Nonprofit virtual assistants: the compliance questions worth asking

Before engaging any virtual assistant provider for nonprofit or church work, ask five things: how are workers vetted, who has access to what data, is there a background check, is access read-only or full, and what happens if the person leaves. Most providers can't answer all five in writing.


Five questions. Ask them before you sign. Illustration: a rosette ribbon on a document with a gold center.
The short answer

Ask any virtual assistant provider five things before signing: how workers are vetted, who has access to what data, whether a background check happens before access, whether access is read-only or full, and what happens if the person leaves. These are questions any legitimate provider should answer in writing, not questions only one company can pass.

This is the diligence companion to a related question we've answered separately: what nonprofit VA advice actually applies to a church. That post sorts the category. This one hands you the checklist to run before you hand anyone, from any provider, access to your donor or member data. It's also part of our guide to what church work you can outsource.

Notice what this post is not. It's not a comparison of features, price points, or platforms. Those questions matter, but they're not the ones that determine whether an outside person handling your church's records turns into a quiet liability. The five questions below are the ones that determine that, and they apply the same way whether you're evaluating a solo freelancer, a large agency, or a managed staffing model.

Most virtual assistant content assumes you'll trust the sales page. A cautious board member doesn't have to. Every question below is one a legitimate provider should be able to answer in writing, before you sign anything.

Use this the way you'd use any due diligence checklist: bring it to the first real conversation, ask the questions in order, and pay attention to how directly they get answered. A provider that answers plainly, even when the answer is a limitation, is more trustworthy than one that answers every question with reassurance and no specifics.

A useful test while you're in that conversation: imagine repeating each answer word for word to your board or finance committee next week. If an answer only works as long as nobody asks a follow-up question, it wasn't a real answer. The five categories below are built to survive that kind of repeating.

What should you ask about vetting?

  • Who actually does the vetting, the company or a third party?
  • Is it verified: references checked, work history confirmed, not just self-reported?
  • For church-adjacent work specifically, is there any faith-specific vetting, or is a worker's familiarity with ministry work left to chance?

Vetting is the question providers most often answer with a slogan instead of a process. "We only hire the best" isn't an answer. Who does the interviewing, what gets checked, and against what standard, is. If a provider can't describe their vetting process in specific, repeatable steps, they likely don't have one beyond a resume review.

What should you ask about data access?

Data access is where a diligence conversation earns its keep. It's easy for a sales conversation to stay abstract, "we take security seriously," and never get specific about what a particular worker can actually see and touch. Push past the abstraction with the question underneath it: for each system this person will use, what exactly can they view, and what exactly can they change.

Data type vs. the access level that should be granted
Data typeAccess that should be grantedRed flag
Financial / bankingNone, everAny request for banking credentials
Bookkeeping softwareRead-only bank feeds onlyFull transfer or payment permissions
Member / donor recordsNamed account, least-privilegeShared login, no individual accountability
General admin systemsNamed account, scoped to taskSole administrator status

If a provider's answer to any row is "full access," that's the red flag, not a feature.

Access questions matter more than most churches realize until something goes wrong. A worker with more access than their task requires isn't a convenience, it's an unmanaged liability sitting in your systems. The standard to hold any provider to is least privilege: access scoped to exactly what the task needs, under a named account tied to one person, never a shared login and never sole administrator rights over a system that touches money or member data.

What should you ask about background checks?

Two questions decide this one: does the check happen before any access is granted, not after a problem, and what does it actually cover. A background check run after someone already has your donor database open protects nobody.

Ask specifically when in the process the check happens. Some providers run a check after a placement has already started working, treating it as paperwork rather than a gate. The check should be a gate: no access to financial, giving, or member personal data until it's cleared, full stop, not a formality that catches up later.

Also worth asking: does the check happen once, at placement, or does it repeat. A single point-in-time check tells you about the person's history up to that date. Whether that's sufficient for your church's risk tolerance, especially for anyone touching giving records long term, is worth deciding on purpose rather than assuming.

What should you ask about continuity?

What happens the day the person leaves? With an unmanaged freelance arrangement, you restart the search from zero, including the vetting and the ramp time. With a managed model built around a replacement guarantee, the person changes and the price and the arrangement do not.

This is the question boards forget to ask until it's too late, usually right after the person they'd built a working relationship with gives notice. Ask it up front instead: what's the actual mechanism for replacement, how long does it take, and does the price change when it happens. A vague answer here means you're the one absorbing the disruption when turnover hits, not the provider.

What should you ask about oversight?

Who is the one named point of contact directing the work, and how much of your own time does the arrangement assume weekly? A workable model runs on roughly 20 to 30 minutes of direction a week from one named person on your side, not a committee and not an open-ended time sink.

Oversight structure predicts almost everything else about how the arrangement will actually run. If the answer to "who directs this person day to day" is vague, or if it requires input from multiple staff members with no single owner, expect the same confusion that made you search for outside help in the first place, just with an extra person now involved in it.

Who's actually behind the vetting

CoLabor Staffing places full-time Christian co-laborers with churches and Christian-owned businesses. Every co-laborer is a Christian, vetted by people who are themselves in ministry, not a general staffing pool screened by a generic HR process. That's one answer to the vetting question above. The other four apply the same way regardless of who you're evaluating.

It's worth saying plainly why a checklist like this exists at all instead of just a list of recommended providers: recommendations go stale, and providers change their practices. A checklist doesn't. Whatever provider you're looking at a year from now, these five categories, vetting, data access, background checks, continuity, and oversight, are still the ones worth running through before anyone gets access to what your church knows about its people and its money.

None of the five questions above are leading questions built to make one company look good. They're the questions a cautious board member should ask any provider, CoLabor included, and a provider that can't answer all five in writing is telling you something. Run through them with a checklist in hand, not from memory, and don't accept "we'll figure that out together" as an answer to any of them before a contract is signed.

For the mechanics behind how offshore arrangements are typically structured, including the ethics question most providers avoid, see offshore support: what you are actually buying and hiring in the Philippines, the honest version. And if you haven't yet sorted which parts of general nonprofit VA advice even apply to your church, start with virtual assistants for nonprofits, and what applies to churches before running this checklist against a specific provider.

Run the checklist yourself

Take the five questions above to any provider you're evaluating, CoLabor or otherwise, and ask for the answers in writing before you sign anything.

Review the questions

Hear the five answers directly

If you'd rather hear these five answers directly instead of reading them, that's what the call is for. Generalist tier runs $1,997 a month, flat.

Book a 30-minute call

Common questions

What questions should a church ask before hiring a virtual assistant?

How workers are vetted, what data access they’ll have, whether a background check happens before access is granted, whether access is read-only, and what happens if the person leaves.

Should a virtual assistant have full access to church financial accounts?

No. Access should be read-only and least-privilege, with named accounts, never a single unsupervised administrator.

What happens if our virtual assistant quits?

With an unmanaged freelance arrangement, the church restarts the search. With a managed model that includes a replacement guarantee, a new person is provided at the same price.

Is it reasonable to ask a provider for these answers in writing?

Yes. A provider that can’t put vetting, access, and continuity answers in writing is telling you something, whether or not that’s the intent.

The CoLabor team

We place full-time Christian co-laborers with churches and Christian-owned businesses, and we publish what church staffing actually costs. Here is how it works.