REVIEW PRACTICE 6 · IN DEVELOPMENT

Data Governance & Payment Security Review

Small governed bodies hold large balances and administer them through a single email inbox. This is the least covered governance dimension and one of the most consequential.

A body with a seven-figure reserve and a two-person office is a soft target holding hard money. The controls that would stop a fraudulent payment instruction are cheap, well understood, and almost never written down.

The gap this addresses

Payment fraud against small institutions is ordinary rather than exotic: a change of bank details arrives by email from a familiar address, and it is actioned. There is typically no adopted control requiring verification through a second channel, no requirement that two people approve a transfer, and no obligation to tell members that it happened.

These points test written controls and disclosure practice. They do not require the reviewer to test any system, and no reviewer should attempt to.

What this review is not

  • It involves no technical testing of any kind — no scanning, no probing, no attempt to access any system. It is a documentary review of adopted controls.
  • It does not publish specifics that would assist an attacker. Findings are reported to the entity in the first instance, at the level of whether a control exists.
  • It is not an audit, examination, or investigation within the meaning of any professional standard, and it produces no assurance.
  • It is not legal, accounting, or tax advice. See our Terms.
  • A review point that resolves against an entity is a question, not a conclusion. Every published finding is designed to state the document it came from and the answer that would close it.
  • Where a TASFGA researcher, founder, or board member is a member, party, or complainant in a matter concerning an entity, TASFGA does not publish a review of that entity. See Methodology.

The review points

12 points, grouped by what each tests. This set is a draft. It would be versioned, opened for public comment, and re-applied to every prior review when it changes, in line with our Methodology.

Moving money

  1. Dual authorisation. Whether any adopted policy requires two people to approve an outbound transfer above a stated amount, and whether the two may be the same person in different roles.
  2. Change of payment instructions. Whether a change to a vendor’s bank details must be verified through a channel other than the one that requested it, and whether the verification is recorded.
  3. Standing authorisations. Recurring payments, purchasing cards, and auto-debits — who may establish them, and who reviews the list.
  4. Reconciliation. Who reconciles the accounts, whether that person is independent of whoever initiates payments, and how often the board sees the result.

Credentials and custody

  1. Multi-factor authentication. Whether it is required on banking, payroll, and email accounts, and whether the requirement is written down or merely customary.
  2. Who holds the credentials. Whether banking and portal credentials are held by the entity or by its agent, and what the management agreement says happens to them at termination.
  3. Turnover procedure. What is revoked, and when, on the departure of an officer, employee, or agent — and whether anyone verifies it was done.
  4. Third-party access. Which vendors hold access to the entity’s systems or member data, under what agreement, and whether that list exists.

Member data and disclosure

  1. Data inventory. What personal information the entity and its agent hold about members, where it lives, and how long it is kept.
  2. Breach notification. The entity’s obligation to notify members under applicable law, whether any adopted policy addresses it, and what was done on any past occasion.
  3. Loss disclosure. Whether any payment loss appears anywhere members can see it — the financial statements, the minutes, or a communication.
  4. Insurance. Whether crime, fidelity, or cyber coverage is carried, at what limit, and whether the limit bears any relation to the balances held.

Where this applies

  • Residential community governance — reserve and operating accounts administered by a third-party agent.
  • Municipal governance — Business Improvement Districts and small authorities operating outside central finance controls.
  • Public agencies — grant disbursement and vendor payment functions.
  • Corporate & institutional boards — small nonprofits and foundations with concentrated signing authority.

How this connects to the rest of the work

Dual authorisation above a threshold, out-of-band verification of payment-detail changes, and a duty to disclose a loss to members are three adopted controls that cost nothing and are almost never required. They belong in a model standard scaled to entity size.

The in-field evidence base for Focus 1 — building by building, firm by firm — is published at condoscoopsnyc.org, which documents the underlying statutory gaps this practice was built to detect.

Other review practices

TASFGA is pre-incorporation. This review practice is a published draft, not an offered service, and no engagement is available. Members of a governed body who wish to apply these points to their own entity are free to do so.