←
AI for Nonprofits
Aware · M10 · lesson 10 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

How to Write a Code of Conduct for Your Nonprofit Community

10 min

A code of conduct is a document that defines expected behavior for people in your community, whether they are members, volunteers, staff, or participants. It sets expectations before anything goes wrong, protects people from harm, and gives you the tools to address violations when they happen. Many nonprofits skip it because writing one feels bureaucratic, or because they worry that naming rules will make a welcoming community feel policed. In practice a good code of conduct does the opposite: it creates safer, more inclusive spaces, because it is a public commitment to standards that benefit everyone rather than a list of ways to get into trouble.

Why a Code of Conduct Matters

1. Safety. Clear expectations reduce harassment, discrimination, and harm because people know what is acceptable and what is not. Most harmful behavior in community settings is not committed by someone who knew the rule and broke it; it is committed by someone operating on assumptions nobody ever corrected. A written code replaces those assumptions with a shared standard, and it gives bystanders language for naming a problem early, while it is still small enough to address in a conversation.

2. Legal protection. If you have enforcement procedures in place and someone violates them, you have documentation to defend the actions you take, whether that is removing a person from events or terminating their membership. The protection comes from the pairing: a rule without a procedure is difficult to enforce fairly, and a procedure applied without a published rule looks arbitrary to everyone watching.

3. Inclusivity. A good code of conduct signals that you take inclusion seriously as a practice rather than as a sentiment. It says plainly: we do not tolerate discrimination, harassment, or exclusion based on identity. For people deciding whether your space is safe to enter, that statement, and the enforcement record behind it, carries far more weight than a welcome message.

4. Clarity. Everyone, including staff and leadership, knows what is expected. This prevents the "well, I thought that was okay" disagreements that consume enormous time and goodwill after an incident, because the question of whether the behavior was acceptable was settled in advance rather than being negotiated while people are upset.

Code of Conduct Structure

A good code has seven sections. Each one answers a question that will otherwise be answered improvised, under pressure, by whoever happens to be handling the situation.

1. Purpose and Values

Start by stating what your organization values and why the code exists. A workable opening reads: "Our community is built on respect, inclusion, and safety. This Code of Conduct defines the behavior we expect from all members, volunteers, staff, and guests. We are committed to providing a welcoming environment for people of all backgrounds and identities." Leading with values rather than prohibitions frames the rest of the document as an expression of what you are for, which is also the honest description of why the rules exist.

2. Scope

Who does this apply to? Everyone, or just members? Staff and volunteers? Events only, or online spaces too? Scope is the section organizations most often leave vague, and it is the one most likely to be contested during an actual incident, particularly where the behavior happened in a social media group rather than at an event.

An example: "This Code applies to all members, volunteers, staff, board members, and guests at our events, programs, and online spaces. Violations may result in removal from events, termination of membership, or employment termination." Naming the possible outcomes here, not only in the consequences section, means nobody can say they were unaware that participation was conditional.

3. Expected Behavior

Describe the behaviors you want, not only the ones you forbid. A community that can point to a positive standard has something to teach toward, and new members have something to copy.

  • Treat others with respect and dignity
  • Listen to understand, not to respond
  • Respect others' boundaries and consent
  • Acknowledge and work to address power imbalances
  • Use people's correct names and pronouns
  • Offer and accept feedback gracefully

4. Unacceptable Behavior

Be specific about what is not tolerated. Vagueness here is what forces the organization to argue after the fact about whether a rule was broken.

  • Harassment, discrimination, or exclusion based on race, ethnicity, gender identity, sexual orientation, disability, age, religion, or any other identity
  • Unwelcome sexual contact or advances; sexual harassment
  • Intimidation, threats, or hostile behavior
  • Disruptive behavior that prevents others from participating
  • Retaliation against someone who reports a violation
  • Violation of others' privacy, including sharing someone's personal information without consent

The retaliation clause deserves particular attention. It is the provision that makes the reporting procedure usable, because a person weighing whether to report is weighing what happens to them afterwards at least as heavily as whether the report will be believed.

5. Reporting Procedure

Tell people how to report violations, and be specific about all three of these:

  • Who can they report to? A named staff member, a committee, or an email address
  • How will reports be handled? Confidentiality, investigation timeline, documentation
  • What support is available to the person reporting? Emotional support, safety planning, and similar

An example: "If you experience or witness behavior that violates this Code, report it to [name/email] or [alternative reporter]. Reports are treated seriously and investigated promptly. Confidentiality is maintained to the extent possible." Naming an alternative reporter is not a formality. The person a member most needs to report is sometimes the person the procedure would otherwise route them to, and without a second route the procedure quietly excludes the hardest cases.

6. Consequences

Be clear about what happens when someone violates the code. A usable ladder runs from lightest to most serious:

  • Verbal warning and conversation
  • Written warning and agreement to change behavior
  • Temporary removal from events or programs
  • Permanent removal or membership termination
  • Referral to law enforcement, if the behavior is criminal

Specify that consequences are proportionate to the violation. Minor offenses do not result in immediate removal, while severe violations, including violence, sexual assault, and hate speech, may. Writing the proportionality rule down protects the process in both directions: it stops a minor incident from escalating past what it warrants, and it stops a serious one from being minimized because everyone likes the person involved.

7. Appeals Process

Give people the right to appeal if they are penalized. This matters for fairness, and it also matters for the credibility of every decision you make, because a process with no route of appeal invites the argument that the outcome was predetermined. An example: "If you believe the decision to enforce this Code against you was unjust, you may appeal in writing to [committee] within 30 days. The appeal will be reviewed and you will receive a written decision." Name the body, the window, and the fact that the answer comes in writing.

Common Mistakes to Avoid

1. Too vague. "Be respectful" is meaningless as a standard because it means whatever the reader already believed. What does respect look like in your community, in behavior someone could observe? Be specific enough that two people who disagree about an incident could still agree about what the rule says.

2. Treating it as purely punitive. A code of conduct should be about creating safety, not simply about punishment. Include support processes for the person harmed and restorative approaches where they are appropriate. An organization whose only tool is removal will hesitate to use it, and hesitation is how minor patterns become entrenched.

3. Not making it accessible. Write in plain language and avoid jargon. Translate it into the languages your community speaks. Make it available in multiple formats, online, print, and audio. A code that only reaches the subset of your community who read English comfortably on a website is not protecting the rest of them.

4. Enforcement inconsistency. If you let some violations slide and enforce others strictly, you lose credibility, and you lose it fastest with exactly the people the code exists to protect. Consistency is harder than it sounds in small organizations where everyone knows everyone, which is why the procedure has to be written before it is needed.

5. Ignoring power dynamics. A violation by someone in power, a staff member or a board member, should be taken more seriously than the same violation by someone without power. The person with power has more responsibility, and the harm travels further because the target has less ability to walk away.

Creating Your Code: A Process

The document matters less than the way it comes into existence. A code written by one person and announced will be read as management policy; a code built with the community will be read as an agreement. Six steps get you there.

1. Start with values. What does your organization stand for? Write that down first, because your code flows from your values and reads incoherently when it does not.

2. Gather input. Interview staff, volunteers, and community members. What do they care about? What violations have they witnessed, and what happened afterwards? Use what you hear to shape the content, because the situations people have already lived through are the ones your code most needs to handle.

3. Draft collaboratively. Do not write this in isolation. Involve a diverse group, including different races, genders, abilities, and backgrounds, in the drafting itself. Homogeneous groups miss important perspectives, and they tend to miss them confidently, because everyone in the room found the draft reasonable.

4. Get feedback from the community. Share the draft, collect responses, and revise. Do this at least twice. The second round is where you find out whether your revisions actually addressed the concerns or merely acknowledged them.

5. Board approval. Once the community is satisfied, take it to the board. Board adoption signals organizational commitment and makes clear that enforcement has backing above the staff member who will handle the first difficult case.

6. Launch and communicate. Do not simply post it on your website. Hold a community meeting to explain it, walk through the reporting route, and answer questions. Make it real rather than merely published.

Implementation

Once your code is approved, embed it in your culture rather than your document library. Include it in volunteer orientation, staff onboarding, and membership agreements, so that agreeing to it is part of joining rather than something people encounter for the first time when it is invoked. Reference it regularly in ordinary circumstances, not only after an incident, because a document that appears only in bad moments becomes associated with them.

Then make enforcement consistent and fair, which is the part that determines whether anyone believes the rest. Review the code annually and ask two questions: is it still reflecting your values, and is it working? A code that has never been used may mean your community is healthy, or it may mean people do not trust the reporting route. For the differences between this document and the neighboring policies organizations often confuse it with, see Community Guidelines vs Code of Conduct vs Terms of Service: Differences, and for the question of whose norms end up encoded in language that reads as neutral, see Inclusive Community Guidelines: Dominant-Culture Norms Hidden in Policies.

Anti-Patterns

  • The values statement wearing a code's name. A document that lists expected behavior but contains no reporting procedure, no consequences, and no appeals process. It cannot support a decision to remove anyone, and it offers the person removed nothing to contest.
  • Silent scope. Leaving out whether the code covers online spaces, or guests, or board members, and then discovering the gap during an incident that happened in a social media group.
  • The single reporting route. Naming one person to receive reports with no alternative. When the person to be reported is that person, or their close colleague, the procedure has quietly excluded the cases it most needs to handle.
  • Enforcement that tracks popularity. Applying consequences strictly to newcomers and leniently to long-serving members or funders. Nothing destroys a code's credibility faster, and the people who notice first are the ones it was written to protect.
  • Holding the powerful to a lower standard. Excusing a board member or senior staff member's behavior because addressing it would be awkward. Power increases responsibility, and treating it as a shield inverts the entire purpose of the document.
  • Drafting in a homogeneous room. Writing the code among people who share a background and assuming the result is neutral, then presenting it to the community as finished.
  • Publish and forget. Posting the code to a website, never mentioning it at orientation, and then invoking it for the first time during a crisis, when it will look like a rule invented for the occasion.

Practice Prompts

  • Write the scope section for your organization. Name every category of person and every setting it covers, including online spaces, and check it against a real incident you know about to see whether it would have applied.
  • Draft your reporting procedure with two independent routes, one of which does not run through your executive director. Then trace what a report would actually do once received: who sees it, how it is recorded, and how quickly the reporter hears back.
  • Take the phrase "be respectful" and rewrite it as three observable behaviors specific to your community's activities.
  • Map your consequences ladder from verbal warning to law enforcement referral, and place three plausible incidents from your own setting on it. Note any you found hard to place; those are the cases where proportionality needs writing down.
  • Identify the five people you would invite to draft this collaboratively and list what each of them would notice that you would not. If the list is short, your drafting group is too similar.
  • Write the appeals paragraph, naming the reviewing body and the window for filing. Confirm that the body you named actually exists and has agreed to the role.
  • Plan the launch meeting rather than the launch email: what you would explain, which section you would spend the most time on, and which question you expect to be hardest to answer.

Reflection

Think about a moment in your community when someone's behavior caused harm and the response was improvised. What would a written code have changed? In most cases the answer is not that the outcome would have been different but that it would have been reached more quickly, with less damage to everyone involved, and with a record that the next person facing a similar situation could rely on. The value of the document is largely in what it removes: the need to invent a process while people are upset.

Then ask the more uncomfortable question. If a member wanted to report the most senior person in your organization tomorrow, would they know how, and would they believe anything would come of it? The reporting procedure is where a code stops being a statement and starts being a system, and the test of it is not whether it exists but whether the people with the least power in your community would use it. If you are not sure, that is the section to rewrite first.

Glossary

  • Code of conduct. A document defining expected behavior for members, volunteers, staff, and participants, setting expectations, protecting people from harm, and providing tools to address violations.
  • Scope. The section stating who the code applies to and where, covering categories of people and settings including events, programs, and online spaces.
  • Expected behavior. The positive standard the code sets out, describing conduct the community is asked to practise rather than only the conduct it forbids.
  • Unacceptable behavior. The specific prohibitions, typically covering identity-based harassment and discrimination, sexual harassment, intimidation, disruption, retaliation, and privacy violations.
  • Retaliation. Adverse action taken against someone because they reported a violation. Prohibiting it explicitly is what makes the reporting procedure usable.
  • Reporting procedure. The section naming who receives reports, how they are handled including confidentiality and investigation timeline, and what support is available to the person reporting.
  • Proportionality. The principle that consequences match the severity of the violation, so that minor offenses do not trigger immediate removal and severe violations are not minimized.
  • Appeals process. The route by which a person penalized under the code may contest the decision, typically in writing to a named body within a stated window, with a written decision returned.
  • Restorative approach. A response oriented toward repairing harm and changing behavior rather than punishment alone, used where the violation and the circumstances make it appropriate.

Closing

A code of conduct is one of the few nonprofit documents whose value is almost entirely determined by how it is made and used rather than by how well it is written. The seven sections are not difficult to draft, and templates for all of them are widely available. What is difficult is gathering honest input from people who have witnessed harm, drafting with a group diverse enough to catch what you would miss, promising only the process you can actually deliver, and then applying that process consistently when the person in front of you is someone you like.

Treat the code as infrastructure rather than as a policy you complete. Embed it in onboarding, mention it when nothing is wrong, review it annually against your values and your capacity, and pay particular attention to whether the reporting route works for the people with the least power in your community. Done that way, it stops being a document you hope never to use and becomes part of how the community explains itself to newcomers.

Key Takeaways

  • A code of conduct defines expected behavior for members, volunteers, staff, and participants; it delivers safety, legal protection, a visible inclusion commitment, and clarity for everyone including leadership.
  • Seven sections make a complete code: purpose and values, scope, expected behavior, unacceptable behavior, reporting procedure, consequences, and appeals process.
  • Scope should name both the people and the settings covered, including events, programs, and online spaces, and state that violations may lead to removal, membership termination, or employment termination.
  • Describe positive expected behavior alongside specific prohibitions, and include retaliation against reporters among the prohibitions.
  • The reporting procedure must say who receives reports, how they are handled and documented, and what support the reporter gets; an alternative reporter keeps the hardest cases inside the process.
  • Consequences run from verbal warning through written warning, temporary removal, permanent removal, and referral to law enforcement, and must be proportionate to the violation.
  • The five common failures are vagueness, a purely punitive framing, inaccessible language or format, inconsistent enforcement, and ignoring power dynamics.
  • Build the code through values, community input, collaborative drafting, at least two rounds of feedback, board approval, and a launch that includes a meeting rather than a website post; then embed it in orientation and review it annually.

Frequently Asked Questions

What if someone reports a violation that seems minor? Take all reports seriously, because the person reporting has usually weighed whether it was worth raising at all. That said, minor violations such as accidentally misusing someone's pronouns or interrupting deserve conversation and education rather than punishment. Reserve severe consequences for serious violations including harassment, discrimination, and violence. Your code should clearly delineate what counts as minor and what counts as serious, so that the distinction is a written standard rather than a judgment made in the moment.

Can we remove someone from our community for violating the code? Yes, provided your code clearly states removal as a possible consequence and you follow your enforcement procedure. Document everything as you go rather than reconstructing it afterwards. Give the person a genuine chance to respond, and only remove them if the violation is serious and documented. The standard to hold yourself to is whether you could defend the decision to someone who was not present and does not already agree with you.

Should the code of conduct apply to board members? Absolutely. In fact board members should be held to a higher standard, since they represent the organization and their conduct sets the ceiling for what everyone else believes is tolerated. If a board member violates the code, leadership should address it directly and consistently with how they would handle a staff or volunteer violation. Deciding this in advance is far easier than deciding it while the situation is live.

What if our community is very small and violations are likely to become public? This is a real problem, and small organizations struggle with it genuinely rather than only procedurally. Maintain confidentiality to the extent possible and keep details limited to those who need to know. Focus the response on resolution and moving forward rather than on blame. If you do need to disclose something, explain only what is necessary to maintain community safety, and say clearly what you are not disclosing and why, so the silence does not read as concealment.