Buidling personal relationships

Do Nonprofit Boards Face Cyber Security Risk?

This image has an empty alt attribute; its file name is id-100325196.jpg

Do Nonprofit Boards Face Cyber Security Risk?

By: Eugene Fram     

Solarwinds and Target and others may seem far afield from the concerns of nonprofit directors, except for the giants in the area, like AARP. However, think about this hypothetical scenario.

A group of high school students hacked into the computer system of a local nonprofit offering mental health services and gain access to records of clients, perhaps even placing some of the records of other teenagers on the internet.  Considering the recent introductions of new AI tools, the power of immature teenagers and adults to initiate Cyber Security (CS) problems seems unlimited.  

What due care obligations did the board need to forestall the above situation? A move to recruit directors with special expertise in information technology or cyber security would be nonproductive. A nonprofit director has broader responsibilities such as the overview of management, approval of budgets, fostering management and staff growth etc. Similarly, when social media became a prominent issue a few years ago, boards debated the advisability of seeking directors with that specific kind of background. Today, a consultant with management is likely to provide guidance to directors on these issues.

After listening to a group of cyber security experts discuss for-profit challenges in this area, I have the following suggestions on how nonprofit boards might respond to similar types of challenges.

1. Carefully “wall off” all confidential information – Have management be certain that private information such as health records, are encrypted and separated from operating data that may be considered public in a nonprofit environment.
2. Review D&O and other liability policies – Determine whether or not the D&O policy protects directors and managers from CS intrusions. (It likely does not, but I understand that some carriers may offer some protection along with smaller policies.) It is clear that most general liability policies do not protect the organization against CS.
3. Board Encouragement – Devote some meeting time, perhaps 10 minutes, to a discussion of the CS topics so that management and staff are aware of the board’s concerns on the subject and will take action when necessary. Appropriate due care actions like frequent password changes should become routine. Some checklists are available online, suggesting questions directors might pose to raise awareness on the topic and avoid potential CS breaches.
4. Can third party payer help? – Many nonprofits deal with third party payers with sophisticated CS systems and may offer the nonprofit some advice or assistance.
5. Education and training of employers – Many CS crimes have been successful because employees have violated or forget to effectively protect their working accounts and information. Proper education and training can help reduce these types of lapses.
6. Finance & Audit Committees – Recent data indicate that only 20% of nonprofits have a CS vulnerability assessment in place and only about the same proportion have a plan  in place should a CS breach take place . *  Due care responsibilities seem to be missing among a large portion of nonprofits.

If a nonprofit, like the one described, is attacked, not only will records be compromised, but also the reputation of the agency will be destroyed, probably along with the nonprofit organization itself. SolarWinds and Target may be able to survive such an attack, but the typical nonprofit may not.

*https://communityit.com/nonprofit-cybersecurity/

Is Your Nonprofit Strategically Deprived?

By: Eugene Fram   

A vital concern to the future of any nonprofit organization is frequently neglected. Responsibility for the lack of strategic planning must reside with the chief executive, board members and the tactical challenges that inevitably flow to the board.

Before a nonprofit board can begin successful strategic planning, it must:
• fully understand the difference between strategic and tactical planning.*
• have a fully engaged chief executive involved with the board in the leadership of the strategic planning process.
• have a proportion of board directors with some specific types of strategic oriented experiences.

For example, one faith based organization recreational facility I know built a modern new building. However, the leadership was unaware of the quietly growing demand for preschool education in the area. As soon as the new building was opened, several parts of the structure had to be remodeled to accommodate a growing preschool population.

While I admit that planning for coming societal and behavioral, changes is difficult, like the one in the example, I suggest that any nonprofit board needs to take “inventory” of the following backgrounds of the current chief executive and board members.

How strategically capable is the organization’s chief executive? Does he or she stay at the leading edge of the field? Has the board recruited the chief executive for a strategic acumen or for just keeping the organization on a stable course?

How successful has an organization been in recruiting some of the following types of board members?
1. Those with enough time to become thoroughly acquainted with field related to the mission, visions of the organization’s operations. After all, many nonprofit directors serve on boards whose fields of focus are quite different from those in which they have working experience.
2. Those who can distinguish between a strategic plan and a tactical plan?
3. Those capable of critical thinking, questioning past assumptions as they relate to the future.
4. Those who have had successful strategic planning experiences at a high (not tactical) levels on other FP or NFP boards.
5. Those who have innate visionary abilities to assess future opportunities or roadblocks.
6. Those who have failed with past unsuccessful strategic plans but learned from their mistakes.
7. Those who can realistically project the financial challenges a strategic plan will develop.
8. Those with significant prior NFP or FP experience who can be models for younger directors with time restrictions who contribute via time limited task force assignments. But they need much more seasoning with understanding governance functions because they often rubber stamp board chair or CEO suggestions.

Addressing these recruitment issues in a forthright manner should enable nonprofit organizations to determine if they are strategically deprived. This move also might improve nonprofits’ records for strategic planning.

*  “strategy is the action plan that takes you where you want to go, the tactics are the individual steps and actions that will get you there”.

Once Again: How to Keep a Nonprofit Board Informed.

Informed.

This image has an empty alt attribute; its file name is id-10046990.jpg

Once Again: How to Keep a Nonprofit Board Informed.

By: Eugene Fram   

With high performing nonprofit boards, its members will rarely be invited by the CEO to participate in operational decisions. As a result, management will always have more information than the board. Yet the board still needs to know what is happening in operations to be able to overview them.
The name of the game is for the CEO to communicate the important information and to keep directors informed of significant developments. Still, there’s no need to clutter regular board meetings by reporting endless details about operations.

Following are some practical suggestions:
• An executive director, in response to a blog post I presented, provided a most creative approach. He and the board chair have a weekly conference call, usually on Thursday. Other board members are invited to join the call if they have time. A few days later, the ED sends a brief e-mail to all board members highlighting the important events that took place during the week. (He joked that his high school English teacher would never approve of its format, but the board is always full informed.)

• Probably the more traditional way of keeping board members aware of what is happening within the organization is to have staff frequently make short presentations. I have seen this approach used in dozens or nonprofit board meetings without success. Two problems frequently occur. First the staff person is so enthusiastic about an opportunity board that the presentation continues well beyond the allotted time, and, second, board members raise “micromanagement” level questions, that further extend the presentation session. To solve these problems, the board chair needs to suggest to those seeking more than appropriate detail that the questions can be answered “offline.” In addition, the chief executive should meet with the staff person well ahead of the meeting to make sure that the material to be presented is succinct, and the staff person is well aware of the time constraint. A “dress rehearsal” might even be appropriate for some staff personnel

• Another technique is to use a consent agenda. With a consent agenda, routine and previously agreed upon items are organized together in the pre-meeting agenda and then, hopefully, approved as a group. If one or more board members question an item in the group, it is placed on the agenda for the next board meeting. This process eliminates the time consuming effort of having a separate discussion for each item.

• A third controversial way is for the chief executive to meet with board members informally about every quarter. (It is controversial because many nonprofit CEOs feel this is too time consuming.) Occasionally, these meetings are with two directors at one time. At the sessions, the chief executive can discuss the more “entrepreneurial or wild ideas” that might need testing and update board members on operational decisions in greater detail. Some of the meetings can happen quite informally, before or after a committee meeting or after a monthly board meeting. Others can occur at appropriate social events. This is a controversial suggestion, as some CEO’s report they don’t have sufficient time for such a rigorous meeting schedule.  My observations of dozens of CEOs indicates that the very best manage to develop the schedule.
It is important to have the executive’s assistant keep track of the meetings and then to have authority to make new appointments to meet the quarterly schedule. Obviously, the CEO would need to meet with the board chair more often. If the board is a national one, meeting less frequently or a scheduled phone call are appropriate. One veteran CEO I know meets frequently with two board members. One is a long serving member, and the other is a newly appointed board member.

Keeping important information flowing to the board is critical to having a high performing nonprofit. It is a significant CEO responsibility

Board Members Need to Review Unwritten Protocols to Boost Nonprofits’ Effectiveness

Board Members Need to Review Unwritten Protocols to Boost Nonprofits’ Effectiveness

By:  Eugene Fram                                       

Nonprofit boards are governed by a series of obligations —some are clearly defined as legal responsibilities such as financial actions. Others, however, are less clearly defined and relate to people who are, in some way, associated with the organization. Guidelines to these diverse interactions are not typically archived in policies but are important to the overall professionalism of the board. They include consideration of its: board structure, internal operations, recruitment methods and leadership style.

(more…)

People Problems Can Put Nonprofits at Risk

People Problems Can Put Nonprofits at Risk

By: Eugene Fram   

Like the Streisand song lyric, nonprofit people who need people must first have the know-how to choose and cultivate those people! If not, the risks to a board can range from modest to substantial. It all begins with making the right choices and vetting board and CEO candidates.  Most nonprofit board members know that they are only required to make one hiring decision—the engagement of the CEO. This is a process that always involves some risk factors. Take the case of the university that has expended substantial amounts to engage a CEO. After a brief “honeymoon period” it was determined that the candidate lacked the requisite background to move the organization forward. His resignation was forthcoming, and with it, a disruption that was costly not only in dollars but in board/faculty morale and public confidence.

A nonprofit board is usually confronted with several people risks. Following are some that should be noted by board members.

Colleagues on the Board- Modest Risk: Except when a crisis occurs necessitating additional time and effort to address the problem, there is often little opportunity for collegiality among nonprofit board members. In recent times, with many board members living time-compressed lifestyles, colleagues not only don’t know each other but may pass each other on the street without recognition! This lack of personal interaction makes it difficult for directors to understand and share perspectives regarding the organization. It is clearly the board and CEO’s responsibility to provide these opportunities by organizing social events and/or small gatherings for board people to interact– perhaps over breakfast, lunch or wine. Another option is to extend an invitation to attend local or regional professional events. Or to invite board members to join a conference call during the weekly call between the board chair and the CEO. People contact within the board cements relationships and becomes an asset to working together as a group.

Financial Personnel-Might Be Substantial Risk?: Financial people, as a group or individually, can constitute a potential risk group. At the very least, each board member should be thoroughly acquainted with the CFO, his/h senior reports and the professional qualifications of each, especially in relation to their abilities to stay current with financial requirements. The board needs to provide sufficient signals to all staff personal that it is alert to unethical behavior, especially fraud.  Similarly, the board and/or its committees need to make certain that there is substantial compliance with all regulations imposed by governmental or professional organizations. Example: One CFO delayed the delivery of an accounts receivable report for an extended time period. Neither the board nor management demanded it. When the report finally arrived, the board found that the CFO had been carrying a substantial number of bad debts as assets.   To rectify the situation, the nonprofit had to engage costly forensic accountants. Although the board was also substantially at fault in its due care, both the CFO and CEO were fired.

The CEO-Can Be A Substantial RiskLike a marriage, there needs to be substantial trust between the board members and CEO. However the CEO should to be comfortable with a policy of “trust but verify.”   This requires that the board members and/or its audit committee ask questions or make inquiries that sometimes might appear be insulting. Some examples:

The Staff- Can Be Moderate RiskBoard members need to be have enough contact with management and staff in order to be able to help identify those who with talent may be eligible for promotion, understanding that traditionally the CEO has is responsible for internal promotions.   Unfortunately this is a nonprofit board responsibility that is often neglected. But it needs to be reviewed annually at the time that CEO succession is reviewed by the board.  

A nonprofit is only as good as its team of people. With many of the board members rotating off after their terms have expired, it becomes an ongoing challenge to keep them apprised of potential risks and challenges. The board must develop its own way to a nonprofit’s success.   In addition, it must overview management and staff to build background knowledge on those with potential to become future leaders. 

Can Business Board Experts Can Offer Nonprofit Gems? 

  

By: Eugene Fram                                 

Chinese Proverb: The wise person learns from his/h own experiences. The wiser person learns from the experiences of others

The CEO Forum published an article covering the governance views of five business board members, known for their wisdom and vision.   Following are some of topics in the article that relate to nonprofit boards. *

Good governance is dependent upon well-curated boards. This means that nonprofit boards must look beyond the functional competencies (e.g. accounting, marketing, law, etc.) for candidates. Within these groupings, they need to seek candidates who have strategic outlooks, are comfortable with critical thinking and have documented leadership skills.   This requires recruiting and vetting efforts that go well beyond the friends, neighbors and colleagues who traditionally have been the sources for board positions. Also related is the issue of board succession, since that many will leave the board after a four to six year period. The current board(s) has an obligation to make rigorous recruiting and vetting become part of the nonprofit’s culture.

Assessing long-term sustainability. In the past, nonprofits have projected longevity because there will always be a need for the services or products they provide. This is no longer an assured proposition. Nonprofit day care centers now must compete with those that are for-profit. Improvements in medication have decreased the need for individual counseling and many new technologies can quickly solve problems that are embedded in the nonprofit’s mission.

Review governance best practices carefully! Know who is suggesting them and make certain they are appropriate for a specific organization. For example, some experts suggest that executive committees should be eliminated. However an executive committee that is responsible for a slim board committee structure can be effective in driving change and promoting better communications throughout the organization. **

Changing public accounting firms. Nonprofit accounting practice suggests changing public accounting firms about every five years. However one expert suggests, “It is important to ensure that judgment areas such as nonGAAP disclosures are well-defined, supporting calculations are well-documented and that the definitions and calculations are consistent across reporting periods.” At times of accounting firm change, nonprofit board members need to be able to add these issues to their question that they pose to management.

Ethics & Compliance. Like business organizations, nonprofits are subject to significant lapses in ethics and compliance. One study of  nonprofit fraud found that it 46% involved multiple perpetrators.  ***  As shown in the Wells Fargo debacle, establishing the tone for rigorous applications of a standard needs to start with the board and flow through all management levels. In the current environment, audit committees have to be especially alert and take immediate actions when red flags arise in either the ethics and/or compliance areas.   In my opinion, a nonprofit audit committee that meets only once or twice a year is not doing the necessary job.

Strategy. The nonprofit board has an obligation to help management see “around the next corner.” This involves board members assessing coming trends and sparking civil and meaningful board and committee discussions.

Board member comfort zones. Like their business counterparts, few nonprofit board members are “comfortable testing how to rock the norms.” It is easier to acculturate new directors to the current norms, a process that is inward bound and self-defeating. But a start can be initiated with questions such as, “If we were to start a new nonprofit across the street, what would it look like and who of the present board and a staff members would we ask to join us?”

*https://www.forbes.com/sites/robertreiss/2017/05/22/americas-five-governance-experts-share-perspective-on-boards/#2a2ee326659a   

**For documentation see: https://goo.gl/QEL8x3

***https://nonprofitquarterly.org/nonprofit-fraud-its-a-people-problem-so-combat-it-with-governance/

Can Using Imperfect Data Assist Nonprofits in Defining Impacts?

 

By Eugene Fram

Nonprofit boards need to expand their evaluations of nonprofit managers and their organizations adding more behavioral impacts * to their evaluations.

For example, a nonprofit might count the number of volunteers that have been trained. But boards must go to the next level in the 21st century.
In the case of volunteers, they must seek to understand the impacts on those trained. They need, for instance, to understand how well these volunteers are assisting clients and how they are representing the nonprofit to the clients. The training is a process, but it determines their relationships with clients and yields impact data.

Qualitative data must be developed to the next level, and the average nonprofit CEO will argue that he/she doesn’t have the staff or expertise to develop impact data. Engaging an outside organization to complete a simple project can cost thousands of dollars.

(more…)

Stay on That Nonprofit Board!

By: Eugene Fram

Gene Takagi, noted San Francisco attorney, who specializes in nonprofit organizations published an article listing 12 reasons for resigning from a nonprofit board. It is worth reading.*

BUT

Nonprofit board members often become impatient with the slow pace of progress toward positive change. Here are some actions that may change the situation, improve service to clients and prepare the organization for any long-term mission disruptions.

• Talk With The CEO: He/s may feel the same frustrations and be delighted to find a board member who shares his goals. In fact, she/h may be thinking of leaving or be wedded to the current area only because of a family situation. As a result, your conversation may give a chief executive new hope and energy. On the other hand, if the CEO is too aligned with the past, it will be unlikely that the board will terminate the current CEO, unless there are some performance malfeasances involved. Then, estimate the CEO’s remaining tenure and use remaining time to find opportunities to make modest increments in change.

• Talk With Other Directors: Between board meetings, have informal coffee sessions with other directors to determine their views on the areas in which you feel change is necessary. Three or four board opinion leaders can garner positive movement, assuming there are no strong objections from the CEO.

• Outside Validation. If sufficient budget is available, ask the board to engage a consultant to examine the potentials for change. The rationale for the request might be: “We are doing well, let’s determine how we can better serve our clients.” If budget isn’t available or the CEO is against the expenditure, try to have the board arrange, for an outside speaker or two who might validate the need for change. This might be a person from the field or a local professor who has some insights aligned with change-focused board members .

• Seek Outside Financing: Personally seek sources for capacity grants that, if awarded, might be developed to further help clients. Ask the board to take leadership in applying for several of these grants. A single successful grant might be the linchpin to promote the type of change desired by the group having similar views.

• Chair The Nominations Committee: As chair, the director can be in a position to search for candidates who are forward looking. In addition, the committee, under the urging of the chair, can seek candidates who have served on other nonprofit boards and who have proven their meddle to bring about change.

Summary
For any single board member of a status quo nonprofit to lead a change on organizational culture will require tenacity, time and patience. The person will need to be extremely dedicated to the organization’s mission and want to improve the services to its clients. Very few board members have the grit to lead such a change. However, a small-motivated group can be an advanced guard to initiate some actions in the right direction. But the group will have to keep Peter Drucker’s insight in mind when the going gets tough, “Culture eats strategy change for breakfast.”

An unusual case of an ED accused of serious malfeasance, but the board refused to fire him. http://bit.ly/1om6XUw

*https://nonprofitquarterly.org/12-reasons-resign-nonprofit-board/

Does A New Nonprofit Board Member Really Understand Your Organization?  The New Board Member Nurturing Challenge!

 

Does A New Nonprofit Board Member Really Understand Your Organization?  The New Board Member Nurturing Challenge!

By: Eugene Fram       Free Digital Image

The careful nurturing of a new board member, whether for-profit or nonprofit, is critical. The pay-off of a robust orientation process is an informed and fully participating board director. The following are very similar occurrences in both for-profit and nonprofit boards:

The CEO of a transportation firm agrees to become a board director of a firm developing computer programs. He has risen through the transportation ranks with a financial background, but he knows little about the dynamics of the computer industry.

A finance professor is asked to serve on the board of a nonprofit school serving handicapped children. She has no children of her own and has never had any contact with handicapped children, social workers or teachers serving handicapped children.

In these similar cases, the new board member needs to become reasonably conversant with a new industry or a new human service field in order to be able to better apply policy development skills, strategic planning skills and to allow generative thinking.

On nonprofit boards, the problem is exacerbated when the new board member often is asked to immediately join a specific board committee without being able to understand the board perspectives and the organization’s mission vision and values. Following are ways in which the nonprofit board can resolve this problem:

  • Don’t appoint the new board member to committee until she/h has completed a board orientation program including a review of board procedures, attending several board meetings, has had visits with the staff, as they normally operate, and becomes alert to the major trends in the field. This ideally should take about six months assuming the board member is employed full-time elsewhere.
  • During this time, the chief executive and board president should be available to visit with the new board member as frequently as she/h wants in order to respond to questions.
  • Hopefully, the chief executive would informally meet the new board member (and each established director) quarterly to review current issues and opportunities. In addition to the information presented at the board meetings, this will provide a better perspective of the board’s mission, vision and values.
  • Ideally, the board volunteer should attend one staff meeting and one outside professional meeting to acquire a feeling for the topics reviewed at these gatherings and the field terminology.
  • During the first year, a senior board member needs be seated next to the new person at meetings to act  as a “host” for the new board member.

If most of these actions can be accomplished within a six-month period, major blind spots are removed, and the new board member can then join a standing board committee or an active task force. Now, reasonably understanding the organization and her/h own participation on the board, she/h has a background to make a substantial contribution for years to come.

Two Nonprofits Merge: Synergy or Collision Course?

 

Two Nonprofits Merge: Synergy of Collision Course?

By Eugene Fram              Free Digital Image

Having led a merger committee that resulted in a successful merger with another nonprofit, I thought my field observations might be of interest to others contemplating a merger. These comments center on a merger of two equal partners, which plan to form a new organization, not the acquisition of one nonprofit by another.

Assuming both organizations have merger committees that meet frequently, over an extended time period, the following initial issues need to be reviewed:

• Are the mission, vision and values of both organizations the same or sufficiently similar?

• Are there any financial issues that might cloud the negotiations?

• Do the two merger committees work well together and view each other positively as potential colleagues?

• Are both groups willing to invest the board time and financial resources to bring about a melding of the two groups?

• Are there any factions in either of the two organizations that might be emotionally opposed to the merger?

• What, at this early stage, might be some barriers (“deal breakers”) to the merger?

• What needs to be done to move the merger process forward and to develop an implementation plan, if both boards agree to the merger?

• How will the impact of the merger be determined and at what intervals will it be measured?

• In the event that either or both organizations are dissatisfied with the merger, what specific detail need to be specified in a “prenuptial” breakup agreement?

• How will the CEO of the merged organization be determined? This will have to be decided amicably

• How can morale of both organizations be maintained during merger discussions? What incentives need to be developed to maintain those who will certainly need a new job, e.g. CFO?

The Devil Is In The Details – Are These “Deal Breakers?

• Consider various stakeholders who might be impacted by the merger. (These can include: community leaders, managers, staff, funders, vendors, media, etc.) How can consensus be achieved?

• Where will the new nonprofit be physically located? What are the real estates implications?

• The combination will probably require layoffs and new reporting arrangements. How will these be decided?

• How will the new board be constituted? Will a larger new board be necessary? If not, what is the plan for paring down the size of the new board.

• What legal counsel will be needed and at what costs? Will foundation support be needed to establish the merger?

• What systems or interpersonal relationships are necessary to avoid “surprises” before or after the merger?

Never Underestimate the Importance of Culture

The failure of the AOL-Time Warner merger has become an all time classic example of the failure of the two cultures to blend into a new culture. I have observed that blending two nonprofit organizations will certainly encounter cultural “bumps in the road,” starting about six months after the merger and can continue for several years. Although the mission, vision and values of both groups may be identical, culturally inspired blips can arise from differences in which previous boards operated, from expectations of the CEO, from staff differences, etc. However, they do take time, persistence and board leadership to resolve.

Any merger will have its own specific imprint. However, I hope that the guidelines cited above will be helpful in navigating the rough shoals that frequently appear after the honeymoon period.