Skip to content
Template18 min

AI use policy for a development office (starter)

Fill every bracketed field with your organization's facts before this goes to anyone for a signature. The Chief Development Officer or Executive Director should own the draft; where your donor base includes residents of a state or country with its own data protection law, have counsel review Sections 5 and 6 before adoption. This is a starting policy, not a finished one. Cut what does not apply to your shop and add what does.

1. Purpose and the standard. This policy governs the use of artificial intelligence tools by staff, volunteers, and anyone acting on behalf of [ORGANIZATION] in fundraising work. One sentence carries the whole policy: we do not make anything in a way we would not describe to the donor it is for. If a use of AI could not survive being named out loud to the donor it touches, it does not belong in this office. Every section below is an application of that sentence to a specific piece of our work. The policy exists because AI tools are already in most development offices, whether or not a decision was ever made about them, and a shop that has not named its own rules is governed by whatever rule an individual staff member happens to guess at on a busy afternoon.

2. Scope. This policy covers every person who does fundraising work for [ORGANIZATION], whether paid staff, volunteer solicitor, contracted consultant, or vendor acting on our behalf, and every kind of output an AI tool can produce: written text, images, audio, video, data analysis, and any score or ranking applied to a person. It covers tools used on our devices and tools used on personal devices for [ORGANIZATION] work. It applies to a single sentence drafted for one letter and to a model that scores an entire file. A vendor contract that gives a third party access to donor data in order to run AI processing is covered by this policy and must meet the requirements in Section 5 before it is signed. A tool that is free, or already built into software we own, is covered exactly the same as one we pay for separately; cost has no bearing on what this policy allows.

3. Permitted uses, by movement. AI tools may be used to prepare the people who do the work of fundraising and to serve the records that support it. Specifically:

  • Pause. Rehearsal: practicing a conversation, an ask, or a difficult response before we have it with a real person, where no donor data is entered and no donor sees the output.
  • See. Summarizing our own meeting notes, call reports, and publicly available information a donor has chosen to make public, so a gift officer arrives at a visit prepared rather than cold.
  • Discern. Building internal checklists, training materials, and decision frameworks that help staff apply their own judgment consistently, such as a qualification checklist or a gift review agenda.
  • Invite. Drafting our own preparation for an ask: talking points, background summaries, and rehearsal scripts a gift officer will use, edit, and speak in their own words. The ask itself, spoken or written to the donor, is prepared by the person making it, not generated for them. See Section 4.
  • Accompany. Reading-level and length checks on our own drafts, so a letter or email reads the way we intend before it goes out, with the words remaining ours.
  • Multiply. Impact reporting built from real, verified program data, with a named staff member who can stand behind every figure and every claim in it.

If a use is not listed here and does not clearly serve preparation or the record, treat it as prohibited under Section 4 until [TITLE] rules on it in writing.

4. Prohibited uses. The following are not permitted, without exception or informal workaround:

  • Generating the ask itself: the specific words spoken or written to invite a specific donor to a specific gift. A tool may help an inviter prepare; it does not stand in the inviter's place.
  • Automatically generating or sending a reply to a donor's no or not-yet. A decline is a relationship event, not a ticket to close, and it is answered by a person who read it.
  • Inferring a donor's protected characteristics, health status, family circumstances, or wealth from thin or indirect signals, such as a name, a neighborhood, or a social media photo. What we do not know, we do not guess at scale.
  • Producing synthetic donor or beneficiary stories, composite people presented as real, invented quotations, or generated images or video of a beneficiary who did not consent to being represented that way. A story we tell is a story that happened.
  • Entering any donor's personal or giving information into a tool whose terms allow that input to train the vendor's models, or into any tool outside our current data processing agreements. See Section 5.
  • Allowing a score, rating, or model output to close a decision about a person on its own, without a human weighing it against what that person actually is to us. See Section 8.

A use not on this list is not automatically permitted. When in doubt, ask [TITLE] before proceeding, not after. These prohibitions exist because each one names a specific way a donor can be misled or reduced: to a person who believes a message came from a relationship rather than a machine, to a set of inferred traits instead of the person who volunteered them, to a story that never happened, to data handed to a stranger, or to a number standing in for a judgment no one made.

5. Donor data custody. Where information may go depends on what kind of information it is.

TierWhat it includesWhere it may go
Public informationPublished annual reports, news coverage, an organization's own website, a donor's own public statementsAny general-purpose tool, for summarizing or drafting
Our own operational recordsDe-identified process notes, internal training content, aggregate and anonymized statisticsTools under a current data processing agreement with [ORGANIZATION]
Donor personal and giving informationNames, contact details, gift history, wealth screening results, notes about an individual donorOnly tools named in Appendix [X] of this policy, each under a signed data processing agreement

Before any vendor tool is added to Appendix [X], it must meet four requirements: a signed data processing agreement covering our donor data; a written commitment that our data is not used to train the vendor's models; a defined process for deleting our data on request or on contract end; and access logging we can review. [TITLE] confirms all four before a tool is approved for donor data use.

The CRM remains the system of record. No AI tool, vendor platform, or generated output replaces it. A fact about a donor lives in the CRM; anything an AI tool produces about a donor is a draft until a person has verified it against the CRM and, where needed, entered the correction back into it.

6. Disclosure. Donors are told, in plain language, in our privacy notice: "We use AI tools to help our staff prepare drafts and summaries for internal use. Every message you receive from us is reviewed and sent by a person who takes responsibility for it." Where a piece of communication uses generated image, audio, or video content, an acknowledgment line appears with it identifying that it was generated. If a donor asks how a specific piece was made, the honest answer is given: what tool assisted, what a person changed, reviewed, or wrote themselves, and who that person was. We do not let a donor believe a person wrote something a tool drafted, or that a tool decided something a person decided.

7. Human accountability. Every AI-assisted piece of fundraising work has one named owner: a specific person who read the final version, would defend every sentence and every figure in it, and is identified in our internal log if asked. Sign-off follows the weight of the piece:

  • Internal preparation and rehearsal material: the staff member using it, no additional sign-off required.
  • Individual donor correspondence: the gift officer or staff member sending it, who has read and edited every word.
  • Any piece sent to more than one donor, or published publicly: the Director of Development or [TITLE].
  • Any use of a predictive score, model output, or generated image, audio, or video: [TITLE], logged before use.

The log records, at minimum, the piece, the owner, the tool category used, and the date. It is reviewed as part of the quarterly review in Section 9. Naming an owner is not a formality: it is the answer to the question a donor, a board member, or a reporter is entitled to ask about any piece of our work, "who stands behind this," and this policy requires that the answer always be a person's name, never a tool's.

8. Scores and models. A predictive score, capacity estimate, or engagement rating is an input to a human's question about a person, never a verdict on that person. A high score does not authorize a visit that has not been earned by relationship, and a low score does not close a door that a relationship has opened. What we will not model, and why, is addressed at length in the analytics policy worksheet in the Philanthropy Analytics module; this policy adopts that worksheet's limits by reference. Any donor may ask whether a score was used in a decision that affected them, and how; the answer is given honestly, in terms a donor without technical background can follow.

9. Review cadence and ownership. The inventory of every AI tool in use across the development office, and what each one touches, is reviewed quarterly using the audit worksheet from this module, "AI use audit: what is already running in your shop." This policy itself is reviewed at least annually by [TITLE], and sooner if the law changes, if a new category of tool is adopted, or if a use under this policy causes harm or a near miss. [TITLE] owns this policy and is the person any staff member, volunteer, or vendor should contact with a concern about an AI use that seems inconsistent with it. No staff member is penalized for raising that concern in good faith, including about their own past use of a tool.

10. Adoption.

Adopted by: [NAME AND TITLE, e.g., Chief Development Officer or Executive Director] Date adopted: [DATE] Next review date: [DATE, no more than one year later]

Signature: _______________________________ [NAME, TITLE]

Signature: _______________________________ [NAME, TITLE, if a second sign-off is required by your organization's governance]

Evidence and adaptation note

This is a working tool, not a universal benchmark. Replace every bracketed field and example number with your organization's facts. Composite cases are labeled; their figures illustrate the method and should not be cited as sector results. Check legal, tax, privacy, employment, and accounting language against current guidance and your jurisdiction before adoption.

Primary references for review

Use these as verification starting points. The named reviewer still owns the final interpretation and must confirm that each source is current.

  • Association of Fundraising Professionals, Code of Ethical Standards: https://afpglobal.org/ethics/code-ethical-standards
  • Association of Fundraising Professionals, A Donor Bill of Rights: https://afpglobal.org/donor-bill-rights
  • NIST AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework
  • Fundraising.AI, responsible AI framework: https://fundraising.ai/

Through the Higher Ed lens

Portfolio work inside a big shop, qualification at scale, and partnering with deans and faculty.