The non-profit organization may have an approved charter, a conflict of interest policy, a financial procedures guide, and a data protection model. However, it may still find itself in violation, starting with an action that seems ordinary: announcing a fundraising campaign before the license is complete, or signing a technical contract that gives the supplier broad access to beneficiary data, or passing a transaction that links a board member to a contracting party without documented disclosure.
At this point, it becomes clear that compliance is not measured by the number of policies the organization maintains, but by its ability to connect every decision with its legal reference, every authority with its holder, and every action with evidence of its implementation.
In the Saudi environment, the compliance system is distributed among the system of associations and charitable institutions and its executive regulations, the fundraising system, governance rules, the personal data protection system, in addition to the services and requirements managed by the National Center for the Development of the Non-Profit Sector. Therefore, the official needs to see these paths as a single system; a single decision may be subject to more than one obligation at the same time.
This article focuses on associations and charitable institutions under the supervision of the National Center, taking into consideration that some other non-profit entities may be linked to supervisory bodies or additional sectoral requirements.
What does compliance mean in a non-profit organization?
Compliance is the organization's ability to conduct its activities in accordance with the laws, regulations, decisions, and requirements that govern it, while retaining evidence that these requirements have transitioned from texts to practice.
In this sense, compliance includes the validity of licensing, the formation of the board of directors or board of trustees, holding meetings according to the approved authorities and procedures, accuracy of financial records, legality of fundraising, protection of donors' and beneficiaries' data, and disclosure of interests, contracts, violations, and results.
As for governance, it is the framework that regulates the relationship between the organization, its employees, and stakeholders, reinforcing fairness, transparency, credibility, and sustainability. Compliance complements it by proving that governance rules are indeed reflected in decisions and procedures, and have not remained mere announced principles.
The Right Beginning: Know Your Organizational Identity
Before creating any compliance list, the organization needs to accurately define its regulatory framework. Is it a charitable association or a charitable institution? What are the purposes approved in its charter? What is the technical supervisory body? What decisions does its board have the authority to make? Which decisions require the approval of the general assembly, the center, or the supervisory body?
The significance of these questions lies in the fact that good intentions do not grant the organization unauthorized powers. A program may be beneficial, a partnership promising, and a campaign impactful, but that does not negate the necessity of ensuring that the activity falls within the organization's purposes, and that the authority has approved it.
The compliance map begins with four primary documents: the license certificate, the charter, the decisions regarding the formation of the board, and the authority matrix. This is connected to records that prove meetings, delegations, approvals, and updates.
Follow-up does not stop at the founding stage; changes in board members, amendments to the charter, creating a branch, appointing some leaders, or changing bank accounts may require action or approval from the center.
The Center's service guide presents electronic pathways including license certificate renewal, approval of charter amendments, approval of board formations or modifications, reporting on general assembly meetings, delegating management of bank accounts, executive leadership-related requests, and approval of certain activities, depending on the type of entity and the nature of the procedure.
Thus, compliance no longer becomes an annual task before the license expires; it becomes continuous monitoring of every change that occurs within the organization.
The Board of Directors is the Starting Point
The organization may appoint a compliance officer or entrust the task to the legal department or internal audit. Despite the significance of these roles, the governance responsibility is originally linked to the board of directors in the association and the board of trustees in the institution.
The board's role goes beyond approving policies; it must monitor performance, review reports, verify the integrity of financial and accounting systems, oversee internal control and risk management, and ensure the organization complies with relevant laws and regulations.
In the executive aspect, the administration is responsible for implementing the approved policies, operating control systems, preparing financial and non-financial reports, and providing accurate information to the board in a timely manner.
This division reveals a common misconception in some organizations: the board asks management to "ensure compliance," then settles for a general report that lacks risks or evidence or corrective actions.
An effective board, however, needs a periodic report that answers specific questions: What obligations were due during the period? What has been accomplished? What are the overdue requirements? What violations or observations were discovered? Who is responsible for addressing them? When is their resolution expected?
In this manner, compliance shifts from a reassuring phrase in meeting minutes to responsibilities that are traceable and accountable.
A Policy Alone Does Not Prevent Conflicts of Interest
A conflict of interest does not necessarily imply the occurrence of corruption or exploitation. An interest may arise when a board member has a direct or indirect relationship with a supplier, a beneficiary of a grant, or an entity proposed to enter into a partnership with the organization.
However, the danger arises when this relationship remains concealed until a decision is made.
Governance rules stipulate that a board member or trustee must disclose their conflict of interest before discussing the issue, and that the disclosure must be documented in the minutes, with the member not attending the discussion or participating in the decision or voting on it. These rules cover direct and indirect interests in activities and contracts executed on behalf of the association or institution.
Therefore, a written policy needs procedures that ensure its implementation, such as periodic disclosures, updates upon the emergence of a new interest, creating a conflict of interest register, and documenting the member's abstention from discussion and voting.
However, having a relationship with a board member does not mean that contracting is prohibited in all circumstances. The key issue is the integrity of the procedure, clarity of the benefit, independence of the decision, and proof that the contracting conditions serve the organization's interest without granting unjustified preference.
Financial Compliance Begins Before Preparing The Statements
Financial compliance often appears at the end of the year during financial statement preparation. However, the quality of those statements starts much earlier; it stems from budgeting, segregating authorities, documenting expenses, bank reconciliations, managing cash, tracking assets, controlling purchases and contracts, and recording restricted funds according to their purposes.
The board of the association bears the responsibility of submitting a detailed annual report on the financial statements, approved by the general assembly within the timeframe specified by the regulations. The center provides a service for depositing financial statements and requires that their documents include the audited financial statement sealed by the auditing office, along with a letter from the auditor addressed to the board, if available. These statements are included in the reports associated with measuring organizational governance.
Therefore, it is better that the role of the external auditor not be limited to discovering errors after they occur. The financial management is required to establish a clear path for every transaction, while the board reviews periodic reports, deviations, observations, and corrective actions.
In every financial transaction, the organization must distinguish between three closely related questions:
Is the expense allowed according to the regulations?
Does the one who approved it have authority?
Was the money used for the purpose it was allocated for?
The answer may be positive to one question and negative to another. Therefore, the completeness of the invoice does not, by itself, prove completeness of compliance.
Fundraising: Licensing Precedes Announcement
Fundraising is one of the most sensitive areas of compliance; it combines money, public trust, advertising, donor rights, and the risks of misuse.
Fundraising regulations define the process as receiving cash or in-kind donations through a call to donate or organizing a campaign for that purpose. The regulations govern the licensed entities, campaigns, means of solicitation, disbursement of proceeds, in-kind donations, and violations associated with this activity.
Thus, the campaign does not begin with the publication of the design or sending the message to the influencer or launching the payment page. Its true beginning precedes that, when the organization defines the purpose, the targeted amount, the duration, the benefiting group, the spending plan, the bank account, and the channels that will be used.
Once these elements are completed, it comes to authorization and licensing procedures, and what relates to the channels used. The center clarifies that the service for issuing a fundraising permit requires registering the fundraising objective and attaching the necessary documents, while issuing a license is linked to having an appropriate bank account for the purpose and completing approvals based on the status of the entity.
The center's services also allow defining a bank account as a donations account and specifying its purpose, as well as activating the collection channels and intermediaries used in them.
In light of this, the content team should work in coordination with financial management and governance. The designer or the platform manager may produce a good announcement from a media perspective, while its publication is premature prior to licensing or contains information not aligned with the approved purpose.
The organization's responsibility does not end when the campaign closes; the next phase requires linking the proceeds to expenditures, documenting what has been spent, monitoring the balance, preparing reports, and ensuring that funds are not transferred to another purpose based on unapproved internal discretion.
This linkage becomes increasingly critical as governance rules require establishing clear policies regarding the relationship with donors and beneficiaries, maintaining the confidentiality of their information, clarifying the administrative percentage the association deducts from donations, and providing donors with the necessary reports on the outcomes of their contributions.
Thus, compliance in fundraising transforms from obtaining a license number to an integrated cycle that begins before the call for donations and continues until the results are disclosed.
Donor and Beneficiary Data Are Not Freely Usable Operational Material
Non-profit organizations often retain extensive data that includes the names of donors and ways to contact them, remittances, donations, beneficiary names along with their social and health conditions, staff and volunteer files, images, and field reports.
While this data may be necessary to implement programs, necessity does not grant the organization the freedom to use it for any purpose that may arise later.
The Personal Data Protection Act and its regulations require the data controller to specify the basis for processing and its purpose, inform the data owner about the identity of the entity and means to contact it, the gathering purpose, retention period, available rights, and whether providing the data is mandatory or optional.
When consent is the legal basis, it must be documented, and its purposes must be clear, independent, and verifiable.
This means that the form used to register the beneficiary should not collect every piece of information that the organization may need in the future. The principle is to gather the minimum necessary to achieve the specified purpose, then protect the data from unauthorized access, update it, and destroy it after the statutory need for it ends, taking into account the required retention periods.
The sensitivity of this principle emerges when preparing stories and media reports. A beneficiary's story may be impactful, yet its communicative value does not eliminate the obligation to verify the basis for publication, the limits of consent, what data can be displayed, and the potential for the public to identify the owner even after the name has been removed.
Thus, the content team needs to pose three questions before publication: Has the data owner consented to this specific use? Does the material include sensitive health or social information? Can the communicative goal be achieved while minimizing data or anonymizing the identity?
The Technical Supplier Does Not Transfer Responsibility Away From The Organization
The organization may utilize a platform for managing donations, a system for managing donor relationships, a cloud service for file storage, a company for sending messages, or an application for managing beneficiary data.
In these instances, the external company may become a processing entity that handles the data on behalf of the organization. However, the organization remains responsible for choosing a provider that offers sufficient guarantees, defining the purpose of processing and categories of data and durations, requiring the supplier to report breaches, specifying sub-entities that may access the data, and periodically verifying its compliance.
For this reason, it should not be sufficient for the supplier to simply state that their platform is secure. The contract must reflect the required level of protection and specify the data storage locations, access permissions, deletion mechanism upon conclusion of the relationship, handling of backups, reporting incidents, and engaging sub-suppliers.
It is also preferable that the technical administration does not solely decide on purchasing; the technical team assesses system efficiency, the legal administration reviews the contract, the data officer identifies the impact of processing, and the financial administration verifies the cost, then the decision is approved by the authorized person.
When these roles are integrated, the process of purchasing technology becomes part of compliance, not a separate operational step.
Breach Does Not Wait for Investigation Completion
When an incident of unauthorized access to beneficiary or donor data occurs, the organization may be tempted to wait until all details are known. However, the executive regulations of the Personal Data Protection Act establish temporal obligations when the incident could harm the data or its owner or conflict with their rights and interests.
In applicable cases, the controller must notify the competent authority within a maximum of 72 hours from the time it becomes aware of the incident, documenting its description, scope, risks, and the measures taken. The data owner must also be notified without unjustified delay if the breach is likely to cause them harm, and the notification must be clear and simplified.
Therefore, a response plan should be prepared before the incident occurs. This plan includes determining who receives the report, who assesses the incident, who has the authority to notify, how information is collected during the first hours, and how to communicate with suppliers and data owners.
In this context, an untested plan may fail at the moment the organization truly needs it.
Disclosure Is Not About Publishing Everything
Transparency is sometimes associated with the idea of publishing as much information as possible. However, good disclosure does not mean revealing personal data or contractual secrets or information that may harm beneficiaries.
Governance rules stipulate that associations and institutions adhere to principles that achieve a high level of disclosure and transparency and limit conflicts of interest. They specify subjects that should appear in the annual report, including the formation of boards and committees and their meetings, main activities, violations or penalties, contracts and works involving interests for board members, and reservations in the financial statements and how to address them.
In a parallel approach, the center provides a service for filling out and updating disclosure data according to regulations and directives, as well as a service for disclosing information about the ultimate beneficiary. Its services also include a record of support provided to beneficiaries, depositing financial statements, and updating account data.
To achieve a balance between transparency and privacy, it is useful for the organization to distinguish between three levels:
Information that must be submitted to the center or the supervisory body.
Information that should be presented to the board or the general assembly.
Information that may be published to the public.
This classification helps achieve the required disclosure without jeopardizing privacy.
How Does an Organization Build a Practical Compliance System?
Initially, the organization does not require a massive administration or a complicated technical program. The priority is to create a clear map linking commitment to procedure, responsible person, evidence, and timelines.
This map begins by cataloging the regulations, rules, directives, and policies applicable to the organization, then translating them into practical commitments. For example, "The Personal Data Protection Act" should not be recorded as a general title but translated into tasks such as updating the privacy notice, reviewing consent forms, documenting requests from data owners, reviewing processing contracts, and testing the response plan for breaches.
In the same way, the "Fundraising System" translates into specific stages that include authorization, licensing, bank accounts, channels, reviewing advertising content, closing the campaign, financial reporting, and documenting expenditures.
Each commitment is then assigned a clear owner. For instance, the board secretary may be responsible for meeting minutes and disclosures, the financial manager for statements and accounts, the resource development officer for fundraising campaign requirements, and the data officer for processing records and incidents.
The required evidence to prove implementation is then defined, as a phrase such as "implemented" does not fulfill the purpose alone; it should be supported by minutes, approvals, contracts, receipts, or an electronic record with a date and authority holder.
In the final phase, the map is reviewed periodically whenever a significant change occurs; because opening a branch, launching a digital service, entering a new area, contracting with a supplier, or changing the board of directors may create obligations that did not previously exist.
A Simple Test Before Any Decision
The organization can significantly reduce risks by passing important decisions through six questions:
Does the decision fall within the organization's purposes?
Who has the authority to approve it?
Does it require approval or authorization from the center or the supervisory body?
Does it involve collecting funds, processing data, or contracting with an external party?
What document will later prove the integrity of the procedure?
Who will follow up on the obligations after the decision has been made?
These questions do not replace specialized legal reading, but they prevent the decision from moving directly from idea to implementation, revealing early the points that need review.
From Avoiding Violation to Building Trust
The organization may view compliance as a burden that slows down operations. However, good organization often leads to the opposite outcome; it reduces hasty decisions, prevents repeated mistakes, clarifies authorities, and preserves the organization's memory when leadership and teams change.
The impact of compliance extends beyond relations with the supervisory body. It protects the board member who made a decision based on documented information, it protects the employee who executed within a clear authority, it protects the donor who knows where their money goes, and it protects the beneficiary whose data or story has not been turned into unregulated accessible material.
Therefore, the question at the end of the year should not be: Do we have the required policies?
The more accurate question is: Can the organization trace the journey of any decision from its proposal, through its approval and implementation, to its impact and disclosure?
When the answer is clear and supported by evidence, compliance becomes more than a means to avoid violation. It is an internal structure that builds trust, protects the mission, and empowers the organization to grow without letting risks expand faster than its impact.
Sources: An Arabic editorial treatment inspired by the Gatekeeper guide to non-profit compliance for 2026, aligned with the associations and charitable institutions system and its executive regulations, the fundraising system, governance rules for associations and charitable institutions, the personal data protection system and its regulations, and the services and guides of the National Center for the Development of the Non-Profit Sector.
This material is general knowledge and does not substitute for consulting specialists when applying provisions to a specific case.
Comments (0)
No comments yet. Be the first to comment!