A letter from the Canada Revenue Agency's Charities Directorate arrived at the registered office of a federally incorporated charitable organization that had operated community support programs in a mid-sized Canadian city for 14 years. The correspondence identified concerns arising from a desk audit of the charity's T3010 filings and requested documentation regarding the organization's disbursement quota compliance, the characterization of certain activities as charitable versus related business undertakings, and the accuracy of official donation receipts issued over the preceding 3 fiscal years. The board chair, a volunteer director serving in her 4th year on the board, convened an emergency meeting of the 7-member board to address the letter's implications.
The charity employed 23 staff members, including an executive director who had held the position for 6 years, and engaged approximately 140 active volunteers across its programming. Its annual revenues had grown from $1.2 million to $2.8 million over the preceding 5 years, funded through a combination of individual donations, 2 major government contribution agreements, foundation grants, and fee-for-service contracts with municipal agencies. The organization maintained a donor database containing personal information on more than 4,500 individuals, a volunteer management system with detailed records including vulnerable sector check results, and employment files reflecting a workforce that had doubled in size since the current executive director's appointment.
As the board began examining the CRA's concerns, additional governance gaps became apparent. The organization had not updated its privacy policy since 2017, when amendments to provincial private sector privacy legislation imposed new breach notification requirements. Employment practices had evolved informally as the organization grew, with inconsistent documentation of overtime arrangements, classification of certain service providers as independent contractors rather than employees, and incomplete records of workplace harassment training required under occupational health and safety legislation. A provincial funder had recently requested evidence of compliance with its contribution agreement terms, including requirements for specific financial controls and conflict of interest policies that the board had not formally reviewed in over 2 years.
The charity's most recent audited financial statements showed adequate reserves, but the board now faced questions about whether those reserves might be needed to address potential reassessments, penalties, or the costs of remediating compliance deficiencies across multiple regulatory domains. The executive director reported that staff morale had declined as word of the CRA inquiry circulated, and 2 long-serving program managers had raised concerns about being asked to implement policies that had never been formally approved by the board. The directors found themselves confronting not a single compliance failure but an accumulated pattern of governance gaps that had developed incrementally as the organization's growth outpaced its internal systems.