
In 2025, roughly a third of nonprofits faced some kind of government-funding disruption, with 21% losing funding outright and 27% experiencing delays or freezes, according to Urban Institute's 2025 nonprofit trends study. That's not a hypothetical risk. It already happened to thousands of organizations.
"Risk assessment" sounds like a dry, checkbox exercise. In practice, results vary enormously depending on who's in the room, how risks get scored, and whether anyone acts on the findings afterward. This guide walks through the exact steps, the risk categories to cover, timing considerations, common mistakes, and when outside help makes sense.
Key Takeaways
- Risk assessments identify, score, and prioritize threats to your mission, finances, and reputation.
- Score each risk by likelihood and impact, then choose a response: avoid, retain, share, or transfer
- Update your assessment at least annually, plus after any major organizational shift
- An outside facilitator brings objectivity and cross-organization benchmarking to the process.
How to Conduct a Risk Assessment for Nonprofits
A solid nonprofit risk assessment follows five steps. Skip one, and the whole exercise tends to lose credibility fast.
Step 1: Assemble the Right Team
The people in the room shape what gets identified and how honestly problems get discussed. A good risk assessment team typically includes:
- Board members who bring fiduciary oversight and outside perspective
- The Executive Director, who sees the organization's full strategic picture
- Finance staff, who understand cash flow realities day to day
- Program leads, who know where service delivery actually breaks down
Staff who work inside a process every day often can't see its blind spots. That's why many boards bring in an external facilitator at this stage. A neutral party asks the uncomfortable questions internal staff might avoid, and reduces the risk that one dominant voice steers the whole conversation.
Step 2: Identify Potential Risks Across the Organization
Brainstorm broadly. Don't just chase the most visible or recent threat. Cover every major function:
- Financial
- Compliance
- Operational
- Reputational
- Cybersecurity
- Human resources
While you're at it, separate inherent risk (the raw exposure before any controls exist) from residual risk (what's left after your current safeguards). ISO risk management guidance frames residual risk as what remains after treatment, and it's easy to miss because organizations often assess only what they see today, not what could happen if a control failed.
Capture both. A grant reporting risk might feel "controlled" because one staff member handles it well. That's inherent risk hiding behind a single point of failure.
Step 3: Score and Prioritize Risks Using a Risk Register
Once risks are identified, rate each one by likelihood (how probable is this?) and impact (how bad would it be?) using a simple scale, such as low, medium, high, or major. Log everything in a risk register. Even a basic spreadsheet works.
Then sort each risk into one of three priority tiers based on likelihood and impact:
- Likely and major: address these first, no exceptions
- Likely but minor, or unlikely but major: address next, based on capacity
- Unlikely and minor: monitor, but don't spend scarce meeting time here
BoardSource also recommends factoring in frequency and expected public reaction when scoring, not just a simple two-axis grid. A risk that happens rarely but would trigger major donor backlash deserves more attention than the matrix alone suggests.

Step 4: Choose a Risk Response Strategy
Every scored risk needs a response. There are four standard options:
- Avoid: stop the activity generating the risk entirely
- Retain: accept the risk and budget for it if it materializes
- Share: split exposure with a partner, vendor, or fiscal sponsor
- Transfer: shift the financial burden elsewhere, typically through insurance
A funding-concentration risk might get "retained" with a plan to build reserves. A cybersecurity risk might get "transferred" through a cyber liability policy. There's no universal right answer here. It depends on your risk appetite, budget, and mission tolerance.
Step 5: Document Findings and Build an Action Plan
A risk register that sits in a shared drive helps no one. Translate findings into an action plan with:
- A named owner for each risk
- A deadline for mitigation steps
- A review cadence (monthly, quarterly, or tied to board meetings)
Make the register a standing agenda item, not a once-a-year artifact. Organizations that treat it as a living document catch emerging risks early. Those that file it away after the board retreat usually rediscover the same problems a year later, minus the head start.
When Should Your Nonprofit Conduct a Risk Assessment?
Most organizations build a formal risk review into their annual strategic and budget planning cycle. But that yearly checkpoint is only a starting point.
Certain events should trigger an off-cycle assessment regardless of when the last one happened:
- Leadership transitions — new executive directors or CFOs inherit risk exposure they didn't create
- New program launches — untested activities carry unknown operational risk
- Major funding changes — a new grant, a lost contract, or a shift in your funding mix all change your risk profile
- Entering a new region or regulatory jurisdiction — new state registrations, tax rules, or compliance obligations
We've seen this play out repeatedly with organizations transitioning out of fiscal sponsorship into independent nonprofit status. That single event touches governance, finance, HR, and compliance simultaneously, which is exactly the kind of moment that demands a fresh risk look rather than waiting for the next annual cycle.
Beyond fiscal sponsorship exits, the same logic applies broadly: treating risk assessment as a one-time compliance checkbox undermines the whole point. Your funding mix shifts, your staff changes, and your program footprint grows. A risk register from three years ago tells you almost nothing useful about today's exposure.
Key Types of Risk Every Nonprofit Should Evaluate
Comprehensive assessments organize risks into a handful of categories so nothing critical slips through.
Financial Risk
This covers cash flow shortages, over-reliance on a single funding source, and budget shortfalls. Left unmanaged, financial risk can force program cuts or threaten solvency outright.
Propel Nonprofits points to a 3-6 month operating expense reserve as a common planning benchmark. The right number depends on your cash flow patterns and funding reliability, not a fixed universal rule.
Compliance/Legal Risk
This category covers 501(c)(3) status, state charitable registrations, grant reporting requirements, and tax filings. The stakes are higher than many boards realize: the IRS automatically revokes tax-exempt status for organizations that miss required annual filings for three consecutive years.
There's no warning grace period built in beyond that window, and the consequences compound quickly: penalties, lost exemption, or damaged funder relationships.
Operational Risk
Program delivery failures, staffing gaps, and weak internal controls, such as no segregation of duties, all fall here. Recent funding disruptions show what this looks like in practice. Nonprofits that got hit reported:
- 23% reduced programs
- 21% served fewer people
- 13% closed locations

The fallout shows up fast as service disruption and, over time, as lost credibility.
Reputational Risk
Fraud, cybersecurity breaches, ethical lapses, or public missteps by staff, board members, or partners all threaten reputation. The Nonprofit Risk Management Center frames reputation as the sum of how your constituents perceive you.
That perception is measured in whether donors and community members still believe you're as good as they thought. Once that trust erodes, it can take years to rebuild.
Common Mistakes That Undermine a Nonprofit Risk Assessment
Even well-intentioned organizations trip on the same issues repeatedly:
- Skipping stakeholder input: one or two leaders complete the assessment in isolation, missing frontline knowledge
- Financial and compliance tunnel vision: teams overlook operational, reputational, or HR exposure entirely
- Inconsistent scoring: without a shared likelihood/impact framework, prioritization becomes arbitrary
- No ownership or follow-up date: the register gets built, then forgotten
That last one deserves extra attention. A risk register with no assigned owner quickly becomes a filing exercise rather than a management tool.
SSIR's nonprofit risk research recommends making the register a recurring agenda item. Organizations that skip this step tend to repeat the same exercise every year, with the same unresolved risks sitting at the top of the list.
Should You Conduct the Assessment In-House or Bring in Outside Support?
There's no single right answer. It depends on your governance maturity and internal bandwidth.
Three common approaches exist:
- Self-guided checklist: The most cost-effective route, best for organizations with strong internal governance, an engaged board, and prior experience running structured risk conversations.
- External facilitator or fractional risk advisor: Brings objectivity and benchmarking against similar organizations, plus more speed for boards with limited bandwidth to run the process themselves.
- Embedded partner model: A middle path where outside support stays engaged with your team over time, instead of delivering a one-time report and moving on.
This is the approach we use at Rodriguez Community Group. Our team works alongside staff and boards over time, rather than showing up once as an outside consultant, delivering a report, and disappearing.
We've supported organizations like the English Learners Success Forum and Climate Lead through fiscal sponsor spin-offs. We also helped The Oakland REACH navigate an interim executive transition, both moments when governance, financial controls, and risk exposure shift at once.
The goal is building the internal governance and financial infrastructure that makes risk assessment sustainable year over year, so your team isn't starting from scratch every twelve months.

Frequently Asked Questions
What are the 5 things a risk assessment for nonprofit organizations should include?
A complete assessment includes risk identification across all major categories, likelihood/impact scoring, a documented risk register, a chosen response strategy for each risk, and an action plan with assigned owners and review dates.
What are the 4 types of risk assessment for nonprofit organizations?
Risk is commonly grouped into financial, compliance/legal, operational, and reputational categories. Larger organizations sometimes break these down further into cybersecurity, HR, and fraud-specific assessments.
What is the 33% rule for nonprofit organizations?
This is often misunderstood as a cap on single-source funding. The actual IRS rule is a public-support test: at least one-third of total support must come from public or government sources to maintain certain tax-exempt classifications—a calculation requirement, not a limit on any single gift.
What is the rule of 3 in nonprofit organizations?
This informally refers to keeping roughly three months of operating expenses in reserve. Propel Nonprofits describes a more common benchmark of 3-6 months, adjusted for your organization's specific cash flow and funding stability rather than a fixed universal minimum.
How often should a nonprofit conduct a risk assessment?
Annual reviews aligned with budget planning are standard practice. Add extra reviews whenever a major organizational or funding change occurs, don't wait for the calendar.
Who should lead a nonprofit's risk assessment process?
The board holds ultimate oversight responsibility, but the process works best as a collaborative effort involving leadership, finance staff, and often an outside facilitator to keep the conversation objective.


