Skip to main content

Why Is Nonprofit Risk Increasing and What Can Organizations Do?

By Travelers Insurance
7 minutes

Key takeaways

  • Nonprofit risk exposure is increasing as financial pressure, governance scrutiny, workforce challenges and cyber threats converge.
  • Nonprofit risk extends well beyond directors and officers (D&O) liability to include workforce, cyber, crime and operational exposures.
  • Governance, internal controls and workforce management remain leading drivers of claims and organizational disruption.
  • Structured risk assessment helps identify vulnerabilities before they disrupt operations.
  • Risk management is most effective when prevention, preparedness and insurance work together. 

Nonprofit risk is increasing as multiple pressures converge, including financial instability, heightened governance scrutiny, workforce challenges and evolving cyber threats. These interconnected risks are driving up the likelihood of incidents that can disrupt operations and strain funding and public trust. Proactive nonprofit risk management can help organizations identify vulnerabilities before they escalate and take practical steps to help safeguard the people, resources and reputation that support their mission. Strengthening internal controls, reinforcing governance practices and aligning insurance coverage with evolving exposures can support continuity, funding stability and organizational trust over the long term.

Nonprofit risk management encompasses how the board makes decisions, monitors finances and maintains transparency with stakeholders, how policies protect employees and volunteers, and how the organization secures sensitive data and keeps day-to-day operations running.

Nicole Murphy

Nonprofit D&O Product Manager, Bond & Specialty Insurance

What is nonprofit risk management?

Nonprofit risk management is a structured approach to identifying and reducing risks that could affect an organization’s people, finances, operations, reputation and ability to meet its mission.

It extends beyond insurance to include regulatory compliance, financial discipline, appropriate and enforced employment practices, cybersecurity readiness and operational planning. These areas are interconnected, meaning a weakness in one can quickly create exposure to others. A lack of financial transparency, for instance, can increase fraud risk, which can then trigger governance scrutiny and reputational damage.

The table below highlights how different risk areas can affect an organization:

Risk area Example exposure Potential impact
Governance Board oversight gaps Directors and officers (D&O) liability claims
Financial Weak internal controls Fraud, theft and financial loss
Workforce Employment or volunteer issues Employment practices liability (EPL)  claims, turnover
Cyber  Data breaches Operational disruption, loss of trust
Operations Lack of economic continuity planning Service interruption


Understanding how these areas interconnect helps nonprofit leaders move beyond reactive risk management and toward a more coordinated and proactive approach.

Why is nonprofit risk exposure increasing?

As budgets tighten, labor markets fluctuate and external disruptions such as economic volatility and public opinion persist, nonprofit risk exposure continues to expand. These conditions not only amplify existing vulnerabilities but also introduce new risks that can challenge organizational stability and long-term sustainability.

Financial pressure and funding instability

Donor fatigue, economic volatility and grant competition can tighten nonprofit funding conditions, particularly for organizations that depend on a limited number of revenue sources. Management may respond with necessary cost-saving measures, but those decisions can create new exposures. Program reductions may leave communities underserved. Staffing cuts can strain operations, increase employee fatigue and affect service delivery. Over time, these pressures can damage the organization’s reputation with funders and beneficiaries, compounding financial risk.

Heightened governance scrutiny and board accountability

In the wake of high-profile scandals involving misuse of funds, conflicts of interest and board oversight failures, donors and the public demand greater transparency from nonprofits. Nonprofits face growing scrutiny around governance, fundraising compliance, donor accountability and financial oversight. Missteps in these areas can lead to regulatory actions, reputational harm and D&O claims.1

Workforce and volunteer-related risks

People are the greatest assets of a nonprofit, but workforce-related exposures are significant. Volunteers with varying levels of training increase the potential for accidents, misconduct or harm to vulnerable populations. Escalating economic pressures may also force leaders to reduce staff or cut corners on employment practices, creating conditions where burnout, turnover and incidents leading to EPL claims become more likely. Social inflation and other personnel-related challenges have contributed to the growing frequency and impact of EPL claims.2

Cyber threats and data vulnerability 

Nonprofits hold sensitive donor information, client data and financial details but often lack the robust security infrastructure of their for-profit counterparts. Many rely on outdated systems and require employees to utilize personal devices – often with minimal cybersecurity training –  making them attractive targets for cybercriminals. The impact of cyber incidents can be significant, particularly when they cascade through interconnected systems: A data breach can erode trust and trigger costly notification requirements, while a ransomware attack may disrupt operations for weeks.

Data from the 2025 Travelers Risk Index revealed that cyber risks remain a top concern for mission-driven organizations, yet a preparedness gap persists. While 73% of nonprofit leaders believe having cybersecurity controls in place is important:


Operational disruption and mission continuity risk

Unexpected events can halt nonprofit operations when communities need them most. Because many nonprofits operate on thin margins, leaders may forgo continuity planning or delay updates to existing plans. A single disruption, such as a technology system failure, executive director departure or key funder withdrawal, can quickly affect service delivery and organizational stability.

5-step nonprofit risk readiness checklist

Once leaders understand the pressures facing nonprofits, the next step is to evaluate whether internal practices are keeping pace. The following checklist can help boards and leadership teams identify areas that may need deeper review.


1. Governance and leadership accountability

Strong governance provides the foundation for effective risk management. Clear roles, active oversight and consistent policy enforcement help ensure that risks are identified and addressed early. When governance gaps exist, such as unclear responsibilities or limited board engagement, risks may go unmanaged and decisions may lack appropriate oversight.

Assess whether:

  • Board roles and responsibilities are clearly defined.
  • Compliance with regulatory requirements is maintained.
  • Conflict-of-interest policies are maintained.
  • Board operations align with organizational bylaws and the mission. 

2. Financial controls and fraud prevention

Effective financial oversight depends on clear, consistently applied internal controls. These controls help prevent fraud, reduce errors and support transparency. When duties are not separated or reporting is inconsistent, organizations become more vulnerable to financial misconduct. Even small control gaps can lead to significant losses or reputational damage.

Assess whether:

  • Financial oversight processes are documented and followed.
  • Key financial duties are separated to support a system of checks and balances. 
  • Reporting is accurate and timely. 
  • Audits or independent reviews are conducted. 
  • A clear process exists to detect and report fraud, theft and misuse of funds.

3. Workforce and organizational practices

Workforce-related risks often emerge when policies are unclear or inconsistently applied. A lack of training or supervision can lead to misunderstandings, compliance issues and workplace disputes. Organizations that promote accountability and consistent compliance with policies are better positioned to reduce these risks.

Assess whether:

  • Employment and volunteer policies are up to date.
  • Staff and volunteers receive harassment and code of conduct training.
  • Roles and reporting structures are clearly defined.
  • Safe reporting channels exist for employees to report misconduct.
  • Workplace issues are addressed consistently.

4. Cyber and data security preparedness

Cyber risk increases when safeguards are limited or inconsistently applied. Without clear controls and training, even routine activities can introduce exposure. Organizations that proactively manage data security and incorporate available risk control guidance into their cyber planning can be better positioned to respond to incidents and reduce operational disruption.

Assess whether:

  • Sensitive data is identified and protected.
  • Access is restricted based on role.
  • Staff receive cybersecurity training.
  • Incident response plans are documented and tested.
  • Systems are monitored for vulnerabilities. 

5. Operational resilience and continuity

Operational resilience depends on understanding which functions are mission-critical and preparing for disruption before it occurs. Without that preparation, disruptions can escalate to crises quickly, affecting service delivery and stakeholder confidence when communities may need the organization most.

Assess whether:

  • Critical operations are identified and prioritized.
  • Continuity and crisis plans are documented.
  • Plans are tested through scenarios or simulations. 
  • Third-party and vendor risks are evaluated.
  • Plans address both operational and reputational disruptions that could affect service delivery or community trust. 

Together, these five areas provide a structured view of where risk may be building. Identifying gaps helps prioritize practical improvements – strengthening oversight, refining controls, enhancing preparedness – before issues escalate. Revisiting this checklist regularly supports a more consistent and proactive approach to nonprofit risk management.

What do common nonprofit risk management gaps reveal?

After completing a risk readiness review, leaders may see patterns that point to broader governance, financial, workforce, cyber or operational vulnerabilities. The table below can help translate those findings into practical next steps.

If the assessment shows… It may indicate... Consider reviewing...
Unclear board oversight Governance accountability gaps Board roles, committee charters, escalation procedures
Inconsistent financial controls  Fraud or reporting exposure  Segregation of duties, audit practices, approval workflows
Outdated employment policies EPL exposure Training programs, reporting channels, documentation practices
Limited cyber planning  Data and operational disruption risk Multifactor authentication, incident response, data access controls
No continuity plan Mission disruption risk Crisis planning, vendor dependencies, communication protocols

How can nonprofits strengthen risk management and resilience?

Once leaders identify priority gaps, the next step is to turn findings into manageable action. The practices below can help nonprofits assign ownership, improve consistency and make risk review part of everyday decision-making.

Strengthen governance practices

Document who owns risk oversight, how often the board reviews risk and when issues should be escalated. Establish a regular agenda item for board-level risk discussions that spans governance, finance, cyber, workforce and operational concerns. Catching issues in board conversation is far less costly than catching them in a claim.

Improve internal controls and oversight

Audit approval authority, reporting timelines and separation of duties across financial functions. When staffing is limited, compensating controls – secondary reviews, reconciliations, periodic independent audits – can improve transparency and reduce opportunities for errors or misuse of funds. Document the controls that are in place so they can be reviewed and updated as the organization grows or changes.

Enhance cybersecurity readiness 

Identify sensitive data, limit system access by role and make cybersecurity awareness part of routine staff and volunteer training. Incident response plans should be documented, updated and tested so leaders know whom to contact, what decisions need to be made and how operations can continue during a cyber incident. Carriers that offer risk control services may be a useful resource for organizations building or improving their cyber protocols.

Align leadership, culture and accountability

Set clear expectations for employees, volunteers and board members about conduct, reporting and accountability. Consistent follow-through on reported concerns, documented outcomes and reinforced policies signal to the organization that accountability is real, not performative. Give people a defined way to raise concerns before issues escalate.

Integrate risk management into strategy

Connect risk discussions to budget planning, program changes, vendor decisions and board reporting. This can help leaders weigh trade-offs more clearly when making decisions that may affect funding, staffing, service delivery or reputation.

Enhance employment compliance

Review hiring, supervision, performance management, complaint reporting and investigation procedures for both employees and volunteers. Document training, performance reviews and corrective actions consistently. Reinforce policies addressing harassment, discrimination, retaliation and other workplace misconduct. The organizations most exposed to EPL claims are often those where policies exist but enforcement is inconsistent.

Consistently applying these actions can improve oversight, reinforce accountability and support a more coordinated approach to managing risk across the organization.

What role does insurance play in nonprofit risk management?

Insurance can provide essential financial protection for nonprofits, but it works best as one component of a broader risk strategy – not a substitute for clear governance and accountability, consistent policies, trained staff and strong internal controls. Identifying risks specific to the organization can help determine which insurance investments make the most sense. Having a D&O policy in place may also help reassure current and prospective board members that coverage may be available for certain covered claims.

Even the most well-run organizations face risks that cannot be fully eliminated. Insurance should act as a safety net that supports resilience and recovery rather than being the primary line of defense, providing financial protection when losses, claims or disruptions occur despite an organization’s best efforts.

Thomas Herendeen

Assistant Vice President, Product Management & Strategy, Bond & Specialty Insurance


Common coverages include:

When aligned with a broader risk management strategy, insurance can help nonprofits strengthen financial resilience while supporting recovery from events that cannot be fully prevented.

How can nonprofit leaders take the next step?

Nonprofit risk management is an ongoing process, not a one-time initiative. Progress typically comes through small, deliberate improvements that strengthen oversight, clarify accountability and boost  preparedness over time. Leaders can begin by revisiting key risk areas on a regular cadence, using structured discussions or simple assessments to identify where vulnerabilities may be building. Incremental changes – strengthening a control, updating a policy, adding risk review to an existing board agenda – can help build consistency without overwhelming staff or resources.

Treating risk management as a continuous part of stewardship rather than a one-time task helps leaders build confidence, strengthen accountability and better support their organization’s ability to adapt and grow while staying focused on its mission.

Nicole Murphy

Nonprofit D&O Product Manager, Bond & Specialty Insurance

Over time, these efforts can help embed risk awareness into daily operations and decision-making, supporting a more proactive and coordinated approach to nonprofit risk management.

How does Travelers help nonprofits manage risk?

Travelers offers nonprofit-focused coverage, educational resources and practical risk guidance to help organizations address the governance, workforce, cyber and operational exposures most likely to affect mission-driven organizations.

To learn more, explore Travelers’ nonprofit risk resources or connect with a local independent agent.

Frequently asked questions about nonprofit risk management

Source
1,2 https://www.insurancebusinessmag.com/us/news/professional-liability/why-nonprofit-boards-face-rising-dando-exposure-563281.aspx

Top stories

Is Your Nonprofit Prepared for a Cyber Breach?

A data breach could put a nonprofit's mission, and reputation, at risk. Understand your potential risks and get tips for preparing for the unexpected with these tips from Travelers.

Related products & services

Travelers understands the unique risks of nonprofit organizations and the importance of protecting your mission.

More Prepare & Prevent

Is Your Nonprofit's Mission Protected?

Learn about protecting your nonprofit organization from potential risks and how to help ensure that your nonprofit is Mission: Protected.

More Prepare & Prevent

6 Considerations Before Joining a Nonprofit Board

Thinking about joining a nonprofit board? Here are some questions from Travelers to consider to help protect your personal assets.

More Prepare & Prevent

Protecting Your Nonprofit from Crime

Employee crime can be devastating for a nonprofit without the proper coverage. Read these steps from Travelers to help protect your nonprofit organization from employee crime.