IT leadership

IT management and volunteers: when goodwill is no longer enough

2 min read Guillaume Duveau

Entrusting a nonprofit's IT to a skilled volunteer creates a fragile dependency: without documentation, continuity, or formal accountability, one person leaving can bring the whole organisation to a halt.

A nonprofit treasurer arrives one morning to find the file server is unreachable. The volunteer who had been managing it for five years, a retired engineer, reliable and well-meaning, has been suddenly hospitalised.

There is no documentation. Nobody else knows the passwords. Ten years of archives, the member database, event photographs and meeting minutes: all sitting behind a blank screen, and nobody knows how to get in.

This is not a rare situation. It is predictable, and yet organisations keep ignoring it.

Why it seems logical at first

Asking a skilled volunteer to handle IT looks like the obvious choice: it costs nothing, the person knows the organisation, and they are motivated. Nonprofits have a long tradition of pooling their members’ expertise, and in many areas that is a genuine strength.

IT is different. Not because volunteers are less capable, but because managing an information system creates structural dependencies that goodwill cannot fix.

The problem with undocumented knowledge

A volunteer works in the flow of doing. They configure a server, set up access rules, fix problems, and they carry all of it in their head because there is no need to write it down while they are there. That tacit knowledge is valuable as long as they are around. It becomes a serious risk the day they are not.

What we see in practice: very few nonprofits have up-to-date technical documentation. Many do not even know who hosts their website or who their internet provider is.

Here is something many nonprofit leaders do not realise: in the event of a serious IT incident (a data breach, archive loss, ransomware attack), it is the organisation’s director who carries legal responsibility. Not the volunteer, however competent they may be.

The volunteer has no contract, no professional liability insurance, no guarantee. If their error or absence causes harm, the organisation and its registered representative bear the consequences.

Availability is a practical problem

IT does not wait. A failure on a Friday evening, an urgent security patch, a data restoration after a human error. All of these need an immediate response. A volunteer has a life, other commitments, and holidays. Goodwill does not solve that.

The complexity of systems has also grown. Managing access rights, keeping security current, monitoring backups, and meeting data protection obligations requires a range of skills that one person rarely covers completely.

Moving to a more reliable model

Outsourcing IT does not mean cutting out volunteers who want to be involved. An internal point of contact for small everyday needs remains useful. The choice between hiring an IT manager or outsourcing is worth weighing up properly. What changes is that security, continuity, and accountability rest on a professional arrangement: a contract, documented systems, and a team that responds when it matters.

To find out more about what a tailored IT arrangement can offer your organisation, visit /en/nonprofits/.

Frequently asked

What are the risks of relying on a volunteer for IT management?
The main risk is dependency on a single person. If they leave, fall ill, or become unavailable, nobody else knows the systems, passwords, or configurations. Without documentation, data can become permanently inaccessible.
Is a volunteer IT manager liable if something goes wrong?
No. In the event of a data breach or serious failure, legal responsibility falls on the organisation's director, not the volunteer. The registered legal representative answers to regulators and affected parties.
How do you protect an organisation when a volunteer IT manager leaves?
By requiring complete documentation of systems, access credentials, and configurations from the start, and by never allowing one person to hold all administrator passwords without a planned handover.
From how many users should a nonprofit professionalise its IT?
There is no universal threshold, but as soon as an organisation handles sensitive personal data and depends on its systems to operate, a professional arrangement is justified, even for five to ten users.
Can a volunteer still contribute when there is an external IT provider?
Yes. Many nonprofits keep an internal contact for everyday small issues, with the provider handling security, backups, and serious incidents. That combination is often the most effective.

In their words

Since InfraPro started managing our IT, we've reached a new stage in our growth.
Claudia Giampietri — Director, HFHPNon-profit

Let's talk.

Book a call