Where the AI runs, what it sees, and how to switch it off

6 min read
02/10/2026, 10:00

The data protection page for the AI Due Diligence Checker in Flexigrant. For IT leads, DPOs and trustees at charities, community funders, research organisations and central government.

Is AI in grant management software safe under GDPR? For Flexigrant’s AI Due Diligence Checker, the facts are these. The AI step runs on Azure OpenAI in the EU. It sees only the organisation name and numbers you type, never your Flexigrant data. It is not used for training. A role restricts access, and a tenant setting switches it off.

The checker turns three public register searches into one, inside the platform that runs your whole grant process. Every applicant gets the same documented check. That is the case your grants team will make for it. This page is for the person who has to approve it. It sets out exactly what leaves your system, where it goes, what happens to it, and how you control it. Where we do not know something, we say so.

Is AI in grant management software safe under GDPR?

It depends on three things. What data the AI processes, where it processes it, and what controls you hold over it. Any vendor who answers with a plain yes has skipped the question. The rest of this page answers those three points for the checker, starting with what the AI actually does.

What does the AI actually do in the checker?

Less than the name suggests. The checker retrieves an applicant’s records from Companies House and the Charity Commission for England and Wales. When you enter a Scottish charity number, it retrieves the OSCR record too. A fixed formula, not AI, calculates the risk score from five factors. The AI does not touch the score.

Azure OpenAI does one job. It writes a plain-English summary and analysis notes to sit alongside the register data. Both are labelled as AI-generated on screen, and you are asked to check them against the source records, which are linked. Think of the AI as a narrator, not a judge. It describes what the registers say. It does not decide anything.

What data is sent to the AI?

The only data drawn from your Flexigrant tenant is the organisation name and the registration numbers your user types into the search. Nothing else from Flexigrant is used. No application forms, no applicant contact details, no grant records, no payment data, no documents. The checker does not read your tenant to build its summary.

That distinction matters for your assessment. The personal data your grants team holds about applicants and their staff stays where it is. The inputs to the AI step are the name and public registration numbers of an organisation. The records the checker summarises are already public on the three registers.

Where is the AI processing carried out?

The AI step is processed in the EU, on Azure OpenAI, Microsoft’s hosted version of the OpenAI models. We state that plainly because it is the question every DPO asks first. The AI step is not processed in the UK, and we do not claim that it is.

Your Flexigrant data itself is a separate matter. Flexigrant’s own hosting arrangements do not change with this feature, and the checker sends none of that data anywhere. Only the typed name and numbers travel to the AI step.

Is your data used to train the AI model?

No. The data sent to Azure OpenAI is not used to train the models. That applies to the name and numbers your users type, and to anything the AI generates in response.

One qualification, stated in full. Microsoft runs abuse monitoring on Azure OpenAI to detect misuse of the service. If a request is flagged by that monitoring, Microsoft may store a sample of it for review. In the checker’s case, the content of any such sample would be an organisation name and its registration numbers. We include this because your record of processing should include it. We would also rather you heard it from us than found it in Microsoft’s terms.

Who can use the checker, and how do you restrict it?

By default, any Flexigrant user with access to the Manage Grants menu can run a check. If you want to limit that, a dedicated role restricts the checker to the users you choose. Ask our support team to enable the role through a support ticket. Then assign it to the people who run due diligence.

That gives you a clean answer for your access control policy. Only named users run checks, and everyone else in Manage Grants carries on as before.

How do you switch it off entirely?

If your organisation decides not to use AI at all, a tenant setting switches the checker off for every user. Again, you request this through a support ticket. Once it is off, no user in your tenant can run a check, and nothing is sent to Azure OpenAI. You can ask for it to be switched back on later in the same way.

We built the off-switch because some funders will need it. A board may have a policy against AI tools. A public body may need to complete its own assessment first. The checker should never be a reason to delay the rest of Flexigrant.

Can the AI be wrong?

Yes. A language model can misread a record or phrase something in a way the source does not support. That is why the summary and notes are labelled as AI-generated. It is also why every register field they describe is linked to its source. The label is not a disclaimer to skip past. It is an instruction to check.

The risk score is not exposed to this problem, because AI does not calculate it. If the summary and the score ever seem to disagree, trust the source record, and read the score’s breakdown.

What should your DPO record?

Your own assessment decides whether the checker is acceptable for your organisation. We do not certify that for you. What we can give you is the fact set to put into it.

The processor for the AI step is Microsoft, through Azure OpenAI. Processing takes place in the EU. The data categories are organisation names and public registration numbers typed by your users. The data is not used for training. Microsoft abuse monitoring may store flagged samples. Access is controlled by a dedicated role, and a tenant setting switches the feature off. The checker is advisory. It supports your due diligence process and does not replace it.

Where the checker sits

The AI Due Diligence Checker is built into Flexigrant, from Fluent Technology, and included in every subscription. It sits in the Manage Grants menu, alongside the applications it supports. Flexigrant holds ISO 27001 and Cyber Essentials Plus certification and is listed on G-Cloud. As of 2026, more than £6.5 billion has been awarded through the platform by 250+ UK and global funders.

Read the full AI Due Diligence Checker feature page

Key takeaways

  • The AI step runs on Azure OpenAI in the EU. It writes the summary only. A fixed formula scores the risk.
  • It uses only the organisation name and numbers you type. No Flexigrant data is sent.
  • Not used for training. Microsoft abuse monitoring may store flagged samples.
  • A dedicated role restricts who can run checks. A tenant setting switches the checker off. Both by support ticket.

 

Frequently asked questions

Is AI in grant management software safe under GDPR?

It depends on what data the AI processes, where, and what controls you have. For Flexigrant’s AI Due Diligence Checker, the AI step runs on Azure OpenAI in the EU, uses only the organisation name and numbers you type, is not used for training, and can be restricted by role or switched off. Your own assessment makes the final call. 

Does Flexigrant send our grant data to the AI?

No. The only data used from Flexigrant is the organisation name and registration numbers your user types into the checker. Application forms, applicant contact details, grant records and documents are not sent. 

Where is the AI processing carried out?

The AI step is processed in the EU, on Azure OpenAI. Flexigrant does not claim UK processing for the AI step. Your Flexigrant data itself is not sent to the AI step at all. 

Is our data used to train the AI model?

No. Data sent to Azure OpenAI by the checker is not used to train the models. Microsoft’s abuse monitoring may store a sample of a flagged request for review; for the checker, that would be an organisation name and its registration numbers. 

What is Microsoft abuse monitoring?

It is a check Microsoft runs on Azure OpenAI to detect misuse of the service. If a request is flagged, Microsoft may store a sample of it for review. The checker sends only organisation names and registration numbers, so that is what any stored sample would contain. 

Can we restrict who uses the AI Due Diligence Checker?

Yes. By default it is available to users of the Manage Grants menu. A dedicated role limits it to the users you choose. Ask Flexigrant support to enable the role through a support ticket, then assign it to your due diligence team. 

Can we switch the AI Due Diligence Checker off?

Yes. A tenant setting switches the checker off for every user in your organisation, and nothing is sent to Azure OpenAI while it is off. Request it through a support ticket, and request it back on the same way. 

Back to top