Author: eugenefram

Dr. Eugene Fram has over 25 years experience as a non-profit board member, consultant, and author. His model of nonprofit governance has been adopted by thousands of organizaations.

Do Nonprofit Boards Face Cyber Security Risk?

This image has an empty alt attribute; its file name is id-100325196.jpg

Do Nonprofit Boards Face Cyber Security Risk?

By: Eugene Fram     

Solarwinds and Target and others may seem far afield from the concerns of nonprofit directors, except for the giants in the area, like AARP. However, think about this hypothetical scenario.

A group of high school students hacked into the computer system of a local nonprofit offering mental health services and gain access to records of clients, perhaps even placing some of the records of other teenagers on the internet.  Considering the recent introductions of new AI tools, the power of immature teenagers and adults to initiate Cyber Security (CS) problems seems unlimited.  

What due care obligations did the board need to forestall the above situation? A move to recruit directors with special expertise in information technology or cyber security would be nonproductive. A nonprofit director has broader responsibilities such as the overview of management, approval of budgets, fostering management and staff growth etc. Similarly, when social media became a prominent issue a few years ago, boards debated the advisability of seeking directors with that specific kind of background. Today, a consultant with management is likely to provide guidance to directors on these issues.

After listening to a group of cyber security experts discuss for-profit challenges in this area, I have the following suggestions on how nonprofit boards might respond to similar types of challenges.

1. Carefully “wall off” all confidential information – Have management be certain that private information such as health records, are encrypted and separated from operating data that may be considered public in a nonprofit environment.
2. Review D&O and other liability policies – Determine whether or not the D&O policy protects directors and managers from CS intrusions. (It likely does not, but I understand that some carriers may offer some protection along with smaller policies.) It is clear that most general liability policies do not protect the organization against CS.
3. Board Encouragement – Devote some meeting time, perhaps 10 minutes, to a discussion of the CS topics so that management and staff are aware of the board’s concerns on the subject and will take action when necessary. Appropriate due care actions like frequent password changes should become routine. Some checklists are available online, suggesting questions directors might pose to raise awareness on the topic and avoid potential CS breaches.
4. Can third party payer help? – Many nonprofits deal with third party payers with sophisticated CS systems and may offer the nonprofit some advice or assistance.
5. Education and training of employers – Many CS crimes have been successful because employees have violated or forget to effectively protect their working accounts and information. Proper education and training can help reduce these types of lapses.
6. Finance & Audit Committees – Recent data indicate that only 20% of nonprofits have a CS vulnerability assessment in place and only about the same proportion have a plan  in place should a CS breach take place . *  Due care responsibilities seem to be missing among a large portion of nonprofits.

If a nonprofit, like the one described, is attacked, not only will records be compromised, but also the reputation of the agency will be destroyed, probably along with the nonprofit organization itself. SolarWinds and Target may be able to survive such an attack, but the typical nonprofit may not.

*https://communityit.com/nonprofit-cybersecurity/

Is Your Nonprofit Strategically Deprived?

By: Eugene Fram   

A vital concern to the future of any nonprofit organization is frequently neglected. Responsibility for the lack of strategic planning must reside with the chief executive, board members and the tactical challenges that inevitably flow to the board.

Before a nonprofit board can begin successful strategic planning, it must:
• fully understand the difference between strategic and tactical planning.*
• have a fully engaged chief executive involved with the board in the leadership of the strategic planning process.
• have a proportion of board directors with some specific types of strategic oriented experiences.

For example, one faith based organization recreational facility I know built a modern new building. However, the leadership was unaware of the quietly growing demand for preschool education in the area. As soon as the new building was opened, several parts of the structure had to be remodeled to accommodate a growing preschool population.

While I admit that planning for coming societal and behavioral, changes is difficult, like the one in the example, I suggest that any nonprofit board needs to take “inventory” of the following backgrounds of the current chief executive and board members.

How strategically capable is the organization’s chief executive? Does he or she stay at the leading edge of the field? Has the board recruited the chief executive for a strategic acumen or for just keeping the organization on a stable course?

How successful has an organization been in recruiting some of the following types of board members?
1. Those with enough time to become thoroughly acquainted with field related to the mission, visions of the organization’s operations. After all, many nonprofit directors serve on boards whose fields of focus are quite different from those in which they have working experience.
2. Those who can distinguish between a strategic plan and a tactical plan?
3. Those capable of critical thinking, questioning past assumptions as they relate to the future.
4. Those who have had successful strategic planning experiences at a high (not tactical) levels on other FP or NFP boards.
5. Those who have innate visionary abilities to assess future opportunities or roadblocks.
6. Those who have failed with past unsuccessful strategic plans but learned from their mistakes.
7. Those who can realistically project the financial challenges a strategic plan will develop.
8. Those with significant prior NFP or FP experience who can be models for younger directors with time restrictions who contribute via time limited task force assignments. But they need much more seasoning with understanding governance functions because they often rubber stamp board chair or CEO suggestions.

Addressing these recruitment issues in a forthright manner should enable nonprofit organizations to determine if they are strategically deprived. This move also might improve nonprofits’ records for strategic planning.

*  “strategy is the action plan that takes you where you want to go, the tactics are the individual steps and actions that will get you there”.

Once Again: How to Keep a Nonprofit Board Informed.

Informed.

This image has an empty alt attribute; its file name is id-10046990.jpg

Once Again: How to Keep a Nonprofit Board Informed.

By: Eugene Fram   

With high performing nonprofit boards, its members will rarely be invited by the CEO to participate in operational decisions. As a result, management will always have more information than the board. Yet the board still needs to know what is happening in operations to be able to overview them.
The name of the game is for the CEO to communicate the important information and to keep directors informed of significant developments. Still, there’s no need to clutter regular board meetings by reporting endless details about operations.

Following are some practical suggestions:
• An executive director, in response to a blog post I presented, provided a most creative approach. He and the board chair have a weekly conference call, usually on Thursday. Other board members are invited to join the call if they have time. A few days later, the ED sends a brief e-mail to all board members highlighting the important events that took place during the week. (He joked that his high school English teacher would never approve of its format, but the board is always full informed.)

• Probably the more traditional way of keeping board members aware of what is happening within the organization is to have staff frequently make short presentations. I have seen this approach used in dozens or nonprofit board meetings without success. Two problems frequently occur. First the staff person is so enthusiastic about an opportunity board that the presentation continues well beyond the allotted time, and, second, board members raise “micromanagement” level questions, that further extend the presentation session. To solve these problems, the board chair needs to suggest to those seeking more than appropriate detail that the questions can be answered “offline.” In addition, the chief executive should meet with the staff person well ahead of the meeting to make sure that the material to be presented is succinct, and the staff person is well aware of the time constraint. A “dress rehearsal” might even be appropriate for some staff personnel

• Another technique is to use a consent agenda. With a consent agenda, routine and previously agreed upon items are organized together in the pre-meeting agenda and then, hopefully, approved as a group. If one or more board members question an item in the group, it is placed on the agenda for the next board meeting. This process eliminates the time consuming effort of having a separate discussion for each item.

• A third controversial way is for the chief executive to meet with board members informally about every quarter. (It is controversial because many nonprofit CEOs feel this is too time consuming.) Occasionally, these meetings are with two directors at one time. At the sessions, the chief executive can discuss the more “entrepreneurial or wild ideas” that might need testing and update board members on operational decisions in greater detail. Some of the meetings can happen quite informally, before or after a committee meeting or after a monthly board meeting. Others can occur at appropriate social events. This is a controversial suggestion, as some CEO’s report they don’t have sufficient time for such a rigorous meeting schedule.  My observations of dozens of CEOs indicates that the very best manage to develop the schedule.
It is important to have the executive’s assistant keep track of the meetings and then to have authority to make new appointments to meet the quarterly schedule. Obviously, the CEO would need to meet with the board chair more often. If the board is a national one, meeting less frequently or a scheduled phone call are appropriate. One veteran CEO I know meets frequently with two board members. One is a long serving member, and the other is a newly appointed board member.

Keeping important information flowing to the board is critical to having a high performing nonprofit. It is a significant CEO responsibility

Are Dysfunctional Nonprofit Boards Interesting?

The current image has no alternative text. The file name is: id-100435120.jpg

By: Eugene H. Fram

My blogs have been drawing an unusual number of views related to dysfunctional nonprofit boards.  Is it because:

  • Nonprofit evaluations have become a prime media interest?
  • Compliance regulations have forced a greater number of nonprofits to substantially review their charters?
  • More boards have found board problems arising as a result of reviewing the expanded 990-form section on governance?
  • More audit committees are being given expanded responsibilities?

Can a nonprofit organization focus on its mission vision and values if it has a dysfunctional nonprofit board?  I have seen this accomplished in situations where the CEO is managerially oriented and can live with the board’s problems or foibles.  For example, one nonprofit I encountered had an eleven person board, four of which never attended meetings and several others were sometimes absent for personal reasons.  Meeting minutes clearly showed a focus on operational detail. However a strong CEO was able to focus well, and the organization prospered. On the other hand,the CEO openly complained that she was overworked, needed board member assistance and easily could become financially liable board, missteps.  

In another situation I encountered, the board chair and ED were very strong, but the board governmentally weak. Work and family pressures constrained the time board members could devote to their governance responsibilities. While the organization performed reasonably well, performance problems and board liability issues might arise, if either the chair or ED retired or resigned.

Although not desirable station, a dedicated mission oriented staff can, at a minimum, perform reasonably well when its board may be dysfunctional.  However the following conditions are needed.

  • Management is able to keep the staff focused on mission, vision and values.
  • A legacy staff person(s) becomes a mentor(s) for more recently engaged staff. 
  • The dysfunction is relatively brief and resolved by board member rotation.  If too long, organizational performance will decline.  
  • Board members involved with the dysfunction do not seek to involve staff in their disputes.  

Board Members Need to Review Unwritten Protocols to Boost Nonprofits’ Effectiveness

Board Members Need to Review Unwritten Protocols to Boost Nonprofits’ Effectiveness

By:  Eugene Fram                                       

Nonprofit boards are governed by a series of obligations —some are clearly defined as legal responsibilities such as financial actions. Others, however, are less clearly defined and relate to people who are, in some way, associated with the organization. Guidelines to these diverse interactions are not typically archived in policies but are important to the overall professionalism of the board. They include consideration of its: board structure, internal operations, recruitment methods and leadership style.

(more…)

The Enron Debacle–2025 Lessons For Nonprofit Boards?

 

By: Eugene Fram               

In 2001 Enron Energy collapsed due to financial manipulations and a moribund board. It was the seventh-largest company in the United States. Andrew Fastow, the former CFO and architect of the manipulations served more than five years in prison for securities fraud. He offered the following comments to business board members that, in my opinion, are currently relevant to nonprofit boards. Quotations from Fastow are italicized.*

• One explanation of his downfall was he didn’t stop to ask whether the decisions he was making were ethical (moral).

Nonprofits directors and managers can find themselves in similar situations. One obvious parallel is when a conflict of interest occurs.  In smaller and medium sized communities, it is wise to seek competitive bids, especially when the purchase may be awarded to a current or former board member or volunteer.

Board members and managers themselves can be at personal financial peril, via the Intermediate Sanctions Act, if they wittingly or unwittingly provide an excess salary benefit to an employee or an excess benefit to a volunteer or donor. Examples: The board allows a substantial above market salary to offer to the CEO. Also the board allows a parcel of property to be sold to a volunteer or donor at below market values. 

One subtle area of decision-making morality centers on whether a board’s decision is immoral by commission or omission. Examples: In its normal course of client duties, the board allows managers to travel by first class air travel. Obviously, resources that are needed by clients are being wasted and morally indefensible. On the other hand the moral issue can come in to play, if the nonprofit is husbanding resources well beyond what is needed for an emergency reserve. The organization, in a sense, is not being all it can be in terms of client services or in seeking additional resources. Overly conservative financial planning, not unusual in nonprofit environments, can result in this latter subtle omission “moral” dilemma. Overtly, universities with billions of dollars on their balance sheets have been highlighted as having the issue, but I have occasionally noted smaller nonprofits in the same category.

• He (Fastow) said he ultimately rationalized that he was following the rules, even if he was operating in the grey zones (area).

There can be grey zones for nonprofits. Example: IRS rules require that the nonprofit board be involved in the development of the annual Form 990 report. But what does this involvement mean—a brisk overview when the report is finished, a serious discussion of the answers to the questions related to corporate governance, a record in the board minutes covering questions raised and changes suggested, etc.? A nonprofit boards needs to make a determination on which course is appropriate.

Boards implementing government-sponsored contracts can get into grey areas. Example: Some contracts require the nonprofits to follow government guidelines for travel expenses. I wonder how many nonprofit audit committees are aware of their responsibilities to make certain these guidelines are followed?

According to Fastow, a for-profit director can ask the wrong question—“Is this allowed?” A nonprofit director can make the same mistake. Instead, in my opinion, the better question for a nonprofit should be “Will this decision help the organization to prosper long after my director’s term limit?”

As Fastow did, human service boards can invite trouble if they falsely rationalize an action as being taken for client welfare, and then conclude they are following the rules.

• Mr. Fastow said one way to start changing an entrenched culture is to have either a director on the board, or a hired adviser to the board, whose role is to question and challenge decisions.

Nonprofit directors are often recruited from friends, family members and business colleagues, etc. This process creates an entrenched board.

When elected to the board, a process begins to acculturate the new person to the status quo of the board, instead making best use of the person’s talents. Example: An accountant with financial planning experience will be asked to work with the CFO on routine accounting issues, far below her/h professional level. One answer is to accept Fastow’s suggestion and to appoint a modified lead director or adviser to a nonprofit board.***

An old Chinese proverb states, “A wise man learns by his own experiences, the wiser man learns from the experiences of others. Nonprofits can learn a something from Andrew Fastow’s post conviction trecollections to hopefully help avoid significant debacles.

*https://video.search.yahoo.com/yhs/search?fr=yhs-iba-syn&ei=UTF-8&hsimp=yhs-syn&hspart=iba&param1=u3aa5HpmsM3IXRQhgULSrC7

**https://www.irs.gov/charities-non-profits/charitable-organizations/intermediate-sanctions

***http://bit.ly/13Dsd3v)

People Problems Can Put Nonprofits at Risk

People Problems Can Put Nonprofits at Risk

By: Eugene Fram   

Like the Streisand song lyric, nonprofit people who need people must first have the know-how to choose and cultivate those people! If not, the risks to a board can range from modest to substantial. It all begins with making the right choices and vetting board and CEO candidates.  Most nonprofit board members know that they are only required to make one hiring decision—the engagement of the CEO. This is a process that always involves some risk factors. Take the case of the university that has expended substantial amounts to engage a CEO. After a brief “honeymoon period” it was determined that the candidate lacked the requisite background to move the organization forward. His resignation was forthcoming, and with it, a disruption that was costly not only in dollars but in board/faculty morale and public confidence.

A nonprofit board is usually confronted with several people risks. Following are some that should be noted by board members.

Colleagues on the Board- Modest Risk: Except when a crisis occurs necessitating additional time and effort to address the problem, there is often little opportunity for collegiality among nonprofit board members. In recent times, with many board members living time-compressed lifestyles, colleagues not only don’t know each other but may pass each other on the street without recognition! This lack of personal interaction makes it difficult for directors to understand and share perspectives regarding the organization. It is clearly the board and CEO’s responsibility to provide these opportunities by organizing social events and/or small gatherings for board people to interact– perhaps over breakfast, lunch or wine. Another option is to extend an invitation to attend local or regional professional events. Or to invite board members to join a conference call during the weekly call between the board chair and the CEO. People contact within the board cements relationships and becomes an asset to working together as a group.

Financial Personnel-Might Be Substantial Risk?: Financial people, as a group or individually, can constitute a potential risk group. At the very least, each board member should be thoroughly acquainted with the CFO, his/h senior reports and the professional qualifications of each, especially in relation to their abilities to stay current with financial requirements. The board needs to provide sufficient signals to all staff personal that it is alert to unethical behavior, especially fraud.  Similarly, the board and/or its committees need to make certain that there is substantial compliance with all regulations imposed by governmental or professional organizations. Example: One CFO delayed the delivery of an accounts receivable report for an extended time period. Neither the board nor management demanded it. When the report finally arrived, the board found that the CFO had been carrying a substantial number of bad debts as assets.   To rectify the situation, the nonprofit had to engage costly forensic accountants. Although the board was also substantially at fault in its due care, both the CFO and CEO were fired.

The CEO-Can Be A Substantial RiskLike a marriage, there needs to be substantial trust between the board members and CEO. However the CEO should to be comfortable with a policy of “trust but verify.”   This requires that the board members and/or its audit committee ask questions or make inquiries that sometimes might appear be insulting. Some examples:

The Staff- Can Be Moderate RiskBoard members need to be have enough contact with management and staff in order to be able to help identify those who with talent may be eligible for promotion, understanding that traditionally the CEO has is responsible for internal promotions.   Unfortunately this is a nonprofit board responsibility that is often neglected. But it needs to be reviewed annually at the time that CEO succession is reviewed by the board.  

A nonprofit is only as good as its team of people. With many of the board members rotating off after their terms have expired, it becomes an ongoing challenge to keep them apprised of potential risks and challenges. The board must develop its own way to a nonprofit’s success.   In addition, it must overview management and staff to build background knowledge on those with potential to become future leaders. 

The Art of the “Ask”: Six tactics frequently ignored by nonprofit board members, CEOs and fund Developers

By: Eugene Fram      

Nonprofit board members and managers have acquired a measured of savvy when it comes to raising funds for their organizations. They have learned that building trust with current and prospective donors is the key to maintaining meaningful support. Here are some overlooked tactics to further strengthen relationships. *

  1. Show the donors “what’s in it for them:” Some development officers still lead by focusing on what is of interest to them—the construction of a new building, providing funds for the nonprofit’s strategic development plan, etc.   But they often lack certain perspectives. These are the skills to effectively interact with business executives like those holding C-Suite positions. These senior managers value evidence that the nonprofit representatives have “done their homework.” Pre-meeting preparation must include generating information on the executive (s’) professional and career background(s) that is readily available from LinkedIn. Also it is necessary to have some information about the challenges the firm or its industry are encountering. This level of preparation helps set a basis for better communications and managerial discussions that C-Suite personnel value.
  1. Consistency: Be ready to clearly indicate that the nonprofit has a well-developed mission that is future oriented. A nonprofit with a record of financial results that consistently meets budget requirements is one example. Low turnover at the management and/or staff level is another. But also be ready to answer such visionary questions as, “How do you expect your organization to change in the next five years?”
  2. Reputation: Every nonprofit, large of small, has a reputation among its peers and the general public.   Be certain that the donor has a clear idea of what it is and is not a wish list of what it might be. Emphasize the impact data available, supported by impact information.   For example, Family Service nonprofits are actually multi-purpose human service organizations. But the chapter names can deliver a different message—organizations devoted to family planning. As a result of this potential interpretation, the names of some chapters have been changed to e.g. Family and Children’s Service or Families First.
  3. Building Personal Relationships: Personal connections are the basic building blocks of donor relationships. Some professional development officers suggest that major donors should be thanked seven times. ** But thanking is only the beginning of a continuing process. Nonprofit CEOs and board chairs need to be proactive in visiting major donors on an annual basis, or more often if the donor wants more contact. The purpose here is not to seek additional funding but rather to reinforce a message related to mission impact. An invitation to a social event is another way of maintaining these connections. Sometimes a follow-up to a major donor can yield unusual results. I recently observed a situation where a board member made an effort to follow through  on a social event invitation to a long-term donor. It yielded a substantial contribution within 10 days of the event.   Every nonprofit board needs a proactive donor response program. These responsibilities should be noted in the CEO’s and Board Chair’s responsibilities.
  4. Be honest, even if that means saying “No”: When a gift involves undesirable mission creep or an unfunded charge to current assets, be prepared to say “No.” Universities, for example, have been known to accept buildings as gifts that can quickly become maintenance liabilities. Cash grants may have unfavorable strings attached tot them. Donor intent must clearly be understood. Princeton University had to return a large endowment when the donor’s heirs proved the university did not use it in a manner that confirmed the donor’s wishes.
  5. Open your Doors to Donors: Where possible, invite current and potential donors to the nonprofit’s offices or operational facilities. Even when the office is a series of enclosures or open offices, the visit gives the donors a feel for the culture and a chance to know the people dedicated to the mission.   A visit is even more helpful when the facility is an active one, such as a food distribution pantry, sheltered workshop or a call center.

The fog of the nonprofit board overviewing processes often obscures the importance of cultivating donor relationships that may, in time, fuel a nonprofit’s progress. The above review is a reminder to board members and management of their responsibilities to the artful pursuit of asking.

*https://www.forbes.com/sites/forbesnonprofitcouncil/2018/04/04/seven-ways-nonprofits-can-build-trust-with-donors/#4d6836067d26

** For more details, see: https://michaelrosensays.wordpress.com/2014/03/18/ensuring-repeat-gifts-the-rule-of-7-thank-yous/

Can Business Board Experts Can Offer Nonprofit Gems? 

  

By: Eugene Fram                                 

Chinese Proverb: The wise person learns from his/h own experiences. The wiser person learns from the experiences of others

The CEO Forum published an article covering the governance views of five business board members, known for their wisdom and vision.   Following are some of topics in the article that relate to nonprofit boards. *

Good governance is dependent upon well-curated boards. This means that nonprofit boards must look beyond the functional competencies (e.g. accounting, marketing, law, etc.) for candidates. Within these groupings, they need to seek candidates who have strategic outlooks, are comfortable with critical thinking and have documented leadership skills.   This requires recruiting and vetting efforts that go well beyond the friends, neighbors and colleagues who traditionally have been the sources for board positions. Also related is the issue of board succession, since that many will leave the board after a four to six year period. The current board(s) has an obligation to make rigorous recruiting and vetting become part of the nonprofit’s culture.

Assessing long-term sustainability. In the past, nonprofits have projected longevity because there will always be a need for the services or products they provide. This is no longer an assured proposition. Nonprofit day care centers now must compete with those that are for-profit. Improvements in medication have decreased the need for individual counseling and many new technologies can quickly solve problems that are embedded in the nonprofit’s mission.

Review governance best practices carefully! Know who is suggesting them and make certain they are appropriate for a specific organization. For example, some experts suggest that executive committees should be eliminated. However an executive committee that is responsible for a slim board committee structure can be effective in driving change and promoting better communications throughout the organization. **

Changing public accounting firms. Nonprofit accounting practice suggests changing public accounting firms about every five years. However one expert suggests, “It is important to ensure that judgment areas such as nonGAAP disclosures are well-defined, supporting calculations are well-documented and that the definitions and calculations are consistent across reporting periods.” At times of accounting firm change, nonprofit board members need to be able to add these issues to their question that they pose to management.

Ethics & Compliance. Like business organizations, nonprofits are subject to significant lapses in ethics and compliance. One study of  nonprofit fraud found that it 46% involved multiple perpetrators.  ***  As shown in the Wells Fargo debacle, establishing the tone for rigorous applications of a standard needs to start with the board and flow through all management levels. In the current environment, audit committees have to be especially alert and take immediate actions when red flags arise in either the ethics and/or compliance areas.   In my opinion, a nonprofit audit committee that meets only once or twice a year is not doing the necessary job.

Strategy. The nonprofit board has an obligation to help management see “around the next corner.” This involves board members assessing coming trends and sparking civil and meaningful board and committee discussions.

Board member comfort zones. Like their business counterparts, few nonprofit board members are “comfortable testing how to rock the norms.” It is easier to acculturate new directors to the current norms, a process that is inward bound and self-defeating. But a start can be initiated with questions such as, “If we were to start a new nonprofit across the street, what would it look like and who of the present board and a staff members would we ask to join us?”

*https://www.forbes.com/sites/robertreiss/2017/05/22/americas-five-governance-experts-share-perspective-on-boards/#2a2ee326659a   

**For documentation see: https://goo.gl/QEL8x3

***https://nonprofitquarterly.org/nonprofit-fraud-its-a-people-problem-so-combat-it-with-governance/

Can Using Imperfect Data Assist Nonprofits in Defining Impacts?

 

By Eugene Fram

Nonprofit boards need to expand their evaluations of nonprofit managers and their organizations adding more behavioral impacts * to their evaluations.

For example, a nonprofit might count the number of volunteers that have been trained. But boards must go to the next level in the 21st century.
In the case of volunteers, they must seek to understand the impacts on those trained. They need, for instance, to understand how well these volunteers are assisting clients and how they are representing the nonprofit to the clients. The training is a process, but it determines their relationships with clients and yields impact data.

Qualitative data must be developed to the next level, and the average nonprofit CEO will argue that he/she doesn’t have the staff or expertise to develop impact data. Engaging an outside organization to complete a simple project can cost thousands of dollars.

(more…)