AI Governance Starter Kit | beneAI

AI Governance Starter Kit

A four-week outline for creating your first AI governance plan.

beneAI provides AI governance services and support for nonprofits, foundations, and government agencies, based in Denver, Colorado and working with mission-driven organizations nationwide. This free starter kit walks your team through building a right-sized AI governance plan in four weeks: setting up, drafting a policy, vetting your tools, and launching.

Week01

Set Up

You can't govern AI use you haven't seen. Before a word gets written down, find out what's already happening, how people are feeling, and how much structure you actually need.

Tasks & Tools

Engage your team

Start with a short staff survey. Keep it anonymous; that matters more than thorough. If answers are attached to names, you'll learn that nobody uses AI, which is never true.

  1. Have you used any AI tools for work in the last month? Which?
  2. On your work account or personal?
  3. What did you use it for? (The most valuable field on the form.)
  4. What parts of your job feel low-value or over-burdensome?
  5. What worries you about our organization using AI?
  6. Where should AI not be used in your work?

Even better, get an hour with your staff

An opt-in listening session complements a survey with nuance, empathy, and trust-building. Open with gathering sentiment toward and familiarity with AI, not "what tools do you want," which most staff can't answer, and the ones who can set the ceiling for everyone else. Capture low-value as well as high-friction work.

Don't chase consensus. When the room splits on whether something is yellow or red, the split is the finding: it tells you which line the policy has to draw explicitly. Capture the reasoning, not the label.

Understand your risk profile

Gauge the sensitivity of your data and activities. Three questions:

  • What's the most sensitive data you hold? Operational data is one thing. Client health records, immigration status, minors' applications, benefits eligibility is another.
  • Does AI touch any decision about a person? Screening, scoring, eligibility, hiring. If yes, you need decision approval gates regardless of size.
  • Who's watching? Funders with data clauses, a state agency, HIPAA, a board that will ask. External obligations raise the floor. Be ready.
Right-size your governance plan

The instinct is to stand up an AI Committee. For most smaller organizations, that committee meets twice and fades away, which makes the policy fade too. Pick the smallest structure that can survive a busy season.

Light StructureSmall · minimal sensitive data

One named owner, two-page guidance, a tool list in a shared doc, annual review.

Standard StructureMedium · some client PII

Owner plus two or three others, guidance and a live registry, training before access, semi-annual review.

Complex StructureLarge · regulated or AI-driven

Working group with an exec sponsor, vendor review before use, gates on high-risk uses, quarterly board review.

Appoint your AI lead

Who will lead your AI governance (and strategy) efforts? A person, not a department. Departments don't answer email.

This person doesn't need to be technical. Sometimes they're in HR, other times Operations or IT. They need to be someone staff will go to with a creative challenge, an idea for a new AI use case, a tool configuration issue, or a policy clarification.

End of week 1

Awareness of staff sentiment, ideas, and curiosities; a known risk profile, a chosen governance scope, and a named AI lead.

Week02

Draft

Aim for no more than two pages and no more than ten permissions and prohibitions, at a scale people can apply themselves, with a promise that reporting a mistake costs nothing. If you need to, call it interim guidance: it's allowed to be wrong and get fixed.

Tasks & Tools

Create an AI Use Statement

Say why before how. A short, plain statement of how and why your organization uses AI, tied to your mission and values.

It sets the tone the rest of the policy fills in. One paragraph or a short list is plenty: name the purpose, the principles you'll hold to (human judgment, privacy, honesty), and who owns it.

Develop your policy template

Determine your non-negotiables, and dovetail with the IT and data policies you already have. Your AI policy should line up with existing procedures, not contradict them.

  1. Organizational accounts, not personal ones.The highest-value rule on the list. Personal accounts are where data becomes unretrievable and where offboarding fails silently.
  2. Some things don't go in. Name them.Not "be careful with sensitive data." A list: client PII, donor giving records, board materials, personnel files, anything regulated.
  3. Verify anything you're publishing or deciding on that humans didn't write.Facts, figures, citations, quotes. If it goes out with your name on it, a human should confirm it, for now.
  4. Disclose your AI use if you think it matters to your audience.You don't need to footnote every drafted email. You do probably want consent before an AI notetaker records a room.
  5. People make the decisions.AI informs; it doesn't decide. Especially where the outcome determines what a person might receive.
  6. Report mistakes within 24 hours.Create a safe harbor, and tie discipline to willful or repeated violations only.

Say the safe harbor plainly

Most drafts put "may result in disciplinary action" in section two and "good-faith reporters will not be penalized" in section six. Staff read the first one. Move the protection earlier than the penalty, or people hide errors and you get more shadow AI, not less.

Put a sentence near the top saying that using AI responsibly is not cheating. It sounds soft. It isn't. Staff who feel they're doing something faintly shameful don't ask questions and don't tell you when something goes wrong.

The section skeleton

AI USE GUIDANCE - v0.1 (interim · review [date])

0.  AI Use Statement   - why we use AI, tied to mission and values
1.  Who this covers    - staff, contractors, volunteers, board members
2.  Accounts           - organizational only
3.  What never goes in - [your specific list]
4.  Embedded AI        - features inside tools you already use
5.  Verification       - you own what you publish and decide
6.  Human decisions    - where AI must not decide
7.  Disclosure         - external work; notetaker consent
8.  Prohibited uses    - impersonation, synthetic likeness, staff
                         monitoring, automated decisions about people
9.  Safe harbor        - 24 hours, good faith, who to tell
10. Ownership          - named owner, review date, how to suggest a change

Appendix A - Tool registry: approved / under review / not approved
Appendix B - Pointer to the use case registry (kept outside this doc)
Paste into your doc

Answer the embedded-AI question

Policies get written around net-new tools you approve. But the AI summary already sitting in your Zoom, your CRM, your Microsoft 365: nobody approved that, and it's already on. State the rule: embedded features in approved software are fine for non-sensitive work, still subject to everything above, and IT may switch specific ones off. Silence reads as prohibition to careful people and permission to everyone else.

Define data sensitivity

Rate both: what goes in, and what comes out. Inputs are the information you provide to an AI tool. Outputs are the products you get from it. A blended rating hides the distinction that matters. Summarizing the board packet for your own reading looks harmless, so people call it green, but restricted material went into a system you may not control.

Green: Go

Public or low-sensitivity inputs and low-stakes outputs. Use an approved tool without extra review.

Yellow: Caution

Internal or moderately sensitive material. Check the vendor's terms and have a person review the output.

Red: Stop

Confidential, regulated, or personal data, or anything that decides something about a person. Requires sign-off or a vetted tool.

Nine combinations, nine handling rules

Staff apply this without asking you. Pick any cell.

Capture use case ideas

Go back to what staff shared in Week 1. For the tasks and workflows they named, unpack each one further:

  1. Iron out the tasks and workflows. Make sure each one is clear and complete before you evaluate it.
  2. Identify the brain, hands, and heart work. Which parts need judgment (brain), doing (hands), or human care (heart)?
  3. Rate the inputs and outputs. What information goes in and what products or activities come out, rated green, yellow, or red for each.
  4. Estimate ROI and return on mission. If AI did part or all of it, what would you gain in time and cost, and in mission and impact?

Run the sort with staff

Write scenarios on index cards, pulled from the survey, in your organization's language. Tables sort them for twelve minutes, then you debrief only the ones tables disagreed on. People remember an argument they had. Nobody remembers a slide.

End of week 2

An AI use statement, a simple draft policy, a traffic light framework, and use cases from your team.

Week03

Inform & Vet

The week your governance starts to wake up. Everything in the policy depends on staff being able to look up what's actually approved.

Tasks & Tools

Audit your software

Check the terms of the software your staff are using. Whatever tools staff named in the survey should be on your list, plus the AI features quietly shipping inside software you already pay for. Most of this is answerable from the vendor's own terms page in ten minutes:

  • Do they train on your inputs? And is that different on the paid or business tier? It usually is.
  • How long is data retained, and can you set the retention period yourself?
  • Is there an admin console? If you can't cut someone off at offboarding, that's a finding.
  • What happens to your data when you cancel? Where does it go, and how would you know?

Write the answers down even when they're fine. In six months someone will ask, and "we checked, here's what it said" beats starting over.

Build the registries

Keep track of standalone and embedded AI: a tool registry for what's approved, and a use case registry for how it's used.

A policy is slow and stable.

Use it for principles and core rules. One sentence can point at your registries, which can live as an editable appendix or documents outside the policy. Changes go through whatever approval you want to set up.

A registry is dynamic.

A spreadsheet the designee updates without asking permission. New tools, use cases, new owners. This is where the classifications actually live.

If approval lists live inside the body of your policy, every update needs whatever approval the policy requires (board review, legal, a committee), so it rarely gets updated or looked at. There's a framing risk too: a policy that lists approved uses quietly tells people anything unlisted is forbidden, which is rarely what you mean.

What a use case registry looks like

Use caseInOutHandlingOwner / Dept.
Translating the public newsletterGreenYellowBilingual staff review before publicationComms
Summarizing prior-year event materialsYellowGreenStrip guest lists and donor names firstEvents
Public FAQ chatbotYellowYellowNo PII, visible disclaimer, escalation pathIT
Scoring scholarship applicationsRedRedNot permittedPrograms

Note the second row: yellow in, green out. A single blended rating would have called that green and missed the scrubbing requirement. A few dozen clean, vetted, and categorized use cases is a working registry. Two hundred is a project that never ships.

Set a request workflow

Make it easy for staff to engage with you. Every request should capture the AI tool, the desired functions within it, and the use case or project proposal, then get logged with a decision.

Within three business days. Give it a clock. A workflow with no turnaround time is how shadow AI starts. People don't wait indefinitely, they just stop asking.

Get leadership buy-in

Bring a decision, not a document. Boards approve faster when you arrive with the framing already set: here's what staff told us, here's the tier we picked and why, here's what this does and doesn't cover, here's the review date.

Ask them to approve the approach, not the wording. A board asked to line-edit a policy will line-edit a policy, and you'll lose a month. Get sign-off on the tier, the scope, and the review cadence.

End of week 3

A populated tools list, a use case registry, a one-sentence request path, and an approval you can point to.

Week04

Launch

Everything so far is paper. This week decides whether it becomes practice, or a document people vaguely remember signing.

Tasks & Tools

Introduce the policy to staff

Don't read the policy aloud. Nobody retains a document read to them. Spend thirty minutes like this: three minutes on your use statement and why the policy exists, seven on the basic rules, fifteen sharing real scenarios with the sensitivity framework, and five showing where the tool registry lives and how staff can engage and upskill. The scenarios are the part that sticks, because people leave having done the thing rather than heard about it.

Say the safe harbor out loud, in your own voice, in front of everyone. A written protection is worth something. A director saying "if you mess this up, tell me, and I mean it" is worth more.

Distribute sign-off forms

Ask staff to commit to the rules, and don't mistake a signed form for understanding.

If your plan calls for a training gate for access to AI tools, this is where it lands: briefing attended, form signed, then an account gets provisioned. Access should always follow a license.

Create a handy guide

A simple one-page guide people can keep with them: the essentials staff need at a glance.

  1. The traffic-light rule. Green, go. Yellow, needs a human. Red, don't.
  2. Keep sensitive data out. No confidential, regulated, or personal data in unapproved tools.
  3. A human stays in the loop. Verify anything you publish, or that affects any person or influences a decision.
  4. Approved tools only. Refer to the tool registry, on licensed organizational accounts only.
  5. Disclose and report. Flag AI use when it matters; report mistakes fast, no penalty.

Post it where people already are: the intranet page they actually open, the pinned channel, the drive folder they're in daily. If you have to explain where it lives, it's in the wrong place.

Set the policy review date

Not "as needed." Send a real invitation to real calendars before you close this out, with three questions already on the agenda: what has changed in our tools or tool usage, what have people asked for that we said no to, and what did we get wrong, and what should we fix? The third one is what keeps the document honest.

Don't let your AI policy wither. AI governance needs to be alive.

End of week 4

Published guidance, a briefed staff, registries people can find, and a policy review schedule. A functioning governance program that fits on a single piece of paper.

What's Next

What happens after week 4?

The planning ends and the deployment officially begins. Hand your team two things:

Training: the driver's license.

Trainings so staff can use AI with skill and judgment, not just permission.

Tools: the keys.

Decide which tools and embedded AI features to turn on (and off), and place them in people's hands.

Access follows the license: training first, then the account. It's the control most organizations skip because it slows rollout, and it prevents most of what goes wrong.

Get Started

Are you ready to take AI governance seriously?

You can develop a right-sized governance plan in less than four weeks that positions you to responsibly build your AI capabilities and set out on identifying and implementing high-value use cases.

It takes a bit of time, concentration, and some support. Please get in touch if you're seeking the latter.

AI for good. Denver, Colorado USA

Free to copy and adapt inside your organization. Last revised July 2026. © 2026 beneAI.