Skip to main content
Insightful AI

AI Ethics and Governance

How a charity board evidences that its AI policy is being followed

Your board has an AI policy. How does it know anyone follows it? What the Charity Governance Code, the Charity Commission, the Fundraising Regulator and the ICO say, and six questions to ask your executive team.

Ben Sefton · Co-founder, Insightful AI · · 10 min read

On this page
  1. 1.Most charities use AI. Few boards look at it
  2. 2.What the Code and the regulators actually say
  3. 3.Why the policy itself evidences nothing
  4. 4.The questions to ask, and what each should produce
  5. 5.What a small charity can produce without an IT team
  6. 6.What boards ask for that is hard to supply
  7. 7.Where this stops and your own adviser starts
  8. 8.What to put on the next agenda

Most charities use AI. Few boards look at it

Across the sector, 79% of charities are using artificial intelligence (AI). Of all charities, 38% are using it actively or strategically, up from 25% the year before. Asked what steps they had taken, 7% said their board regularly reviews AI use and risks. Another 6% had risk assessed their AI use cases.

The figures above come from the Charity Digital Skills Report 2026 (opens in a new tab), answered by the same 807 charities. They answer two of its questions: what stage of AI adoption an organisation has reached, and what steps it has taken. None of them is calculated from another.

The report ran from 5 March to 20 April 2026. It is open to any UK not-for-profit and respondents choose to take part, so the figures describe the charities that answered.

Two other figures in the steps question are worth reporting carefully. Reviewing data protection, security and safeguarding came in at 19%, which the report records as a fall from 36% the year before. Updating the risk register came in at 15%, down from 23%. The report says it was surprised by the first and calls the second worrying.

The report also notes that its respondent base shifted towards small charities this year. Small charities are much less likely to have taken any of these steps. The report does not connect the two, so treat both falls as recorded observations rather than proof that charities stopped checking.

This article covers England and Wales and reports Charity Commission material. Scottish charities will find no AI guidance from OSCR. Its November 2025 news statement (opens in a new tab) points the third sector at the Scottish Government’s cyber resilience framework.

Northern Irish charities will find none from the Charity Commission for Northern Ireland either. Its fundraising guidance (opens in a new tab) dates from 2024 and its serious incident reporting guide (opens in a new tab) from 2022. Neither mentions AI.

So do not assume the position below carries across the border. Neither regulator has published AI-specific guidance that we could find.

If your board has written an AI policy, you’ve done more than half the sector. You still have no way of knowing whether anyone follows it. No UK regulator sets out an evidence pack that answers that question. What the Code and the regulators do supply is the assurance routes your board already uses.

What the Code and the regulators actually say

Nothing below requires a charity to hold AI evidence. One voluntary code names an AI policy as suggested evidence. One regulator recommends keeping records of checks and decisions, in one defined area of charity work. If your board cannot tell those apart, it will defend a choice as though it were a duty. Or drop a duty, thinking it was a choice.

The Charity Governance Code

The Charity Governance Code 2025 (opens in a new tab) lists ‘A policy for the use of technology and AI tools’. It appears on page 35, under Principle 6, Managing resources and risks, in the suggested evidence and assurance list. It sits between a range of policies for staff and volunteers and a fundraising policy.

That single line is the whole of the Code’s treatment of AI. It appears nowhere else across the eight principles.

The Code also states on page 3 that compliance with it is not a regulatory requirement. It is charity law, the Commission and other regulators that tell a charity what it must do. So a technology and AI policy is something a board can hold up as evidence of good governance.

The Charity Commission

The Commission set out its position in a blog post on charities and AI (opens in a new tab) on 2 April 2024, rather than in formal guidance. It says trustees stay responsible for decision making, and that the process must not be delegated to AI. A charity must not rely on AI-generated content alone for a critical decision. The Commission will expect charities to ensure ‘human oversight is in place to prevent material errors’.

On its own plans, the Commission said in April 2024 that it did not anticipate producing new AI-specific guidance. It preferred trustees to apply existing guidance as new technology appears. So the blog is both the current published position and the only one.

Read the date carefully. That post cites the 2023 Charity Digital Skills Report, where 35% of charities reported using AI. The 2026 report puts it at 79%.

The Fundraising Regulator

The Fundraising Regulator published guidance on using AI in fundraising (opens in a new tab) in December 2025. It recommends a risk assessment proportionate to the intended use, carried out before any AI tool is used. It recommends an agreed AI policy, published on the charity’s website. It holds the charity accountable for AI output, including output from third-party fundraisers.

One recommendation goes further than anything else in this article. The guidance advises charities to keep a record of the checks they carry out and the decisions they make about AI content. That record is there so the charity can justify those decisions if a complaint arrives or the regulator investigates.

It is the closest a UK regulator comes to telling a charity to hold evidence of its own AI use. It applies to fundraising. It does not reach AI used in casework, human resources or administration.

The Information Commissioner’s Office

UK data protection law restricts decisions made solely by automated means where they have legal or similarly significant effects on a person. Where a decision is not solely automated, the ICO says the human involvement has to be meaningful. The reviewer needs to be actively involved, competent to understand what the system produced, and able to change the outcome.

The ICO is direct about what does not count. Its guidance on AI and individual rights (opens in a new tab) says that a person rubber-stamping a decision does not take that decision outside these rules. The ICO flags that guidance as under review, because the law on automated decisions changed on 5 February 2026.

Regulations in force from 12 May 2026 (opens in a new tab) require the ICO to prepare a code of practice. It covers good practice in handling personal data when developing and using AI, and in automated decision-making. It must also cover children’s personal data.

No code has been published. The ICO lists its related guidance on automated decision-making and profiling (opens in a new tab) as still in drafting. A final version is due in winter 2026, and the ICO says that work will feed the code. Until the code lands, your duties come from existing data protection law and ICO guidance.

Why the policy itself evidences nothing

A written policy is a document. It tells your board that a document exists.

The Code lists it under evidence and assurance because it shows the governance structure is there. That’s not the same as showing anyone behaves differently on a Tuesday afternoon with a deadline approaching. Across the same report, 51% of charities have no AI policy at all, and 18% have a formal one.

Boards we work with reach this point quickly. The question they ask is not how to write the policy. It’s how to see whether the policy changed anything.

The questions to ask, and what each should produce

Six questions, each with the artefact it should produce, and a column naming where the expectation comes from. Where that column names our analysis, the row is our judgement rather than a regulator’s requirement.

Only one of these six rests wholly on a regulator. That is the point of the column.

The first row decides whether the rest of the table works. The tools a board does not know about are the ones the policy was written for.

Two terms in the table need a word of explanation. A data protection impact assessment is a written record of how a project uses personal data and what could go wrong with it. A nil return is a recorded answer of nothing to report, which is different from a blank.

Question a trustee asks Evidence it should produce Named by
Which AI tools are in use, including the ones nobody bought? A tool register covering staff-chosen tools as well as paid ones Our analysis
Where does AI touch personal or beneficiary data? A data protection review, a data protection impact assessment, or a recorded decision that one was not needed ICO, and our analysis
Who checked the output before we relied on it? Named reviewer, date, and what was changed Our analysis, on Charity Commission and ICO expectations
Where does AI touch fundraising? A risk assessment predating first use, and a record of the checks and decisions on AI content Fundraising Regulator
What has gone wrong? An incident and near-miss log, including a nil return Our analysis
When did the board last look at any of this? A standing agenda item with a nil-report option Our analysis, on Charity Governance Code Principle 6

What a small charity can produce without an IT team

Four of the six rows need a spreadsheet and a standing agenda item.

The register can be a single sheet with the tool, the owner, what it is used for and what data it touches. The incident log can sit on the same sheet. The agenda item needs a nil-report option, so that ‘nothing this quarter’ is a recorded answer instead of a gap. The rule about personal data can be one line in the policy you already have.

Training records are the fifth item, and most charities already keep them for other reasons. Tie them to the tools on the register rather than to a general session on AI awareness.

Size drives the difference. Of all charities, 44% have taken none of the listed steps. Among small charities that rises to 55%, against 15% of large ones.

The Fundraising Regulator frames its own expectations as proportionate to the risk. That gives a small charity room to scale the effort to the use.

What boards ask for that is hard to supply

Three patterns come up across charity governance reviews, and none of them is fixed by the policy document.

Staff use consumer AI tools despite a policy existing. The tools are free, they’re on a phone, and the work still has to go out. A register that only lists paid licences will miss this entirely.

Records get copied out of a database onto a local drive, where a connected assistant can index them. The charity’s data controls were designed around the database. The copy sits outside them.

Boards want a verification step around AI output before anyone relies on it. They also want training that tests behaviour rather than recall. A completion certificate shows someone sat through a session. It does not show what they would do with a beneficiary’s details and a bid deadline.

The Charity Commission for Northern Ireland writes that verification step into its own customer charter (opens in a new tab) of 31 March 2026. Staff review AI-assisted outputs before they go out, and decisions stay human decisions. That’s a regulator describing its own practice rather than telling charities what to do. It’s still the clearest short version of the control we’ve seen written down.

We have not found published guidance that addresses how a board tests any of this in practice. That gap is why the last row of the table asks when the board last looked, rather than whether a policy exists.

Where this stops and your own adviser starts

Four questions sit beyond what an article can answer. Put them to your own adviser or your data protection lead.

Does a particular use in our charity count as a decision made solely by automated means? Is a data protection impact assessment legally required for this processing? What does trustee responsibility for AI risk amount to in our circumstances, given what we hold and who we serve? What will the ICO’s code require of us when it is published?

Anyone who answers those from a blog post is guessing about your charity.

What to put on the next agenda

Ask for two things before the next meeting. The tool register, and the answer to the last row of the table.

If the register comes back as a list of what the charity has paid for, that is your first finding, not a good result. If the answer to the last row is that the board has never looked, minute that as a finding.

For the risks themselves, our guide to AI ethics for UK charities sets out what to watch for. If you want help building the assurance route rather than the policy, our AI ethics and governance work with charities starts there. Book a free discovery call.

Back to top

AI ethics & governance

79% of UK charities now use AI, yet half have no AI policy at all, rising to 62% among small charities (Charity Digital Skills Report 2026). Across Europe, staff in most organisations are now using generative AI at work, yet only 31% have a formal, comprehensive AI policy to govern it. Governance does not restrict AI adoption; it makes adoption sustainable. This service is particularly relevant to charities, public sector teams, and any SME handling sensitive client or beneficiary data.

Read more

Ready to put this into practice?

Book a free 30-minute discovery call. Tell us where you are with AI and we will tell you where to start.

Book a free discovery call