Elementum
← Back to compliance, legal and risk

Find and Manage Your Risks.

The everyday risks no one has mapped are the ones that become the crisis that eats a year.

An uninsured accident, a contract signed without reading it, a data breach, a duty to a client or an employee that no one knew about until it was breached. Most organizations manage risk by hoping, and find out what they were exposed to only when the exposure arrives. This work replaces hoping with a clear review: you find your real risks, get the right insurance, protect your contracts and data, and meet your duties to the people you serve and employ, so the predictable crises are prevented or covered instead of survived. It is not disaster and continuity planning, the lost funder, the flood, the systems failure, which is its own work in operational resilience; this covers the legal and liability side and hands the operational side there. And the standing rule for this guide: if anything here surfaces a person in danger right now, stop and act on it before any of the review work.

Step 1

Run a risk review

You cannot manage risks you have not named. Work across the areas: people and safety, money and fraud, property and operations, contracts and partners, data and privacy, and reputation. For each, name what could go wrong and how badly. Then rank the risks by how damaging and how likely they are, and assign an owner to the ones worth acting on.

Who: you, with the Board Chair or a board risk lead, because risk oversight is a board responsibility, and staff who know the daily operation. Produces: a named, ranked register of your real risks, each serious one with an owner, replacing a vague sense of exposure with a list you can work.

Open the Risk Register →
Step 2

Get the right insurance

Insurance is how a nonprofit survives the risks it cannot prevent, and many organizations are underinsured, wrongly insured, or missing coverage their board members personally need. Take your risk register to a broker and check your coverage against it: general liability, coverage that protects your board and officers, property, and any coverage specific to your programs. Find the gaps and the overlaps, adjust or add coverage to close the serious gaps, and put renewals on your compliance calendar.

Who: you, with the Board Treasurer, and a licensed insurance broker who works with nonprofits. Produces: insurance matched to your actual risks, with the dangerous gaps closed and renewals tracked.

Open the Insurance Coverage Review →
Step 3

Protect your contracts and your data

Two everyday risks quietly sink organizations: contracts signed without understanding the obligation, and data about donors and the people you serve held without protection. Decide which contracts get read carefully and which get an attorney's eye before signing, especially anything with a large commitment, a liability clause, or a long term, and set who may sign what. Then take stock of the sensitive data you hold, and set basic protections: who can access it, how it is stored, and what you would do if it were breached.

Who: you, with an attorney for significant contracts and whoever manages your technology and data. Produces: a discipline that keeps contracts from becoming traps and data from becoming a breach, with an attorney on the significant contracts. The systems and technology this runs on live in operations and systems.

Open the Contract and Data Safeguards Guide →
Step 4

Protect people and meet your mandatory duties

The most serious risks a nonprofit carries are its duties to the people it serves and employs, and the law imposes specific ones, screening those who work with vulnerable people, reporting certain harms, keeping a workplace free of harassment and discrimination. Walk each duty and confirm it is met or name the gap, routing the internal work to where it lives. Then decide, before you need it, how a safety concern or a mandatory-reporting situation is raised, escalated, and reported, so no one has to improvise in a crisis.

Who: you, with the Board Chair for the board's duty of care, the right professional, and the staffing, volunteer, and culture work for the internal work. Produces: your duties to people confirmed or routed, the specifics in the right work and professional hands, and a plan for handling a concern before one arrives.

The safety gate

If anyone is being harmed or is at credible risk right now, a vulnerable person, an employee, a client, stop everything else. Act to protect them, meet your legal duty to report, and get the right professional involved, immediately. Only then return to the system work. Route the internal side to the volunteer, staffing, or culture work. Nothing in this guide outranks a person's safety.

Open the People-Safety and Mandatory-Reporting Guide →

The honest edge

Significant contracts deserve an attorney before you sign. Coverage decisions deserve a licensed broker. And any matter of a person's safety, a mandatory-reporting duty, or a harassment or discrimination complaint is acted on immediately and taken to the right professional, because these are the risks where getting it wrong harms a person, not just the organization. The guide surfaces and routes your risks; it does not replace the attorney, the broker, or the professional who handles the serious ones, and it says so plainly at each.

How you will know it worked

You have a risk register you actually review, not a vague worry. Your insurance matches your real risks. Your significant contracts get read or lawyered, and your data is protected. And your duties to the people you serve and employ are met or clearly routed, with a plan for a crisis before one comes.

This completes the compliance foundations

If your plan named other priorities, return to your plan for the next one, and consider handing your disaster and disruption risks to operational resilience and disruption planning. If the risks were about people, the staffing, volunteer, and culture work holds the internal work.

And if you came to this framework in a crisis, handled the acute thing, and worked your way here to build the compliance underneath it, then this is the moment the door that was wrong when you arrived is finally right. You were frightened then, and a full look across the whole organization would have been the wrong thing to hand you. You are steady now. When you are ready, there is a short check-up that looks across the whole organization and shows you what deserves attention next. That is not an offer and it is not a sale. It is the next honest thing to look at, the way a doctor says come back in a few weeks now that you are on your feet. The whole-organization check-up →

You can always go back to the overview or start over from the welcome page.