A mid-size Toronto non-profit faced board concerns about AI use with donor and beneficiary data. With limited IT budget, the organization needed a governance approach that was practical, not enterprise-scale. This composite case study covers the lightweight governance framework, board-level AI briefing, and the policy adoption process that gave the board confidence in 60 days.
AI Governance for a Toronto Non-Profit: A Budget-Conscious Framework That Satisfied the Board
This is a composite case study. The scenario, challenge, and outcome are based on patterns Group 4 Networks observes across Toronto non-profit clients. No individual organization is identified.
The Problem
A Toronto non-profit organization with 65 staff and an annual operating budget in the low millions served a population of vulnerable beneficiaries and managed relationships with a donor base of several thousand individuals. Its IT environment was lean - Microsoft 365, a CRM, a donor management platform, and a small number of productivity tools managed by Group 4 Networks under a managed IT engagement.
In early 2026, a board member raised a concern at a governance committee meeting: had the organization thought through how AI tools were being used with donor and beneficiary data? The executive director did not have a ready answer. A second board member noted that several grant funders had begun asking about data governance practices in grant applications. A third raised the reputational risk if donor data ended up in an AI training dataset.
The concern was legitimate. Staff had begun using AI tools organically - grant writers were using ChatGPT to draft proposals, program coordinators were using AI writing assistants for beneficiary case notes, and the fundraising team was experimenting with an AI tool for donor segmentation. None of it was sanctioned. None of it had been assessed for PIPEDA implications. And none of it was visible to the executive director or the board.
The executive director engaged Group 4 Networks to address the board's concerns and build a governance framework scaled to the organization's budget and operational reality.
What the Audit Found
Group 4 Networks completed an AI inventory audit within five business days, covering the organization's Microsoft 365 tenant, network, and a staff survey.
Findings:
- 8 AI tools in active use across program, fundraising, and administrative teams
- 3 of the 8 tools were processing personally identifiable information - including donor names, contact details, gift history, and in two cases, beneficiary information
- None of the 3 tools had Canadian data residency or data processing agreements
- Beneficiary case notes containing sensitive personal information had been input into a consumer AI writing tool by two program coordinators at different sites
- The organization's privacy policy did not address AI tool use and had not been updated since 2022
From a PIPEDA perspective, the organization had accountability obligations for the personal information in its custody - both donor data and beneficiary personal information. Processing that information through unapproved AI tools without data processing agreements and without disclosing AI use in the organization's privacy policy was a material gap.
The board's concern was well-founded.
The Approach
The governance framework was designed explicitly for a non-profit operating reality: limited IT staff, constrained budget, staff accustomed to using free tools, and a board that needed clear communication rather than technical detail.
Board-level AI briefing (week 2)
Before implementation began, Group 4 Networks delivered a two-hour briefing for the board's governance committee. The briefing covered:
- What AI tools were in active use and what risks each created
- What PIPEDA requires and why donor and beneficiary data is subject to those requirements
- What governance controls were recommended and why
- What the implementation timeline would look like
The briefing was written for a non-technical audience. It gave board members the information they needed to fulfill their governance oversight role without requiring them to understand technical controls. Board members left the session with a clear understanding of the risk and the proposed response.
Lightweight data classification
Rather than a four-tier enterprise classification model, Group 4 Networks designed a simplified two-category framework appropriate for the organization:
- Protected (donor personal information, beneficiary personal information, staff HR data): no external AI processing permitted
- General (public communications, program descriptions, anonymized reporting): approved AI tools with standard controls permitted
This binary framework was simple enough for staff to apply without IT support and clear enough to be enforced by policy rather than requiring complex technical controls.
Priority tool controls (weeks 2 to 4)
The 3 tools processing Protected data were addressed as the immediate priority. Two were blocked on the organization's network within two weeks. The third - a donor segmentation tool with a free tier - required a conversation with the fundraising team about whether a PIPEDA-compliant alternative existed. A replacement with Canadian data residency was identified and adopted within the implementation window.
Plain-language acceptable-use policy (weeks 3 to 5)
The AI acceptable-use policy was written in plain language, in a format that matched the organization's existing HR policies. It covered:
- The two data categories and what each means
- Which tools were approved for which categories
- The process for requesting approval of a new tool
- What to do if you realize you have input Protected data into an unapproved tool
The policy was reviewed by the executive director and the board's governance committee before distribution. It was distributed to all 65 staff via email with a read-receipt request and a brief Q&A session available for staff with questions.
Annual review cycle (established at week 8)
Rather than a quarterly review cadence - appropriate for larger organizations with more complex AI use - the organization established an annual AI governance review. The review covers the AI tool inventory, updates to the acceptable-use policy, and a one-page governance summary for the board's annual report.
Outcome
At the 60-day mark:
- Board governance policy adopted at the governance committee meeting, with the board formally noting the organization's AI acceptable-use policy in the committee minutes
- 3 high-risk AI usages identified and controlled: 2 tools blocked, 1 replaced with a PIPEDA-compliant alternative
- Donor-data AI rules documented in the acceptable-use policy and distributed to all 65 staff
- Privacy policy updated to reflect AI tool use and the organization's data governance approach
- Staff Q&A session completed with 48 of 65 staff attending; written Q&A posted to the intranet for the remainder
- Board briefing delivered: all governance committee members received the AI risk briefing
- 0 unapproved AI tools processing Protected data detected in the 60-day follow-up network audit
- Annual review cycle established: next governance review scheduled for 12 months from implementation
The executive director's assessment: the framework gave the organization something concrete to point to when grant funders asked about data governance, and it gave the board confidence that AI tool use was being managed rather than ignored.
What This Means for Toronto Non-Profits
Non-profits are not exempt from PIPEDA. The personal information of donors, beneficiaries, volunteers, and staff is subject to PIPEDA's accountability, safeguard, and consent requirements - and AI tool use creates the same risks for a non-profit as it does for a for-profit organization. The difference is that non-profits often have less IT capacity, tighter budgets, and staff who are more accustomed to using free tools because the organization cannot afford paid alternatives.
A governance framework for a non-profit does not need to be enterprise-scale. It needs to be clear, practical, and appropriate to the organization's actual AI use and data risk. A lightweight policy that staff understand and follow is more effective than a comprehensive framework that sits unread on a shared drive.
Group 4 Networks' AI Governance service is available in a non-profit-scaled engagement - covering the audit, the policy, the board briefing, and the annual review cycle. Our managed IT engagements for non-profits, which connect to our broader non-profit technology support, are priced to reflect the operational reality of the sector.
Contact us at (416) 623-9677 or book a free AI Governance assessment.
Frequently Asked Questions
Are non-profit organizations subject to PIPEDA?
Yes. PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activities - including non-profits that engage in commercial activities such as fundraising, fee-for-service programs, or membership administration. Most Canadian non-profits are subject to PIPEDA for at least some of their data handling. Ontario non-profits handling personal health information are additionally subject to PHIPA. The safeguard obligations under PIPEDA apply to AI tools that process personal information, regardless of whether the tool was officially sanctioned by the organization.
How should a non-profit board approach AI governance oversight?
Board governance of AI is the same as any other organizational risk: the board's role is to set policy, confirm that management has implemented appropriate controls, and receive regular reporting. The key deliverables for board oversight are: an acceptable-use policy that the board has reviewed and approved; a process by which management identifies and addresses new AI risks; and periodic board reporting on AI governance status. Group 4 Networks' board-level AI briefing is designed specifically to give governance committee members the information they need to fulfill this role without requiring technical expertise.
What AI tools are safe for non-profit grant writing and fundraising?
The answer depends on what data the tool accesses. AI tools used to draft program descriptions, refine public communications, or generate non-sensitive content with no personal information are generally lower risk. Tools that access donor lists, donor gift history, or beneficiary information require assessment - including review of where data is processed, whether the vendor has a data processing agreement available, and whether Canadian data residency is offered. Many popular free AI tools do not meet these requirements and should not be used with donor or beneficiary data.
How much does AI governance cost for a small non-profit?
Group 4 Networks prices AI Governance for non-profits as a scaled engagement - the full audit, lightweight policy framework, board briefing, and annual review cycle are available at a lower cost than the full enterprise implementation. For non-profits already on a Group 4 Networks managed IT engagement, AI Governance is available as an add-on. Contact us at (416) 623-9677 to discuss pricing for your organization's size and scope.
How long does it take for a non-profit to implement AI governance?
For a non-profit of 50 to 100 staff, the initial implementation - covering the audit, data classification, priority tool controls, and policy distribution - can be completed within 60 days. The board briefing is typically delivered within the first two weeks so the board receives early visibility into the audit findings and proposed response. The annual review cycle replaces the quarterly cadence used by larger organizations, keeping ongoing governance overhead proportionate to the organization's capacity.