Audit an AI tool for risks before you adopt it
Work through a tool's terms and produce a plain-English flag list: data protection, safeguarding, vendor terms, and what to ask before signing.
Yours to copy, change, and make your own.
Replace every [BRACKETED PLACEHOLDER] with your own material before you send it.
I am considering adopting an AI tool. Help me work out what to check before we do. Tool and what it does: [TOOL AND PURPOSE] What we would put into it: [DATA WE WOULD ENTER] Who would use it: [USERS] Our organisation: [ORGANISATION TYPE AND SIZE] Terms, privacy policy, or data processing agreement: [PASTE WHAT YOU HAVE] Produce a plain-English flag list: 1. Data protection: where data goes, who can see it, whether it trains their models, how long they keep it, and who the sub-processors are. Quote the clause behind each point. 2. Safeguarding: what could go wrong if a beneficiary's information, or a child's, ended up in this tool. 3. Vendor terms: liability, indemnity, price changes, termination, and what happens to our data if they close or are acquired. 4. Practical risks: accuracy, accessibility, what staff do when it is wrong, and what happens when it is down. 5. Questions to put to the vendor in writing before signing. For each flag give red, amber, or green, one sentence on why, and what would move it to green. Rules: - Quote the terms. Where the documents I gave you do not answer a point, write "not covered in what you supplied" rather than assuming. - Mark anything needing a DPO, a lawyer, or an insurer as [SPECIALIST REVIEW]. - Ignore vendor marketing language. Where the terms and the marketing page disagree, the terms win. - Use British English.
- [TOOL AND PURPOSE]
- The tool, and what you would actually use it for.
- [DATA WE WOULD ENTER]
- What staff would put into it, being honest about personal and special category data.
- [USERS]
- Who would have access: staff, volunteers, trustees, contractors.
- [ORGANISATION TYPE AND SIZE]
- What kind of organisation you are and roughly how many staff.
- [PASTE WHAT YOU HAVE]
- The vendor terms, privacy policy, and DPA. Paste the documents, not a summary.
Where it shines, and where it falls over.
- A first pass on a tool a colleague is keen to adopt
- Preparing questions for a vendor call or a procurement form
- Giving trustees a plain-English summary of what a tool would mean
- Paste the terms, the privacy policy and the data processing agreement, not the product page. Marketing copy is the least informative thing a vendor publishes.
- Run it twice: once as written, once as "you are the vendor's lawyer defending these terms". The gap between the two is where to push.
This reads the documents you paste and nothing else. It has not seen the sub-processor list, the security page, the enterprise addendum that overrides the public terms, or last year's breach, and it will hand you a confident green where it simply has no information. The absence of a flag is not assurance.
The data protection sections are the weakest: fluent, plausible, and wrong in ways only a specialist spots. It cannot settle your lawful basis or whether an international transfer needs safeguards. Treat the output as the questions you take to your DPO rather than the answers, and act on every [SPECIALIST REVIEW] mark.
AI output is a first draft, not a finished product. You are responsible for whatever you send, publish, or decide with it.
More prompts worth exploring.
Draft a first version of an AI acceptable-use policy
Produce a workable first draft of an AI usage policy for your organisation, sized to your sector and risk appetite.
Plan a project kickoff
Turn a rough project idea into a structured kickoff plan: scope, phases, owners, risks, and the questions to settle first.
Onboard a new volunteer
Build a welcome pack, a first-shift plan, and an induction checklist for a new volunteer, with the mandatory items marked as mandatory.

