Faith Docs

Church Governance & the Board

The Whistleblower Policy: Why the IRS Asks About It

Published · Church Governance & the Board

Short answer: a nonprofit whistleblower policy gives anyone in your church a defined, safe way to report suspected wrongdoing, and protects them from retaliation for using it. It matters because the reporting route almost always has to bypass the person the concern is about, and without a written policy there's no such route. The IRS asks tax-exempt organizations whether they have one because it treats the answer as a signal about how the organization is governed.

The bookkeeper notices that the person who signs the checks is also the person who reconciles the bank statement, and that a few transfers don't look right. Who does she tell?

If the answer is "the pastor" and the concern is about the pastor, there's no answer. That's the specific gap a whistleblower policy fills. It sits next to the church conflict of interest policy your board needs as a core board document, and it's the shorter of the two. Most churches don't have it, and the day it matters, it matters enormously.

Why does the IRS ask about it?

The IRS governance questions on Form 990, the annual information return most tax-exempt organizations file, ask whether the organization has a written whistleblower policy, a conflict-of-interest policy and a document retention policy.

Two honest points about that:

Most churches don't file Form 990. Churches are generally excepted from the annual filing requirement, so for many congregations the form itself never arrives (IRS Publication 1828, Tax Guide for Churches). That's why this question surprises church boards.

The signal survives anyway. Having the policy isn't required by the question; the question exists because the IRS treats these three policies as markers of an organization that governs itself. That framing shows up wherever your church is examined by anyone: a lender underwriting a building loan, an insurer quoting directors-and-officers coverage, a denomination reviewing standing, a foundation considering a grant, or an accountant beginning a review. Even the IRS has to follow special procedures before it examines a church, which makes the church's own governance file the first thing anybody reads (IRC §7611, Church tax inquiries and examinations).

And separately from any form: federal law includes protections that apply to nonprofit organizations, not only to public companies. Two stand out. There's a prohibition on retaliating against someone who reports a suspected federal offense to law enforcement, and a prohibition on destroying documents to obstruct an investigation. A church with no policy isn't exempt from any of that. It's simply improvising.

What a whistleblower policy has to contain

Six components do the work. Anything beyond them tends to be padding.

1. Who it covers. Employees, volunteers, board members, contractors and members. Write it broadly. The person who notices a problem is often not on payroll.

2. What can be reported. Suspected financial misconduct, theft, fraud, falsified records, misuse of designated gifts, safety violations, violations of church policy, and legal violations. Say plainly that a good-faith report is welcome even if it turns out to be mistaken.

3. How to report, with at least two routes. This is the heart of the policy. Name a primary contact, usually the board chair or the chair of an audit or finance committee, and an alternate who isn't in the same reporting line, so the route works even when the concern involves the first person. Give an actual address, phone number or mailbox, not a job title alone.

4. Non-retaliation, stated flatly. No one who makes a good-faith report will be fired, demoted, disciplined, excluded from ministry roles or harassed for it. Say that retaliation is itself a violation of the policy with its own consequences. This clause is the reason the policy works, because without it nobody uses the route.

5. What happens next. Who receives the report, what timeframe they respond in, who investigates, when the board is informed, and how the outcome is recorded. Confidentiality to the extent practical, and be honest that it may not be absolute, because some reports must be passed to law enforcement or an insurer.

6. Anonymous reports. Say whether you accept them. Most churches should, while noting that anonymity can limit how far an investigation can go.

Where churches get this wrong

All roads lead to one person. A policy that routes every concern to the senior pastor fails at the exact moment it's needed. Build in an alternate outside that chain.

No dates. "Reports will be reviewed promptly" means nothing. Put a number on it: acknowledge within a set number of days, report to the board at its next meeting.

Adopted and never mentioned. A policy nobody knows about isn't a route. Include it in onboarding for staff and volunteers, reference it in the handbook, and put the contact details somewhere findable.

The recipient investigates their own conduct. If the report concerns the person who receives it, the policy must reassign it automatically. Write that rule down rather than hoping someone thinks of it.

Retaliation by omission. Nobody gets fired. The person who reported is simply moved off the finance team, dropped from the rotation, and stops being invited. That's retaliation, and the policy should say so explicitly.

Handling a serious report entirely in-house. Some reports need outside help immediately. See below.

When a report means you call a lawyer, not a committee

Be honest about the limits of an internal process. Some reports should trigger outside counsel, and in some cases law enforcement, before the board does anything else:

In each of those, the board's job is to preserve evidence, restrict access, notify its insurer where the policy requires it, and get counsel involved. It isn't to run its own inquiry first. Boards that investigate serious allegations themselves usually damage both the evidence and the people involved.

A worked example: a report about the checks

A part-time bookkeeper submits a written concern to the board chair, the alternate contact under the policy, because the concern involves the church administrator, who is the primary contact.

Day 1. The chair acknowledges receipt in writing, as the policy requires within three business days, and tells no one else yet.

Day 2. The chair informs the treasurer and one other director who has no working relationship with the administrator. They do three things: they preserve records rather than reviewing them informally, they suspend the administrator's ability to initiate transfers without a second approval, and they check the church's insurance policy for a notification requirement.

Day 3. They call a lawyer. On advice, the church engages an outside accountant to examine the transactions rather than having a volunteer do it.

Day 10. The board meets in a properly noticed session, records that a report was received under the whistleblower policy, records the steps taken and the professionals engaged, and records nothing about the substance of the allegation beyond what's necessary.

Throughout. The bookkeeper's hours, role and standing don't change. Nobody discusses her name. If the examination clears the administrator entirely, that's a good outcome and she's still protected, because she reported in good faith.

Notice what the policy actually did: it gave her a route that wasn't through the person concerned, and it told the board what to do in the first seventy-two hours. Everything else came from professionals.

What to do about it

  1. Adopt the policy at your next board meeting, and minute the adoption with the date and the version.
  2. Fill in real names and real contact details for the primary and alternate recipients. Review them whenever leadership changes.
  3. Tell people it exists. Staff onboarding, the volunteer handbook, the annual board packet.
  4. Adopt it alongside the other two. The IRS governance questions travel as a set: whistleblower, conflict of interest and document retention. If you're adopting one, adopt all three.
  5. Test the route once. Have someone confirm the reporting email actually reaches a human and the mailbox is monitored.
  6. Put the annual reminder on your governance cycle, next to the annual conflict-of-interest disclosures.

Common questions

Do we have to have one if we don't file Form 990?

Not as a filing requirement, since churches are generally excepted from the annual return, assuming the organization actually qualifies as a church for that purpose (IRS, Definition of a church). But the policy isn't really about the form. It's about having a functioning route for a serious concern, and about how your governance looks to an insurer, a lender or a denomination. It's a one-page document. There's no good reason not to have it.

Does it apply to volunteers and members, or only employees?

Write it to cover everyone connected to the church. The people best positioned to notice a problem are often volunteers: the counting team, the childcare coordinator, the person who reconciles the benevolence fund.

Can we accept anonymous reports?

Yes, and most churches should. Be clear in the policy that anonymity may limit what can be investigated, because you can't ask follow-up questions of someone you can't contact. Don't promise an outcome you can't deliver.

What if the report turns out to be wrong?

A good-faith report that proves unfounded is protected, and it should be. Protection extends to honest mistakes, not to knowingly false reports made to harm someone. Say both things in the policy so people know where the line is.

Who should the alternate contact be?

Someone outside the day-to-day reporting chain and, ideally, without a close personal or family relationship to senior staff. A board chair, an audit committee chair, or an at-large director in a small church. Two names, both reachable.

Does adopting a policy mean we can handle a serious allegation internally?

No. The policy tells you how a report arrives and who receives it. It doesn't qualify a volunteer board to investigate abuse, fraud or a claim likely to end up in litigation. For those, the policy should route straight to counsel and, where required, to law enforcement.

The practical wrap

A whistleblower policy takes one meeting to adopt and one page to state. What it does is make sure a person with a genuine concern has somewhere to take it that doesn't run through the person they're concerned about, and that using it won't cost them their place in the church. That's worth having in the file long before anyone needs it.

---

Close the gap this quarter. The Whistleblower Policy is the protection clause most church bylaws are missing. It carries the reporting routes, the non-retaliation language and the handling procedure, ready for your board to adopt and minute. $29, instant download. See how it sits with the rest of your governance set on the church operations hub.

*Faith Docs provides self-help document templates, not legal advice. We are not a law firm. For representation, consult a licensed attorney.*

The document for this, ready to fill in.

Faith Docs sells the fill-in-the-blank templates churches actually need — drafted by church attorneys, yours to download the moment you buy.

Browse all documents →