AI use audit: what is already running in your shop
Nobody decided to bring these tools in, one at a time, through a CRM update, an email platform's new feature, or a staff member's own browser extension. That is how it usually happens, and it is why this worksheet starts with an inventory, not a policy. You cannot govern what you have not found. Work it with every staff member who touches a donor, and with whoever holds the vendor contracts. Give yourself the full sixteen minutes for the first pass; a real inventory takes longer than a review of a policy already written.
The rule behind every column and every score: AI may prepare the inviter and serve the record. It may never stand in for the relationship or decide who a person is. Nothing below replaces that sentence. It only tells you where to apply it.
Part 1: Inventory
One row per use, not per tool. A single platform can carry three uses (a draft, a summary, a score) and each gets its own row. Ask each staff member: what does the software already do without you typing the words yourself? Check every vendor: CRM, email platform, wealth screening, grant software, design tools, meeting note-takers, browser assistants. A use nobody can name is not evidence it does not exist.
For each row, record:
- Use: the plain description of what happens (example: "drafts thank-you letter openers from gift amount and fund").
- Tool: the product or vendor name.
- Who uses it: the role or person.
- Movement it touches: Pause, See, Discern, Invite, Receive, Accompany, or Multiply.
- Data it touches: public information; our operational records; or donor personal or giving information.
- Output it shapes: a draft; a summary; a score; a decision; or a message sent.
- Human owner named: yes or no. A named person, not "development staff."
- Disclosed to donors where required: yes or no.
- Vendor terms allow training on our data: yes, no, or unknown. If unknown, that is the finding; read the terms before the next section.
Worked example row (composite, for scoring only):
| Use | Tool | Who uses it | Movement | Data | Output | Owner named | Disclosed | Vendor training terms |
|---|---|---|---|---|---|---|---|---|
| Suggests an opening line for a stewardship email from gift date, amount, and fund | Email platform's built-in assistant | Annual fund coordinator | Accompany | Donor personal or giving information | A draft | No | No | Unknown |
That row is fabricated to teach the method. It is not a claim about any vendor named or unnamed.
Add a row for every use found. Most shops that ask every staff member, not just the development director, find more rows than they expected. A meeting note-taker in one recurring donor call is one row. A browser assistant summarizing a prospect's public profile is another. A grant platform drafting boilerplate is a third. Stop adding rows only when two staff members in a row have nothing new to report.
Part 2: Rating
Score each row 0, 1, or 2 on three questions. Write the score and one line of evidence, not a guess.
- Does a person read and own the output before it acts? 2 if yes, always. 1 if sometimes. 0 if no.
- Does the data stay in our custody under terms we have read? 2 if yes. 1 if the terms are read but the answer is qualified. 0 if the terms are unread or say no.
- Could we describe this use to the donor it touches without embarrassment? 2 if yes, plainly. 1 if we would soften how we said it. 0 if we would not say it at all.
Total per row, 0 to 6.
- 5 or 6: keep.
- 3 or 4: change, and name the change in Part 4.
- 0 to 2: stop until fixed.
Worked example, scored:
| Question | Score | Evidence |
|---|---|---|
| Person reads and owns the output before it acts | 2 | Coordinator edits every draft before sending; confirmed by spot check of ten sent emails |
| Data stays in our custody under terms we have read | 0 | Vendor terms not read before the feature was turned on |
| Could describe this use to the donor without embarrassment | 1 | Would describe the draft step but not mention which product generates it |
Total: 3. Decision: change. The fix is to read the vendor's data-training terms before Part 4 is closed, and to add one sentence to the gift acknowledgment process describing that a first draft is machine-generated and staff-edited.
A row can score 5 or 6 on these three questions and still fail Part 3. Score first, then check Part 3 before you record a final decision.
Part 3: The three questions never scored by a tool
Ask these of every row regardless of its Part 2 total. Any yes is a stop, no matter the score.
- Does this use decide who a person is: their capacity, their intent, their worth of attention, their readiness?
- Does it send anything to a donor without a person reading it first?
- Does it infer something the donor did not tell us and that is not public: a life event, a health circumstance, a family change, a financial position beyond verified screening?
These three cannot be improved by better prompts, better vendors, or a closer reading of terms of service. A use that trips one of them is not a change candidate. It stops until the use itself is redesigned so the answer is no.
Worked example: none of the three apply to the drafting use above. It stays a change, not a stop, once the vendor terms are read and the disclosure line is added.
Part 4: Decisions
For every row, record the decision and what follows from it.
- Decision: keep, change, or stop.
- If change: the specific change, in one sentence a new staff member could act on.
- Owner: the named person responsible for making the change happen, not the person who found the row.
- Date: when the change is verified complete, not when it was assigned.
- Donor-facing disclosure: the exact sentence that will appear where donors would see it, if this use touches donor personal or giving information and disclosure is required. If none is required, write "not applicable" and say why in one line.
Worked example:
- Decision: change.
- Change: read the email platform's vendor terms on data use for training before the next renewal date; add one sentence to the gift acknowledgment page describing that a first draft may be machine-assisted and is reviewed by staff before sending.
- Owner: development operations manager.
- Date: within thirty days of this audit.
- Donor-facing disclosure: "A first draft of some of our messages may be machine-assisted; a staff member reads and approves every message before it reaches you."
Work every row this way before moving to the summary. A row with no owner named is not finished, whatever its score.
Part 5: The one-page summary for the ED or board
One page, four items, built from the completed rows above.
- Count of uses found: the number of rows in the inventory.
- Count by decision: how many keep, how many change, how many stop.
- The three highest-risk uses and their fixes: the three lowest-scoring rows, or any row that tripped a Part 3 question, named plainly with the fix and owner already assigned in Part 4.
- The sentence the shop will use with donors: one sentence, consistent across every disclosure in Part 4, that states plainly that some drafting or record-keeping work is machine-assisted and that a person reads and approves it before it reaches a donor.
This page is the audit's real deliverable. A completed inventory that never reaches the person who can fund the fixes and set the cadence has not changed anything. Set a date to run this audit again: annually at minimum, and again whenever a new tool or vendor feature is adopted.
Evidence and adaptation note
This is a working tool, not a universal benchmark. Replace every bracketed field and example number with your organization's facts. Composite cases are labeled; their figures illustrate the method and should not be cited as sector results. Check legal, tax, privacy, employment, and accounting language against current guidance and your jurisdiction before adoption.
- The worked example row and its scoring in Parts 2 through 4 are composite, built to teach the method. They are not a claim about any named or unnamed vendor.
Primary references for review
Use these as verification starting points. The named reviewer still owns the final interpretation and must confirm that each source is current.
- Association of Fundraising Professionals, Code of Ethical Standards: https://afpglobal.org/ethics/code-ethical-standards
- Association of Fundraising Professionals, A Donor Bill of Rights: https://afpglobal.org/donor-bill-rights
- National Institute of Standards and Technology, AI Risk Management Framework: https://www.nist.gov/itl/ai-risk-management-framework
Through the K-12 Schools lens
Participation-rate strategy, auction ROI, grandparent programs, and working with room parents as volunteers.