Risk Management for Your Organization

Jun 15, 2021 | Business Health, Non-Profit

In order to fulfill their charge to provide direction and guide an organization, the Board of Directors must manage risk.  Effective risk management involves a process of planning, prioritizing and protecting.

In the planning stage, it’s important to identify all the risks facing the organization.  This might include things like:

  • fraud
  • theft
  • injury
  • reputation
  • cybersecurity
  • product obsolescence
  • investment market volatility
  • disaster loss
  • employee dissatisfaction
  • customer dissatisfaction

A nonprofit organization might add others like:

  • tax compliance
  • grant compliance
  • medical billing compliance
  • volunteer dissatisfaction
  • donor dissatisfaction
  • conflicts of interest

It’s unproductive to try to tackle everything at once, so the next step is to prioritize the risks that have been identified.  This is a subjective process, so there’s no one right way to do this.  Many organizations assign two separate criteria to each risk: one for likelihood and the other for impact.  Likelihood can be assigned several levels- certain, likely, possible, unlikely or rare.  Impact can be assigned as insignificant, minor, moderate, serious, and catastrophic.  Once put in grid form, it’s easy to see which items need to be addressed first and which the organization can wait to deal with or accept risk for.

Once priorities have been established, the hard work begins.  In general, risks can be avoided, accepted, reduced or transferred.  Risks should be individually analyzed to determine the best way to manage them.   For example, fraud risk over cash might be controlled by training and internal controls to ensure that no one person can receive it, record it, and disburse it.  Injury risk might be controlled by facility maintenance and insurance.  Each problem will need to be solved individually.

The Board has the ultimate responsibility to guide the organization in the best possible way to fulfill its mission and protect its assets.  Being proactive about risk and establishing a process to mitigate it is critical to an organization’s viability, health and resilience.

Article submitted by Donna Buzby, CPA, RMA, CGMA

Photo by Ben Collins on Unsplash

Subscribe to our Accounting, Tax and Business Insights Newsletter

This field is for validation purposes and should be left unchanged.
Email Address:
Name(Required)
Privacy(Required)
Client Spotlight: Ozzie’s Luncheonette

Client Spotlight: Ozzie’s Luncheonette

If Longport could be said to have a landmark, that would be Ozzie’s. Ozzie’s opened in 1948 at the corner of 24th and Atlantic Avenue as a food market and a liquor store. Ozzie Lenzsch acquired the lots directly next door and opened the luncheonette in 1952. For...

read more
The One Big Beautiful Bill Act

The One Big Beautiful Bill Act

On July 4th, 2025 President Donald Trump signed the One Big Beautiful Bill Act (OBBBA).  This bill has several important changes to various aspects of the tax regime.  This article is a summary of the bill’s extension of expiring tax codes and updates for individuals,...

read more
The Baby Boom is Now the Aging Boom

The Baby Boom is Now the Aging Boom

According to the Wall Street Journal, the US octogenarian population is expected to increase by 4 million over the next 5 years. The oldest “boomers” are approaching 80, and advances in technology and medicine mean that enjoying life well into one’s 90s is...

read more