Skip to content

Compliance pressure on not-for-profits.

Donor data, volunteer data, vulnerable-client records, and funder security questionnaires that now match the ones corporates send. The compliance load is rarely funded by the grant that brings it.

What's being asked of you ·  not-for-profits

What not-for-profits have to prove on compliance in 2026.

Your pressure is less regulator-led than in finance or health, and no less real. Reporting to the Australian Charities and Not-for-profits Commission. Privacy Act obligations on donor and service-user data. Security questionnaires from corporate partners and government grant programs. Provider obligations under the National Disability Insurance Scheme for disability-sector organisations. Funding security expectations from the Department of Social Services for community services. The load adds up without a single dominant regulator.

The questionnaires from corporate partners and government funders get more sophisticated each cycle. A 60-seat community-services organisation can receive a supplier-assurance review from a federal department. It asks the same Essential Eight questions a Tier 1 corporate sends its commercial suppliers. The questions do not adjust for sector or budget.

Sensitive client data is the heaviest weight underneath all of it. Organisations working with vulnerable clients hold information that warrants the strictest Privacy Act handling. Mental health, family services, refugee and migration support, disability. The governance expectation is real and the staffing to meet it usually is not, so the work is finding proportionate controls that actually get operated.

What we do ·  Map, build, maintain

What not-for-profits get from a compliance engagement.

The focus is proportionate control. Your organisation almost certainly handles personal information at meaningful scale, across donors, service users and volunteers, and often sensitive information in the Privacy Act sense. The governance expectation is real. The staffing to implement it usually is not. We make the controls practical, so they are operated rather than documented and ignored.

In practice that means identity and access built for the volunteer turnover you actually have. Privacy Act hygiene that stands up to an enquiry from the Information Commissioner. Funder-questionnaire readiness, so a grant does not stall in a security review. If you run a client-management platform such as iCare, Penelope or SupportAbility, we build the security stack around it. No duplicating what the platform already does.

The cycle is continuous, the way it has to be for an organisation that cannot afford to scramble. Gap analysis against the funder obligations you actually hold. Monitoring across access changes driven by volunteer turnover. Remediation when something drifts. Evidence that pre-fills the next funder questionnaire rather than starting it from scratch.

We are direct about what a not-for-profit budget can and cannot cover. The same baseline a 100-seat law firm operates may be partly out of reach for a 60-seat charity without philanthropic IT funding. We name the trade-offs so your board can decide with full information. Which controls cut the most risk per dollar. Which can be staged across two budget cycles. Where a funder's grant could be redirected to security uplift. The aim is build-to-defensible, not build-to-bank-grade.

The tools and the role ·  the operational toolkit

The capabilities most not-for-profits need at once, and rarely have in-house.

Whichever framework you are measured against, it asks for roughly the same operational set. These five we run as a service, so the framework cycle is a continuing operation rather than an annual scramble.

  • Trouble shows up while it is still recoverable

    Security information and event management, or SIEM, collects logs from your devices, identity, network and cloud services. The alerting answers 'are we under attack right now' rather than 'were we under attack last quarter'.

  • Unapproved software never gets to run

    Allowlisting stops unauthorised executables running on managed devices. One of the highest-impact Essential Eight controls, and one of the hardest for in-house IT to operate without breaking the business. We run it as a service, exception handling included.

  • Known vulnerabilities get closed, not just listed

    Most providers run a scanner and email you a list. We run the scanner and do the labour-intensive remediation work that actually closes the vulnerabilities inside the thirty-day window most frameworks expect.

  • Staff finish the training, and you can prove it

    Annual training your staff actually complete, plus phishing simulations that escalate rather than scold. Your compliance officer gets the completion reporting they can show an auditor or an insurer.

  • Someone senior owns the roadmap, without the salary

    Strategic IT advice, framework gap analysis, board-level reporting, risk register maintenance and vendor management oversight. That is the virtual chief information officer, or vCIO, role most firms our size cannot resource internally.

    More on our vCIO service

What goes wrong ·  for not-for-profits

The compliance risk that actually costs not-for-profits work.

The one that hits hardest is a grant or corporate partnership that survives a smooth questionnaire response. Then a breach arrives a year later and the partnership does not survive it. A major funder asks for evidence that the controls you answered yes to were operating in the relevant period. If the evidence does not exist, the partnership is at risk along with the funding. Saying it up front, with where you are and a dated plan to close the gap, almost always preserves the relationship better.

Already included ·  baseline plan

What your managed IT engagement already covers.

The controls we require are the minimum for every CCP client, not-for-profits included. Where you have specific funder obligations or regulatory overlays, we handle those per engagement against the same baseline. Department of Social Services funding conditions, disability-scheme provider obligations, and state-funding security clauses are the three we see most.

Compliance is an overlay, not a tier on its own. The Managed IT + Compliance plan exists for organisations with continuing funder and regulator obligations and a regular questionnaire calendar. Simpler obligations can run on the baseline plan, with overlays added where a funder or an insurer requires them.

Some of it stays with you. Program design, the service-delivery decisions, the funder relationship at program level, and board-level governance reporting. We provide the IT and compliance machinery the program work and the board reporting depend on to be defensible.

Common questions

The framework questions not-for-profits ask us first.

Can you help us answer funder security questionnaires?
What about ACNC compliance and reporting obligations?
Do you handle Privacy Act obligations around donor and service-user data?
Can you help with NDIS provider obligations in the disability sector?
What about Department of Social Services funding security expectations?
Can we afford compliance on a not-for-profit budget?
Do you help us answer corporate-partner due-diligence questionnaires?

Next step ·  start with the evidence

Find out what your Essential Eight maturity actually is.

Ten minutes of questions gives you a PDF report on your Essential Eight maturity. Hand it to your compliance officer, your insurer or your board the same day. If you want to check we are the right shop for the work, start with the fit check.

See if we're a fit