Industries: Nonprofit

How to Become a Tax-Exempt Organization

By Richard J. Locastro, CPA, JD and Katelyn Miller, CPA, MST The terms “nonprofit” and “tax-exempt organization” are often used interchangeably. And while there may be considerable overlap in their definitions, there is a distinction, especially for a 501(c)(3) public charity or private foundation. As explained further below, the process to become a tax-exempt organization…

Read more ›

A Guide to Third Party Risk Management

Understanding and mitigating third party risk has become more important than ever, which makes now the perfect time for your organization to implement a third-party risk management program. This guide covers several aspects of third-party risk management, including steps for developing a program, tips for vetting new vendors, and the new risks presented by AI tools.

ESG for Non-Profit Risk Managers

Bottom Line: ESG is becoming more important to donors, employees, partners, and other stakeholders. Non-profit risk managers need to be prepared to answer tough questions about how their organization is managing critical ESG risks. ESG Basics for Non-Profits ESG refers to environmental, social, and governance factors in an organization’s operations. There is no universal definition…

Read more ›

Mitigate Online Donation Risks with PCI Compliance and Third-Party Risk Management

Taking donations online is a huge benefit to nonprofit organizations, but online payments also expose potential risks. To safeguard their operations and donors’ financial information, nonprofits must prioritize Payment Card Industry (PCI) compliance and third-party risk management. Nonprofits are at a higher risk of credit card test attacks than other organizations due to certain functionality…

Read more ›

Risk Management is on the Rise at Not-For-Profit Organizations

2023 State of Risk Oversight Survey Results By Amy Wares, CPA, MBA, Enterprise Risk Management Specialist Managing risk is more challenging than ever. New research reveals that not-for-profit organizations are responding by expanding their risk management practices. On July 11, 2023, the Enterprise Risk Management (ERM) Initiative at NC State University published the 14th edition…

Read more ›

How ERM Helps Organizations Navigate Their ESG Journey

ESG (Environmental, Social, and Governance) frameworks provide a sustainable approach to doing business. Existing ERM tools can help support these efforts.

Optimize Risk Management Efforts with Enhanced Collaboration

To some extent, all business functions are responsible for managing risks. However, certain departments have direct responsibilities in risk management, such as Internal Audit, Enterprise Risk Management (ERM), and Fraud Risk Management. Integrating and fostering collaboration between these functions can result in more effectively addressing risks and protecting against fraudulent activities. This is particularly critical…

Read more ›

Best Practices for Mitigating Risk in Expense Reporting Platforms

Expense reporting platforms have simplified the review and approval processes, making it easier to submit documentation for payment. However, this convenience can also lead to less stringent review of submitted documents and opportunities for changing electronic receipts. As a result, organizations need to implement best practices to reduce the risk associated with these reporting systems….

Read more ›

How Internal Audit Can Support Whistleblower Investigations

Do you know if an employee is stealing from your company?  Quite often, the first hint of a problem comes from an insider tip. Having a comprehensive whistleblower program in place is a powerful early warning mechanism for identifying potential fraud or misconduct. If you have an internal audit function, you already have the tools…

Read more ›

Aligning Business Continuity Planning with Third Party Risk Management

Does your organization know all the third-party vendors who access and manage data on your behalf? In the event of a disaster, any gaps in responsibilities, security, and communications prolong the outage of business operations, so it’s better to identify and eliminate these gaps now before a disaster happens.