IT leadership

Managed IT for foundations: governance and accountability

2 min read Guillaume Duveau

Foundations and endowment funds have transparency and traceability obligations that go beyond those of standard nonprofits; their IT governance needs to match those requirements.

An external auditor delivers their report to a foundation. They flag serious gaps: no system documentation, uncontrolled access rights, backups that have never been tested, and total dependence on a technical provider with no formal contract in place.

The annual report due to oversight authorities is at risk. The founding donors, companies that apply the same standards to their philanthropic commitments as to their business affairs, are starting to ask questions.

This situation is not exceptional in the foundation world. And it is entirely avoidable.

What sets a foundation apart from a standard nonprofit

Company foundations and endowment funds occupy a hybrid position. They pursue a public benefit mission, like any nonprofit, but their governance is subject to demands closer to those of the business world: financial traceability, stronger director accountability, public transparency.

Their assets, from initial endowments to major donations, must be managed with the same rigour as a financial portfolio. Their donor data, often involving companies or families with high expectations around confidentiality, is an intangible asset that needs protecting. That subject is covered in our article on donor data security.

Annual reporting requirements

Each year, a foundation produces a management report submitted to oversight authorities and available to the public. This document must accurately reflect how resources were used, what programmes were delivered, and what outcomes were achieved. The reliability of that information depends directly on the quality of the IT systems behind it.

Inconsistent data between systems, lost historical records, an inability to locate accounting documents: any of these can lead to a report being challenged or an order from the supervisory authority. That is not a theoretical risk.

Trustee accountability

Foundation trustees carry a real duty of care. They must ensure that assets, information assets included, are protected. Negligence in managing donor or beneficiary data can result in personal liability for individual board members.

In a serious incident, it is not just the foundation that may be held accountable, but potentially its directors as individuals.

What serious managed IT delivers

A specialist provider does not take responsibility away from the board. It gives the board the means to carry out its responsibilities properly, through:

  • Complete, up-to-date system documentation
  • Tested backups and a formalised recovery plan
  • Role-based access controls, reviewed regularly
  • Documented incident response procedures
  • A contract with defined service commitments and audit rights

The contract matters. Depending on a provider with no formal arrangement is itself a governance failure.

Long-term thinking

Endowment funds are built to last. Technical choices made today need to anticipate handover to future teams, data compatibility a decade from now, and the ability of an auditor to locate and verify historical information. Documentation and interoperability are not administrative details; they are central to long-term governance.

To find out more about IT support tailored to foundations, visit /en/nonprofits/.

Frequently asked

Why do foundations have specific IT requirements?
Because they combine nonprofit obligations (public benefit mission) with business-level governance demands (financial transparency, reporting, director accountability). Their assets and donor data must be managed with rigour.
What annual reporting obligations require serious IT governance?
Foundations produce an annual report submitted to public oversight and accessible to the public. IT systems must generate reliable, traceable records, with data retained according to legal timeframes.
Can foundation board members be personally liable for IT failures?
Yes. Foundation trustees have a duty of care comparable to company directors. Negligence in managing donor or beneficiary data can result in personal liability.
Does outsourcing IT remove responsibility from the foundation?
No. It provides the means to fulfil obligations, but accountability remains with the board. Outsourcing must be backed by a formal contract, audit rights, and a clear data portability clause.
What contractual guarantees should a foundation require from an IT provider?
A formal contract with defined service levels (SLA), audit rights over data, a data portability clause enabling full retrieval at contract end, and documented incident management procedures.

In their words

Since InfraPro started managing our IT, we've reached a new stage in our growth.
Claudia Giampietri — Director, HFHPNon-profit

Let's talk.

Book a call