I build the policy that stops the next mistake, and the automation that makes AI actually worth the risk. One person, both tracks, so nothing gets lost between the policy and the actual work.
It's 4:50 on a Friday. Your board chair forwards an email asking what your AI policy is. You don't have one. Neither does anyone you know running an org your size.
Meanwhile, your program coordinator has been using ChatGPT to draft grant reports for months. Nobody told her not to. There was nothing to tell her.
That's not a hypothetical. That's Tuesday, at most organizations your size, right now.
Your staff are already pasting client names, grant language, and internal notes into ChatGPT. Nobody told them not to, because there was nothing written down to tell them.
If your board asked right now how AI is being used, and by whom, could you actually answer? Most leaders can't, and it shows the moment someone audits.
You already know which report or intake process should be automated. You just don't have anyone on staff who can actually build it.
A compliance consultant won't touch your Zapier account. A developer won't sit through a funder audit. Most organizations your size can't afford both, so nothing happens.
"I spent sixteen years being the person large, regulated companies called when something had to work and couldn't fail. Then I built an AI product myself, alone, from scratch. You don't have to choose between someone who understands compliance and someone who can actually build the thing. I've been both, for a long time."
One honest boundary: this isn't custom software engineering or LLM fine-tuning. It's real configuration, automation, and integration work using tools built for this, documented clearly enough that your team can maintain it without me.
Map where AI is already being used across your teams, and where the manual work is worth automating, so you know exactly what you're dealing with before we design anything.
Write the usage policy and data-handling rules, and architect the automation that will run inside them, together, not in sequence.
Configure and ship the actual workflow, and train staff on what's approved and why, so the policy and the tool arrive at the same time.
Stand up the reporting cadence your board needs, and document the build so your team can maintain it without me.
You answer to funders and a board. You need AI use that's defensible in an audit, not just convenient.
HIPAA and client confidentiality aren't optional. Any AI workflow has to be built with that as the starting constraint.
Under roughly 50 staff, no dedicated IT or compliance function, and no appetite to hire two separate vendors to solve this.
You know AI is already in use on your team. You just need someone to make it defensible and actually useful, at the same time.
Before AI was the topic, the job was the same: take an ambiguous, high-stakes problem and build something out of it that actually holds up. I did that in enterprise change management at Bank of America, in release governance at Endava, and now in compliance coordination inside a HIPAA-regulated nonprofit. The tools changed. The job didn't.
In 30 minutes, we'll walk through how your team is currently using AI and where the real exposure is. You'll leave with a short written summary. No pitch, no obligation.
Book Your Free AI Readiness Audit