
Governance, Risk Management and Controls for NPO’s
GRIPP was engaged by the HCI Foundation to facilitate a Governance, Risk and Internal Control (“GRC”) workshop and share some of our insights and thinking within the GRC space, with specific reference to the non-profit sector being the Foundation key partners and beneficiaries. Our learnings from Community Keepers and Leap Schools were leveraged coupled with principled, generic, and leading practice GRC topics.
Shuaib kicked off by unpacking the definitions of Governance, Risk and Internal Control. Shuaib presented the case for good governance, governance challenges within the non-profit sector, the benefits of good governance, leading practice frameworks and literature such as King IV™, the Independent Code of Governance for the Non-Profit Sector in South Africa and the Department of Social Development’s Codes of Good Practice for South African NPOs.
Some of the key governance challenges in the NPO sector include:
- Limited resources
- Informal structures
- Overreliance on donors/ funders
- Donor pressures
- Weak oversight
- Skills and expertise (board members)
The benefits good governance within the NPO space include:
- Added credibility and enhanced reputation.
- Within the context of the POPI Act, protecting donor, employee, and volunteer information.
- Consistent Policies and Procedures.
- Better access to funding.
- Enhanced fraud prevention and safeguarding of funds due to improved controls.
- The ability to leverage a wider pool and expertise for employment, for guidance and advice as well as volunteer work.
- Business continuity arrangements that permit the NPO to operate under conditions of volatility and withstand or recover from this.
- Leadership continuity through succession planning.
Shuaib ended off with the governance outcomes which can be achieved if adequate structures, practices, and processes are implemented. The argument made in this section is that any organisation (private, public, non-profit) can achieve good governance outcomes when considering its nature, context, proportionality and fit-for-purpose thinking.
Lesego started off the Risk discussion by inviting participants to assess their GRC maturity, being “Average”, “Good” or “Excellent”, but also to consider “Poor” as a unit of measure and to take a view of what assessment an independent person may arrive at.
He began his presentation by highlighting the definition of risk management and drawing the link between the process, being driven by people in pursuit and furtherance of organisational objectives.
Lesego indicated why the adoption of risk management is important within the NPO space, highlighting the two key risks, being:
- Financial risks – funding shortfalls, fraud, or donor dependency.
- Operational risks – staff turnover, system failures, or program disruptions.
He further articulated how NPOs may benefit form risk management, with specific reference to it protecting the organisation’s mission and objectives, strengthening governance and accountability and enhancing donor and stakeholder confidence.
Lesego highlighted two key opportunities that may lie within the NPO space:
- Digital Transformation and Technology Adoption – Use technology to streamline operations, improve donor engagement, and enhance service delivery.
- Strengthening Governance and Leadership Capacity – Invest in board and leadership development to improve oversight, accountability, and strategic direction.
In wrapping up, Lesego took the audience through a sample risk register and noted that there isn’t a single generic risk register that is specific to the NPO space. What is important is that the context of each NPO be identified to understand its outcomes and goals. Risks to the achievement of outcomes and goals should be the ones that receive attention and prioritisation from management. If a risk has little to no impact on objectives, it is not sustainable to try and manage that risk.
Carla started off the Internal Control session by defining Internal Control and indicating that effective internal controls help an organisation achieve its objectives by minimising risks, preventing errors and fraud, and establishing a system of checks and balances.
She shared examples of the most common types of controls, being:
- Preventive controls – the proactive measures designed to stop an error or irregularity from occurring; and
- Detective controls – Designed to identify an error or irregularity after it has occurred.
She further took the audience through the limitations of internal control:
- Human judgment and error
- Collusion among employees
- Management override of controls
- The cost of implementing controls outweighing their potential benefits
Carla then identified some of the challenges for South African NPO’s, which includes resource constraints, outdated or non-existent policies and training as well as poor policy implementation. She ended off the session by providing ways in which these challenges can be overcome / managed:
- Creative segregation of duties: Crosstrain staff and volunteers to rotate through duties monthly or quarterly. This will help identify irregularities and ensure that not just one person has control over all aspects of a financial area for an extended period.
- Leverage technology effectively: Use affordable or free accounting software that can automate tasks, reduce manual errors, and provide clear reporting. Utilise cloud-based document storage to make financial records accessible and secure.
- Free or low-cost training: Non-profit resource centres, accounting associations, and grant-making foundations often offer free workshops and webinars on financial management and internal controls.
- Conduct a policy audit: Review all financial and operational policies to ensure they are up-to-date, relevant to the organisation’s current activities, and compliant with current South African legislation and donor requirements.
- Standardise and enforce handover procedures: Create a comprehensive handover checklist for departing employees, particularly those in financial roles.
- Prioritise regular reconciliation: Consistent, independent reconciliations of key accounts, including bank and petty cash accounts, can quickly detect errors or fraud. This practice is a simple yet powerful detective control.
- Conduct timely internal reviews: Perform a self-evaluation of internal controls regularly. This proactive approach ensures accountability and catches issues early.
In closing, it was clear that good governance, risk management, and internal controls are crucial because they work together to ensure an organisation is efficient, ethical, and successful. They provide a framework for achieving strategic objectives, safeguarding assets, ensuring compliance, preventing fraud and errors, and improving overall performance and stakeholder confidence.