AI governance assessment for nonprofits and small businesses.
AI is already in your organization. Governance is how you make sure it helps your mission instead of creating a privacy, compliance, or reputational problem. This is the practical framework we use with lean teams.

Shadow AI is already happening.
Staff are using AI to write emails, analyze spreadsheets, summarize case notes, and create content — usually without guidelines and often without anyone knowing. That is not a discipline problem; it is a governance gap. An AI governance assessment closes it by answering four questions: what tools are in use, what data they touch, what could go wrong, and who is accountable.
Six pillars of practical AI governance.
Visibility
Know which AI tools staff already use. Shadow AI is the default state in most organizations — an inventory is step one of any governance program.
Risk tiering
Rank each use case by the harm a bad output could cause. Drafting a newsletter is low risk; screening applicants or clients is not.
Policy and guardrails
One short, readable AI use policy: approved tools, what data may never be pasted in, when a human must review, and who to ask.
Data protection
AI inherits the access of the person using it. Tighten permissions and licensing before you scale usage, not after.
Accountability
Name an owner for AI decisions, give the board a one-page briefing, and log significant use cases so decisions are traceable.
Review cadence
Reassess quarterly. Tools, vendors, and regulations move faster than annual policy cycles.
Not every AI use case needs the same oversight.
Internal drafting, summarizing public documents, brainstorming. Allow broadly with basic guardrails.
Donor or customer communications, grant research, data analysis on internal records. Require named owners and human review.
Anything touching eligibility, hiring, health, finances, or protected client data. Requires documented approval, human decision-making, and audit logging.
The 10-point AI governance assessment.
Work through these in order. Most small organizations can complete the first pass in two to four weeks without buying anything new.
See our AI and automation services- Inventory every AI tool in use, including free personal accounts.
- Classify data your team handles: public, internal, confidential, regulated.
- Tier each AI use case as low, moderate, or high risk.
- Publish a one-page AI use policy staff can actually read.
- Require human review for anything affecting a person's money, care, or eligibility.
- Confirm vendor terms: does the tool train on your data?
- Restrict AI tools to accounts with least-privilege access.
- Train staff once per year and at onboarding.
- Log high-risk use cases and outcomes.
- Review the whole program quarterly with leadership.
Ready to see how your organization scores?
Take the free AI Readiness Assessment — about seven minutes, a personalized score, and a clear roadmap for the next steps.
Start the FREE AI Readiness AssessmentAI governance questions we hear most.
What is an AI governance assessment?
An AI governance assessment is a structured review of how an organization uses AI: which tools are in play, what data they touch, how risky each use case is, and which policies, approvals, and human-review steps are in place. It produces a prioritized list of gaps and guardrails rather than a technical audit.
How is AI governance different from AI readiness?
Readiness asks whether your organization can adopt AI usefully — data, skills, and processes. Governance asks whether you can adopt it safely — risk, policy, privacy, accountability, and oversight. Most organizations need both, and governance is what keeps a successful pilot from creating a privacy or compliance incident later.
Do small nonprofits and businesses really need AI governance?
Yes, and it does not need to be heavy. Employees at organizations of every size already paste internal information into AI tools. A one-page policy, an approved-tools list, tightened permissions, and a quarterly review cover most of the realistic risk for a small organization.
Who should own AI governance in a small organization?
A single accountable leader — often the executive director, COO, or operations lead — supported by whoever manages IT. The owner maintains the tool inventory and policy, approves high-risk use cases, and briefs the board or ownership at least twice a year.
How long does an AI governance assessment take?
For an organization under about 100 staff, a first pass usually takes two to four weeks: a week to inventory tools and data, a week to tier use cases and draft policy, and a short leadership review. Our free AI Readiness Assessment gives you a scored starting point in about seven minutes.
Related reading: the Nonprofit IT Guide and cybersecurity services.
Let's find the right technology for your organization.
A free, no-obligation consultation with a vendor-neutral advisor — backed by access to 250+ technology partners.