Responsible AI for NGOs and Local Organizations
This workbook helps an NGO team turn AI interest into a practical governance conversation. It is not legal advice, a data-protection audit, or a certification instrument.
1. AI Use-Case Map
List the places where staff already use or want to use AI. Start with low-risk support tasks before considering sensitive workflows.
| Workflow | Possible AI support | Data involved | Risk level | Human reviewer |
|---|---|---|---|---|
| Monthly report | Structure notes into a first draft | Internal program notes | Medium | Program manager |
| Proposal review | Check clarity and compliance against a call | Draft proposal and donor call | Medium | Grants lead |
| Safeguarding case notes | Do not use public AI tools | Highly sensitive personal data | High | Safeguarding focal point |
2. Red Lines
Agree what staff should not enter into public AI tools unless an approved, secure, contracted, and internally authorized setup exists.
- Survivor, child protection, GBV, safeguarding, or complaint details.
- Beneficiary lists, personal identifiers, phone numbers, addresses, or case files.
- Unpublished partner records, donor negotiations, HR files, investigation notes, or security-sensitive information.
- Anything the organization could not safely explain to the person, partner, donor, or regulator concerned.
3. Risk Register Starter
| Risk | Example | Control | Owner |
|---|---|---|---|
| Privacy exposure | Staff paste identifiable field notes into a tool | Use anonymized summaries; train staff on red lines | Data focal point |
| Inaccurate output | AI invents a statistic or donor rule | Require source check before use | Document owner |
| Bias or missing context | AI weakens local context or community voice | Review with local staff and evidence holders | Program lead |
| Accountability gap | No one knows who approved AI-supported content | Add a human approval line to the workflow | Team manager |
4. Human Review Checklist
- Does the output match the actual evidence?
- Are all numbers, donor rules, claims, and citations checked against real sources?
- Has sensitive data been removed or protected?
- Could this output create harm if misunderstood or published?
- Who is the named human owner of the final version?
5. Source Basis
This starter material is informed by public responsible-AI and humanitarian data responsibility guidance, including OECD AI Principles, NIST AI Risk Management Framework, IASC Operational Guidance on Data Responsibility in Humanitarian Action, and the EU AI Act regulatory framework. It adapts those ideas into a practical NGO training format.