ATO logo

Forgotten about access? Let's fix that

Simple steps you can take to keep your NFP’s information, accounts and authorisations secure.

Published 24 August 2026

Not-for-profit (NFP) organisations rely on volunteers, committee members, employees and external advisers to help manage day-to-day activities. Over time, people change roles, move on or leave altogether.

Unfortunately, when this happens their access to systems, accounts and official records is not always removed. Former employees, volunteers or office holders may still have access to:

  • bank accounts and other financial accounts
  • online services and government portals
  • email and social media accounts
  • accounting and payroll systems
  • grant management platforms
  • cloud storage and shared records.

Case study: one departure, multiple risks

Riverbend Community Services (RCS) has operated successfully for many years with a small board of dedicated volunteers. Earlier in the year Sally, a long serving secretary, resigned following a disagreement with the board.

Everyone assumed her access had been removed, but months later RCS began encountering a series of unexpected issues:

  • Suppliers started calling RCS and asking why their invoices hadn't been paid. Looking into the missed payments, RCS found their primary email address was still linked to Sally, meaning they weren't receiving invoices and important correspondence.
  • Checking their other contact details, RCS realised that letters were still being sent to Sally's postal address.
  • This prompted a review of RCS's authorised contacts for the ATO, which found that Sally was still an authorised contact. A further review of their internal systems found that she also retained access to several organisational systems.

While Sally did not misuse her system access, RCS’s relationships with suppliers were affected due to the payment delays. RCS also missed important regulatory updates because correspondence was not reaching the right people.

End of example

If you don't ensure your records and access permissions are up to date your NFP can be exposed to the risk of unauthorised access, misuse or disruption. Having accurate records helps ensure that:

  • only current representatives can access your NFP’s affairs
  • important correspondence reaches the right people for action
  • former office holders do not retain authority unnecessarily.

Where possible, use contact details for your organisation that will remain current even when role holders change. For example, instead of someone using their personal email address, use a dedicated email address owned and managed by your NFP or a postal address specifically for your NFP. This helps maintain continuity as committee members and other personnel change.

Reviewing your organisation's authorised contacts and access permissions is an important part of good governance. We explain how to review and update these records in our companion article, Managing authorised contacts and permissions.

Regularly reviewing authorised contacts, access permissions and governance arrangements helps your organisation maintain control of its information, records and systems as people inevitably move into and out of roles. By making these reviews part of your normal governance practices, you can reduce risk, avoid unnecessary disruption and stay focused on delivering for your community.

Stay informed

Managing your organisation's access permissions is one part of keeping your NFP safe. We recently covered the importance of having financial controls in 'It won't happen to us' - until it does. Take a look if you missed it in the last edition.

Our newsletter, Not-for-profit news, helps you stay up to date with all the latest tax and super news within the NFP sector. SubscribeExternal Link to get it straight to your inbox. If you’d like earlier notification when articles are published, you can also subscribe to ATO site updates.

QC107933