Charities manage personal data, donor information, payment flows and often data about vulnerable target groups. Reliable digital processes support the trust of donors, participants, funds and cooperation partners.

What does the CBF Recognition Scheme on Information Security require?

The standards for 2026 are part of the system for the recognition of charities. The specific requirements vary by category. Privacy, information security, internal control and control are reflected in this as topics that call for demonstrably attention.

Good implementation starts with current policies and a well-founded picture of risks. Organisational and technical measures shall be linked to ownership, supporting documents and periodic evaluation. This creates a workable line from standard to daily execution.

  • privacy and information security policy that connects to the organisation
  • protection of donor, volunteer and participant data
  • control of payment flows, phishing and digital fraud
  • reliable reporting to governance and internal oversight
Governance is given practical value when digital responsibility becomes visible in decisions, ownership, evidence and periodic reporting.

Protect donors' data and payment flows carefully

Fundraising is highly digitized. Websites, CRM systems, payment providers, marketing platforms and external agencies process data and support revenue. A risk analysis makes visible where unwanted access, errors, fraud or failure may affect the organisation.

Measures remain proportionate when chosen on the basis of data, processes and threats. Think of strong authentication, function separation, check of payment data, logging, backup, vendor agreements and a clear reporting route in case of incidents.

What does this require of governance and oversight around digital resilience?

Governance and oversight need to understand the risks that can affect trust, revenue, service and reputation. A compact report connects technical topics to impact, ownership, progress and decisions.

Evidence arises by logically linking established policies, current analyses, checks carried out, recorded incidents and subsequent improvement actions. This supports both internal management and preparation for external assessment.

Include recognition standards in the improvement cycle

Kynexis Information Security can combine the relevant CBF standards with baseline assessment information security, risk analysis information security or governance GAP analysis. The scope follows from the category, organisational scale, data and digital dependencies.

The outcome contains concrete findings, risks, priorities and ownership. Normity allows for the central monitoring of documents, evidence and improvement actions, so that the organisation is focused on demonstrable assurance.

Source and demarcation

The sectoral framework sets out a direction; digital translation requires customization

This article translates the official code or arrangement into information security and internal control. For formal application, the original text of the framework remains guiding.

View Standards Recognition Scheme Good Objectives 2026 at the official source →