An external auditor delivers their report to a foundation. They flag serious gaps: no system documentation, uncontrolled access rights, backups that have never been tested, and total dependence on a technical provider with no formal contract in place.
The annual report due to oversight authorities is at risk. The founding donors, companies that apply the same standards to their philanthropic commitments as to their business affairs, are starting to ask questions.
This situation is not exceptional in the foundation world. And it is entirely avoidable.
What sets a foundation apart from a standard nonprofit
Company foundations and endowment funds occupy a hybrid position. They pursue a public benefit mission, like any nonprofit, but their governance is subject to demands closer to those of the business world: financial traceability, stronger director accountability, public transparency.
Their assets, from initial endowments to major donations, must be managed with the same rigour as a financial portfolio. Their donor data, often involving companies or families with high expectations around confidentiality, is an intangible asset that needs protecting. That subject is covered in our article on donor data security.
Annual reporting requirements
Each year, a foundation produces a management report submitted to oversight authorities and available to the public. This document must accurately reflect how resources were used, what programmes were delivered, and what outcomes were achieved. The reliability of that information depends directly on the quality of the IT systems behind it.
Inconsistent data between systems, lost historical records, an inability to locate accounting documents: any of these can lead to a report being challenged or an order from the supervisory authority. That is not a theoretical risk.
Trustee accountability
Foundation trustees carry a real duty of care. They must ensure that assets, information assets included, are protected. Negligence in managing donor or beneficiary data can result in personal liability for individual board members.
In a serious incident, it is not just the foundation that may be held accountable, but potentially its directors as individuals.
What serious managed IT delivers
A specialist provider does not take responsibility away from the board. It gives the board the means to carry out its responsibilities properly, through:
- Complete, up-to-date system documentation
- Tested backups and a formalised recovery plan
- Role-based access controls, reviewed regularly
- Documented incident response procedures
- A contract with defined service commitments and audit rights
The contract matters. Depending on a provider with no formal arrangement is itself a governance failure.
Long-term thinking
Endowment funds are built to last. Technical choices made today need to anticipate handover to future teams, data compatibility a decade from now, and the ability of an auditor to locate and verify historical information. Documentation and interoperability are not administrative details; they are central to long-term governance.
To find out more about IT support tailored to foundations, visit /en/nonprofits/.
