30 Days Gen AI Risk Trial -Start Now
Skip to main content
Charity AI risk assessment

Assess the use case. Not just the tool.

A charity AI risk assessment should examine the intended outcome, people affected, donor or beneficiary data, decision impact, vendor handling, human oversight and evidence. Score the specific use case before approval, apply critical-risk overrides for sensitive or consequential work, assign an owner, and record controls and residual risk. This template provides a practical Australian NFP workflow.

Practical NFP resource
Reviewed
1Define one use case
2Score six dimensions
3Apply overrides

For Australian organisations

For charity risk, privacy, security, program and procurement teams reviewing a proposed AI use before deployment or renewal.

Reviewed: 14 August 2026Australian context | General guidance, not legal advice

What the key terms mean

Inherent risk

The risk before controls are applied.

Residual risk

The risk that remains after controls are designed and verified.

Consequential use

A use that may materially affect a person's access, rights, safety, opportunities or treatment.

Law and recommended practice

Legal position: applicable privacy, discrimination, employment, consumer, safeguarding and sector laws depend on the use case. Recommended practice: this score is a triage aid, not a legal determination or a substitute for specialist assessment.

A practical implementation workflow

Use this sequence to turn the resource into an owned, reviewable process rather than a document that sits on a shared drive.

1

Define one use case

Write the purpose, user, people affected, input, output and real-world action. Do not assess a vendor in the abstract.

Output: one-sentence use case and accountable owner

2

Score six dimensions

Score people, data, decision impact, vendor exposure, human oversight and evidence from 0 to 3 using the rubric below.

Output: inherent score from 0 to 18

3

Apply overrides

Escalate even when the total looks low if the use involves vulnerable people, sensitive information, automated eligibility or an unapproved public tool.

Output: risk tier and required approver

4

Verify controls

Name the evidence that proves each control works, then rescore residual risk and set a review trigger.

Output: decision, conditions, evidence and review date

Six-dimension assessment rubric

Score each dimension 0 to 3. Document why, not only the number. Total the inherent score, then apply the override rules in the decision table.

1. People and potential harm

0: no identifiable person affected. 1: staff support or low-impact public content. 2: service users or donors may be affected. 3: children, people with disability, people in crisis or another group may face material harm.

  • Who experiences the output?
  • Can they understand or challenge it?
  • Could error cause exclusion, stigma, distress or safety impact?

2. Data sensitivity

0: public or synthetic data. 1: internal non-personal data. 2: personal or confidential information. 3: sensitive information, detailed case data, credentials or a large linked dataset.

  • List every prompt, file, integration and output.
  • Check whether a person remains reasonably identifiable.
  • Record retention, training and access terms.

3. Decision impact

0: brainstorming only. 1: drafting with routine review. 2: recommendation influences a person or allocation. 3: AI makes or materially shapes eligibility, safeguarding, employment, grants or service access.

  • Name the final human decision-maker.
  • Describe what happens if the output is wrong.
  • Provide a challenge and correction path.

4. Vendor and deployment exposure

0: controlled internal system with assessed terms. 1: approved enterprise service. 2: new vendor, integration or uncertain subprocessors. 3: public account, unclear terms, external action-taking or broad system access.

  • Identify account tier and contractual terms.
  • Check storage location and overseas disclosures.
  • Review security, incident and deletion arrangements.

5. Human control

0: no operational output. 1: named reviewer with time and skill. 2: review exists but criteria or authority are weak. 3: automation bias is likely or meaningful intervention is not practical.

  • Give reviewers a checklist and authority to reject output.
  • Measure overrides and missed errors.
  • Avoid rubber-stamp review.

6. Evidence and monitoring

0: logged, tested and monitored. 1: records and acceptance tests exist. 2: partial logging or unclear success measures. 3: no reproducible test, record or incident signal.

  • Define acceptable quality before launch.
  • Retain decisions, versions and material changes.
  • Set monitoring thresholds and a stop condition.

Decision thresholds and override rules

The additive score supports consistent triage. Overrides prevent a low score in one area from hiding a critical exposure in another.

ResultDefault decisionGovernance action
0 to 5: LowApprove with ownerRecord the use and review on material change
6 to 10: ModerateConditional approvalAdd controls, evidence and a scheduled review
11 to 14: HighEscalatePrivacy, security and accountable executive review
15 to 18: CriticalDo not deploy yetRedesign, obtain specialist review and board visibility where material
Critical overrideTreat as high or criticalSensitive data in public AI, no meaningful human control, or material impact on vulnerable people

Keep the assessment connected to actual AI use

Aona can support the operational controls around an assessment by showing which AI tools the workforce uses, guiding users to approved services, applying prompt and file controls, and providing evidence for reviews. The organisation remains responsible for impact analysis, approvals and human decisions.

Compare the approved inventory with observed workforce use.

Apply policies by tool and data type.

Identify exceptions that require reassessment.

Bring usage evidence into periodic risk review.

See how the Aona platform works
Questions from NFP teams

Frequently asked questions

Assess both the service and each materially different use case. The same account may be low risk for drafting a public event description and high risk for reviewing beneficiary files. Reassess when the purpose, data, integration, model, terms or affected people change.
Put the guidance into practice

See and govern AI use across your workforce

Aona helps not-for-profits discover AI use, guide teams to approved tools, protect sensitive information and bring evidence into governance reviews.