Your nonprofit doesn’t build its own donor management system. It doesn’t run its own email platform, host its own case management database, or process its own credit card donations. Almost everything that touches your sensitive data runs through someone else’s software, on someone else’s servers, managed by people you’ve never met.
That’s not a criticism — it’s just how nonprofits operate, and there’s nothing wrong with it. But it means your organization’s data security depends on decisions made by every vendor you work with, not just the decisions you make internally. If one of those vendors has weak security, that weakness becomes your weakness, regardless of how careful your own team is.
Third-party risk management is the practice of figuring out which vendors actually pose risk, how much, and what to do about it — before a problem forces you to find out the hard way.
Why This Matters More for Nonprofits Than People Assume
There’s a common assumption that vendor risk is a big-company problem. Enterprises have dozens of vendors and complex supply chains, so they need formal risk programs. Nonprofits are smaller, so surely this matters less.
That assumption doesn’t hold up. Nonprofits frequently handle data that’s more sensitive than what many for-profit companies manage — donor financial information, health records for client services, case files involving vulnerable populations, and government program data subject to specific federal or state requirements. A breach involving any of this isn’t just a security incident. It’s a betrayal of the trust that your entire fundraising and program model depends on.
At the same time, nonprofits typically have the least internal capacity to manage vendor risk. There’s no dedicated IT security team reviewing every new software subscription. There’s often no formal procurement process that includes a security review step. Decisions about which tools to adopt get made by program staff who need to solve a problem quickly, not by anyone thinking about data security implications.
This combination — high sensitivity of data, low internal capacity to manage risk — is exactly the situation where a vendor security failure does the most damage.
The Vendor Landscape Most Nonprofits Don’t Realize They Have
When asked to list their vendors, most nonprofit leaders name the obvious ones: their donor CRM, their accounting software, maybe their email platform. The actual list is almost always longer.
Case management systems that store client records, often including health or behavioral health information. Payment processors handling donor credit card and bank information. Email marketing platforms that store donor and supporter contact information. HR and payroll systems with employee Social Security numbers and banking details. Volunteer management platforms with background check data. Cloud storage and file-sharing tools where staff put everything from grant applications to client files. Survey and data collection tools used for program evaluation. Website hosting and content management platforms. Any AI tool staff have started using for drafting communications, summarizing client notes, or analyzing program data.
Each of these is a third party with some level of access to your organization’s data. Most nonprofits have never inventoried this list in one place, which means nobody can answer a basic question: if any one of these vendors had a breach tomorrow, what exactly would be exposed?
Building a Vendor Risk Process That Fits a Nonprofit’s Reality
A formal third-party risk management program at a Fortune 500 company involves dedicated staff, enterprise software, and security questionnaires running to hundreds of questions per vendor. That model doesn’t fit a nonprofit with a five-person operations team. Trying to force it will result in a program nobody maintains.
What works instead is a scaled-down process built around the same principles, sized for the resources you actually have.
- Start with an inventory. Before you can manage vendor risk, you need a complete list of every vendor with access to your data or systems. This includes obvious software vendors and less obvious ones — the freelance bookkeeper using their own laptop, the volunteer coordinator using a personal Google account for program signups, the marketing consultant with admin access to your website. Build this list once, then assign someone the responsibility of updating it whenever a new tool gets adopted.
- Classify vendors by what they touch. Not every vendor needs the same level of scrutiny. A vendor with access to donor financial data or client health records needs significantly more attention than a vendor providing graphic design templates. Sort your vendor list into tiers — typically high, medium, and low risk — based on the sensitivity of the data they can access and how deeply integrated they are into your operations.
- Ask the right questions, scaled to the tier. For high-risk vendors, ask about how they encrypt data, whether they’ve had any past breaches, what their data retention and deletion practices are, whether they carry cyber insurance, and whether they’ll sign a data processing agreement that specifies their security obligations. For lower-risk vendors, a lighter review — checking whether they have a published privacy policy and basic security practices — is proportionate. You don’t need a 200-question questionnaire for every vendor. You need the right depth for the right risk level.
- Put security requirements in your contracts. Whatever you learn during a vendor assessment is only useful if it’s backed by a contractual obligation. Standard vendor agreements should include language requiring the vendor to maintain reasonable security practices, notify you within a specific timeframe if they experience a breach affecting your data, and allow you to review or audit their practices periodically. Many vendors will accept this language if asked. Many nonprofits never ask.
- Reassess periodically, not just at signing. Vendor risk doesn’t stay static. A vendor’s security posture can change after an acquisition, a leadership change, or simply over time as its practices evolve. High-risk vendors should be reassessed annually. Medium-risk vendors can be reviewed every two years. This doesn’t need to be elaborate — even a short check-in confirming nothing material has changed is better than never revisiting the relationship.
- Connect vendor risk to your incident response plan. If a vendor notifies you of a breach, your team needs to know what to do immediately — who’s responsible for assessing what data was exposed, who needs to be notified, and what your contractual and regulatory obligations are. This should be part of your broader incident response planning, not something you figure out for the first time when the notification email arrives.
The Compliance Layer Nonprofits Often Miss
For nonprofits handling health-related data, vendor risk management isn’t just good practice — it’s a regulatory requirement. If a vendor accesses protected health information on your behalf, HIPAA requires a signed Business Associate Agreement specifying how that vendor will protect the data and what happens if it’s breached. Many nonprofits use vendors handling health data without ever putting this agreement in place. For a full breakdown of what’s required, see our HIPAA compliance guide for organizations handling health data.
California nonprofits participating in health and social services data exchange face additional vendor obligations under the state’s Data Exchange Framework, which sets specific security expectations for any system involved in that data sharing. And nonprofits accepting credit card donations through any platform have PCI DSS obligations that extend to how their payment processor and any connected systems handle cardholder data.
None of these requirements disappear because the vendor — not your organization directly — is the one storing the data. Regulators and auditors expect you to have done the due diligence regardless of who’s actually holding the information.
What Happens Without a Process
The cost of skipping vendor risk management rarely shows up as a dramatic event. It shows up as exposure that nobody notices until something forces the issue.
A donor management vendor gets breached, and your organization discovers — only after the notification arrives — that the vendor never had multi-factor authentication enabled internally. A foundation funding a major grant asks for evidence of how you vet your vendors’ security practices, and there’s no documentation to provide. A case management vendor changes their data retention policy without telling clients, and client records that should have been deleted are still sitting in a system nobody is monitoring.
None of these scenarios requires sophisticated attackers or unusual circumstances. They happen because nobody asked the questions early enough to catch the problem before it became one.
How CISOSHARE Supports Nonprofit Vendor Risk Management
CISOSHARE’s third-party risk management services provide everything needed to build, implement, and execute the policies and processes around finding and managing vendor risk — sized appropriately for organizations that lack the internal resources or formalized processes to do this alone.
Their approach assesses and improves existing vendor processes or builds new ones from scratch, depending on where an organization currently stands. Using a combination of skilled resources, a proven methodology, and adaptable technology, their team integrates directly with an organization’s overall security program and risk management processes — focusing on efficiency and continuous progress without requiring additional headcount.
This matters specifically for nonprofits, where adding a dedicated vendor risk role simply isn’t realistic. CISOSHARE’s learning-and-teaching culture means the goal isn’t permanent dependency — it’s building a process your existing team can sustain, with CISOSHARE providing the expertise and structure that nonprofits typically can’t staff internally.
For organizations building broader risk management capability beyond just vendors, the cybersecurity risk management program guide covers how vendor risk fits into your overall risk posture. And if your organization is still establishing its core security foundation, vCISO for nonprofits covers how fractional leadership can bring structure to vendor risk and everything else your security program needs.
FAQ
How many vendors should a small nonprofit expect to manage?
More than most leaders initially estimate. A nonprofit with 20–30 staff often has 15–25 vendors with some level of data access, once you include payment processors, HR systems, case management tools, and cloud storage. The first step is simply building the complete list.
Do we need a different process for free or low-cost software tools?
Free tools deserve the same scrutiny as paid ones, sometimes more. Free platforms sometimes monetize through data use in ways that paid enterprise tools don’t. A free tool with broad data access still needs a basic security and privacy review before adoption.
What’s the minimum a small nonprofit should do if a full TPRM program feels out of reach?
Start with the inventory and tiering step. Even without a formal questionnaire process, knowing which vendors touch your most sensitive data and confirming they have basic security practices in place addresses the highest-risk gap most nonprofits have.


