Would Your Data Practices Pass a Funder’s Security Review?
Answer 8 quick questions about how your organization protects payroll, HR, and grant-funded program data — and get a personalized readiness score with specific steps to prepare for funder due diligence and audits.
Start Your AssessmentDo you know whether your major funders or grant agreements include specific data security or cybersecurity requirements?
Since October 2024, OMB’s Uniform Guidance (2 CFR 200.303(e)) requires federal grant recipients and subrecipients to take “reasonable cybersecurity measures” — and private foundations are following suit.
If a funder asked for evidence of your data security practices during a site visit or audit, what could you produce today?
Funder due-diligence reviews increasingly ask for documented policies, not just verbal assurance.
How is personally identifiable information (PII) — employee, donor, and program participant data — segmented across your grant-funded programs?
Multi-program nonprofits often mix restricted-fund data in ways that don’t match what each funder actually authorized.
Does your payroll and HR system require multi-factor authentication (MFA) to log in?
MFA is one of the specific safeguards named in OMB’s 2024 cybersecurity guidance for grant recipients.
If a subgrantee, fiscal sponsor, or program partner requested access to shared payroll or HR data, how would that access be managed?
Collaboratives, fiscal sponsorships, and pass-through grants are common in the nonprofit sector — and each one is a data-sharing relationship that needs its own controls.
Does your organization have a documented incident response plan for a payroll or HR data breach — including funder and donor notification steps?
Many grant agreements now specify a notification window if a breach affects grant-funded data or personnel.
Have staff who manage payroll, HR, or grant reporting been trained on funder-facing data security expectations?
This includes knowing what a funder site visit, compliance review, or audit is likely to ask for.