Getting the right people will be the best investment your organisation ever makes
Posted on 15 Apr 2026
Lately I’ve been spending a lot of time in interview rooms.
Posted on 10 Apr 2024
By Matthew Schulz, journalist, Institute of Community Directors Australia
Not-for-profits must brace for the challenges of an increasingly volatile world in which risks span regulation, climate, ESG (environmental, social and governance factors), reputation, AI, and cyber and IT threats.
In a recent study of more than 400 organisations by Maddocks – ICDA’s legal partner – participants said the areas in which their operations were highly vulnerable were:
The Risk, Regulation and Resilience report, released late last year, represents the first time the firm has benchmarked Australian businesses in these areas, and it found that “no one sector … is better or worse equipped to deal with the risk of a major incident”.
The report provides useful guidance on understanding crises, and it distills characteristics of a crisis and suggests appropriate responses:

In the report, Maddocks proposes organisations consider conducting drills and exercises to test organisational capabilities.
"It is important that NFPs understand the common features of a crisis and test your systems bearing those features in mind, so that you will be well prepared if you are faced with a crisis,” Maddocks partner Catherine Dunlop said.
The central conclusion of the 36-page document is that the set-up, management and enforcement of compliance and risk policies are crucial to preparedness.
It is no surprise that cyber risks are now at the forefront of many NFP leaders’ minds, given the recent spate of cyber attacks affecting the community sector.
In a worrying trend, the report found that small organisations (with less than 100 staff) were far less likely to have existing cyber risk plans (47%), consequence management plans (19%), business continuity plans (55%) or crisis management plans (32%).
A separate study last year by community tech advocate Infoxchange suggests that the cyber risk situation could be even more dire than the Maddocks report suggests: it found that as few as 23% of smaller NFPs had “effective processes to manage information security risks”.

Ms Dunlop said that a significant area of concern for not-for-profits would be “those where the risk is difficult to quantify or address merely with internal resources”. She cited situations in which organisations and their leaders were reliant on external advice in relation to cyber and privacy risks or ageing IT systems.
Ms Dunlop said NFPs would also need to take a close interest in risks “arising from the behaviour of people, such as fraud or poor behaviour (e.g. sexual harassment), which can be unexpected and confronting given how many NFPs rely on dedicated and hard-working staff who are committed to the principles of their organisation.”
According to the Maddocks study, the top three barriers to good risk management are:
The Maddocks report suggests a series of strategies to overcome these barriers:

Those suggestions align with ICDA’s own recommendations, as outlined in this helpsheet: An introduction to the risk management process.
The Maddocks report also provides a sample risk management checklist and places risk management within an overall “organisational resilience framework”, which also encompasses incident management and recovery management.
Maddocks report: Risk, Regulation and Resilience
ICDA tools and resources: Insurance and risk management
Posted on 15 Apr 2026
Lately I’ve been spending a lot of time in interview rooms.
Posted on 15 Apr 2026
Tania Sacco knows what it means to aim carefully. As a competitive archer who has represented…
Posted on 15 Apr 2026
Australian boards are being urged to strengthen their oversight of technology and artificial…
Posted on 15 Apr 2026
Earlier this year, a nine-member board I worked with lost four of its directors on the same day. It…
Posted on 15 Apr 2026
Many new directors walk into their first board meeting unprepared – not because they lack…
Posted on 15 Apr 2026
The average Australian not-for-profit sector employee is less satisfied about the rewards and…
Posted on 15 Apr 2026
Not-for-profits that seek to solve performance problems by hiring new staff might be missing the…
Posted on 15 Apr 2026
The Australian Red Cross has overhauled its governance, replacing a large member-based board with a…
Posted on 13 Apr 2026
A Community Directors survey of not-for-profit leaders’ biggest governance concerns has prompted a…
Posted on 12 Mar 2026
Australia’s not-for-profits win nearly half the grants they apply for, but time and resourcing…
Posted on 12 Mar 2026
If government were to give you a blank cheque for one million dollars tomorrow, what would you do…
Posted on 12 Mar 2026
Sector advocates are ramping up a campaign to give tens of thousands more charities favoured tax…