Five decisions to write down before anyone on your team uses AI to check a grant applicant, with a one-page policy template. For charities, community funders, research organisations and central government, including teams using Flexigrant, from Fluent Technology.
An AI due diligence policy for grant funders answers five questions in writing. What may the AI do? What may it not do? What data may it receive? Who checks its output? How do you record the result? Answer them before the first check, and the AI works inside your process rather than around it.
Most funders do not need a new due diligence policy to use AI. They need five extra lines in the one they have. This guide gives you those lines, and shows how the AI Due Diligence Checker in Flexigrant is built to sit inside them.
Before you start
Read your current due diligence policy and note where it says who checks what, and how deep the check goes. Find out who signs off policy changes in your organisation. That may be a trustee committee, a director, or an SRO (the Senior Responsible Owner for a central government programme). Ask your data protection lead what they will want to see before they approve any AI use.
How do you set the parameters?
- Write down what the AI may do. Keep it narrow. A good starting line is: the AI may read public register data and write a plain-English summary of what it holds. In Flexigrant, that is all the AI does. It writes analysis notes, labelled as AI-generated commentary, from the record the checker retrieved.
- Write down what the AI may not do. The AI may not calculate the score, approve or decline an application, or replace an officer’s judgement. In Flexigrant, a fixed formula calculates the score across five factors, and the result is advisory. Nothing in the checker decides.
- Set the data boundary. State exactly what leaves your system and where it goes. In Flexigrant, only the organisation name and registered numbers an officer types are sent, and processing takes place in the EU. No application data, grant records or personal data from your tenant is used.
- Decide who may run a check. By default, any Flexigrant user with access to the Manage Grants menu can run one. If you want a shorter list, the GMSAIDueDiligence role restricts the checker to named users. If your governance group has not yet approved AI use, a tenant setting switches it off. Both changes are made by raising a ticket on the support portal.
- Set the review rule. State that every AI-generated note is checked against the source record before anyone relies on it. State too that the AI-generated label travels with the note into any paper. Every item on the Flexigrant results page links to its register entry, so the check takes a click rather than a search.
- Set the thresholds. Decide what happens in each band. For example, a Low band (0 to 30%) proceeds on the officer’s sign-off. A Medium band (31 to 60%) needs a second reviewer. A High band (61 to 100%) goes to the panel with a written note. The bands are Flexigrant’s. The actions are yours.
- Decide how you record each check. At minimum: the date, the score and band, which factors could be assessed, what the officer verified, and who signed off.
- Put the five answers on one page and get them approved. Our guide to explaining AI due diligence to trustees gives you a briefing you can attach to the same paper.
A one-page policy template
AI in our due diligence process: parameters
The AI may: read public register data retrieved for an applicant and write a plain-English summary of it.
The AI may not: calculate the risk score, approve or decline an application, or replace an officer’s judgement.
Data boundary: only the applicant’s name and registered numbers are sent. Processing takes place in [location]. No application or grant data is used.
Who may run a check: [named roles].
Review rule: every AI-generated note is checked against the source record before use, and stays labelled in any paper.
Thresholds: low [action], medium [action], high [action].
Record: date, score and band, factors assessed, what was verified, who signed off.
Approved by: [name, role] on [date]. Review date: [date].
The simplest way to put these parameters into practice
Writing the parameters is the easy half. The hard half is a tool that respects them without every officer having to remember them. The AI Due Diligence Checker in Flexigrant, from Fluent Technology, is built to do exactly that.
This is why we think the checker is the go-to way to run AI due diligence within your parameters. It is simpler, because the limits are built into one screen in the system your team already uses. It is more reliable, because a search by registered number lands on the right record and a fixed formula gives the same score every time. Every AI note sits one click from the source that proves or disproves it. The policy stays yours. The checker makes it the default.
Key takeaways
- Five written answers make an AI due diligence policy: what the AI may do, may not do, what data it receives, who checks it, and how you record.
- Keep the AI to reading and explaining. Keep scoring with a fixed formula and decisions with people.
- Set the data boundary in one sentence: name and registered numbers only, with the processing location stated.
- Decide the action for each band before the first check, and record every check the same way.
- The AI Due Diligence Checker in Flexigrant is built inside these five parameters, which makes it the simplest and most reliable way to apply them.