Skip to main content
Skip to main content
Free · no sign-up · UK English

AI compliance for individuals and small charities

Most AI compliance material is written for organisations with a legal team. This hub is written for the opposite case: one person, or a charity with a handful of staff and volunteers. Everything here is proportionate, free to download, and requires no account.

Downloadable policy templates and logs

Open the Markdown policy in any editor and the CSVs in Excel, Numbers or Google Sheets. Nothing is gated and nothing phones home.

  • AI use policy template

    A two-page policy with permitted uses, prohibited uses, approved tools, oversight, transparency and incident reporting.

    Use it for: The single document a funder, insurer or client will ask to see first.

    Download Markdown
  • AI incident log

    One row per incident: what happened, whether personal data was involved, action taken, root cause and whether it was reported.

    Use it for: Evidencing that you notice and correct AI errors rather than hoping nobody spots them.

    Download CSV
  • Data-source inventory

    Every system, file store and export an AI tool can reach, with refresh cadence.

    Use it for: Answering 'what data can this tool actually see?' before you are asked.

    Download CSV
  • AI controls matrix

    Risks paired with controls, evidence and a test date.

    Use it for: Showing each risk you named has a control somebody owns.

    Download CSV
  • Roles and RACI matrix

    Who approves an AI use case, who operates it and who can stop it.

    Use it for: Small teams where one person quietly holds every role.

    Download CSV

Checklists you can work through in an afternoon

Sole traders and freelancers: the minimum that stands up to scrutiny

You do not need a governance department. You do need written answers to the questions a client, insurer or the ICO would ask.

  • List every AI tool you use for paid work, including free browser tools.
  • Write down which of those tools you will never paste client information into.
  • Check whether you process personal data at all — if you do, confirm whether you need to pay the ICO data protection fee.
  • Add one line to your client contract or terms explaining where you use AI assistance.
  • Name yourself, in writing, as the person accountable for checking AI output before it goes to a client.
  • Keep an incident note whenever an AI output was wrong in a way that reached someone else.
  • Set a date each year to re-read the list, because your tools will have changed.

Small charities: trustee-ready in one meeting

Trustees carry the accountability, so the goal is a short paper they can approve and minute. Everything below fits on two sides.

  • Adopt the AI use policy template and record the approval in the trustee minutes.
  • Decide which beneficiary information is never entered into any AI tool, and say so explicitly.
  • Complete a DPIA before any use of AI involving beneficiary personal data — not after the pilot.
  • Confirm your ICO registration is current and that your privacy notice mentions AI-assisted processing where relevant.
  • Name one trustee as the AI lead and one staff member or volunteer as the operational owner.
  • Brief volunteers: personal accounts used for charity tasks are in scope of the policy.
  • Agree how an AI-related concern reaches the safeguarding lead when a beneficiary may be at risk.
  • Add AI use to the risk register with a review date, and report exceptions to trustees.

Before you pay for any AI tool

Five questions that prevent most of the cost and most of the regret.

  • Where is the data processed and stored, and is that written down anywhere you can keep?
  • Is your input used to train the provider's models, and can you turn that off?
  • Can you export or delete everything if you stop using it?
  • Does the price recur whether or not you use it, and what happens to your work if you cancel?
  • If the tool is wrong about a person, who finds out, and how quickly?

Questions people in small organisations actually ask

Does AI compliance actually apply to individuals and very small organisations?
Data protection law applies regardless of size, so if you process personal data with an AI tool you carry the same duties as a large organisation — lawful basis, transparency, security and a DPIA for higher-risk uses. What scales with size is the paperwork, not the duty. A two-page policy, a tool list and an incident log are usually proportionate for a sole trader or a small charity.
What is the smallest set of documents I should have?
An AI use policy, a list of approved tools with the data each may touch, and an incident log. Add a DPIA for any use involving personal data, and a risk-register entry if you have a board or trustees. All of those are downloadable from this page.
Do I need a DPIA before using an AI assistant?
You need one where the processing is likely to result in a high risk to people — which includes large-scale or systematic use of personal data, decisions with real effects on individuals, and processing data about children or vulnerable people. For general drafting with no personal data, a note in your policy explaining why no DPIA was needed is usually enough. Record the reasoning either way.
Are free AI tools acceptable for charity work?
They can be, provided the policy says what may and may not be entered into them and somebody checks the output. The risk is rarely the price — it is the volunteer who pastes a beneficiary's details into a consumer tool because nobody told them not to.
Do these templates make us compliant?
No template can. They give you the structure and the evidence trail; the compliance comes from the decisions you record in them and from actually following the policy. If your circumstances are complex, take professional advice — these are practical starting points, not legal advice.

Written by Andy Wake, Founder and Managing Director of Automated Governance Systems Ltd. Practical guidance, not legal advice — take professional advice where your circumstances are complex.

Try the demo