

THE CALIFORNIA NONPROFIT AI GOVERNANCE RISK ASSESSMENT WORKBOOK
The practical guide California nonprofits need before artificial intelligence creates a privacy failure, unsafe output, vendor problem, compliance gap, or loss of community trust.
Artificial intelligence is already changing nonprofit work.
It appears in writing assistants, chatbots, meeting transcription tools, applicant-screening systems, fundraising platforms, grant-writing tools, customer-service software, cloud applications, design tools, and automated features built into systems staff already use.
But most organizations do not have a clear answer to the most important questions:
What AI systems are we using?
What data is entering those systems?
Who is affected by their outputs?
Who is responsible for oversight?
What happens when the system is wrong?
Can we prove that we reviewed the risk before relying on it?
THE CALIFORNIA NONPROFIT AI GOVERNANCE RISK ASSESSMENT WORKBOOK gives nonprofit founders, executive directors, board members, program leaders, operations teams, privacy professionals, technology staff, consultants, and community organizations a clear, structured way to answer those questions.
This is not a book about technology hype.
It is a hands-on governance workbook for organizations that want to use AI in ways that protect people, support mission, preserve confidentiality, improve accessibility, strengthen accountability, and build long-term trust.
Inside, you will learn how to:
Identify every AI tool, embedded feature, chatbot, automation, vendor platform, and AI-enabled workflow used across your organization.
Build a complete AI inventory that tracks each system’s purpose, vendor, owner, users, affected people, data, integrations, permissions, controls, findings, risk level, and approval status.
Create practical rules for public, internal, confidential, and restricted or sensitive data.
Prevent staff from entering client records, behavioral-health information, protected health information, donor records, HR documents, minors’ data, Social Security numbers, and other sensitive information into unapproved AI tools.
Understand the difference between an AI tool that produces an output quickly and a workflow that genuinely improves service delivery.
Identify hidden labor created by AI, including verification, correction, exception handling, complaint response, content maintenance, and human support.
Assess risks involving privacy, cybersecurity, inaccuracy, misinformation, bias, discrimination, accessibility, employment, safety, vendor practices, automated decisions, and public trust.
Use likelihood and severity ratings to prioritize risks and determine when corrective action, executive review, a pause, or retirement is required.
Review AI vendors, contracts, data-processing terms, retention practices, model-training settings, security controls, access permissions, audit logs, incident notifications, and deletion options.
Establish meaningful human oversight so staff can review, correct, reject, escalate, or stop AI-generated outputs.
Build safeguards for public chatbots, including approved-source limits, human handoff, escalation procedures, crisis protocols, accessibility review, content maintenance, and output monitoring.
Test AI systems for safety, accuracy, reliability, privacy, accessibility, escalation, and real-world performance before launch and throughout operation.
Track unsafe outputs, override rates, human escalations, complaints, incidents, near misses, corrective actions, and closure evidence.
Create evidence indexes, risk registers, findings registers, vendor registers, decision records, monitoring dashboards, and retirement checklists.
Use a practical decision ladder to prohibit, hold, pilot, approve with conditions, approve for a defined use, suspend, or retire an AI system.
Prepare boards and leadership teams to ask better questions before approving AI tools, connected data sources, automated workflows, vendor relationships, and high-impact systems.
Build a 90-day implementation plan that helps your organization start with its highest-priority risks and grow stronger over time.
This workbook is especially valuable for nonprofits working in public education, workforce development, healthcare, behavioral health, disability services, community programs, youth services, social services, privacy education, cybersecurity, public-interest technology, and other settings where mistakes can affect real people.
It also explains a critical truth: AI is not just a model.
AI is a socio-technical system. It is shaped by people, policies, source materials, data practices, vendor settings, contracts, organizational incentives, accessibility, workflows, human judgment, and community conditions. When something goes wrong, the cause may not be the algorithm alone. The problem may be outdated information, weak vendor settings, missing human review, poor training, unclear ownership, inaccessible design, an unsafe integration, or the decision to use AI for the task in the first place.
That is why responsible AI governance cannot be reduced to a policy statement or a one-time approval. It requires repeatable practice.
This workbook helps California nonprofits build that practice through practical forms, field tools, decision frameworks, and step-by-step guidance. It helps organizations distinguish between what is currently verified and operating, what is planned, and what is missing or unsupported. It shows how to gather evidence before relying on a vendor claim, how to document gaps, how to assign owners, and how to preserve the records needed for board review, funder confidence, audits, investigations, and responsible decision-making.
The California focus matters. Nonprofits may face different obligations depending on their legal structure, charitable activities, fundraising, workforce practices, contracts, data use, technology systems, and the people they serve. This workbook helps organizations identify issues involving nonprofit governance, privacy, cybersecurity, accessibility, vendor oversight, employment-related AI, sensitive information, and public accountability. It is designed to help leaders recognize when a question requires deeper legal, tax, privacy, security, accessibility, employment, or technical review.
You do not need a large technology team or a large budget to begin.
Start with one use case.
Identify the system.
Define the purpose.
Name the owner.
Classify the data.
Identify the people affected.
Assess the risks.
Review the vendor.
Test the system.
Set boundaries.
Create a human path for support and correction.
Document the decision.
Monitor what happens next.
THE CALIFORNIA NONPROFIT AI GOVERNANCE RISK ASSESSMENT WORKBOOK is more than an introduction to responsible AI. It is a practical operating system for nonprofit leaders who want to move from informal experimentation to informed, accountable, evidence-based governance.
Use it to protect confidential information.
Use it to strengthen board oversight.
Use it to improve staff confidence.
Use it to reduce harmful errors.
Use it to build accessible and trustworthy services.
Use it to make better decisions before risk becomes harm.
Because the best time to build AI governance is not after the incident.
It is now.
