An AI governance policy is a board-approved framework that guides the responsible, ethical, and compliant use of AI. Many organizations already use ChatGPT, Microsoft Copilot, Grammarly, AI meeting assistants, and embedded generative AI tools within their daily workflows. In practice, however, AI adoption often outpaces board-approved rules.
That creates a governance gap. Uncontrolled use of AI in the boardroom can expose the organization to legal, reputational, privacy, security, and technology risk within the board’s fiduciary duty of oversight. IBM-cited research from the Institute for Business Value has found that many business leaders view AI explainability, ethics, bias, or trust as barriers to adoption.
This guide explains what an AI governance policy must include, how it differs for nonprofits and corporate boards, and how boards can create one through a practical approval and review process.
Key takeaways
- An AI governance policy framework outlines the process for selecting, approving, using, monitoring, and reviewing AI systems.
- Boards should treat AI governance and policy as part of risk oversight, not as a narrow IT project.
- A robust policy should cover AI ethics, data governance, risk classification, compliance, accountability, human oversight, review cycles, and incident escalation procedures.
- Charity boards need an AI policy for nonprofits that addresses donor data, beneficiary information, grant compliance, and mission trust.
- Public company boards may need documentation to support AI-related disclosure, internal controls, and board risk oversight where AI use or AI-related risks are material.
- An AI governance policy template helps boards formalize approval, improve version control, and simplify annual review.
What is an AI governance policy?
An AI governance policy is a board-approved document that defines how an organization uses artificial intelligence responsibly across its operations.
In practice, it covers the full AI lifecycle: procurement, approval, deployment, monitoring, employee use, vendor review, incident handling, and decommissioning. It applies to custom-built systems, third-party platforms, embedded AI features, and general-purpose tools used by staff, volunteers, executives, or board members.
At the board level, one common mistake is confusing an AI strategy with an AI policy. AI strategy defines which tools the organization wants to adopt and why. AI governance and policy, by contrast, define how those tools are used safely, fairly, and lawfully.
That distinction matters because each use case carries different risks. AI-supported fundraising, meeting summaries, and predictive analytics may all seem practical, but they require different controls.
Data governance is one part of the policy, while the broader scope also encompasses transparency, accountability, fairness, bias mitigation, human review, vendor assurance, and regulatory compliance.
Why boards must own AI governance, not just IT
Boards bear fiduciary responsibility for AI governance because AI decisions carry legal, reputational, and ethical risks that fall within the board’s duty of care.
AI may start as a technology tool, but its impact does not stay inside IT. It can affect privacy, employment decisions, donor trust, customer outcomes, board confidentiality, disclosure controls, and the way leaders make decisions.
That is why board AI governance belongs with the board. Directors do not need to manage every technical detail, but they do need to oversee how AI risk is identified, reviewed, controlled, and documented.
This connects directly to fiduciary duty technology risk. BoardSource guidance frames risk management as a board and executive responsibility, including setting the tone and ensuring proper processes are in place.
For boards still building the basics of oversight, this also reflects the broader importance of corporate governance: clear roles, informed decisions, documented review, and accountable leadership.
The risk profile depends on the organization:
- For nonprofits. AI tools used with donor data, grant applications, or beneficiary information may create privacy and compliance obligations under GDPR, state charity laws, grant terms, or sector-specific rules.
- For public company boards. AI governance can affect SEC disclosures, proxy-season questions, internal controls, and investor confidence, especially where AI is material to strategy, operations, or risk.
- For organizations operating in or serving the EU. The EU AI Act raises the stakes. Certain violations, including prohibited AI practices, can lead to penalties of up to €35 million or 7% of global annual turnover.
Key elements of an AI governance policy
Key elements of an AI governance policy provide the board with a clear structure for approving, controlling, and reviewing AI use.
- Purpose and scope
Define why the policy exists, which AI tools it covers, and which teams, vendors, board committees, volunteers, or subsidiaries must follow it. The scope should include commercial tools, AI features inside existing software, and internally developed AI applications. - Ethical principles
State the organization’s standards for responsible AI, fairness, non-discrimination, transparency, accountability, human oversight, and mission or business alignment. - Data governance
Explain what data may be used with AI tools and what data is prohibited. For example, include personal data, donor data, employee data, beneficiary data, financial records, board materials, trade secrets, confidential legal information, and intellectual property. - Risk classification
Classify AI use cases by risk level. A low-risk use case may involve drafting internal meeting reminders. A high-risk use case may involve employment screening, grant eligibility, beneficiary assessment, investment analysis, healthcare-related decisions, or automated decision support. Boards can align this section with the NIST AI RMF and the EU AI Act’s risk-based approach. - Accountability and roles
Assign responsibility for approval, monitoring, reporting, and policy review. The policy should name the accountable staff lead, the board committee responsible for AI oversight, and the decision rights for sensitive or high-risk use cases. - Compliance requirements
Map AI use to applicable laws and standards. Depending on the organization, this may include GDPR, CCPA, the EU AI Act, HIPAA, where the organization is a covered entity, business associate, or otherwise subject to healthcare privacy obligations, employment law, consumer protection rules, grant terms, data protection obligations, and sector-specific regulations. - Review cycle
Set a fixed review cadence. Annual review is a reasonable minimum. The policy should also require a review after major AI incidents, adoption of new tools, regulatory changes, merger activity, or significant changes in organizational data use. - Incident response and escalation
Define what happens when AI produces harmful, inaccurate, biased, or unauthorized output. The process should identify who investigates the case and leads its resolution, and how corrective action is documented.
AI governance policy requirements: nonprofit vs corporate boards
Nonprofit and corporate boards need the same core policy elements, but their risk drivers differ.
For example, a nonprofit board usually focuses on mission trust, donor data, grant compliance, and beneficiary protection.
By contrast, a corporate board usually prioritizes investor disclosure, internal controls, customer impact, and regulatory exposure.
Here are the main differences:
| Dimension | Nonprofit boards | Corporate boards |
|---|---|---|
| Primary regulatory driver | State charity laws, donor privacy expectations, grant terms, GDPR, where relevant, and sector-specific rules | Securities disclosure, internal controls, privacy law, employment law, and industry regulation |
| Data sensitivity | Donor records, beneficiary information, volunteer data, and health or community-service data | Customer data, employee records, financial data, proprietary models, and operational data |
| Board oversight mechanism | Governance committee, risk committee, technology committee, or full board review | Audit committee, risk committee, technology committee, or board-level AI oversight process |
| Key stakeholders | Donors, beneficiaries, grantors, staff, volunteers, regulators, and community partners | Shareholders, customers, employees, regulators, investors, vendors, and auditors |
| Consequence of non-compliance | Loss of trust, grant risk, privacy complaints, mission harm, and governance scrutiny | Enforcement risk, disclosure risk, litigation, financial loss, and reputational damage |
| Policy emphasis | AI policy for nonprofits, donor trust, accessibility, and staff and volunteer guidance | AI compliance, internal controls, risk reporting, vendor assurance, and disclosure readiness |
Boards overseeing AI should align the policy with the role of ESG and the board of directors, especially where AI affects fairness, transparency, workforce decisions, or stakeholder trust
Here is a step-by-step guide for drafting an AI governance policy from scratch.
Step 1. Conduct an AI audit
Inventory every AI tool currently used across the organization. Include free tools, browser extensions, meeting assistants, board portal features, CRM tools, fundraising platforms, document review software, and AI functions inside existing systems.
Step 2. Classify risk by use case
Map each tool to a risk tier. Low-risk tools may support internal drafting or summarization. Medium-risk tools may process internal documents or stakeholder communications. High-risk tools may affect people, eligibility, employment, healthcare, financial decisions, or legally significant outcomes.
Step 3. Assign governance ownership
Designate a board committee and staff owner. Many organizations assign this to the audit, risk, governance, or technology committee. Smaller nonprofits may retain oversight by the full board while still assigning a management lead.
Step 4. Draft the policy elements
Use the eight core elements above. An AI governance policy template should include purpose, scope, ethical principles, data rules, risk classification, accountability, compliance requirements, review cadence, and escalation procedures.
Step 5. Review and approve at the board level
The full board should review the draft, ask risk-based questions, and formally approve the final policy. Approval should be recorded in the minutes, including the motion, vote, and review cycle.
Step 6. Communicate the policy
Staff, executives, volunteers, and relevant vendors should understand what the policy allows and prohibits. Anyone using AI tools should acknowledge the policy and know when to escalate concerns.
Step 7. Build an AI review into the board calendar
Add AI governance to the annual board work plan. The policy should be reviewed at least once per year and whenever the organization adopts a new high-risk AI tool.
Step 8. Evaluate policy effectiveness
AI governance should improve over time. Boards can use board evaluations and self-assessments to assess whether directors understand AI risk, ask informed questions, and receive adequate reporting.
How boards document AI governance decisions in meeting minutes
For board oversight of AI governance, the record should show that the board received appropriate information, considered relevant risks, and approved or amended the policy through a formal process.
When a board adopts, reviews, or updates an AI governance policy, that decision should be recorded in the board meeting minutes, including the motion made, the vote result, and any noted dissent or conditions. The record should show that directors received the relevant materials, considered the main AI risks, and approved the policy or amendment through a formal board process.
Boards should document:
- AI governance policy adoption, review, or amendment
- AI tool adoption approvals
- AI-related risk assessments presented to the board
- AI incidents escalated to the board level
- Vendor, privacy, or data protection concerns
- Changes to review cadence or committee ownership
- Restrictions on AI use in board meetings or confidential documents.
A sample minutes entry may read:
| “[Name] moved to adopt the AI Governance Policy as presented. The motion was seconded by [Name]. The board approved the policy by [unanimous/majority] vote. The policy will be reviewed annually or upon adoption of any new AI system.” |
This level of detail helps create a clear governance record without turning minutes into a transcript.
For broader guidance on what to include, boards can follow established board meeting minutes best practices: record the decision, the materials reviewed, the key risks considered, and the action agreed upon
Boards should also address AI meeting assistants within the same policy. Transcription tools, AI-generated summaries, and automated minutes software may process confidential board discussions, so their use should be approved, restricted, or prohibited under the AI governance policy. The policy should explain when these tools may be used, who can access outputs, how long records are retained, and whether sensitive board discussions are excluded.
A board management platform like Ideals Board can help boards store the AI governance policy in the document repository, set review reminders as action items, and record governance decisions in structured meeting minutes.
Teams that need tighter control over sensitive board materials can also use board document management software to keep policies, minutes, approvals, and review records organized in a single secure place
AI governance frameworks boards should know
These references give directors a practical starting point for policy design, risk classification, and board reporting.
- NIST AI RMF (2023). The NIST AI risk management framework is a voluntary U.S. framework built around four functions: Govern, Map, Measure, and Manage. Boards can use it to structure AI oversight, risk reporting, and policy review.
- EU AI Act (2024, enforcing 2025–2026). The EU AI Act is the world’s first comprehensive, binding AI law that classifies AI systems by risk level: unacceptable, high, limited, and minimal. Boards should assess whether their organization falls within the EU AI Act’s scope as a provider, deployer, importer, distributor, product manufacturer, authorized representative, or non-EU provider/deployer whose AI system output is used in the EU.
- OECD AI Principles (updated 2024). The OECD AI Principles (adopted in 2019 and updated in 2024) provide an international consensus on trustworthy AI among OECD members and partner countries. They are useful for international boards that need a common reference point for fairness, privacy, transparency, accountability, and human-centered AI governance.
- ISO/IEC 42001 (2023). ISO/IEC 42001 is the first international AI management system standard. It is useful for organizations that want a structured, certification-ready approach to AI governance.
AI governance policy for nonprofits: unique considerations
For nonprofits, AI ethics policy and governance should start with donor data. AI tools used in fundraising, donor screening, or wealth analytics may process sensitive personal information. Without clear rules, the organization can create privacy risk and lose donor trust.
Grant compliance is becoming another concern. Some foundations and government grantors are starting to ask how applicants use AI in research, writing, evaluation, or program delivery. The policy should explain when the use of AI must be disclosed and who approves that disclosure.
Boards should also document AI oversight as part of their accountability record. For example, IRS Form 990 does not currently require a separate AI governance disclosure, but minutes, policy approvals, and annual reviews can show that the board treats AI as a governance issue.
AI oversight may also connect to ESG compliance, reporting, stakeholder governance, or sustainability commitments when AI affects fairness, accessibility, stakeholder trust, or service delivery.
Boards should pay particular attention to:
- Approving AI tools without a risk classification process.
- Allowing staff to enter confidential, donor, beneficiary, or board data into public AI tools.
- Using AI-generated board minutes without reviewing confidentiality controls.
- Delegating all AI decisions to IT without board-level risk oversight.
- Writing a policy that mentions ethics but has no approval, monitoring, or escalation process.
- Ignoring embedded AI features inside existing software.
- Failing to review vendor terms, data retention, and model training practices.
- Treating agentic AI governance as a future issue when autonomous tools are already appearing in workflow software.
Conclusion
An AI governance policy is becoming a practical governance expectation for boards as AI becomes embedded in operations, board work, donor management, compliance, and decision support.
A well-drafted AI governance policy framework helps directors bring structure to AI oversight, improve decision-making, and manage risk as AI tools evolve.
For boards ready to move from discussion to documentation, use the AI governance policy template as a starting point.
Ideals Board can support the governance workflow by helping boards store policies, manage versions, track action items, and maintain a clear record of AI oversight decisions in a secure board portal.