Trustee AI Oversight Assessment
Methodology & Standards Mapping
Every question in this assessment is grounded in a named source, not house opinion. This page shows which, for all twenty-six questions across the free screener and the full assessment: the duty it tests, the exact source it is drawn from, and why it is included.
| Question | Source | Why included |
|---|---|---|
| Named Accountability | ||
| One specific trustee, or a small group, is written down as being in charge of AI, not just "the board." | Charity Governance Code 2025 | Moves "one trustee owns AI" from a claim to something evidenced. Unwritten ownership isn't ownership if it's ever questioned. |
| The board has formally discussed AI risks and recorded the outcome. | Charity Commission trustee duties (Essential Trustee, CC26) | Distinguishes a trustee who happens to use AI personally from a board that has actually considered the risk as a board. |
| AI is listed by name on our risk register, not lumped in with general IT risk. | Charity Commission trustee duties (Essential Trustee, CC26) | Charity Commission guidance expects risks to be tracked individually. AI buried inside "IT risk" usually means nobody is actively watching it. |
| At least one trustee has had some training on what AI means for their responsibilities as a trustee. | Charity Governance Code 2025 | Different from staff learning how to use a tool. This checks a trustee understands what they're accountable for, not how to operate ChatGPT. |
| Transparency & Disclosure | ||
| We have a written AI policy that covers every AI tool we use, not just the obvious ones like ChatGPT. | Charity Excellence AI Governance & Ethics Framework | Charities often write a policy for the AI they notice and miss AI already built into their CRM, fundraising platform, or accounting software. |
| We tell beneficiaries or donors when AI is involved in something that affects them. | Charity Excellence AI Governance & Ethics Framework | Sector guidance expects disclosure where AI touches services or communications people receive, not just internal admin use. |
| Our AI policy has a scheduled review date. | Charity Governance Code 2025 | A policy written once and never revisited ages badly against a fast-moving technology. |
| Data Protection & Safety | ||
| We know the legal reason we're allowed to put people's personal data into an AI tool. | ICO guidance on AI and data protection | Data protection law calls this a "lawful basis." Without one, the charity can't show the processing is legal if challenged. |
| We've checked whether any of our AI tools need a more detailed data protection risk assessment. | ICO guidance on AI and data protection | This detailed check is called a DPIA. The question here is whether the need for one has even been considered, which most charities haven't done. |
| We have signed agreements with our AI suppliers covering how they handle our data. | ICO guidance on AI and data protection | Called a Data Processing Agreement (DPA). It makes the charity's data protection duties binding on the supplier too, not just assumed. |
| Only approved AI tools are used. | Charity Excellence AI Governance & Ethics Framework | Unvetted tools, picked up informally by staff, are the most common source of avoidable data exposure. |
| Fairness & Safeguarding | ||
| We've checked our AI use doesn't unfairly affect children, women, or other vulnerable groups we work with. | Charity Excellence AI Governance & Ethics Framework | Named specifically rather than a generic "vulnerable adults" box, which is easy to tick without real thought. |
| Potential impacts on beneficiaries have been considered before using AI. | Charity Commission trustee duties (Essential Trustee, CC26) | Deliberately not "we asked beneficiaries." This scales the question to what's actually reasonable to expect. |
| If we use AI-generated images, we have safeguards against deepfakes or misleading pictures. | Charity Commission trustee duties (Essential Trustee, CC26) | A specific, current risk flagged by the Charity Commission and the sector press. Skipped entirely, not scored as a gap, for charities that don't use AI imagery at all. |
| Redress & Human Oversight | ||
| There's a clear way for someone to complain or raise a concern if AI causes a problem. | Charity Excellence AI Governance & Ethics Framework | Tests whether this is a real, named process a beneficiary or donor could actually use, not an assumption someone would just complain. |
| We keep records of important AI-assisted decisions. | Charity Excellence AI Governance & Ethics Framework | Deliberately "important decisions," not every interaction. |
| Staff and volunteers know how to spot AI problems, like fake images, impersonation, or factual mistakes. | Charity Excellence AI Governance & Ethics Framework | Redress only works if the people closest to beneficiaries can actually recognise a problem when it happens. |
| Ongoing Review | ||
| The AI policy and risk assessment have a confirmed next review date. | Charity Governance Code 2025 | Turns "we reviewed it once" into an ongoing commitment rather than a one-off box-tick. |
| A spot-check process exists to confirm actual AI use matches the written policy. | Charity Governance Code 2025 | Policies drift from practice quickly. This is the only question in the set that checks reality against the document rather than the document's existence. |
| The charity could produce a funder- or Commission-ready summary of AI tools and data flows within 48 hours. | Charity Commission trustee duties (Essential Trustee, CC26) | The practical test of everything above. If the other answers are genuinely true, this one should already be easy. |
| Named Accountability (free screener) | ||
| One named trustee owns oversight of AI. | Charity Governance Code 2025 | Tests whether responsibility sits with a specific, named trustee or sub-committee, not "the board generally." The single strongest predictor, across every source reviewed, of whether AI use is actually governed rather than merely occurring. |
| Transparency & Disclosure (free screener) | ||
| We could explain how and where AI is used in our charity if asked. | Charity Excellence AI Governance & Ethics Framework | Tests whether a written policy or equivalent record exists. The Governance Code's 2025 update expects charities to have considered their approach to AI. |
| Data Protection & Safety (free screener) | ||
| We know what data our AI tools touch. | ICO guidance on AI and data protection | A plain-language proxy for the ICO's lawful-basis and DPIA expectations. |
| Fairness & Safeguarding (free screener) | ||
| We've checked whether our AI use could harm vulnerable beneficiaries. | Charity Excellence AI Governance & Ethics Framework | Deliberately phrased as an action, not a belief. A trustee can't answer "yes" here without having actually done something. |
| Redress & Human Oversight (free screener) | ||
| A human reviews AI before it affects people, and decisions can be challenged. | Charity Excellence AI Governance & Ethics Framework | Tests the practical control behind every other duty. |
Sources: Charity Governance Code 2025, Charity Commission trustee guidance (Essential Trustee, CC26), ICO guidance on AI and data protection, Charity Excellence AI Governance & Ethics Framework. Questions are written independently and are not endorsed by these bodies.