Why NFP and NDIS Boards Need an AI Policy Before Staff Build Their Own Workarounds

A boardroom table rendered as a compass, with connected building blocks radiating outward to represent a governance framework

Why NFP and NDIS Boards Need an AI Policy Before Staff Build Their Own Workarounds

You don't need to wait for a regulator to tell you this. The template already exists — someone just has to put it on the agenda.

The gap your board hasn't noticed yet

Here's what I think most NFP and NDIS boards get wrong about AI: they're waiting to be asked. Someone assumes the CEO, the CFO or IT will bring an AI policy to the table when it becomes necessary. Meanwhile, staff are already using AI. Not in six months — now.

A commissioned national survey published this month (Employment Hero's AI Paradox at Work report, based on 1,634 Australian workers and 1,008 business leaders) found that one in three Australian workers are using AI tools at work without their employer's knowledge. There's no reason to assume finance, program and intake teams in the NFP and NDIS sector are the exception. If anything, the pressure to save time on case notes, funding acquittals and reporting makes it more likely, not less.

If your board hasn't discussed AI governance, that doesn't mean AI isn't in use in your organisation. It means nobody has decided what acceptable use looks like, who is accountable when something goes wrong, and what data should never go anywhere near a public chatbot. Left unaddressed, that vacuum tends to get filled by staff themselves, with whatever tool is free, fast, and doesn't ask permission.

1 in 3
Australian workers say they use AI tools at work without their employer knowing (Employment Hero AI Paradox at Work report, July 2026)
56%
of directors surveyed say they're not yet ready to invest in secure, governed AI tools (Governance Institute of Australia, 2025 Board Effectiveness Survey)

What APRA told its regulated entities — and why it still matters to you

Your NFP or NDIS provider almost certainly isn't regulated by APRA. But it's worth knowing what APRA told the banks, insurers and superannuation trustees it does regulate, because the reasoning applies well beyond that audience.

On 30 April 2026, APRA published an open letter to all APRA-regulated entities summarising what it found after a targeted review of AI adoption at a group of large banks, insurers and super funds in late 2025. The finding, in plain terms: AI adoption is outrunning governance. APRA wrote that "assurance practices are not keeping pace with the scale, speed and complexity of AI," and that many boards are "still developing the technical literacy required to provide effective challenge on AI related risks and oversight." It also flagged something I'd bet is just as true in the NFP sector — an overreliance on vendor demonstrations and glossy summaries instead of genuine scrutiny of how a tool actually behaves.

What I find most useful about the letter isn't the warning — it's the checklist. APRA set out, at minimum, what it expects governance to include:

  • a documented AI policy or framework, with clear reporting lines
  • ownership and accountability across the whole lifecycle of an AI tool, from adoption to retirement
  • an inventory of what AI tools and use cases actually exist in the organisation
  • human review built in for high-risk decisions
  • training so staff understand appropriate use, misuse and the limits of what these tools can do

None of that is APRA-specific. It's a governance checklist any finance function could use today, regardless of what regulator — if any — sits above you. That's the point I'd make to any board still treating this as someone else's problem to solve later.

AI6: a free, ready-made starting point for the policy itself

If APRA's letter tells you why a board needs to act, the National AI Centre's Guidance for AI Adoption tells you what to write down. Released on 21 October 2025 by the National AI Centre (part of the Department of Industry, Science and Resources), it sets out six essential practices — commonly shortened to "AI6" — that replace and simplify the government's earlier 10-guardrail Voluntary AI Safety Standard. It's voluntary, not law, but it's the framework referenced across government guidance and increasingly built into procurement requirements, so it's a safe, credible reference point to hand your board rather than something drafted from scratch.

The six practices, in plain language:

  • Decide who is accountable — name an owner for each AI use case, not just "IT"
  • Understand impacts and plan accordingly — know who could be affected if a tool gets something wrong, including NDIS participants and their families
  • Measure and manage risks — put AI on the enterprise risk register like any other material risk
  • Share essential information — be transparent with staff, funders and clients about where AI is used
  • Test and monitor — check tools before go-live and keep checking, not "set and forget"
  • Maintain human control — humans stay responsible for decisions, especially ones that affect funding, employment or a participant's support

You don't need to write a 50-page framework to start. A one-page board paper that walks through these six practices against your organisation's actual AI use — even if that use is currently three staff members using ChatGPT to draft emails — gives your board something concrete to discuss and approve.

One item that belongs explicitly in any board-approved AI policy: vendor due diligence on data handling. Before your finance, intake or case management staff use any AI tool with payroll figures, participant data or financial information, confirm in writing whether that vendor trains its underlying models on customer inputs. Free consumer-tier tools often do, by default, unless you actively opt out — and opting out isn't always available on a personal account. The safer posture for anything sensitive is a business or enterprise-tier product with a contractual commitment that your data isn't retained for model training. Your policy should also set a default of stripping or de-identifying personal information before it goes into an AI tool wherever the task allows it — a no-training agreement reduces one risk, not all of them. Your AI policy should require both checks before any new tool is approved, not after.

What should actually be in the board paper

Note: The scenarios in this post are based on real experiences — mine and those shared by colleagues across the sector. Details might have been changed and modified slightly to protect confidentiality, and mostly used 1st person perspective for convenience.

In the board papers I've reviewed across the NFP and NDIS sector, AI barely rates a mention outside a line item on the IT risk register, if it appears at all. That's not because boards don't care. It's because nobody's framed it as a governance decision rather than a technology decision. Combining APRA's checklist with AI6 gives you a short, practical paper that does that framing for you. At minimum, it should cover:

  • a current inventory — what AI tools are staff actually using today, sanctioned or not
  • a named accountable owner, ideally the CFO or a delegate, not "the IT committee"
  • a short list of what's off-limits without approval — participant data, unredacted financials, anything covered by a funding agreement's confidentiality clause
  • a vendor data-handling standard, per the disclaimer above
  • a commitment to review the policy at least annually, because the tools and the risks are both moving fast

This is a one or two-page paper, not a governance project. The goal isn't to slow AI adoption down. It's to make sure the organisation, not individual staff members improvising with their own logins, is the one making the call on what's acceptable.

Why proactive beats reactive

The reason I'd put this paper in front of the board now rather than wait to be asked is simple: once shadow AI use is entrenched, a policy stops being a governance decision and starts being an enforcement problem. It's much easier to set expectations before habits form than to walk them back afterwards. And the two things staff are already doing with AI — pasting sensitive data into free tools, and running up unmonitored subscription and usage costs — are exactly the risks this week's other two posts covered in detail. A board-level policy is the piece that sits above both of them: it's what tells staff what data is off-limits and what tells finance who's allowed to approve a new AI subscription in the first place.

You don't need APRA's authority over your organisation to use APRA's checklist. You don't need to be a bank to benefit from a framework the government built specifically to be usable by organisations with far fewer resources than a bank. What you need is a CFO or finance leader willing to write the one-page paper and put it on the next board agenda, before the AI usage that's almost certainly already happening in your organisation becomes too embedded to govern properly.

Has your board actually discussed AI, or just heard about it in passing?

PFL provides senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations — including helping finance leaders build the board-ready AI governance paper their organisation doesn't have yet.

Talk to PFL →
Timothy, CPA is Managing Director of Professional Financelink (PFL), providing senior-level outsourced finance, management reporting, and AI automation for Australian NFP, NDIS, and SME organisations. 20+ years in finance leadership across NFP, NDIS and SME.

Sources:
APRA Letter to Industry on Artificial Intelligence (AI) — APRA, 30 April 2026
Essential AI practices (Guidance for AI Adoption / AI6) — National AI Centre
Voluntary AI Safety Standard — Department of Industry, Science and Resources
Australian workers still hiding AI use from employers, studies find — HRD Australia
Boards divided on AI: What 2025 data reveals — Governance Institute of Australia

Next up: our weekend wrap of the AI and finance stories worth your time this week.

Comments

Popular posts from this blog

Google Gemma 4 Just Launched — And It Might Solve Finance's Biggest AI Privacy Problem

Why NFP Boards Are Finally Talking About AI — And What the Finance Team Should Do Before They Ask

Claude vs Gemini for Australian Finance: An Honest Comparison After 12 Months of Using Both