The situation
What worried Rizki was not the leak itself, at first. It was a phone call from a colleague on the organization's staff, telling him that a rival service provider, one the organization was competing against for a renewal contract with a regional funder, had shown up to a pre-bid meeting with figures and language that sounded very close to what had been discussed in a closed board session three weeks earlier. If that provider had the organization's actual cost structure and its planned pitch to the funder, the renewal, worth a meaningful share of the organization's annual operating budget, could be lost before the bid was even submitted. That was the practical fear driving everything that followed, not the abstract idea of a breach, but the very real possibility of losing the funding that kept the organization's programs running.
Rizki had joined the board two years earlier, alongside Sophia, both of them drawn from the community the organization served rather than from a corporate background. Rizki worked as an HVAC technician; Sophia worked as a paramedic. Neither had governance experience going in, and the board itself ran on trust and informal habits built up over years, minutes taken loosely, materials emailed around without much thought to who forwarded what. Rizki spoke limited English, and board meetings were conducted with an interpreter present, which had always worked well enough for participation but had never been tested against a situation where precision mattered, where the exact wording of what was said and what was merely implied could matter a great deal.
The organization's revenue sat in the low single-digit millions, funded mostly through the contract now at risk plus a handful of smaller grants. A lost renewal would not close the organization, but it would force real cuts to programs the board had spent years building. One board member, Anahit, had been unusually active in outside meetings around the same period the material appeared to have leaked, though nobody on the board wanted to say so directly, and Rizki, uncertain of both the facts and his own footing in a language that was not his first, did not know how to raise the question without it sounding like an accusation he could not yet support.
The board met again the week after the phone call, and the meeting was tense in a way none of them were used to. Sophia raised the pre-bid meeting rumor openly, which put Anahit on the spot in front of colleagues who had known each other for years and generally trusted one another. Rizki, watching the exchange through the interpreter, was struck by how much of the discomfort in the room seemed to come from not knowing what the right process even was, whether to investigate, confront, or simply hope the funder decision went their way regardless. He left that meeting convinced the board needed outside guidance before it did anything further, since none of the volunteers around the table had ever handled a situation like this before.
The risk we had to size
Before anything else, we had to separate what the board actually knew from what it suspected. A staff member's secondhand account of a pre-bid meeting was not proof that confidential material had left the boardroom, let alone proof of how it had left or who was responsible. Treating suspicion as fact, particularly suspicion pointed at a specific board member, risked turning a containable problem into a governance crisis and, potentially, a defamation exposure of the board's own making if the accusation turned out to be wrong.
So the first task was sizing the risk honestly, on two separate tracks. The first was the competitive exposure: what, specifically, had been discussed in that closed session, and how much of it, if it truly had reached the competing provider, would actually matter to the funder's decision. Cost structures and pricing strategy mattered a great deal. General discussion of program priorities, which had also been on that meeting's agenda, mattered much less, since funders in this sector typically see similar priorities across most applicants in any case. Narrowing the exposure to what was genuinely sensitive kept the board from treating the whole meeting as compromised when only part of it likely was.
The second track was internal: what the board's own practices actually required of its members, and whether there was anything in writing that a member could be said to have breached. Not-for-profit boards frequently operate without a signed confidentiality agreement at all, relying instead on an unwritten expectation that what happens in the boardroom stays there. That gap mattered here, because it meant that even if Anahit, or anyone else, had discussed the meeting's contents outside the room, there was no clear written standard they could be shown to have violated, which limited what formal response was realistically available.
Layered over both tracks was the interpretation question. Board discussions had been conducted with an interpreter for two years, and we needed to understand whether anything in that process, informal side conversations, imprecise translation of a sensitive point, had itself contributed to information moving outside the room in a way nobody intended as a breach at all. An interpreter present in a closed session is, functionally, another person with access to sensitive material, and if the board had never turned its mind to that fact, the leak, if there truly was one, might not trace back to any board member at all.
We also had to weigh what confronting Anahit directly, on the strength of a colleague's impression from a meeting they were not even in, would do to a small volunteer board that depended on trust to function. A wrong accusation would likely end that person's willingness to serve and could fracture relationships the organization would need intact long after this particular contract renewal was decided one way or the other. Sizing the risk meant weighing the cost of being wrong about a person against the cost of doing nothing at all.
What we did
We started by interviewing Rizki and Sophia separately, with a qualified interpreter present for Rizki's account, to build an accurate picture of what had actually been said in the closed session and by whom, rather than relying on the staff member's secondhand summary of what the competing provider had appeared to know. This produced a much narrower list of genuinely sensitive details than the initial alarm had suggested, which mattered for everything that followed.
We then reviewed the organization's governance documents and found, as expected, no signed confidentiality undertaking and no board policy addressing external communications about board business. Without that gap closed, any response to the suspected leak would have been standing on unstable ground, since there was nothing formal to say had been broken.
Rather than confront Anahit directly on the strength of a secondhand account, we recommended the board introduce a written confidentiality undertaking for all members going forward, framed not as a response to a specific accusation but as a standard governance improvement the board should have had in place from the start. This let the board tighten its practices without forcing a premature judgment about who, if anyone, was responsible for the earlier leak.
We drafted the undertaking in plain language, translated accurately for Rizki's review before it went to the full board, covering what counted as confidential board material, how it could and could not be shared outside meetings, and what the consequences of a breach would be once the policy was formally in place. Every member, including Anahit, signed it.
Separately, we advised the board on how to handle the funder relationship, recommending that the executive director speak informally with the funder's contact to reinforce the organization's competitive position, without raising the suspected leak directly, since doing so risked drawing more attention to a problem that was not yet confirmed and might do more harm than the leak itself.
Finally, we reviewed the interpretation arrangement for future closed sessions, recommending a formal confidentiality undertaking for the interpreter as well, and a practice of keeping sensitive numerical detail off shared screens and out of circulated materials, discussed verbally instead, to reduce how much sensitive material existed in a form that could travel.
We also sat with Rizki afterward, through the interpreter, to walk through the whole file in plain terms, what had been found, what remained unknown, and why the board had chosen a governance fix over a direct confrontation. He had come into the process worried that his limited English meant he had missed something important along the way, and part of our job was making sure that language was never the reason he understood less about his own organization's affairs than any other board member did.
The outcome
The renewal contract went ahead to bid, and the organization retained it, though the board could never establish with confidence whether the competing provider's apparent knowledge had come from a genuine leak or from an experienced guess at figures any organization in that position might plausibly propose. Anahit was never formally confronted, and the question of what, if anything, they had done was left unresolved. That was a real concession, not a clean resolution, and Rizki was candid that it did not fully answer the question that had prompted the call in the first place.
What the board did get was a functioning confidentiality framework it had never had before, signed by every member including the one under quiet suspicion, which meant that if a similar situation arose again, there would be a clear written standard to point to rather than an unwritten expectation nobody could enforce. The interpretation process was also formalized, closing a gap the board had not previously considered a risk at all.
Rizki described the outcome afterward as unsatisfying but honest. The board had not caught anyone, and it had not proven a leak had occurred in the way first feared. It had, however, made a repeat of the underlying vulnerability much harder, and it had done so without turning a two-year working relationship among volunteer board members into an accusation nobody could take back.
Sophia, who had raised the concern most directly at that tense meeting, later said she had expected the process to end with someone being asked to leave the board. Instead it ended with a signed policy, a formal process for closed sessions, and a board that understood, for the first time, that trust among volunteers was not itself a substitute for having anything in writing. Whether that would have been enough had the leak turned out to be real and provable is a question the board never had to answer, and Rizki, for his part, was glad it did not have to.
What you can learn from this
- Secondhand knowledge of a leak is not proof of one. Investigate what was actually discussed before assuming the worst version of events is what happened.
- A not-for-profit board without a signed confidentiality undertaking has no written standard to enforce, even when a breach seems obvious in hindsight.
- Introducing a policy as a general governance improvement, rather than as a response to a specific person, lets you tighten practices without a premature accusation.
- If board discussions rely on interpretation, extend confidentiality obligations to the interpreter and consider what sensitive detail should be spoken rather than circulated in writing.
- Not every risk resolves cleanly. Sometimes the honest outcome is a stronger process going forward and an open question you choose not to force closed.
This is a corporate problem we handle
Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.