Skip to content
Several people are sitting around a table discussing documents
AI governance for NGOs and NPOs

AI policy for NGOs: decide clearly what is allowed

For NGOs and NPOs in Switzerland: a facilitated process for management and the governing body — with a short policy ready for adoption, a maintainable annex and clear checkpoints for everyday practice.

Initial consultation: Clarify data classes and approval path

What you receive

  • A two-page short policy, ready for adoption
  • A maintainable approval annex for tools and data types
  • A draft resolution for the board or foundation board
  • A communication package for staff
  • An escalation list with questions to be clarified with a lawyer

The AI policy for an NGO or NPO in Switzerland is the result of a facilitated decision process. Management and the governing body answer six core questions on data types, responsibilities and accountability. The outcome is a short policy ready for adoption, a maintainable approval annex and a clear path for open legal questions. The goal is not legal certainty in every individual case, but a solid basis for everyday work.

The Gap

In non-profit organizations, three out of four staff members use AI. Nine percent of organizations have rules for it.

This does not mean that nothing is happening. It means that it is happening invisibly: in private accounts, with unclear data, without anyone having approved it, and without anyone finding out if something goes wrong. A policy does not create this usage—it brings it to light.

What a policy must achieve

Allow rather than prohibit

Most available templates are prohibition lists. A prohibition document does not reduce usage; it shifts it into the shadows. What is needed is a format that states what is allowed, tiered by data type.

A two-page core, an amendable annex

Tool names in the approved text become outdated within nine months. The core should contain principles, data classes, and responsibilities; the annex should list the tools that management may adjust without a new governing body resolution.

The framework is decided, not the list

The board decides on risk appetite, responsibilities and how changes are made. After that, a new piece of software no longer costs a board meeting.

A path for errors

People who must report an accidental input and are punished for it will not report it. A duty to report without sanctions for negligence is the only way to learn about incidents at all.

From open chat to local — and what it costs

The question is never just whether a tool is secure. It is always twofold: What data goes in, and where is it processed?

The most effective and least costly lever is neither: reduce data. Remove names, use cases instead of individuals, extracts instead of full files. This costs nothing and shifts many tasks out of the most sensitive class. The preceding question is anyway: Does this task require personal data at all?

LevelSuitable forCost range
Private accountNo data processing agreement, free tiers often train on your inputs, no administration.Public information only0 to about 25 per month
Business planTraining contractually excluded, data processing agreement, administration, logs.Internal work data without personal dataPer seat; check NPO rates
API with selectable regionProcessing location set by contract, billed by actual usage.Internal to sensitive cases in small quantitiesUsage-based, often cheaper than seats
Swiss providers, open modelsProcessing in Switzerland, no lock-in to a big tech company.Increased requirements, concerns within the governing bodySubscription or usage-based
Local, on your own hardwareNothing leaves the premises. The organization is responsible for operation, updates, and security.Individual highly sensitive text tasksOne-time hardware
Deliberately notA legitimate option, not a failure.Professional secrecy, lack of legal basis0

A word against the reflex: running it yourself sounds safest, but for a small organization it is often the opposite, because nobody keeps it updated and monitored. A neglected server of your own is a bigger risk than a contract with a proper data processing agreement.

And one limit no contract can move: where professional or official secrecy applies — social counseling, victim support, health, migration — a contract may not be enough. That is a legal question, and we mark it as one instead of answering it.

The decisions are the product

Not the document. No template can answer these six questions for you — and once they are answered, the text almost writes itself.

  1. 01

    How do we handle free tools on personal devices?

    Entscheidet: Management with IT and data protection

  2. 02

    Under what conditions may data about donors, clients or employees go into an AI tool at all?

    Entscheidet: Board or foundation board with data protection

  3. 03

    Does the policy also apply to honorary officers, volunteers and contractors?

    Entscheidet: Board or foundation board

  4. 04

    When do we disclose externally that AI was involved?

    Entscheidet: Management with communications

  5. 05

    What happens if someone accidentally enters something incorrect?

    Entscheidet: Board and management

  6. 06

    Who decides when a team wants to use a new tool?

    Entscheidet: Management

Assess yourself first — 5 minutes

Twelve questions, three groups. You receive an immediate assessment — structured, no score, and your data never leaves your browser.

  • Duration: approx. 5 minutes
  • No storage, no transmission — runs entirely in the browser.
Start self-assessment

Who it suits — and who it does not

A sober assessment for NGOs and NPOs in Switzerland.

A good fit if

  • management or the governing body genuinely needs to decide.
  • data types, responsibilities and current use are discussed openly.
  • someone with access to the governing body and authority to decide takes part.

Not a fit if

  • all you want is a free template without working through your own questions.
  • the six decisions have already been made internally and hold up.
  • you expect legal clearance; the policy is not legal advice.

The process

About two weeks of calendar time. The effort on your side is approximately half a workday, distributed among a few people.

  1. 1

    Preliminary clarification

    45 minutes, asynchronous

    Existing data protection and IT rules, tools actually in use, sensitive data types, legal form, EU connection.

  2. 2

    Decision workshop

    2.5 to 3 hours

    Management, whoever is responsible for data protection or IT, one or two subject-matter representatives, one person with access to the governing body. Not the whole team. The result is recorded decisions, not a discussion.

  3. 3

    Draft

    about one week

    Two pages of core content, an approval annex, and an explicit list of questions to be clarified with a lawyer.

  4. 4

    Approval loop

    45 minutes

    Only the people with authority to decide. We test the text against three real cases from your daily work.

  5. 5

    Team launch

    60 to 90 minutes

    Not an introduction to AI, but four real cases: allowed, allowed with conditions, approval required, ruled out. This is where the policy meets the work for the first time.

  6. 6

    Follow-up

    30 minutes after 30 days

    What questions arose, did the team become more confident or cautious, and does the annex need to be adjusted?

Person at a table with many documents

What you keep

  • A two-page short policy, worded ready for adoption
  • An approval annex that your management can maintain themselves
  • A draft resolution for the board or foundation board meeting
  • A communication package for staff
  • An escalation list: which questions need to be clarified with a lawyer and why
  • The record of your decisions — the real substance

Honest limits

Where legal questions remain open, we document them as specific review points and hand them over to the responsible body.

  • This is not legal advice. We facilitate an internal decision-making process and formulate its outcome. Where a question requires legal clarification, we state this explicitly rather than glossing over it.
  • A policy does not make any use legally watertight. Whether a specific processing activity is permissible depends on the data, tool, contract, use case and jurisdiction.
  • We do not promise increased usage. The assumption that clear rules increase usage is plausible and supported by practice reports, but not causally proven. We therefore state it as an expectation, not a guarantee.
  • There are plenty of free templates, and some are good. If you can make the six decisions internally, you do not need us for that.

Frequently Asked Questions

There are free templates. Why should we pay for them?

You should not, if you can make the decisions yourselves. You are not paying for the text but for facilitating the trade-offs: how much risk do we accept, who is accountable, what do we do after an incident. A template can ask these questions — your organization has to answer them.

Two pages — will anyone take that seriously?

Experience with comparable rulebooks suggests so: long documents make it more likely that rules are ignored. The volume does not disappear; it moves into the annex that management maintains. The adopted part stays readable.

Who must sign it?

That depends on your legal form, articles of association and delegation rules and cannot be answered in general. Usually the supreme governing body adopts the core and delegates maintaining the annex to management. We clarify this in the preliminary clarification.

Professional secrecy rules out a lot for us. Is it still worth it?

Especially then. Most of the work in an organization does not touch protected data. Without a rule, in practice either everything or nothing is allowed — and both are wrong. The policy draws a clean line and marks what stays outside.

Do we need to know in advance which tools we want?

No, and you should not. First you decide which data needs which processing level. The tools follow from that — and go into the annex, because they change.

What if everyone at our organization is already using ChatGPT?

That is the norm, not the exception. The preliminary clarification records it anonymously. For a leadership body, its own previously invisible use is usually the most convincing reason to start at all.

Does such a policy apply equally in Germany, Austria, and Switzerland?

The organizational framework largely carries over: data classes, approval process and escalation path do not stop at a border. The legal assessment does not. It depends on the applicable data protection law, professional or official secrecy and the specific use. For a Swiss organization with ties to Germany or Austria, we mark the points that need an additional jurisdiction-specific review; that is not a blanket clearance.

Decision workshop

In the initial consultation we clarify which data types and current AI uses exist, who decides along the approval path and whether this process fits your organization.

Request initial consultation

And once the rules are in place: How your team learns to actually work with them.

How to make it work in your team