by Ann Bown, Non-profit Management and Financial Sustainability Consultant
“If a digital asset is essential to fundraising, reputation, donor relationships or operations, [We] the board should know who owns it, who controls it, what happens if it disappears, and what risks it creates.” – Ann Bown
When nonprofit boards review their financial statements, they focus on income, expenditure, assets and liabilities. But there is another balance sheet that rarely appears in the board pack – it’s the organisation’s digital assets.
Its website. Domain name. Donor database. Social media accounts. Email systems. Online fundraising platforms. Cloud storage. Digital content. And increasingly, AI tools.
These may not appear on the financial statements, but losing control of them can have very real consequences for fundraising, donor trust, reputation, privacy, compliance and operational continuity.
South Africa’s corporate governance code, King V, adds weight to the case for NPO board-level digital oversight. Its guidance for NPOs retains an outcomes-based and proportional approach, recognising that governance practices should reflect an organisation’s size, complexity and circumstances. It also highlights the board’s responsibility to understand emerging technologies, including AI, and their associated risks and opportunities.
A simple question illustrates the risk:
Who actually owns your organisation’s digital keys?
A website domain may be registered in a volunteer’s name. A social media account may be controlled through a former employee’s email. A donor database may only be accessible to one person. An organisation may discover that its website has never been backed up — when it is already too late.
These are not simply IT problems. They are governance and risk-management issues.
Boards don’t need to become IT experts. They do need to ask five questions:
1. What are our most important digital assets?
2. Who legally owns and controls each one?
3. Who has access and what happens when they leave?
4. Could we recover the asset if it were hacked, locked or deleted?
5. Could weaknesses in our digital systems expose the organisation to major risks such as reputational, privacy, financial, even money laundering and terrorist financing (AML/TF) ?
The last question is increasingly important. In a Financial Action Task Force (FATF) environment, NPOs need to understand and manage AML/TF risks in a risk-based and proportionate way. Weak digital controls can create vulnerabilities, from compromised payment accounts and fraudulent changes to banking details to hacked or cloned social-media accounts.
There is also an environmental dimension. Websites, cloud storage and AI all have resource costs. A recent calculation by Website Carbon of a conservation website scored it, shamefully, as 65% dirtier than other webpages globally! For organisations committed to sustainability, “going digital” does not automatically mean “going green.”
The bottom line: Who Actually Owns Your Digital Keys?
Digital assets are now part of an organisation’s essential infrastructure. They may be invisible on the balance sheet, but they represent years of investment in donor relationships, reputation, intellectual property, public trust and organisational knowledge.
Good governance means knowing what you own, who controls it, what risks it creates and making sure the organisation can still function when the person holding the digital keys walks out the door.
About Ann Bown: She is a semi-retired non-profit management and financial sustainability consultant with more than 35 years’ experience across South Africa and Africa. Ann currently contributes to South Africa’s NPO Policy Framework review and FATF Recommendation 8 work. She engages on NPO law and regulatory reform with NPO Working Group colleagues. She is passionate about strengthening civil society and creating an enabling environment for sustainable, well-governed non-profit organisations.
