Nonprofit board members often have some distance from the day-to-day operations of the organization, which is generally good. That separation helps board members take the long view, a necessary perspective to uphold their governing responsibility.
One of the board members’ primary governance duties is risk management for your nonprofit, which is the process of identifying potential harms, minimizing opportunities for those harms to inflict damage, and planning responses if harms do occur. Managing risks proactively and objectively is imperative for your nonprofit’s organizational health and sustainability, which is why it traditionally falls under the board’s jurisdiction.
In this article, we’ll explore the specifics of board members’ responsibilities in keeping your nonprofit running, no matter what is thrown your way.
Assessing Your Nonprofit’s Risks
Risky situations are delicate, and having a one-size-fits-all response for when harmful things happen will quickly make them go from bad to worse. That’s why your board’s first step for risk management is understanding your organization’s unique situation.
Common risks for nonprofits typically fall into four categories.
- Cybersecurity violations: In addition to putting your nonprofit in a vulnerable position, data breaches of sensitive information (like bank account numbers, home addresses, credit card details) belonging to donors and individuals you serve also expose them to risk.
- Fraud: While bad actors sometimes intentionally prey on nonprofits, your organization should also be aware of unintentional fraud. Accidents happen, but your nonprofit needs to be prepared either way.
- Noncompliance: There is a strict legal framework that nonprofits have to follow, and you can put your organization’s tax-exempt status and reputation in jeopardy if you’re not playing by the rules.
- Theft: Just like any other organization, there is a risk of your money, technology, and physical assets being stolen if internal systems are faulty or if individuals gain access to resources they shouldn’t.
Your nonprofit’s location, organization size, and program focus area are just a few of the factors that can influence the mix and level of risks your organization is likely to face. Your board will need to conduct a thorough evaluation of your organization to get the full picture. To make this exercise as productive as possible, vet each potential risk with two questions:
- How likely is this to actually happen?
- What is the severity of the impact if it does happen?

By understanding the likelihood of the risk occurring and the potential extent of the consequences, you’ll know where to focus your attention first: on the risks that are most likely to occur and that would have the most severe consequences.
Your board should regularly undertake risk assessments and also set triggers for when a refreshed risk assessment would be beneficial. For instance, if your nonprofit is expanding and conducting a needs assessment, your board might also simultaneously run a risk assessment that illuminates how the proposed action plan would impact your organization’s risk level.
Steps Boards Should Take to Manage Risk
With a clear picture of your risk exposure, your board will be empowered to take action. We’ll walk through five tactics they can employ to protect your nonprofit from future harm.
1. Develop Specific Mitigation Strategies for Each Risk
Using the prioritized list of potential risks your board prepared in the assessment, they should first figure out how to handle each scenario. By facing the risks head-on, you can take actions today that lessen the likelihood of the risk occurring.
For instance, Heller Consulting’s nonprofit data management guide recommends limiting the data you collect to only what is strictly necessary. In implementing this practice, you reduce your risk exposure because “hoarded data is a liability.”
Mitigation strategies should prepare your nonprofit for the impact if risky situations occur. Proactively defining a strategy when you have the time to think calmly through the best response means your nonprofit team won’t be reacting out of panic. For instance, if your nonprofit doesn’t file its Form 990 by the deadline, have a clearly defined process for paying the late fee or preparing for a potential IRS audit.
2. Design Policies That Safeguard Operations & Employees
Clearly defined policies are the first line of defense in protecting your nonprofit, along with its employees, volunteers, community members, and board members, from harm. They get everyone on the same page about the ethical and safe way to perform activities.
A few key policies for board members to consider implementing or updating for their nonprofit include:
- Conflict of Interest Policy: This vital blueprint lays out processes for disclosure and management of potential conflicts to safeguard your nonprofit’s reputation, ensure ethical behavior, and reinforce a culture of accountability.
- Reserves and Investment Policies: These policies guide the purposeful deployment and stewardship of reserves to ensure fiscal stability against unforeseen challenges.
- Compensation Policy: This outlines the procedures for setting staff members’ salaries and benefits, especially for leadership. Jitasa’s guide to nonprofit compensation policies explains that because of nonprofits’ unique compliance requirements, executive salaries should be “considered reasonable, but not excessive.”
In addition to setting these policies, the board helps ensure compliance with them, alongside staff members who are more familiar with how they impact day-to-day operations.
3. Establish Internal Controls
In conjunction with overall organizational policies, internal controls are expectations for the day-to-day activities of the nonprofit. Following internal controls minimizes risky behavior and helps employees avoid unintentional fraud and other exposure.
Internal controls often concern your nonprofit’s financial management, like the following examples:
- Requiring leadership approval for purchases over a certain threshold
- Having two employees count cash and sign checks
- Conducting background checks on employees who handle money
Your team can think of internal controls as guardrails that protect your nonprofit from getting into dangerous situations.
4. Implement Regular Risk Oversight
Risk management should be a regular item on your board’s agenda—ensuring policies are being upheld, periodically reassessing risks, and monitoring potentially harmful situations.
In addition to the oversight the board provides, they should also bring in employees as “first lines of defense.” It should be clear who is responsible for high-priority activities, like filing Form 990 and reconciling budgets. This ownership holds team members accountable, making sure it gets done. It’s also important to spread out these responsibilities, so no one team member is overly burdened, and you implement a natural system of checks and balances for extra security.
5. Secure Expert Financial Support
If you find that your nonprofit doesn’t have enough team members to handle your financial workload or that your employees don’t have the right skillset, that presents a risk for your organization. Your board can mitigate this by bringing in an outsourced accountant or even a fractional CFO.
Not only will an external financial professional be able to fill in the gaps on your team, but they can also advise your board on further risk management and mitigation strategies, due to their objective perspective and specific expertise in this area. Your board may also consider conducting independent financial audits to illuminate any organizational weaknesses and be better prepared for the future.
To keep your nonprofit focused on its mission, board members look ahead and ensure the path is clear. The forethought that they provide makes it possible for nonprofit employees to fully immerse themselves in the work in front of them while being confident in their organization’s future.