Board members and volunteers rotate constantly — but the accounts and file access you gave them rarely rotate with them. Here's the annual reset that keeps donor and financial data actually protected.
Nonprofit boards are built to turn over. Terms end, officers rotate, volunteers come and go with the seasons — especially as giving season approaches and volunteer rosters swell. It's a healthy structure for governance. It's a quiet problem for IT, because access rarely rotates on the same schedule people do.
In nearly every nonprofit assessment we run, we find the same pattern: a former treasurer who can still open the accounting system, a past board chair still on the donor CRM, a volunteer coordinator from two galas ago still holding a shared drive link. None of it is malicious. All of it is exposure — and if that data includes donor payment information or client records, it's exposure your board is accountable for whether or not anyone remembers granting it.
Before you can close gaps, you need the full map. Board members and active volunteers commonly touch more systems than most executive directors realize:
You don't need a complex system — you need a scheduled one. The nonprofits we work with run this every year, typically after board elections or before the giving season crunch:
Grant applications and cyber-insurance renewals are both trending toward the same question set: who can access sensitive data, and how do you know? A nonprofit that can produce a current access log looks like a well-run organization. One that answers "we're not totally sure" invites exactly the follow-up questions nobody wants mid-application.
Pull your board roster and your system access list side by side this week — before giving season volunteer numbers swell further. Anyone on the access list who isn't on the current roster gets revoked today. If you'd like help building the annual process, our free nonprofit IT assessment starts with exactly this review.
Board turnover is a sign of healthy governance. Make sure your systems reflect that same health — access that changes when people do, not access that just quietly accumulates.
Our free IT security assessment gives your leadership a plain-English report on your risks, your compliance gaps, and exactly what it would cost to fix them. No obligation, no jargon.