←
AI for Nonprofits
Aware · M22 · lesson 22 of 23 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
📖
in this lesson

The Essential Policy Library: 15 Documents Every Nonprofit Needs

10 min

Policies are the governance skeleton of a nonprofit. They codify how decisions get made, who is accountable for what, and how the organization responds when something goes wrong. Yet plenty of nonprofits operate with almost none of them, treating policies as bureaucratic overhead rather than as infrastructure. The reality runs the other way: policies protect the organization and the board. They create consistency, establish procedures, demonstrate good governance to funders and regulators, and leave a paper trail when disputes arise. This lesson walks through 15 essential policies, grouped into tiers, explaining what each one should contain and why it earns its place in your library.

Four Things to Settle Before You Write Anything

Written matters. Unwritten practices are not policies. They live in one person's head, and when that person leaves the organization the practice leaves with them, along with the reasoning behind it. Policies should be documented and genuinely accessible to everyone who needs them, not filed somewhere only the executive director can find.

Consistency beats perfection. A good policy applied consistently matters more than a perfect policy that nobody follows. The corollary is uncomfortable but useful: if you are not going to enforce it, do not adopt it. An unenforced policy is worse than no policy, because it teaches everyone that the library is decorative.

Board adoption and review. Major policies should be formally adopted by the board and reviewed annually. Minor operational policies can be delegated to staff or committees, but governance policies, including conflict of interest, whistleblower protection, and executive compensation, need board authority behind them to mean anything.

Know your context. Some policies are legally required, such as equal opportunity employment once you have staff. Some are required by specific funders, since federal grants often mandate particular policies. Others are best practice. Your library should reflect what your organization actually needs rather than a generic checklist.

Tier 1: Non-Negotiable Governance Policies

These five are foundational to responsible governance, and every nonprofit should have them regardless of size.

1. Conflict of Interest Policy

This policy requires board members and staff to disclose financial interests, relationships, and business affiliations that could create conflicts, and it establishes how the board handles a disclosed conflict through voting recusal and a transaction approval process, along with consequences for non-disclosure. Include a definition of what counts as a conflict, a mandatory disclosure process, annual certification, specific scenarios such as contracts with a board member's business or donations to related entities, recusal procedures, and documentation requirements. It matters because IRS Form 990 Schedule O calls for disclosure of conflict of interest policies, and because the policy protects the organization from self-dealing while demonstrating good governance to funders.

2. Whistleblower Protection Policy

This policy encourages staff and board members to report legal violations, ethical breaches, and mismanagement without fear of retaliation, by establishing safe reporting channels and protecting people who report in good faith. Include the protected reporting channels, an explicit prohibition on retaliation, confidentiality protections, investigation procedures, and how outcomes are communicated. It is required for most federal grants and is best practice everywhere else. Beyond compliance, it is how an organization catches problems while they are still small; without it, staff either tolerate misconduct or quietly leave rather than raise it.

3. Document Retention and Destruction Policy

This policy establishes how long the organization keeps each type of document and when those documents are destroyed, which protects you from disputes about records that went missing. Set retention periods by document type: board minutes indefinitely, financial records for 7 or more years, and employment records for 3 to 4 years in line with labor law, alongside storage procedures and destruction requirements. It matters because IRS audits examine retention practices and funders want to know records are held securely. Destroying records on a published schedule demonstrates responsibility, while indiscriminate deletion looks like something else entirely. Note also that IRS regulations require nonprofits to retain certain records, particularly Form 990 and tax documentation, indefinitely.

4. Whistleblower Non-Retaliation Policy

This curriculum treats non-retaliation as a separate document from whistleblower protection. It specifically prohibits retaliation against anyone who reports violations internally or to external authorities, and it is legally required for many federal grants. Include examples of protected reporting, an explicit prohibition on retaliation, confidentiality protections, investigation requirements, and remedies where retaliation occurs. Federal grant requirements under OMB Uniform Guidance mandate whistleblower non-retaliation language, so for many organizations this is a condition of funding. The more durable reason is that it stops you losing capable people who did the right thing and were punished for it.

5. Gift Acceptance Policy

This policy clarifies which donations the organization will accept and on what conditions, so that gifts with strings attached do not quietly reshape your programs. Include the types of gifts you accept, covering cash, property, securities, and in-kind donations, the gifts you will decline, such as those from competing organizations or restricted gifts that limit program flexibility, donor naming expectations, and endowment requirements. Donors sometimes give with hidden expectations, and a written policy prevents the misunderstanding before it becomes a dispute. It also signals to major donors that you are a sophisticated organization that takes gifts, and donor intent, seriously.

Tier 2: Essential HR and Operations Policies

These become necessary once you have staff. All-volunteer organizations can defer some of them, but have them ready before the first hire rather than after it.

6. Equal Opportunity Employment Policy

This policy affirms the organization's commitment to non-discrimination in hiring, compensation, promotion, and termination, and it is required if you have employees and receive federal funding. Include the protected classes of race, color, religion, sex, national origin, age, and disability, a non-discrimination affirmation, an anti-harassment statement, complaint procedures, and investigation protocols. It is legally required, it protects the organization against discrimination claims, and it sets an explicit expectation of respectful workplace behavior that you can point to when the expectation is not met.

7. Sexual Harassment and Harassment Prevention Policy

This policy defines harassment, establishes reporting procedures, and sets out consequences for violators; many states require it for organizations with five or more employees. Include definitions of sexual harassment and other forms of harassment, worked examples, reporting channels, investigation procedures, confidentiality protections, and a prohibition on retaliation. Beyond the legal requirement, it creates a demonstrably safer workplace and shows staff and donors that the organization treats harassment as a serious matter. Many funders now require harassment prevention policies as part of grant agreements, so its absence can cost you money as well as people.

8. Professional Conduct and Code of Ethics Policy

This policy establishes expectations for professional behavior, integrity, and ethical decision-making, applying to board members and staff and sometimes to volunteers as well. Include your ethical principles, the professional behavior you expect, confidentiality obligations, rules on the use of organizational assets, and the consequences of violations. Its practical value is twofold. It makes organizational values explicit rather than assumed, and it gives you defensible grounds for disciplinary action when someone falls short of a standard they were told about in advance.

9. Compensation Committee Charter and Process

This policy, which some organizations adopt as a board resolution, establishes how executive director compensation is set and reviewed, ensuring it is decided through an independent board process rather than by the executive director. Include the committee composition of independent board members with no conflicts, the process covering market research, documentation and approval, the frequency of review, and documentation requirements. The IRS and state attorneys general both scrutinize executive compensation, and a documented independent process that arrives at reasonable, market-based pay is your defense against any suggestion of self-dealing.

10. Diversity, Equity, and Inclusion Statement

This policy affirms the organization's commitment to diversity and inclusivity across hiring, programming, and board composition, and it is increasingly expected by both funders and staff. Include commitments to diverse hiring and board recruitment, inclusive programming, staff training on cultural competence, and the accountability mechanisms that make those commitments checkable. Many foundations now require a DEI statement in grant applications. More substantially, it helps attract diverse talent, makes the organization more reflective of the communities it serves, and provides evidence of intent if claims of systemic discrimination are ever raised.

Tier 3: Specialized Policies

These address specific situations. You may not need all of them, but read the list and adopt what is relevant to your operations.

11. Financial Management and Internal Controls Policy

This policy sets the procedures for approving expenditures, managing bank accounts, reconciling accounts, segregating duties, and handling audits. Include approval authority by dollar amount, segregation of duties so that no single person handles an entire transaction cycle, bank account procedures, rules for credit card use, an investment policy where applicable, and financial reporting requirements. It prevents fraud and embezzlement by requiring multiple approvals and documented procedures, and it is one of the first things auditors and funders examine when they want to know whether an organization is well run.

12. Data Privacy and Information Security Policy

This policy establishes how the organization collects, stores, and protects sensitive information, including donor details, client data, and employee records, and it grows more important as organizations move to cloud-based systems. Include the types of data you collect, storage procedures, access controls, breach notification protocols, vendor management where third-party software is involved, and compliance with applicable privacy laws such as HIPAA for health data or FERPA for education data. Nonprofits hold genuinely sensitive material, from donor contact information to client medical or social records and employee social security numbers, and a breach damages trust and can carry legal consequences.

13. Technology Use and Social Media Policy

This policy governs how staff and board members use organizational technology and how they represent the organization on social media, protecting against liability from inappropriate posts and misuse of resources. Include acceptable use of computers and phones, the line between personal and professional use, social media guidelines, consequences for violations, and content approval procedures. A staff post that travels for the wrong reasons can damage a reputation built over years, and a written policy both clarifies expectations in advance and provides grounds for discipline afterwards.

14. Donor Communications and Stewardship Policy

This policy establishes how the organization communicates with donors, honors donor restrictions, and reports on impact, and it matters most for organizations with major donors or restricted grants. Include communication frequency, reporting requirements by gift size, donor naming and recognition standards, and how compliance with restricted use is tracked. Its effect is to make donors feel valued and to ensure their restrictions are actually honored, which reduces disputes about what was promised versus what was delivered and demonstrates that you manage other people's money responsibly.

15. Board Member Recruitment and Orientation Policy

This policy sets expectations for board service, recruitment standards, and orientation procedures, so that people understand what they are agreeing to before they join. Include the expectations around meeting attendance, committee service, and fundraising participation, along with term limits, conflict of interest disclosure, orientation requirements, and the evaluation and renewal process. Clear expectations reduce misalignment and improve board effectiveness, orientation helps new members understand their fiduciary duties and the organizational context, and term limits with evaluation create natural renewal points instead of awkward conversations.

Building the Library in Phases

Adopting fifteen policies at once is neither realistic nor necessary. Sequence them against the organization's stage, so each policy arrives shortly before the risk it addresses does.

PhaseEssential PoliciesTimeline
Phase 1: Launch (0-6 months)Bylaws, Conflict of Interest, Whistleblower Protection, Document Retention, Gift AcceptanceBefore first board meeting
Phase 2: Growth (6-18 months)Add: Equal Opportunity, Harassment Prevention, Professional Conduct, Compensation Committee, Financial ControlsBefore first hire or major grant
Phase 3: Maturity (18+ months)Add: DEI Statement, Data Privacy, Technology Use, Donor Communications, Board RecruitmentAs organization scales

Notice what drives each phase. The launch set is about governance existing at all, which is why it lands before the first board meeting. The growth set is triggered by employment and by funding, which is why the deadline is the first hire or the first major grant rather than a date. The maturity set responds to scale: more donors, more data, more public presence, more board turnover.

Making Policies Stick

Writing policies is the first step, and using them is the second, which is where most nonprofits fall down. Start with real adoption: the board should adopt policies through a formal resolution rather than an email thread, and adopted policies should then be communicated to all staff and board members rather than filed. Then make them accessible, in a current policy library kept somewhere everyone can reach, whether a shared drive, a wiki, or an intranet. Staff cannot follow policies they cannot find, and a library only the executive director can navigate is not a library.

Require acknowledgment next. New staff and board members should sign a form confirming they have read and understood the key policies, typically conflict of interest, harassment prevention, and professional conduct, and those signatures should be kept on file. Enforce consistently, because addressing one violation and ignoring the next teaches everyone that the policies are optional. Review annually, with the board confirming that each policy is still current and relevant, updating what has drifted, and tracking when each was last reviewed. Finally, highlight policies in onboarding: new staff should receive actual training on the policies that affect their work, not a link and an assumption.

What to Do Next

Start by auditing what you already have against the list above, marking each policy as adopted, drafted, or missing, and noting when each was last reviewed. That single page usually makes the priority obvious. From there, Conflict of Interest Policies That Actually Get Used: Templates and Real Scenarios gives you template language and implementation guidance for the policy most likely to be examined, Robert's Rules of Order for Nonprofits: A No-Jargon Translation for Meetings covers the meeting procedures through which policies are formally adopted, and Annual Filing Requirements: Never Miss a Deadline maps the compliance and record-keeping calendar your retention policy has to serve.

Anti-Patterns

  • Adopting policies you have no intention of enforcing. Inconsistent enforcement is worse than absence, because it teaches staff that the whole library is theater.
  • Copying another organization's policies unchanged. Learning from peers is smart, but an unadapted policy describes their board size, staff structure, and funding sources rather than yours.
  • Approving governance policies by email. Major policies need formal board adoption, because the authority behind the policy is what gives it effect with regulators and funders.
  • Keeping the library where staff cannot reach it. A policy nobody can find at the moment they need it does not function as a policy.
  • Treating onboarding as a reading assignment. Sending a link is not training; the policies that affect someone's daily work should be covered explicitly with them.
  • Letting the library age. Law changes, the organization changes, and a policy that has not been reviewed in years may now describe an organization that no longer exists.
  • Deferring the foundational five because you are small. Size does not change the governance exposure the Tier 1 policies address.

Practice Prompts

  • Audit your library against the 15 policies in this lesson. Mark each as adopted, drafted, or missing, and record the date of last board review.
  • For every policy you marked adopted, find the board minutes that record its adoption. Note any you cannot find.
  • Draft the retention schedule for your five most common document types, giving each a retention period and a destruction procedure.
  • Write the acknowledgment form new staff and board members will sign, naming the specific policies it covers.
  • Take one policy you already have and ask whether you have enforced it consistently in the past year. If not, decide whether to enforce it or retire it.
  • Map your organization against the phase table and identify the next policy your stage calls for, along with who will draft it and when the board will consider it.

Reflection

Think about the last time something went wrong in your organization: a departure that turned sour, a gift that came with conditions nobody had agreed to, a question from a funder that nobody could answer with a document. Which policy would have changed the outcome, and did you have it? Then ask the second question, which is usually the more revealing one: of the policies you do have, how many would your staff be able to describe if asked today? A library that exists on paper but not in practice satisfies an auditor for exactly as long as the auditor is looking, and protects nobody afterwards.

Glossary

  • Conflict of interest policy: The governance document requiring disclosure of interests that could compromise judgment, with recusal and documentation procedures.
  • Whistleblower protection: Safe channels and good-faith protections for people reporting legal violations, ethical breaches, or mismanagement.
  • Non-retaliation: The explicit prohibition on punishing anyone who reports violations internally or to external authorities.
  • Document retention schedule: The list of document types with how long each is kept and how it is destroyed.
  • Gift acceptance policy: The written rules on which donations the organization will accept, decline, and under what conditions.
  • Segregation of duties: The internal control that prevents one person from handling an entire financial transaction alone.
  • OMB Uniform Guidance: The federal grant requirements that mandate whistleblower non-retaliation language for many funded organizations.
  • Compensation committee: The independent board committee that sets and documents executive compensation.
  • Board adoption: Formal approval of a policy by board resolution, which is what gives a governance policy its authority.

Closing

A policy library is not paperwork for its own sake; it is the accumulated answer to questions your organization would otherwise have to improvise under pressure. Who discloses what. How long records live. What happens when someone reports a problem. Which gifts you will not take. Which of those questions you answer first is a matter of stage rather than preference, and the phase table gives you the order. Build the foundational five before your first board meeting, add the employment and financial set as staff and grants arrive, and let the specialized policies follow the risks you actually take on. Then do the unglamorous part: adopt them formally, keep them findable, train people on them, enforce them evenly, and review them once a year.

Key Takeaways

  • Policies protect the organization and the board, create consistency, and demonstrate good governance to funders and regulators.
  • The Tier 1 governance set, conflict of interest, whistleblower protection, document retention, non-retaliation, and gift acceptance, applies to every nonprofit regardless of size.
  • Tier 2 policies are triggered by employment and funding; have them ready before the first hire rather than after.
  • Tier 3 policies follow the specific risks you take on, from data you hold to donors you steward.
  • Governance policies need formal board adoption and annual review; operational ones can be delegated.
  • Retention periods differ by document type, with board minutes kept indefinitely and IRS records including Form 990 retained indefinitely as well.
  • An unenforced policy is worse than no policy, because inconsistent enforcement teaches people the library does not matter.
  • Adoption, accessibility, signed acknowledgment, consistent enforcement, annual review, and onboarding training are what turn a document into a practice.

Frequently Asked Questions

Do I really need all 15 policies? We're a small nonprofit. Start with Tier 1, the five non-negotiable policies, at minimum. As you grow, add the Tier 2 policies before your first hire. Tier 3 policies can come later as they become relevant to your situation. But do not skip the foundational five; they are essential for any nonprofit regardless of size.

Can I adapt policies from another nonprofit? Yes, and learning from other organizations is sensible. But do not copy and paste. Adapt each policy to your context, meaning your board size, staff structure, and funding sources, and have your board review the adapted version to confirm it fits. If you can afford it, have legal counsel review before adoption.

What happens if we don't have policies? You are exposed on several fronts at once: IRS scrutiny, since the 990 asks about conflict of interest and whistleblower policies; funding loss, since many grants require specific policies; employee disputes, since claims of discrimination or harassment are harder to defend without documented procedures; and fraud, since theft is easier without financial controls. Board members are also less protected from liability where policies and procedures are undocumented.

How often should we update policies? The board should review all policies at least annually, looking for changes in law, in organizational context, or in effectiveness. Major updates should be formally adopted by the board, while minor clarifications can be made without full re-adoption. Keep a log recording when each policy was last reviewed and updated.