Not-for-profits should prioritise data readiness before AI
Not-for-profits should prioritise data readiness before AI
AI can unlock significant value from organisational information, but it also exposes weaknesses in how that information is governed, managed and protected. For many not-for-profits (NFPs), discussions about AI focus on the technology. In practice, the greater risk often sits within the data already held across the organisation. Unstructured content, weak retention practices and inherited access can increase the risk of oversharing and unintended disclosure. Improving data readiness is therefore critical before scaling AI.
Across emails, shared drives, attachments, and legacy archives, large volumes of sensitive information continue to grow with limited visibility and inconsistent control.
As AI tools make information easier to discover and use, weaknesses that have existed for years can become more visible.
Why unstructured data matters more in an AI-enabled environment
Unstructured data is typically harder to govern than information held in core systems. Access is broader, ownership is unclear, and retention practices are inconsistent.
AI tools make this more consequential by:
- Making information easier to locate and summarise
- Reducing the effort required to reuse content
- Increasing the likelihood that data is shared beyond its original context.
When permissions and retention are weak, AI can quickly expose information that was never intended to be widely accessible.
Common data risk patterns in the not-for-profit sector
Across the sector, similar hotspots appear repeatedly:
- Shared drives with historic, inherited access
- Email inboxes used as record stores
- Archived folders created during restructures or system changes
- Case notes copied into general documents
- Attachments containing sensitive data circulated informally.
These environments often contain the most sensitive information and the least governance.
What regulators expect
Privacy and AI regulation in Australia is principles based, but expectations for everyday operations are clear.
Collection and use
Organisations should only collect personal information that is reasonably necessary for their activities and only use it for the purpose for which it was collected, unless an exception applies.
Lifecycle management
Retention and disposal are core privacy obligations. Retaining information longer than necessary can increase risk without delivering additional value.
Security and access control
Reasonable steps must be taken to protect information from unauthorised access or disclosure, including through access reviews and monitoring.
AI‑specific considerations
The Office of the Australian Information Commissioner (OAIC) has clarified that personal information used in AI systems, including AI‑generated or inferred information, remains subject to the Privacy Act. This means oversharing unstructured data into AI tools can create obligations the organisation did not anticipate.
A staged, defensible approach to data readiness
Rather than attempting to fix everything, a structured pathway helps organisations reduce risk while building confidence that data readiness is improving.
Phase 1: Identify and prioritise
Start by identifying where sensitive personal information exists, particularly in unstructured locations. Prioritise data sets involving vulnerable individuals, health information, financial details or donor records.
Phase 2: Reduce unnecessary volume
Apply retention decisions to stale content. Remove duplicate, outdated or unnecessary information. This reduces exposure and aligns with proportionality expectations.
Phase 3: Correct access and ownership
Review permissions on high‑risk repositories. Ensure access reflects current roles and assign clear responsibility for ongoing oversight of key data collections.
Phase 4: Prepare for AI use
Before enabling AI broadly, introduce clear rules about what data can be used, how outputs should be handled, and how usage will be reviewed. This embeds privacy‑by‑design into AI adoption.
The governance lens: why boards should care
The ACNC Governance Standards require NFPs to operate in an accountable and responsible way. Boards are not expected to manage data and day‑to‑day operations, but they are expected to understand and oversee material risks associated with information handling, privacy and AI adoption.
Unmanaged, unstructured data presents:
- Privacy and compliance risk
- Reputational risk
- Increased likelihood of incidents when AI is introduced.
From a governance perspective, data readiness is a risk management obligation, not an IT deliverable.
How BDO can assist
Many NFPs recognise that AI adoption will surface existing data risks, but struggle to determine where to start and what is “good enough” before enabling new tools.
Our not-for-profit and cyber security teams help organisations establish data readiness for AI by addressing unstructured data risk, retention discipline and access governance in a way that directly supports privacy obligations and board oversight. Our support typically includes:
- Conducting data visibility and risk assessments across shared drives, email, collaboration platforms and legacy repositories
- Supporting proportionate retention and disposal uplift, reducing unnecessary exposure while preserving operational value
- Designing and implementing data trust and protection controls using Microsoft Purview, including information classification, retention, access governance and oversight
- Preparing organisations for AI adoption by establishing clear rules for what data can be used, how outputs are handled, and how use is monitored
- Delivering targeted education and awareness sessions so staff understand why data discipline matters before AI is introduced.
If you would like to explore how data readiness could be improved in your organisation, please contact our cyber security and data advisory, and not-for-profit teams.


