
AI Policy for Small Charities: A Practical Admin Workflow Checklist
Why it matters: Small charities can use AI for some routine admin, but only with clear boundaries. This practical checklist helps trustees, coordinators, staff, and volunteers decide what AI ca...
You'll explore:
- Introduction: simple AI rules should come before experimentation
- 1. Decide the admin task before choosing an AI tool
- 2. Sort charity admin tasks into red, amber, and green risk levels
- 3. Green uses: where AI may help with routine admin
- 4. Amber and red uses: tasks that need extra caution or should stay out of AI
- 5. Set minimum AI policy rules for small charities
- 6. Use the AI admin workflow checklist before each new use case
- 7. Review the policy regularly with trustees, staff, and volunteers
- Red, amber, and green AI admin risk sorting table
- Minimum AI policy rules for small charities
- Before choosing an AI tool: task scoping template
- AI admin workflow checklist before each new use case
- Trustee and coordinator review checklist
- Do not start with the tool
- The safest first AI uses are boring
- Red-line rule: AI must not replace human judgement
- Frequently asked questions
Introduction: simple AI rules should come before experimentation
AI tools can be useful for routine charity admin, but they are not harmless just because they are easy to open in a browser. Small charities and community organisations often work with limited time, mixed staff and volunteer teams, and sensitive community relationships. That makes simple rules more important, not less important. A practical AI policy for small charities does not need to be long or technical. It should answer everyday questions: What can we use AI for? What information must never be entered? Who checks the output? When do we escalate to a manager, safeguarding lead, trustee, or adviser? The safest approach is to treat AI as admin assistance, not as a decision-maker. It may help draft, reword, format, summarise, or brainstorm low-risk material. It should not replace human judgement, confidentiality duties, safeguarding processes, consent requirements, or trustee accountability.
- Start with the admin task, not the AI tool.
- Keep personal, sensitive, confidential, safeguarding, employment, complaints, and beneficiary information out of general AI tools unless your policy explicitly allows a controlled use.
- Require human review before any AI-assisted output is used or shared.
- Escalate anything that could affect a person’s safety, rights, access to support, reputation, employment, funding, or care.
1. Decide the admin task before choosing an AI tool
Tool-led experimentation is where many risks begin. Someone tries an AI tool, pastes in a real email thread, uploads a spreadsheet, or asks for help with a sensitive issue before the organisation has agreed boundaries. Instead, define the workflow first. Be specific. “Use AI for admin” is too broad. “Reword a public event description for a newsletter” is clearer. “Summarise beneficiary case notes” is much riskier and should usually be treated as red or tightly controlled specialist work. Before choosing any tool, record the task, the information involved, the intended output, and the person responsible for review. This gives staff and volunteers a simple pause point before information is copied into a system they may not understand.
- Name the exact admin task you want to improve.
- Identify the information involved: public, internal, personal, sensitive, confidential, or safeguarding-related.
- Decide what AI is allowed to do: draft, summarise, format, translate, brainstorm, or compare options.
- Name the human reviewer before the tool is used.
- Check whether the output could affect someone’s rights, access to support, safety, employment, reputation, or finances.

2. Sort charity admin tasks into red, amber, and green risk levels
A red, amber, and green model is easier for small teams than a complex risk assessment. It helps volunteers and coordinators make the same first judgement before using AI. Green uses are low-risk and usually involve public or non-sensitive information. Amber uses may be allowed, but only with extra review because they involve internal context, reputation, service delivery, or judgement. Red uses should stay out of AI tools unless there is a formally approved, legally and operationally safe arrangement. If the team is unsure whether a task is green or amber, treat it as amber. If there is any safeguarding, employment, complaint, eligibility, legal, or confidential beneficiary element, pause and escalate.
- Green means AI may assist with clear boundaries and review.
- Amber means AI use needs approval, stronger checking, and a record.
- Red means do not use AI for that workflow unless there is explicit policy approval and specialist assurance.
3. Green uses: where AI may help with routine admin
The best first uses of AI in a small charity are often ordinary, low-risk, and slightly dull. That is a strength. If the information is already public or non-sensitive, and a human checks the output before use, AI may save time without changing decisions or exposing private information. Green uses should still be reviewed for accuracy, tone, accessibility, inclusiveness, and fit with the charity’s values. AI can produce confident but wrong text, over-polished wording, or language that does not sound like your organisation.
- Rewording a public event description for a newsletter, poster, or website listing.
- Creating a first draft of a meeting agenda from non-sensitive agenda points.
- Turning rough public notes into a plain-English announcement.
- Suggesting headings for a volunteer handbook section that contains no personal information.
- Formatting a public FAQ into shorter questions and answers.
- Drafting alternative versions of social media posts based on already-approved public content.
- Creating a checklist from an existing public procedure.
- Suggesting plain-language wording for a public policy summary, followed by human checking.
- Brainstorming inclusive wording for non-sensitive community engagement materials.
- Creating a first draft of a thank-you message that does not include private donor, beneficiary, or volunteer details.
4. Amber and red uses: tasks that need extra caution or should stay out of AI
Small charities often hold information that is sensitive because of context, even when it does not look dramatic. A volunteer rota, a complaint email, a funding report, a safeguarding concern, or a beneficiary referral can reveal private details about people and communities. Amber workflows may be possible, but only with approval and careful controls. Red workflows should not be handled through general AI tools. The key question is not “Could AI produce a useful answer?” It is “Should this information or decision be placed into an AI workflow at all?”
- Treat funding application drafts as amber when they involve unpublished strategy, financial figures, service outcomes, partner commitments, or claims that need verification.
- Treat volunteer emails as amber if they include personal circumstances, performance concerns, conflict, complaints, or rota information that identifies individuals.
- Treat policy summaries as amber where misunderstanding could affect safeguarding, HR, complaints, finance, or service delivery.
- Treat translation or accessibility support as amber where the wording affects consent, rights, safety, or access to services. Use human checking.
- Treat beneficiary eligibility, safeguarding concerns, complaints, disciplinary matters, employment decisions, legal questions, and financial approvals as red for AI decision-making.
- Do not upload credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records into AI tools.
5. Set minimum AI policy rules for small charities
A small charity AI policy can be short, but it must be clear enough for real day-to-day decisions. The policy should tell staff, trustees, and volunteers what is allowed, what is banned, what data rules apply, who reviews outputs, and who to ask when unsure. The policy should be written in plain English and shared during onboarding or volunteer briefings. If people only hear the rules once, or the rules are buried in a long governance document, they may not remember them when they are under time pressure.
- List approved low-risk admin uses rather than giving blanket permission to use AI.
- List banned uses and banned information types in direct language.
- Make human review mandatory for all AI-assisted outputs before they are shared or acted on.
- Keep accountability with named people and the organisation, not the AI tool.
- Include escalation routes for safeguarding, HR, complaints, finance, confidentiality, and legal uncertainty.
- Review the policy when tools, services, staff, volunteers, or guidance change.
6. Use the AI admin workflow checklist before each new use case
The checklist below is designed as a copyable workflow for each new AI admin use case. It is especially useful when a volunteer or coordinator wants to try AI for a task the organisation has not previously approved. For green uses, the checklist may take only a minute. For amber uses, it creates a record of what was considered and who reviewed it. For red uses, it should stop the workflow before information is entered into a tool. A good rule is: if the checklist feels too burdensome for the task, the task may either be too risky for casual AI use or not important enough to justify introducing AI at all.
- Use the checklist before the first use of a new AI-supported workflow.
- Repeat it when the information type changes, even if the task sounds similar.
- Keep a simple record for amber workflows so trustees and coordinators can see what has been approved.
- Stop immediately if someone would need to paste in private, sensitive, confidential, or identifiable information that the policy does not allow.
7. Review the policy regularly with trustees, staff, and volunteers
An AI policy is not a one-off document. Tools change, team members change, services change, and volunteers may bring their own habits from work or study. Trustees and coordinators should review the policy regularly enough to keep it useful, but not so often that it becomes a burden. A practical review can be simple: ask what AI has been used for, whether any amber workflows were recorded, whether anyone felt unsure, and whether any new red lines are needed. Include safeguarding, privacy, tone, accessibility, consent, and escalation in the discussion. The aim is not to block every useful admin shortcut. It is to make sure AI use stays proportionate, lawful, respectful, and accountable.
- Check whether staff and volunteers understand approved and banned uses.
- Review any amber use cases and update guidance if patterns are emerging.
- Ask whether any AI outputs caused confusion, inaccurate wording, tone issues, privacy concerns, or accessibility problems.
- Confirm that red areas such as safeguarding, HR, complaints, financial approvals, and eligibility decisions remain protected.
- Make sure new volunteers know who to ask before trying AI for charity work.
Red, amber, and green AI admin risk sorting table
| Risk level | Typical charity admin examples | What AI may do | Required safeguards | Who should approve |
|---|---|---|---|---|
| Green: low-risk | Rewording public event descriptions, drafting a non-sensitive meeting agenda, formatting public FAQs, creating social media options from already-approved text. | Draft, reword, format, summarise public content, suggest headings, brainstorm non-sensitive wording. | Use only public or non-sensitive information; check accuracy, tone, accessibility, and fit with charity values; do not publish without human review. | Coordinator, staff lead, or approved volunteer within the written policy. |
| Amber: caution needed | Volunteer communications with internal context, funding application drafts, internal policy summaries, service delivery updates, translated text affecting access to support, reports using unpublished organisational information. | Support structure, create first drafts, summarise non-sensitive extracts, suggest plain-language wording, compare options for a human to consider. | Remove or anonymise personal and confidential data; get approval before first use; name a reviewer; verify facts and figures; record the use case; escalate if unsure. | Manager, coordinator, trustee lead, data protection lead, safeguarding lead, or another named role depending on the topic. |
| Red: do not use for casual AI workflows | Safeguarding concerns, beneficiary records, eligibility decisions, complaints, legal decisions, employment or disciplinary matters, confidential financial approvals, donor or service-user records, credentials, private records, analytics exports, screenshots containing private information, identifiable sensitive records. | AI should not make decisions or process this information in general tools. Do not paste, upload, summarise, or ask the tool to decide what to do. | Stop and use the organisation’s normal process. Seek specialist advice where needed. Keep human decision-making, confidentiality, consent, and safeguarding procedures in place. | Relevant senior lead, safeguarding lead, trustees, legal/data protection adviser, or appropriate specialist. In many cases AI use should be banned. |
Minimum AI policy rules for small charities
| Policy area | Minimum rule | Why it matters | Owner or reviewer |
|---|---|---|---|
| Purpose and scope | State that AI may support limited admin tasks but must not replace human judgement or charity decision-making. | Sets expectations and prevents people assuming AI can be used for any task. | Trustees or senior coordinator. |
| Approved uses | List low-risk tasks where AI may help with drafting, rewording, summarising, formatting, brainstorming, or plain-language suggestions using non-sensitive information. | Gives staff and volunteers confidence about safe, proportionate uses. | Coordinator, manager, or trustee lead. |
| Banned uses | Ban AI use for safeguarding decisions, beneficiary eligibility, complaints decisions, HR decisions, legal decisions, financial approvals, and other high-risk judgement areas. | Protects people, confidentiality, legal duties, and organisational accountability. | Trustees, safeguarding lead, HR/finance lead where relevant. |
| Data handling | Do not enter credentials, private records, analytics exports, screenshots containing private information, identifiable sensitive records, or confidential charity information into AI tools unless explicitly approved under policy. | Reduces privacy, confidentiality, and security risks. | Data protection lead, trustees, or named privacy owner. |
| Human review | Require a named person to check every AI-assisted output for accuracy, tone, bias, accessibility, confidentiality, and suitability before use. | AI can be inaccurate, misleading, incomplete, or inappropriate for the charity’s context. | Named reviewer for the workflow. |
| Accountability | Make clear that staff, volunteers, managers, and trustees remain responsible for what is sent, published, submitted, or decided. | Prevents people blaming the tool for organisational decisions or communications. | Trustees and role holders named in procedures. |

Before choosing an AI tool: task scoping template
| Question to answer | What to record | Example |
|---|---|---|
| What admin task are we trying to improve? | Record the specific task, not a broad ambition such as “use AI for admin”. | “Create a first draft of a public event reminder from approved event details.” |
| What information will be used? | Identify whether the information is public, internal, personal, sensitive, confidential, safeguarding-related, or commercially restricted. | “Public event title, date, location, booking link, and accessibility information.” |
| What output do we want? | Define whether AI is drafting, summarising, formatting, translating, brainstorming, or suggesting options. | “Three short newsletter versions in a friendly tone.” |
| Who will review the output? | Name the person or role responsible for checking accuracy, tone, privacy, accessibility, and suitability. | “Volunteer coordinator checks before the newsletter is scheduled.” |
| Could the output affect a person’s rights, access to support, reputation, safety, employment, funding, or finances? | If yes, classify as amber or red and escalate before using AI. | “A message about eligibility for support affects access to services, so it is not a green use.” |
AI admin workflow checklist before each new use case
- Define the exact admin task before opening an AI tool.
- Confirm the task is not on the organisation’s banned-use list.
- Identify what information will be entered into the AI tool.
- Do not send credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records.
- Remove personal, sensitive, confidential, safeguarding, employment, complaints, financial, or beneficiary information unless explicitly approved under policy.
- Classify the workflow as green, amber, or red risk.
- Check whether consent, privacy notice updates, funder rules, client confidentiality rules, or partner agreements are relevant.
- Decide what the AI is allowed to do: draft, summarise, format, translate, brainstorm, or compare options.
- Name the human reviewer responsible for checking accuracy, tone, bias, confidentiality, accessibility, and suitability.
- Confirm AI output will not be used as the final decision-maker for people, funding, safeguarding, HR, complaints, eligibility, service access, or financial approvals.
- Record the use case if required by the policy, especially for amber workflows.
- Escalate to the manager, safeguarding lead, trustee, data protection lead, funder contact, or adviser if any uncertainty remains.
- Review the workflow after first use and update the policy if a new risk appears.
Trustee and coordinator review checklist
- Do we have a written AI policy that staff and volunteers can understand?
- Are approved and banned uses clear enough for day-to-day admin decisions?
- Have we explained what data must never be entered into AI tools?
- Do volunteers know who to ask before trying a new AI use case?
- Are safeguarding, confidentiality, HR, complaints, service-access, eligibility, and financial decision areas protected?
- Do we require human review for every AI-assisted output before it is sent, submitted, published, or acted on?
- Do our review steps include privacy, tone, accessibility, consent, equality, and potential bias?
- Is there a simple record of amber-risk AI use cases?
- Have we reviewed the policy after changes in tools, services, staff, volunteers, funder rules, or legal guidance?
- Do we know what to do if an AI-assisted output causes a concern, complaint, data issue, or safeguarding worry?
Do not start with the tool
The safest first AI uses are boring
Red-line rule: AI must not replace human judgement
Frequently asked questions
Do small charities need an AI policy before using AI for admin?
Yes, even a short policy is useful. Small charities often rely on volunteers, shared responsibilities, and sensitive community relationships, so people need clear boundaries before experimenting. A practical AI policy for small charities should explain approved uses, banned uses, data rules, human review, and escalation routes. It does not need to be technical, but it should be written down and easy to follow.
What should an AI policy for small charities include?
At minimum, include: the purpose of the policy, approved low-risk admin uses, banned uses, information that must not be entered into AI tools, human review requirements, accountability, consent and confidentiality rules, escalation routes, record-keeping for amber workflows, and a review schedule. The policy should make clear that AI can assist with drafting or formatting but must not make decisions for the charity.
Can volunteers use AI to write emails or social media posts for a charity?
They may be able to use AI for low-risk drafting if the charity has approved that use, no confidential or personal information is entered, and a named person reviews the output before it is sent or published. Volunteers should not use AI for emails involving complaints, safeguarding, HR, beneficiary details, conflict, sensitive personal circumstances, or anything that could affect someone’s access to support without approval and escalation.
What charity information should never be put into AI tools?
As a red-line rule, do not send credentials, private records, analytics exports, screenshots containing private information, or identifiable sensitive records. Small charities should also avoid entering safeguarding details, beneficiary case notes, complaint records, HR information, disciplinary matters, confidential financial information, unpublished legal advice, sensitive personal data, or anything that identifies a person in a vulnerable context unless there is explicit policy approval and appropriate safeguards.
Can AI help write funding applications?
AI may help with structure, headings, plain-language drafting, or turning non-sensitive notes into a first draft. Treat funding applications as amber, not green, because they can involve claims, figures, outcomes, eligibility, budgets, partner commitments, and reputational risk. A human must verify every factual statement, financial figure, promise, and funder requirement before anything is submitted.
Who is responsible if an AI-assisted admin task causes a problem?
The organisation and the named human reviewers remain responsible. The AI tool is not accountable for the charity’s decisions, communications, safeguarding duties, privacy obligations, or use of funds. Your policy should make clear who reviews outputs, who approves amber workflows, and who must be contacted if something goes wrong.
Interactive checklist
Assess readiness with the Community AI checklist
Work through each section, get a readiness score, and print the results to align your team before you launch any AI project.



