Assess the use case.
Not just the tool.
A charity AI risk assessment should examine the intended outcome, people affected, donor or beneficiary data, decision impact, vendor handling, human oversight and evidence. Score the specific use case before approval, apply critical-risk overrides for sensitive or consequential work, assign an owner, and record controls and residual risk. This template provides a practical Australian NFP workflow.
For Australian organisations
For charity risk, privacy, security, program and procurement teams reviewing a proposed AI use before deployment or renewal.
What the key terms mean
Inherent risk
The risk before controls are applied.
Residual risk
The risk that remains after controls are designed and verified.
Consequential use
A use that may materially affect a person's access, rights, safety, opportunities or treatment.
Law and recommended practice
Legal position: applicable privacy, discrimination, employment, consumer, safeguarding and sector laws depend on the use case. Recommended practice: this score is a triage aid, not a legal determination or a substitute for specialist assessment.
A practical implementation workflow
Use this sequence to turn the resource into an owned, reviewable process rather than a document that sits on a shared drive.
Define one use case
Write the purpose, user, people affected, input, output and real-world action. Do not assess a vendor in the abstract.
Output: one-sentence use case and accountable owner
Score six dimensions
Score people, data, decision impact, vendor exposure, human oversight and evidence from 0 to 3 using the rubric below.
Output: inherent score from 0 to 18
Apply overrides
Escalate even when the total looks low if the use involves vulnerable people, sensitive information, automated eligibility or an unapproved public tool.
Output: risk tier and required approver
Verify controls
Name the evidence that proves each control works, then rescore residual risk and set a review trigger.
Output: decision, conditions, evidence and review date
Six-dimension assessment rubric
Score each dimension 0 to 3. Document why, not only the number. Total the inherent score, then apply the override rules in the decision table.
1. People and potential harm
0: no identifiable person affected. 1: staff support or low-impact public content. 2: service users or donors may be affected. 3: children, people with disability, people in crisis or another group may face material harm.
- Who experiences the output?
- Can they understand or challenge it?
- Could error cause exclusion, stigma, distress or safety impact?
2. Data sensitivity
0: public or synthetic data. 1: internal non-personal data. 2: personal or confidential information. 3: sensitive information, detailed case data, credentials or a large linked dataset.
- List every prompt, file, integration and output.
- Check whether a person remains reasonably identifiable.
- Record retention, training and access terms.
3. Decision impact
0: brainstorming only. 1: drafting with routine review. 2: recommendation influences a person or allocation. 3: AI makes or materially shapes eligibility, safeguarding, employment, grants or service access.
- Name the final human decision-maker.
- Describe what happens if the output is wrong.
- Provide a challenge and correction path.
4. Vendor and deployment exposure
0: controlled internal system with assessed terms. 1: approved enterprise service. 2: new vendor, integration or uncertain subprocessors. 3: public account, unclear terms, external action-taking or broad system access.
- Identify account tier and contractual terms.
- Check storage location and overseas disclosures.
- Review security, incident and deletion arrangements.
5. Human control
0: no operational output. 1: named reviewer with time and skill. 2: review exists but criteria or authority are weak. 3: automation bias is likely or meaningful intervention is not practical.
- Give reviewers a checklist and authority to reject output.
- Measure overrides and missed errors.
- Avoid rubber-stamp review.
6. Evidence and monitoring
0: logged, tested and monitored. 1: records and acceptance tests exist. 2: partial logging or unclear success measures. 3: no reproducible test, record or incident signal.
- Define acceptable quality before launch.
- Retain decisions, versions and material changes.
- Set monitoring thresholds and a stop condition.
Decision thresholds and override rules
The additive score supports consistent triage. Overrides prevent a low score in one area from hiding a critical exposure in another.
| Result | Default decision | Governance action |
|---|---|---|
| 0 to 5: Low | Approve with owner | Record the use and review on material change |
| 6 to 10: Moderate | Conditional approval | Add controls, evidence and a scheduled review |
| 11 to 14: High | Escalate | Privacy, security and accountable executive review |
| 15 to 18: Critical | Do not deploy yet | Redesign, obtain specialist review and board visibility where material |
| Critical override | Treat as high or critical | Sensitive data in public AI, no meaningful human control, or material impact on vulnerable people |
Keep the assessment connected to actual AI use
Aona can support the operational controls around an assessment by showing which AI tools the workforce uses, guiding users to approved services, applying prompt and file controls, and providing evidence for reviews. The organisation remains responsible for impact analysis, approvals and human decisions.
Compare the approved inventory with observed workforce use.
Apply policies by tool and data type.
Identify exceptions that require reassessment.
Bring usage evidence into periodic risk review.
Primary Australian sources
Use these official sources alongside advice specific to your organisation and sector.
ACNC duties of Responsible People
Official guidance on care, diligence, information and responsible management.
Open official sourceOAIC AI privacy guidance
Due diligence, privacy impact and human oversight considerations.
Open official sourceAustralian Government Guidance for AI Adoption
Voluntary practices covering accountability, risk, transparency, testing and human control.
Open official sourceFrequently asked questions
See and govern AI use
across your workforce
Aona helps not-for-profits discover AI use, guide teams to approved tools, protect sensitive information and bring evidence into governance reviews.
Continue through the NFP governance cluster
AI governance for NFPs
Set accountability and approval thresholds for the assessment process.
NFP AI policy template
Turn assessment decisions into workforce rules.
ChatGPT and community data guide
Apply the assessment to a common frontline workflow.
AI governance risk pillar
Connect use-case assessments to a wider risk program.