Almost every software product now claims to be “AI-powered.” Meanwhile, your staff are probably already using AI tools on their own, with or without a policy. The pressure to do something with AI is real. But the organizations getting the most value are not the ones buying the most tools. They are the ones that answered a few hard questions first.
Here are the twelve we walk through with leadership teams before recommending any AI investment.
Purpose
1. What problem are we actually trying to solve?
“Use AI” is not a goal. “Cut the time it takes to produce a grant report from ten days to three” is. Start with a specific, painful, measurable problem, and only then ask whether AI is the right tool for it. Sometimes a better process or a simple automation is the answer.
2. Who benefits, and who could be harmed?
Map the people affected: staff, customers, clients, donors, and communities. For mission-driven organizations especially, consider whether an AI system could disadvantage the people you exist to serve, through biased outputs, loss of human contact, or misuse of sensitive data.
3. What does success look like in 90 days?
Define a small number of metrics before you start: hours saved, response times, error rates, satisfaction, or revenue. If you cannot measure it, you will not know whether to scale it or stop it.
Data
4. What data would this use, and where does it live?
AI is only as good as the information it can draw on. Inventory the documents, databases, and systems involved. Scattered, outdated, or duplicated data is the most common reason promising pilots fail.
5. How sensitive is that data?
Classify it. Public content carries very different risks than personal health information, case notes, donor records, or financial data. Your answer determines which tools, vendors, and deployment options are acceptable.
6. Do our vendor agreements protect it?
Consumer AI tools may use inputs to improve their models, depending on settings and terms. Business and enterprise agreements typically offer stronger commitments. Read the terms, confirm data retention and training policies, and make sure they match your obligations to the people whose data you hold.
Risk and governance
7. Do we have an AI acceptable-use policy?
If staff are using AI today, and they almost certainly are, you need clear guidance on approved tools, prohibited data, required human review, and disclosure. A short, plain-language policy is far better than none. (We wrote about what to include in an AI use policy.)
8. Where must a human stay in the loop?
Decide in advance which decisions AI can make, which it can recommend, and which it should never touch. Anything affecting eligibility, employment, safety, or someone’s access to services deserves human judgment.
9. How will we catch it when it’s wrong?
Every AI system makes mistakes. Plan how you will test outputs before launch, monitor quality after launch, and give users an easy way to flag problems. Frameworks like the NIST AI Risk Management Framework, organized around Govern, Map, Measure, and Manage, offer a helpful structure without requiring a compliance department.
People
10. Who owns this?
AI initiatives without a clear owner drift. Name an accountable leader for the outcome, and a practical owner for the day-to-day system, including prompts, configurations, integrations, and costs.
11. Are our people ready, and are they on board?
Adoption is the difference between a pilot and a result. Involve the people who do the work in designing the solution, address fears about job loss honestly, and invest in hands-on training that goes beyond a single lunch-and-learn.
Economics
12. What will this really cost to run?
Look beyond the license. Account for implementation, integration, usage-based fees, data preparation, training, monitoring, and the staff time to maintain it. Then compare against the value you defined in question three.
How to use this checklist
You do not need perfect answers to all twelve questions before experimenting. But if you cannot answer most of them, your next step is not a new tool. It is a short readiness assessment that gives you a policy baseline, a clear picture of your data and risk, and a prioritized shortlist of use cases worth piloting.
That is the kind of clarity we help organizations find. If you would like a structured way to work through these questions with your team, start a conversation with us.