Fundraising systems
2026-07-16
The decisions that come before a fundraising CRM is configured
An ACT audit found a government CRM that went largely unused despite likely spending above $1.46 million, and put its failure down to governance and unmade decisions rather than the technology. Nonprofit guidance points to the same decisions a fundraiser has to make before a CRM is configured.
In its Report No. 6 of 2024, the ACT Auditor-General examined the Public Trustee and Guardian's (PTG) technology renewal and the Microsoft Dynamics 365 customer relationship management (CRM) system at its centre. The audit concluded that the CRM "has been a failure". Four of the nine planned modules had gone live by June 2023, three of them used by one or two people each, and the audit found the system "not used widely across the organisation" and "currently irrelevant to most of the PTG's staff". Spending had likely exceeded $1.46 million between 2017 and 2023, and the audit found that "at no point in time did the PTG make a reasonable estimate of actual costs".
The audit's findings were about governance and planning, not the software. It recorded "limited governance, management and administrative arrangements". The programme, it found, "lacked detail on what success would look like, what the timeframe would be for this to occur and how it would be resourced". A foundational business case "did not address the fundamental question as to whether a CRM was actually necessary", and a later business case "was not clear on what was to be delivered and at what cost".
The PTG is a public trustee, not a fundraiser, and the audit examines one organisation. But a foundation configuring a fundraising CRM faces the same questions the audit found unanswered, whether the system is needed, what success looks like and what it will cost and deliver. The audit is a record of what a programme looks like when those questions are left open.
NonProfit PRO's guide to nonprofit CRM implementation identifies those decisions for a fundraising system. It says a rollout should be treated as a strategic business initiative rather than an IT project, and that before configuration or migration an organisation should anchor the project to its strategic objectives, define what success looks like, establish data ownership and cleanse its data. Blackbaud's change-management guidance adds that a CRM project plan should cover goals, measures, people management and an integrated workstream structure, not only integrations and go-live dates.
Infoxchange's 2025 report, covering 824 Australian and New Zealand organisations, records "data and reporting for evidence-based decision making" rising as a stated priority from 17% in 2023 to 37% in 2024 and 44% in 2025. Blackbaud's vendor-sponsored 2024 research found that 60% of more than 150 participants agreed improved data management would bring the greatest value to their organisation. In its global highlights, Blackbaud reported that only a handful of respondents described their technology stack as perfectly integrated.
In hospital fundraising, some of these decisions involve patient information. NORTH Foundation, describing US health philanthropy, documents grateful-patient programmes in which care teams recognise moments of gratitude, structured programmes support warm introductions and development teams receive limited patient information under opt-out models. The Office of the Australian Information Commissioner (OAIC) states that health information may be used or disclosed for the primary purpose for which it was collected, and that another purpose requires the patient's consent or one of the limited circumstances set out in privacy law. Its guidance for not-for-profits adds that personal information should only be retained as long as it is needed.
In December 2016 the UK Information Commissioner's Office fined the RSPCA £25,000 and the British Heart Foundation £18,000 over their fundraising data practices. It found that the RSPCA had "repeatedly wealth screened all seven million of its supporters" without their consent, and that both charities had traced supporters' missing contact details through third parties. The RSPCA had also disclosed more than one million supporters' records, including records of people who had opted out. The Commissioner, Elizabeth Denham, said donors "were not informed of these practices, and so were unable to consent or object". That was a UK enforcement action. In Australia, as the OAIC states, whether health information may be used for another purpose is a consent decision the organisation makes.
The audit located the CRM's failure in decisions the organisation had not made, including whether it needed the system at all, rather than in the technology. A fundraising organisation that configures a CRM before settling the same questions is in the same position, building the system ahead of the decisions that govern it.