Nonprofit Risk Management

Nonprofit board and staff working through a risk management review
📖 22 min readLeadership
FG
For Good Consultants
Published 14 August 2026 · Updated 14 August 2026

Risk management sounds like something for organisations with a compliance department. In a small Canadian charity it means something considerably more practical: knowing what could stop you delivering, deciding in advance what you would do, and writing it somewhere the board can see.

Most nonprofits do this implicitly and incompletely. The executive director carries a mental list, the board hears about a risk when it becomes a problem, and nobody has ever compared the list against what is actually insured. This guide is about making that explicit without turning it into bureaucracy.

What is nonprofit risk management?

It is the practice of identifying what could prevent your organisation achieving its purpose, judging how likely and how damaging each of those things is, deciding what to do about the significant ones, and reviewing that judgement regularly. It is a governance responsibility that sits with the board, informed by staff.

Key takeaways

  • Financial and people risks dominate in small charities. Dramatic risks get attention; concentration risk causes the failures.
  • A risk register is one page, not a document. If nobody reads it, it is not managing anything.
  • Not every risk should be mitigated. Accepting a risk deliberately is a valid and underused decision.
  • Insurance is not a risk strategy. It transfers financial consequence, not operational disruption.
  • Review quarterly at board level. Risks that are reviewed annually are effectively unmanaged.

What actually goes wrong in small charities

Ask a board to list risks and you get fire, flood, fraud and reputational damage. Look at what actually stops small Canadian charities delivering and the list is different and considerably more mundane.

Funding concentration is first. One funder providing a large share of income, whose decision cycle you do not control, is the single most common existential risk in the sector and the one most often normalised because it has been fine for years.

Key person dependency is second. One individual holding the relationships, the passwords, the institutional memory and the operational knowledge. It is not a failure of that person; it is a structural exposure that becomes visible only when they leave.

Then compliance lapses, usually during transition. Then safeguarding, which is low likelihood and severe consequence. Then cash timing. Dramatic risks make the register; these five cause the actual damage.

A fast diagnostic: What proportion of your income comes from your largest funder, and how many people could do the executive director’s job tomorrow? Two questions, and most organisations already know both answers are uncomfortable.

The categories worth thinking about

Categories help because they prompt you to look where you would not naturally look. Five cover almost everything relevant to a small charity.

Financial

Funding concentration, cash timing, reserve levels, cost inflation, under-costed contracts.

People

Key person dependency, staff turnover, volunteer reliability, burnout, board vacancies.

Operational

Delivery capacity, premises, technology failure, supplier dependency, data loss.

Compliance and legal

Filing deadlines, employment obligations, privacy, contractual commitments, charitable status.

Reputational and safeguarding

Harm to a participant, a partner’s conduct, a public complaint, a communications error.

Work through them once a year as a board. The value is less in the list produced than in the conversation, which regularly surfaces something everyone assumed somebody else was handling.

Team workshop building a nonprofit risk register together
The value is in the conversation. The register is just what survives it.

Building a risk register that gets used

Risk registers fail by being too long. A thirty-row spreadsheet covering every conceivable eventuality is completed once, filed, and never influences a decision. The version that works fits on one page.

Include only risks significant enough to change what the organisation does. For a small charity that is usually eight to twelve. Each row needs the risk described specifically, a judgement of likelihood and impact, what you are doing about it, and one named person accountable.

Describe risks as consequences rather than as topics. “Funding” is not a risk. “Our largest funder does not renew in March, leaving a gap we cannot cover from reserves” is a risk, and it is specific enough to plan against.

“A risk register nobody reads is a document about risk, not a way of managing it. One page that changes a decision beats thirty that do not.”

Assessing likelihood and impact

Rate each risk on how likely it is and how damaging it would be, on a simple scale. Precision is not the point; the point is comparing risks against each other so attention goes where it matters.

The category that most deserves attention is low likelihood combined with severe impact, because organisations systematically under-prepare for it. Safeguarding failures, sudden loss of the executive director and serious data breaches all sit here, and all are survivable with preparation and devastating without.

Be honest about likelihood. Boards routinely rate uncomfortable risks as unlikely because considering them properly is unpleasant, and that is precisely how organisations end up unprepared for the thing everyone privately worried about.

The four responses

For each significant risk there are four options, and choosing deliberately is the whole exercise.

  1. Avoid: stop doing the thing that creates the risk. Sometimes correct, often not available.
  2. Reduce: make it less likely or less damaging. Most mitigations sit here: second signatories, cross-training, backups.
  3. Transfer: move the financial consequence elsewhere, usually through insurance or contract terms.
  4. Accept: decide consciously to carry it, because mitigation costs more than the exposure is worth.

Accept is the most underused and the most honest. A small charity cannot mitigate everything, and a board that has explicitly accepted three risks with reasons recorded is in a considerably better position than one that has silently ignored ten.

Record acceptance: “The board considered this and accepted it because mitigation would cost more than the exposure” is a defensible governance position. Saying nothing is not.

Insurance, and what it does not cover

Insurance transfers financial consequence. It does not prevent disruption, and organisations that treat a policy as a risk strategy discover the gap at the worst moment.

Check what you actually hold and what it covers. General liability, directors and officers, property, and cyber are the common categories, and coverage for volunteers, for activities away from your premises, and for driving on organisational business is frequently absent by default.

Directors and officers cover deserves particular attention, because board recruitment becomes considerably harder without it and because prospective directors increasingly ask. If you do not have it, that is a board decision to take consciously rather than a gap to discover.

Read the exclusions once, as a board. It is dull and it is the only way to know what you are actually carrying.

Safeguarding and duty of care

For organisations working with children or vulnerable adults, safeguarding is the risk that sits in a category of its own. It is low likelihood, catastrophic in consequence, and it is the area where informal practice is least defensible.

The essentials are a written policy, consistent screening matched to role risk, clear reporting routes that do not depend on one person, training for anyone in a position of trust, and records that show the policy was applied rather than merely written.

Apply it consistently, including to volunteers who are known to the board. Most safeguarding failures involve someone trusted precisely because they were familiar, which is why exceptions made for good reasons are the pattern to guard against. Our guide to volunteer management covers the screening side.

The board’s role

Risk oversight is a governance function. The board owns the judgement about what risk the organisation carries; staff own the operational management of it. Boards that delegate the whole thing to the executive director have delegated their own duty.

In practice that means the register comes to the board quarterly, with changes highlighted, and the board asks about the two or three that moved rather than reviewing all twelve. It also means the board decides which risks are accepted.

Where the board lacks confidence, the honest response is to ask for the information in a form it can use rather than to nod through a document nobody understood. That request is itself good governance, which we cover in our guide to board governance.

Having a plan for the bad day

Most small charities have no crisis plan, and the ones that do usually wrote it after needing one. A workable plan is short and answers a small number of questions in advance, while nobody is under pressure.

A one-page crisis plan

  • Who decides, and who decides if that person is unavailable
  • Who speaks publicly, and who does not
  • Which board members are contacted immediately, and how
  • What is said to staff, and when, relative to any public statement
  • Which funders and partners must be told directly rather than reading about it
  • Where the contact details live so they are reachable outside office hours
  • When to seek legal or professional advice rather than proceeding

Test it once. A twenty minute tabletop discussion of a plausible scenario reveals most of the gaps, and it is the difference between a document and a plan.

Digital and data risk

Most risk registers in the sector are strong on safeguarding and premises and silent on technology, which no longer reflects where the exposure sits. For an organisation holding personal information about vulnerable people, a data breach is a safeguarding incident as much as a technical one.

  1. Know what personal data you hold, where it lives, who can reach it and how long you keep it. Most organisations cannot answer this, and the answer is the foundation of everything else.
  2. Limit access by role. Not everyone needs the case notes. The most common breach is not an attacker, it is an internal permission nobody reviewed.
  3. Require strong unique passwords and two-factor authentication on email, finance and any system holding client information. Email compromise is the most common entry point and the most damaging.
  4. Remove access the day someone leaves, including shared accounts, cloud drives and the phone with the organisation’s social media on it.
  5. Back up and test the restore, because an untested backup is a hope rather than a control.
  6. Train people on phishing, especially finance staff and anyone who can move money. Invoice redirection fraud targets small organisations precisely because approval processes are informal.
  7. Have a breach response plan, including who is told, how quickly, and what your notification obligations are. Those obligations vary by jurisdiction and are time-limited, so this is a question to answer before an incident rather than during one.
  8. Check what your insurance covers in relation to cyber incidents, which is frequently less than assumed.

Financial and funding risk

For most nonprofits the largest single risk is not dramatic. It is that a significant proportion of income comes from a small number of sources, and one of them changes its priorities.

Concentration

Work out what share of income comes from your largest funder. If a single source represents a large fraction of the budget, that is a strategic risk regardless of how good the relationship is.

Timing

Grant income arriving in arrears while payroll runs monthly is a cash flow risk even when the organisation is solvent. Model the timing, not just the totals.

Restricted income

Money that can only be spent on specific things does not help with the costs that keep the organisation running. A budget that looks healthy can be unable to pay for finance, governance and management.

Contract terms

Service contracts with clawback provisions, fixed unit prices or volume assumptions can transfer significant risk to you. Read them before signing, and price for the risk you are accepting.

Cost inflation

Multi-year funding agreed at fixed amounts becomes a real-terms cut over time. Raise this at negotiation rather than absorbing it silently.

Reserves

The buffer that turns a funding shock into a difficult year rather than a closure. Set a target, state what it is for, and monitor it.

People risk

In organisations under a certain size, key person dependency is usually the most serious unmanaged risk, and it is the one boards find hardest to discuss because the key person is often in the room.

  1. Identify the dependencies honestly. Which relationships, passwords, funder contacts, systems knowledge and institutional memory exist in one head?
  2. Document the critical things, starting with access: bank, payroll, funder portals, website, email administration and cloud storage. Where they are and who else can reach them.
  3. Write down the processes that would stop if one person were unavailable for a month, and decide who would do them.
  4. Plan for planned departures and unplanned ones separately. A resignation gives you notice. An illness does not.
  5. Develop a second person for each critical function, even partially. Shared knowledge is the only real mitigation.
  6. Treat recruitment and retention as risk management, because sustained vacancies in key roles cause most of the damage attributed to other causes.
  7. Include the board. A board where the chair and treasurer both leave in the same year, with no succession plan, is a governance risk of the same order.

Keeping it proportionate

Risk management in a small organisation goes wrong in two directions. Either it does not exist, or it becomes a forty-page document produced for a funder and never opened again. Neither manages any risk.

What works at small scale is short and alive. A single register, no more than a dozen or fifteen entries, each with a named owner and a next action, reviewed properly at four board meetings a year. The review matters more than the document: what changed, what is now more likely, what did we say we would do and did we do it. An organisation that spends twenty minutes a quarter on that conversation is managing risk. One with an immaculate register nobody discusses is not.

What the board should be asking

Risk oversight sits with the board, and in practice it is often reduced to noting that the register was circulated. A board doing this properly asks a small number of persistent questions, and asks them regardless of whether anything appears to be wrong.

  1. What has changed since last time? Risks move. A register where nothing has changed in a year is a register nobody is reviewing.
  2. What are our top three, and who owns each? If nobody can answer without reading the document, the register is not being used.
  3. What did we say we would do, and did we do it? Mitigation actions with no follow-up are the most common failure.
  4. What would have to be true for this to become critical? Identifying the trigger in advance means you notice it when it happens.
  5. What are we not talking about? Boards are reliably better at discussing risks that are already documented than at surfacing new ones. Ask the question directly.
  6. Are we taking too little risk? An organisation that never risks anything is not usually safe, it is usually shrinking. Risk appetite works in both directions.
  7. Who would tell us if something went badly wrong? If the answer is only the executive director, the board has a single point of failure in its own information.

Risk appetite, and why avoiding risk is not the goal

The purpose of risk management is not to minimise risk. It is to take the risks that serve the mission deliberately, and to avoid the ones that do not. An organisation that declines every new program, never speaks publicly on a contested issue and holds no reserves has not eliminated risk, it has chosen irrelevance and called it prudence.

A short written statement of risk appetite helps here. It says, in a few sentences, where the organisation is willing to accept exposure in pursuit of its mission and where it is not. Most organisations conclude that they have a low appetite for anything touching safeguarding, finances and legal compliance, and a considerably higher appetite for programmatic experimentation, advocacy and new partnerships. Writing that down gives staff permission to try things, which is usually the binding constraint in a sector where the instinct is caution.

The framing that helps boards: asking what would we regret not having tried, alongside what could go wrong. Both questions are risk questions, and only one of them usually gets asked.

The gaps we see most often

  1. No named owner. Risks assigned to the organisation are assigned to nobody.
  2. Controls listed but never tested. A policy that exists is not a control. A policy people follow is.
  3. Nothing about the board itself, such as vacancies, skills gaps, or a chair with no successor.
  4. Insurance assumed rather than read. Coverage, exclusions and limits are rarely checked against the risks actually on the register.
  5. Volunteers left out of policies written for employees, despite often doing the same work with the same exposure.
  6. Partner and subcontractor risk ignored, even where you remain accountable to the funder for their delivery.
  7. No incident log, so patterns that would be obvious across a year are never seen.
  8. Reviewed annually rather than quarterly, which is slower than the environment changes.

Building your first risk register

If your organisation has never had one, the sensible starting point is a single meeting and a single page rather than a framework. The register is a tool for a conversation, and the conversation is the part that manages risk.

  1. Get the right people in a room for ninety minutes, which means at least one board member, the person running operations, and someone who does frontline delivery. Risk looks different from each of those seats.
  2. Ask what keeps each person awake, and write everything down without filtering. Filtering comes later.
  3. Group into categories such as safeguarding, financial, people, legal and compliance, reputational, digital, and operational. Gaps become obvious once things are grouped.
  4. Score simply. Likelihood and impact, each as low, medium or high. Numerical scoring in a small organisation creates false precision and long arguments.
  5. Cut to the top twelve to fifteen. A register longer than that will not be reviewed, and an unreviewed register manages nothing.
  6. Give every entry a named person and one next action with a date. This is the step that turns a list into management.
  7. Book the next review before leaving the room, and put it on the board agenda as a standing item.

The first version will be imperfect and that is expected. A rough register reviewed quarterly is worth considerably more than a thorough one produced once for a funder and filed. The value is entirely in the repetition.

The short version

Get fifteen risks on one page, each with a named owner and a next action, and review them properly four times a year. Include the ones organisations usually miss: digital and data, funding concentration, key person dependency, and the board itself. Test your controls rather than listing them. And remember that the goal is not the smallest possible risk, it is the deliberate acceptance of the risks that serve the mission and the avoidance of the ones that do not.

A final note

The organisations that handle a genuine crisis well are almost never the ones with the best documentation. They are the ones that had the conversation before it happened, so that when it did, people knew who decided what, who spoke, who was told, and what mattered most. The register is the artefact. The conversation is the control.

Where to start this quarter

Book ninety minutes with a board member, an operations lead and a frontline colleague, and build the first register in that meeting. Cap it at fifteen entries, give each a named owner and one action with a date, and put the review on the agenda for the next four board meetings before anyone leaves the room.

Then do the two things most registers omit. Write down what personal data the organisation holds, where it lives and who can reach it. And write down what would stop tomorrow if the person who knows the most were unavailable for a month. Those two lists surface more real exposure than any framework, and both can be drafted in an afternoon.

Everything else is refinement. Organisations do not get into difficulty because their risk methodology was unsophisticated. They get into difficulty because a known risk had no owner, no action and no date, and nobody looked at it again until it happened.

Reading your insurance properly

Insurance appears on almost every nonprofit risk register as a mitigation and is almost never checked against the risks it is supposed to mitigate. It is worth an hour with the actual policy documents rather than the renewal summary.

  1. Directors and officers liability. Confirm it exists, what it covers, and whether it extends to former directors and to employment practices claims, which are among the most common.
  2. General liability. Check the limits against the scale of your activities and whether your events and off-site work are included.
  3. Abuse and molestation coverage, which is frequently excluded from general policies and is essential for any organisation working with children or vulnerable adults.
  4. Volunteers. Confirm they are covered as though they were staff, because many policies define the insured group narrowly.
  5. Property and equipment, including anything staff use at home, which standard policies often exclude.
  6. Cyber and data breach, which is usually a separate product and usually assumed to be included when it is not.
  7. Contractual requirements. Funders, landlords and partners frequently impose minimum coverage levels. Check you meet them before signing, not at renewal.

Then note the answers on the risk register itself, beside the risks each policy addresses. A register that says insured is not a control. A register that names the policy, the limit and the renewal date is.

Not sure what your real exposure is?

Our free nonprofit assessment looks at governance, finance and capacity together, and tells you plainly which risk should be at the top of your register.

Take the free assessment

Frequently asked questions

What is the biggest risk for a small nonprofit?

Usually funding concentration and key person dependency. Both are normalised because they have been fine for years, and both are the most common causes of serious difficulty in the sector.

How long should a risk register be?

One page, typically eight to twelve risks for a small charity. Longer registers get completed once and never influence a decision, which means they are documents about risk rather than risk management.

How do we write a risk properly?

As a consequence rather than a topic. “Funding” is not a risk; “our largest funder does not renew in March, leaving a gap we cannot cover from reserves” is specific enough to plan against.

Is it acceptable to do nothing about a risk?

Yes, if the decision is deliberate and recorded. Accepting a risk because mitigation costs more than the exposure is a defensible governance position. Silently ignoring it is not.

Does insurance count as managing risk?

Partly. It transfers financial consequence but does nothing about operational disruption, and coverage for volunteers, off-site activity and driving is frequently absent by default. Read the exclusions as a board.

Do we need directors and officers insurance?

It makes board recruitment considerably easier and prospective directors increasingly ask. If you do not carry it, that should be a conscious board decision rather than something discovered later.

How often should the board review risk?

Quarterly, with changes highlighted, focusing on the two or three that moved rather than reviewing everything. Annual review means risks are effectively unmanaged between meetings.

What should a crisis plan contain?

Who decides, who speaks, which board members are contacted immediately, what staff are told and when, which funders must hear directly, where contact details live, and when to seek professional advice.

Scroll to Top