A governance structure can look perfectly respectable on paper while failing during an ordinary operating day. The board has a chair, committees meet on schedule, policies sit in a shared folder, and management still can't answer who owns a failed ACH batch, an overdue concentration report, or an investor statement that never reached the mailbox.
For a Church Extension Fund, governance isn't an org chart. It's the operating system that connects mission, authority, risk, financial reporting, technology, and daily decisions. The World Bank's Worldwide Governance Indicators framework measures governance through six separate dimensions, including government effectiveness, regulatory quality, rule of law, and control of corruption. That multidimensional view applies well to a CEF. Strong policy approval doesn't compensate for weak reconciliations, unclear escalation, or untested recovery procedures.
The Tuesday Morning That Reveals Your Governance Structure
A CEF executive director arrives on Tuesday morning to find three problems already in motion.
The overnight ACH batch failed. A staff member has paused the next payment run, but nobody knows whether the operations manager, controller, or technology vendor should authorize the rerun. An investor is waiting on the phone because a quarterly statement is missing. At the same time, the board chair wants to know why last month's loan concentration report arrived late and whether the figures are reliable.
None of these events is merely a technology problem. The ACH file may have failed because of a system defect, but the governance question is different: who owns the service, who can approve the recovery, and what evidence must be retained? The missing statement raises the same issue. Someone must own investor communications, validate the underlying note data, and escalate a recurring production failure. The delayed concentration report demands a documented explanation, not a hurried spreadsheet assembled before the board meeting.
Practical rule: If staff members need to negotiate authority during an incident, the governance structure is incomplete.
A CEF serves churches and investors through connected services: loan payments, construction draws, investor notes, general-ledger close, cash management, ACH, and regulatory reporting. A weakness in one service can affect confidence in the entire fund. Investors don't separate a statement failure from the institution, and a board can't oversee risk it sees only after the fact.
The right response isn't automatically another committee or a larger policy manual. It begins with named owners, clear decision rights, useful reporting, independent challenge, and controls that work in the systems staff use every day. That is the standard this article applies to governance structure, from board design and risk management to operational resilience and CEF-specific reporting.
Defining Governance Structure for a Church Extension Fund
A governance structure is the system of people, policies, controls, and decision rights that directs strategy, manages risk, and holds an organization accountable. For a CEF, it determines who may approve a church loan, change an investor-note term, release construction funds, accept a policy exception, or authorize a liquidity response.
The org chart is only the wall plaque. Governance structure is the operating system underneath it.
Four building blocks make the system usable:
- Oversight. The full board sets mission alignment, risk appetite, strategic direction, and reserved authorities. Finance, audit, or risk committees can review detail, but delegation doesn't remove the board's accountability.
- Roles and responsibilities. The executive director, CFO, controller, treasury manager, loan team, compliance staff, IT leaders, and independent reviewers need documented responsibilities. A RACI matrix can identify who is responsible, accountable, consulted, and informed for each critical process.
- Policies and limits. Written policies define lending authority, concentration limits, liquidity requirements, related-party lending, investor-note administration, cybersecurity, vendor management, and escalation thresholds.
- Controls and evidence. Segregated duties, reconciliations, approvals, access reviews, audit trails, and exception reporting enforce the policy in daily work.

Authority must follow the transaction
A board policy that says management oversees investor notes is too broad to guide an incident. The operating detail should identify who can create a note, approve its terms, release funds, reconcile the balance, correct a statement, and report an exception. The same principle applies to a loan, ACH file, general-ledger journal, and construction draw.
NIST Cybersecurity Framework 2.0 makes this leadership principle explicit. Its governance requirements call for accountable leadership, communicated roles and authorities, and responsibilities that are understood and enforced, as described in the NIST Cybersecurity Framework 2.0. A CEF should apply the same discipline beyond cybersecurity.
The rest of the governance structure should answer four practical questions. Which model fits the fund's size and complexity? Which risks belong to the board, management, or independent oversight? What information must reach the board, and when? Which controls make those decisions traceable rather than dependent on individual memory?
Comparing Governance Models Used by Church Extension Funds
CEFs commonly operate through one of three arrangements, even when their bylaws use different labels.
A working board combines governance and substantial operational involvement. Directors may participate in loan reviews, investment-product decisions, or finance work alongside management. This model can move quickly and preserve close mission alignment, but it creates a higher risk that directors will influence transactions involving their own church, congregation, or related party.
A policy board reserves strategy, risk appetite, executive oversight, and policy approval for the board. Executive and finance or audit committees examine detail, while management runs the fund. This model creates clearer boundaries and deeper specialization, although decisions can slow if committee authority overlaps or reserved matters are too broad.
A delegated denominational model places ultimate authority with a parent church body or wider governing conference, while the CEF board manages operations within delegated limits. It can align the fund with denominational priorities, but the delegation must be specific. A parent body's authority shouldn't create uncertainty about who approves liquidity action, lending exceptions, or investor communications.
The OECD Corporate Governance Factbook 2023 compared listed-company governance arrangements across 49 jurisdictions through the end of 2022. It found one-tier systems favored in 23 jurisdictions and two-tier systems favored in eight, while many jurisdictions allow a choice. The lesson for CEFs isn't to copy a public-company model. It's to choose deliberately, preserve independent judgment, and document how authority moves between the board, committees, management, and the wider church body.
| Model | Decision Speed | Expertise Depth | Conflict-of-Interest Risk | Best Fit |
|---|---|---|---|---|
| Working board | Fast for familiar matters | Often concentrated in a few people | Higher unless recusals and independent review are strong | Smaller or closely connected funds with disciplined controls |
| Policy board | Moderate, with clearer escalation | Stronger through committee specialization | Moderate, depending on committee independence | CEFs with complex lending, investor, and reporting programs |
| Delegated denominational model | Varies with reserved powers | Broad if the parent body provides resources | Depends on related-party safeguards and reporting lines | Funds operating under formal church-body authority |
A board should review its model against fund complexity, loan and note activity, denominational expectations, staff capacity, and regulatory exposure. The building governance frameworks that work perspective is useful here because it treats structure as something that must support actual decisions, not merely describe reporting lines.
Compliance and Risk Management in the Governance Structure
Compliance becomes credible when governance assigns ownership and demands evidence. A CEF answers to state securities regulators, the IRS, its board, investors, borrowing churches, auditors, and the wider denominational body. Those obligations meet in daily workflows such as note issuance, interest reporting, lending, cash management, ACH activity, construction draws, and financial close.
A practical three-line structure gives each responsibility a clear home:
- Board and risk or audit committee: Set risk appetite, approve policies, reserve material decisions, review exceptions, and challenge management's reporting.
- Executive management: Fund and operate the control environment, assign owners, monitor thresholds, and report failures or accepted risks.
- Operational, compliance, and internal-audit functions: Execute controls, preserve evidence, test results, monitor compliance, and challenge management independently.
The board should also treat technology governance as a control issue. FFIEC guidance defines IT governance as the leadership structure and process that aligns technology with business objectives while mitigating technology risk. Its IT Management booklet states that the board sets the tone and direction for technology use and should approve the IT strategic plan, information-security program, and related policies.
Map each risk to an accountable owner
Reserve board decisions for risk appetite, material policy exceptions, related-party lending, significant concentration exposure, liquidity action, and major vendor dependency. Management owns implementation and must escalate when a threshold is reached. A policy without a named owner is not a control.
| Risk area | Management owner | Independent challenge | Board evidence |
|---|---|---|---|
| Loan concentration | Chief lending or credit leader | Finance, risk, or internal audit | Concentration report, limit breaches, remediation |
| Investor-note redemptions | Treasury manager | Controller or compliance | Maturity profile, liquidity pressure, exceptions |
| Related-party activity | CFO or executive director | Audit committee | Disclosure, recusal, independent approval |
| Cybersecurity and access | IT or security lead | Compliance or internal audit | Access reviews, incidents, overdue remediation |
| Vendor concentration | Operations or technology lead | Risk or audit committee | Critical dependencies, contingency plans |
| Financial reporting | Controller | External or internal audit | Reconciliations, close exceptions, certifications |
The governance baseline should include conflict-of-interest rules, whistleblower procedures, executive certifications, auditor independence, private board sessions without management, and an audit committee with authority to oversee the external auditor. Faith-based nonprofit governance research also identifies controls such as prohibiting loans to directors and requiring CEO and CFO certification of financial information and internal controls, as summarized in financial governance guidance for faith-based NGOs.
A CEF that holds or controls investor assets should document custody authority, segregation of duties, reconciliations, and independent review. The SEC custody rule framework illustrates the principle, even though a CEF is not automatically an investment adviser. Ask who can initiate, approve, release, and reconcile investor or borrower funds. Apply the same discipline to ACH approvals, investor-note payments, and construction draws.
For boards reviewing control ownership and staffing, using psychometric data for hiring may inform talent decisions, but it cannot replace transaction evidence, independent testing, or documented authority.

CEF leaders can use governance, risk, and compliance services guidance to organize policies, ownership, and evidence around the fund's actual workflows. The board should challenge whether those controls still work under staff absence, system failure, delayed reconciliations, or a sudden liquidity request.
Board-Ready Reporting and KPIs That Strengthen Oversight
A board can't govern from a data dump. It needs a reporting package that separates information from decisions and shows where management requires direction.
The full board should receive a concise recurring view of financial condition, mission alignment, risk, and exceptions. Committees can receive supporting schedules, but the board pack should make material movement visible without requiring directors to reconstruct the story from spreadsheets.
Portfolio and investor measures
Loan portfolio reporting should include delinquency, nonaccrual exposure where applicable, concentration by borrower or church relationship, covenant exceptions, construction-draw status, and criticized credits. Each measure needs a defined owner and a threshold that triggers action. A concentration report without approved limits is descriptive, not governable.
Investor-note reporting should show outstanding balances, maturities, renewal activity, redemption requests, interest obligations, and any unusual statement or payment exceptions. Treasury should connect that information to available cash, expected inflows, borrowing capacity where applicable, and liquidity stress scenarios.
Operating and resilience measures
The board should also see:
- Cash and capital: Cash position, forecast variance, liquidity policy exceptions, and capital or reserve measures approved by policy.
- Reconciliation quality: Open subledger-to-general-ledger items, aging of unresolved differences, and the owner assigned to each exception.
- Access governance: Completed access reviews, privileged-access exceptions, terminated-user cleanup, and overdue remediation.
- Service reliability: Failed ACH batches, delayed investor statements, payment-processing interruptions, and recovery-test outcomes.
- Vendor exposure: Critical third parties, control deficiencies, concentration concerns, and contingency actions.
- Reporting integrity: Late regulatory filings, 1099 production exceptions, close adjustments, and audit findings.
The most useful report pairs each KPI with four fields: current status, threshold, owner, and required decision. For example, a failed reconciliation may require management remediation, while a liquidity threshold breach may require board approval for a documented response. The report should also identify whether figures are system-generated, independently reviewed, or awaiting validation.
A board reporting package should be designed around decisions rather than presentation. The executive summary reporting approach provides a useful model for turning detailed operational data into a concise governance record.

How CEFCore Features Support Each Layer of Governance
A Tuesday morning exposes weak governance quickly. A construction draw awaits approval, an ACH file needs release, and an investor note requires correction. If those activities sit in separate tools, staff may rely on email, spreadsheets, or informal evidence to prove who approved what.
The control objective should come first. Role-based access controls should separate the people who prepare, approve, modify, and release transactions. Maker-checker workflows should apply dual approval to payments, construction draws, policy exceptions, and other sensitive actions. Immutable audit trails should record who acted, when the action occurred, and what changed. CEFCore is one example of a unified platform designed to connect these records, but the same requirements should guide any software assessment.

Controls should follow the money
A CEF needs a connected transaction record from loan servicing and investor-note issuance through daily interest accrual, payment processing, statements, 1099 reporting, cash operations, and the general ledger. Repeated manual entry creates gaps that weaken reconciliation and board challenge.
Subledger reconciliation should surface differences before they become board-level surprises. ACH controls should restrict preparation and release authority. Construction-draw workflows should require documented approvals and supporting evidence before funds move. Scheduled reports should deliver recurring management and board information without depending on one employee's memory.
Dashboards show conditions sooner; they do not make governance decisions. Management must investigate exceptions, document remediation, and escalate matters under board-approved policy.
Evaluate every system against those requirements. Ask whether it preserves evidence, separates duties, supports reconciliation, handles exceptions, and produces the reports the board has agreed to review. A long feature list is not a control environment. The test is whether the platform supports accountable service delivery when a payment fails, a draw changes, or an investor record needs correction.
Why Adding Committees Is Not the Same as Better Governance
Committee growth often hides an authority problem. A fund adds a technology committee because the board doesn't understand vendor risk, then a risk committee because the technology committee can't decide escalation, then a special working group because management still lacks a service owner. The calendar fills up while the failed ACH file continues to have no clear recovery authority.
Operational-resilience guidance points toward a better test. The Central Bank of Ireland states that the board has ultimate responsibility and that resilience belongs in the wider governance and risk-management framework, as described in its operational-resilience guidance. The UK FCA approach similarly emphasizes important business services, tolerable disruption, dependency mapping, testing, and remediation.
Govern the service, not just the committee
For each critical CEF service, document:
- Service owner: The person accountable for performance and recovery.
- Maximum tolerable disruption: The point at which the service failure creates unacceptable financial, regulatory, or stakeholder harm.
- Decision rights: Who can pause, rerun, restore, approve an exception, or notify the board.
- Dependencies: Systems, vendors, people, data, bank relationships, and manual workarounds.
- Escalation path: The threshold and timing for management, committee, and full-board reporting.
- Evidence standard: The records required to demonstrate recovery, approval, and post-incident learning.
Apply that structure to ACH, investor statements, loan payments, construction draws, general-ledger close, and regulatory reporting. A committee may review the service, but a named owner must run it.
A small fund can begin with a focused operating review rather than a new committee. Use the internal controls framework to document the current process, identify the two or three largest decision-rights gaps, and assign owners.
A practical 90-day reset
Days 1 to 30: Inventory critical services, existing committees, policies, decision rights, and unresolved exceptions. Mark every place where two roles believe the other owns the decision.
Days 31 to 60: Fix the largest gaps. Assign service owners, define escalation thresholds, update policy language, and establish the minimum board evidence for each service.
Days 61 to 75: Install the reporting cadence. Start with a concise package covering portfolio health, investor obligations, liquidity, reconciliations, access, incidents, vendors, and open audit findings.
Days 76 to 90: Rehearse the model against a failed ACH file or delayed investor statement run. Record who acts, who approves, what evidence is produced, and what reaches the board.
A committee that can't improve those four outcomes is probably adding ceremony rather than control.
Frequently Asked Questions About CEF Governance Structure
What's the practical difference between a working board and a policy board?
A working board participates directly in operational or transaction decisions. A policy board focuses on strategy, risk appetite, executive oversight, and policy approval, then delegates execution to management and committees. A CEF can use either model, but it must define recusals, approval limits, and independent review where directors have relationships with borrowing churches or investors.
What minimum committee structure can a CEF defend?
Most funds need a clear full-board authority, a finance or audit function, and an independent path for risk and control challenge. One committee may cover several responsibilities if its charter, expertise, meeting cadence, and access to information are adequate. Adding committees won't compensate for missing owners, weak reconciliations, or unclear escalation.
How often should the governance structure be reviewed?
Review it whenever the fund adds a material product, changes a core system, enters a significant vendor relationship, changes denominational authority, or experiences a serious control failure. Management should also maintain current role assignments, policies, committee charters, and decision records so the board isn't relying on outdated documents.
What can a smaller CEF implement first?
Start with a service inventory, a RACI matrix, segregation of duties, monthly reconciliations, conflict-of-interest controls, a board reporting pack, and an incident escalation procedure. A small staff can combine roles, but it shouldn't combine incompatible duties without compensating review.
CEFCore provides a unified platform for loan management, investor notes, general ledger, cash and ACH operations, reporting, reconciliation, role-based access, maker-checker approvals, and immutable audit trails. Review CEFCore to see how those controls and reporting workflows can support a governance structure built around accountable services, reliable evidence, and responsible stewardship.
