive prompt details. |
| Trustee or trustee group | Set the charity’s overall boundaries, review the policy, and oversee higher-risk categories without approving every low-risk task. | Record policy approval, review date, major changes, and any decisions about red or amber categories. |
| Safeguarding, HR, complaints, advice, or high-impact situation | Keep AI out of the decision-making process and use the charity’s normal specialist process. | Record through the normal secure process, not through an AI prompt or AI-generated summary containing sensitive information. |
| Mistake, concern, or near miss | Stop using the output, avoid sharing it further, tell the named person, and decide whether the policy needs to change. | Brief incident note with date, issue type, action taken, and policy follow-up. Do not include unnecessary personal data. |
Privacy checklist before using AI
- Is the task non-sensitive?
- Have all names, contact details, case notes, donor details, HR details, safeguarding information, financial details, private emails, credentials, analytics exports, screenshots with private information, and access details been removed?
- Could someone still be identified from the remaining information?
- Would the person reasonably expect their information to be used this way?
- Is the task allowed under the traffic-light checklist?
- Has a human been assigned to review the output before it is shared?
- If unsure, stop and ask the named approver instead of using AI.
Accuracy, bias, tone, and confidentiality review checklist
- Check facts against trusted internal records or original sources.
- Check that no made-up names, dates, quotes, figures, policies, or commitments have been added.
- Check whether the wording is fair, respectful, inclusive, accessible, and suitable for the audience.
- Check whether the output could misrepresent the charity’s position or promise something the team cannot deliver.
- Check that confidential or sensitive details have not been included, reconstructed, or implied.
- Edit the output into the charity’s normal voice before publishing or sending.
- Escalate if the output is wrong, harmful, inappropriate, biased, confidential, inaccessible, or outside the reviewer’s knowledge.
Copyable responsible AI checklist for staff and volunteers
- I know why I am using AI for this task.
- The task is green or has been approved as amber.
- I have not entered credentials, private records, analytics exports, screenshots containing private information, sensitive, personal, confidential, safeguarding, HR, donor, casework, private, or identifiable information.
- I have checked the output myself and, where needed, asked the right person to review it.
- I have edited the output so it is accurate, kind, clear, accessible, and appropriate for our charity.
- I have considered consent, tone, safeguarding, privacy, and whether the audience could be harmed or misled.
- I have not used AI as the final decision-maker.
- I have recorded the use or approval if the policy says I should.
- I know who to ask if I am unsure.
Do not enter sensitive records into AI tools
Plain-English working policy, not legal advice
Evidence note for this article
Frequently asked questions
Can volunteers use AI for charity admin?
Yes, if your charity’s policy allows it and the task is appropriate. Volunteers should use AI only for green tasks or approved amber tasks, remove all sensitive or identifiable information, and make sure a human checks the output before it is shared. Volunteers should know who to ask if they are unsure.
What information should never be put into an AI tool?
Do not put credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records into AI tools. Also avoid service-user details, safeguarding information, donor records, HR issues, private emails, case notes, financial access details, names, contact details, and anything that could identify a person or reveal confidential charity information.
Does every AI-assisted task need trustee approval?
No. Under a light-touch policy, routine green tasks can usually be handled by staff or volunteers who follow the checklist and review the output. Amber tasks should be approved by a coordinator, manager, or trustee depending on your structure. Red tasks should not be done with AI under this policy.
Can AI write funding applications, newsletters, or social media posts?
AI can help draft ideas, outlines, plain-English wording, or first versions, but the charity remains responsible for the final content. Funding applications, newsletters, and social media posts are public-facing or important communications, so they should be checked carefully for accuracy, tone, confidentiality, accessibility, consent, and promises the charity cannot keep. Do not paste private donor, service-user, staff, or casework information into an AI tool.
How often should a small charity review its AI use policy?
Set a review date when you adopt the policy and review it whenever tools, tasks, risks, staff roles, volunteer arrangements, or incidents change. If you want a simple rhythm, make it a short trustee or management agenda item at agreed intervals, record any changes, and keep the policy narrow if you do not have capacity to supervise wider AI use.
Interactive checklist
Assess readiness with the Community AI checklist
Work through each section, get a readiness score, and print the results to align your team before you launch any AI project.



