How to Build an Effective Church Risk Management Team

Effective church risk management doesn’t require a massive staff or another complicated committee. It requires the right people, clear responsibilities, practical safeguards, and a consistent process for identifying and addressing risks before they become crises.

Most ministries don’t think much about risk management until something goes wrong.

A child is injured during an event. A volunteer is accused of misconduct. A severe storm damages the church building. An employment issue turns into a legal dispute. Or an emergency reveals that no one is quite sure who is responsible for making important decisions.

Risk management is not just an administrative exercise or an insurance issue— it is an act of stewardship that includes taking reasonable steps to identify vulnerabilities, reduce preventable risks, and prepare for the unexpected. 


Build a Safer, Better-Prepared Church

Good risk management starts before something goes wrong. Church Law & Tax Advantage Members get practical guidance, policy templates, checklists, training resources, and trusted legal and tax insights to help identify vulnerabilities and strengthen their churches.

Become an Advantage Member and put trusted risk-management resources to work for your church.


One of the best ways to make that work sustainable is to assign responsibility to a team instead of expecting one individual to manage every area of exposure.

Who Should Be Part of a Ministry Risk Management Team?

The strongest ministries bring together a small group of leaders with different perspectives and areas of expertise to help identify risks, evaluate priorities, and ensure important issues do not go unnoticed.

Most ministries benefit from a team, though the right size depends on the ministry’s scale and structure. A smaller congregation does not need to form a committee for its own sake. The same process works well with one named owner, an honest annual review with the board, and outside help brought in once a year. Depending on the ministry’s size and structure, the team may include:

  • A pastor or executive leader
  • A board representative
  • An administrative or HR leader
  • A facilities representative
  • A children’s or youth ministry leader
  • A finance representative
  • A local first responder with experience in law enforcement, fire services, emergency medical services, or emergency preparedness

The importance of the first responder

The first  responder role is one that many ministries overlook, yet it is often one of the most valuable seats at the table. 

Because these professionals have firsthand experience responding to real-world emergencies, they can help ministries identify risks that others may miss and evaluate whether existing plans will work under pressure.

For example, they may notice an exit blocked by stacked chairs, a building address that is difficult to see from the street, or an assembly area located in the path of arriving emergency vehicles. They can also provide insight into what responders need during the first few minutes of an incident and help determine whether an evacuation or emergency response plan is workable in practice rather than merely reasonable on paper.

Including someone with this background is one of the simplest and most effective ways to strengthen emergency preparedness and improve overall safety planning.

Many ministries also draw on outside partners, such as insurance professionals and legal counsel, who serve the team when a topic calls for their expertise without attending every meeting.


Stay Ahead of Risks Facing Your Church

Legal requirements change. New risks emerge. And yesterday’s policies may not protect your church tomorrow. Get practical guidance on risk management, child protection, cybersecurity, governance, tax, finance, and other issues affecting churches delivered straight to your inbox.

Sign up for our free weekly Church Law & Tax newsletter.


What Does a Ministry Risk Management Team Do?

Creating a team is only the first step. To be effective, team members need a shared understanding of what ministry risk management involves. While every ministry faces different challenges, healthy organizations tend to follow four basic steps when managing risk.

1. Identify Potential Risks

When people hear the term “risk management,” they often think about catastrophic events, such as natural disasters, serious injuries from accidents, or lawsuits. In reality, many ministry challenges begin with everyday activities, such as volunteer supervision, facility use, transportation programs, or child protection procedures that have become so familiar they no longer attract much attention.

One helpful question for leadership teams is: What could realistically disrupt our ministry, harm the people we serve, or damage the trust we’ve worked so hard to build? That question often reveals risks that have been overlooked for years.

2. Assess the Potential Impact

Once risks have been identified, leaders must determine which issues deserve the most attention.

Not every risk presents the same level of exposure. Some concerns are unlikely to occur and pose limited consequences. Others may be less likely but could have devastating financial, legal, operational, or reputational effects.

It helps to ask a few questions:

  • How likely is this?
  • Who would be affected?
  • What would it cost?
  • Could it interrupt ministry?
  • Do we have safeguards in place today?

Ministries with effective risk management focus their time and resources on the areas with the greatest potential impact before moving on to lower-priority concerns.

3. Implement Safeguards and Controls

This is where risk management moves from awareness to action.

Once exposures are understood, ministries can take steps to reduce either the likelihood of a problem occurring or the severity of its impact.

The most effective safeguards are often the simplest and most repeatable:

Each safeguard may seem small on its own, but together they create layers of protection that help ministries operate with greater confidence and consistency.

4. Review and Improve Regularly

Perhaps the most overlooked aspect of risk management is ongoing review.

Ministries are constantly evolving. New staff members join the team, programs grow, regulations change, facilities age, technology advances, and community expectations shift. 

As a result, a policy or procedure that worked five years ago may no longer reflect current ministry operations. Rather than waiting for a problem to force change, the risk management team should build regular reviews of common risk areas into its annual planning.

How Ministries Use a Risk Management Team

The purpose of the team is not to create another committee. Its role is to provide accountability and ownership. In many ministries, the team serves as a resource to leadership by helping identify risks related to people, property, programs, and operations.

It may review incidents and near misses, evaluate safety and child protection practices, assess facility concerns, support emergency preparedness efforts, and recommend practical improvements.

For the team to be effective, leadership should establish three things:

  • Authority: What decisions can the team make independently, and what should be escalated to senior leadership or the board?
  • Rhythm: How often will the team meet, review policies, inspect facilities, evaluate incidents, and report back to leadership?
  • Scope: Which areas of ministry will the team review? The five areas below offer a practical starting point.

Five Risk Areas Every Ministry Should Evaluate

Every ministry is different, but a handful of areas consistently create significant exposure. These five areas provide a practical starting point for evaluating a  ministry’s overall risk profile.

1. Child Protection and Reporting

Few responsibilities are more important than protecting children.

Ministries often devote tremendous energy to creating welcoming environments for families. But hospitality alone is not enough. Effective child protection depends on documented systems that create consistency, accountability, and transparency.

Strong child protection systems help protect children from harm while also demonstrating that ministry leaders have exercised appropriate care and diligence in fulfilling their responsibilities.

In California, for example, AB 506 brought background screening and abuse prevention training expectations to many youth-serving organizations, and similar requirements have appeared in other states with meaningful variation between them. Church leaders should consult with qualified local legal counsel to determine what applies where they serve. Regardless of location, the principle remains the same: ministries have a responsibility to create environments that are safe, accountable, and worthy of the trust families place in them.

2. People and Volunteer Readiness

People are the ministry’s greatest asset. They are also an area where many risks originate when expectations, training, and accountability are unclear.

Every ministry should regularly evaluate its approach to volunteer screening, background checks, staff onboarding, leadership accountability, and ongoing supervision.

A lack of training, inconsistent supervision, or unclear boundaries can create vulnerabilities that are often difficult to address after the fact.

3. Programs and Activities

Ministries are active environments. Camps, retreats, mission trips, youth events, community outreach programs, transportation services, and special events all create opportunities for impact.

They also introduce unique operational risks. Before activities occur, leaders should consider questions such as:

  • Have responsibilities been clearly assigned?
  • Have volunteers been properly trained?
  • Are emergency procedures documented and communicated?
  • Do we have a crisis response plan?
  • Have transportation risks been evaluated?
  • Are drivers properly screened?

Taking time to evaluate these questions before an event often prevents problems that are far more difficult to address later.

4. Compliance and Governance

Leaders often place compliance in the “legal” category, but compliance is really a leadership responsibility.

Most compliance failures do not result from intentional wrongdoing. They occur because policies become outdated, responsibilities become unclear, or leaders are unaware that requirements have changed.

Strong governance helps prevent those gaps. Boards and leadership teams should regularly review policies, evaluate responsibilities, discuss emerging risks, and ensure accountability systems are functioning properly.

5. Coverage and Operational Alignment

One of the most common challenges ministries face is that their operations evolve faster than their insurance program.

New programs are launched, facilities gain additional use, counseling ministries expand, transportation activities increase, and staffing changes occur.

Yet many ministries rarely revisit whether their protection strategies still reflect those realities. Periodic reviews help ensure coverage remains aligned with ministry operations and that leadership understands both existing protections and potential gaps.

Final Thoughts

Effective risk management isn’t about predicting every possible problem; it is about building a ministry that’s prepared to respond wisely when challenges arise. The ministries with strong risk management are not necessarily the largest or best resourced. They are simply more intentional.

They build systems instead of relying on specific individuals. They document key responsibilities so important knowledge does not get lost when people leave. They train consistently, reinforce expectations over time, address concerns before they become larger problems, and regularly revisit their practices because they understand risk management as an ongoing part of faithful leadership.

Ultimately, risk management is not about eliminating every possible problem. It is about leaders stewarding the people, resources, and mission God has entrusted to their care. The goal is not perfection, but progress. Start by identifying one area that needs attention, then bring together the right people to help lead the conversation. Small, intentional steps taken today can strengthen ministry and help prevent significant challenges tomorrow.

Charlie Cutler is President of ChurchWest, a California-based firm that specializes in insurance advisory and risk management for some of the nation's leading churches.

Year-End Church Payroll and Tax Planning: 3 Steps to Take Before January

Before closing the books on another year, churches should review clergy housing allowances, compensation decisions, and taxable fringe benefits.

Effective year-end church payroll and tax planning should address three key areas: clergy housing allowances, compensation decisions, and taxable fringe benefits.

Key takeaways:

  • Designate clergy housing allowances before payments are made.
  • Review compensation changes before next year’s payroll begins.
  • Identify taxable fringe benefits that should be treated as wages.
  • Document compensation and housing decisions appropriately.
  • Don’t wait until W-2 preparation to discover payroll problems.


Put trusted church tax guidance at your fingertips

Church Law & Tax Advantage Members get trusted guidance designed specifically for the legal and tax questions that churches face, including the online Church & Clergy Tax Guide and the annual Tax Prep Guide for Churches & Clergy.


Churches should review housing allowance designations, employee compensation, and taxable fringe benefits before year-end. Doing so can maximize benefits for clergy, prevent payroll mistakes, and put the church in a stronger position when the new year begins.

1. Plan next year’s clergy housing allowances now

Bottom line: Ministers who live in a church-provided parsonage can exclude from their income for federal income tax reporting purposes (1) the fair rental value of the parsonage, and (2) the portion of their compensation designated in advance by the church as a “parsonage allowance” to the extent it covers housing expenses and does not exceed the fair rental value of the residence (furnished, plus utilities). 

Separately, ministers who own or rent their own homes can have a portion of their compensation designated in advance by the church as a “housing allowance.” It is not subject to income tax to the extent it is used for housing expenses and does not exceed the home’s annual fair rental value (furnished, plus utilities).  

A church must officially designate a minister’s housing or parsonage allowance before any payment is made. To fully maximize the benefit for the full calendar year, a church should work with its minister to designate an allowance before January 1. 

A church can still set an allowance after that point, however, it only works prospectively. This means the church cannot retroactively designate previous compensation as a housing allowance and the minister misses out on maximizing the benefit for the entire year.

As such, the end of the year is an ideal time to review and set allowances for eligible ministers.

The IRS says the employing church or organization must officially designate a definite amount as housing allowance before making any payment. The designation can appear in an employment contract, church minutes, a budget, or another official action. 

With an official designation, church leaders are encouraged to include “safety net” language that can ensure a housing allowance that takes effect in one year remains in effect the following year in the event a new designation is inadvertently overlooked. However, such “safety net” language should not be used in lieu of an annual designation, since numerous circumstances–including projected expenses–will change.


Get a sample housing allowance designation for 2027 when you become a Church Law & Tax Advantage Member. 


Don’t forget self-employment tax with allowances

There is another important detail to note.

The Section 107 housing allowance exclusion applies to federal income tax. Generally, it does not remove the housing allowance from a minister’s net earnings when calculating self-employment tax. 

That distinction can surprise ministers who assume “tax-free” means exempt from all federal taxes.

Year-end housing allowance checklist

2. Review compensation adjustments before year-end

Bottom line: Year-end is a natural time for churches to review salaries, bonuses, allowances, and other compensation. Changes should be properly approved, documented, and communicated to payroll.

Compensation planning involves more than deciding whether someone gets a raise.

Church leaders should look at the employee’s total compensation package.

That may include:

  • Salary;
  • Bonuses;
  • Housing allowance for qualifying ministers;
  • Employer retirement contributions;
  • Health benefits;
  • Expense reimbursements;
  • Automobile benefits;
  • Other allowances; and
  • Other taxable or nontaxable benefits.

For tax purposes, wages generally include salaries, bonuses, commissions, vacation allowances, and taxable fringe benefits. 

Therefore, churches should not assume every payment outside an employee’s regular salary receives different tax treatment.


Stay current on tax developments, legal decisions, finance issues, and other changes affecting churches with our free weekly newsletter.


Pay particular attention to bonuses

A Christmas or year-end bonus is compensation, not a tax-free gift.

Churches should make sure payroll properly handles year-end bonuses rather than treating them as informal gifts.

Look ahead, not just backward

Year-end church payroll and tax planning should also prepare the church for the coming year.

Ask:

  • Are salary changes approved?
  • Are those changes reflected in the upcoming budget?
  • Are new benefits being introduced?
  • Are reimbursements being handled through an accountable reimbursement arrangement?
  • Does payroll have the information needed to implement changes correctly?

In addition, churches should document compensation decisions through the appropriate governing body or process.


Get help making compensation decisions

ChurchSalary.com offers nationwide data, pay analysis, and customized insights for all types of church positions.


3. Identify taxable fringe benefits before W-2 preparation

Bottom line: Some benefits churches provide employees are taxable compensation. Identifying them before year-end gives the church time to properly value and report them.

This is one of the easiest areas to overlook.

Churches sometimes provide employees with benefits outside normal payroll. However, paying for something directly does not automatically make it tax-free.

Under Internal Revenue Code Section 61, gross income generally includes compensation for services, including fringe benefits, unless another provision provides an exclusion.

IRS Publication 15 likewise states that employers generally must include taxable fringe benefits in an employee’s wages. 

Potential issues can include:

  • Personal use of a church-owned vehicle;
  • Certain club memberships;
  • Personal expenses paid by the church;
  • Expense reimbursements that don’t satisfy accountable reimbursement arrangement requirements;
  • Certain employer-provided lodging;
  • Tickets to entertainment or sporting events; and
  • Other benefits primarily benefiting the employee personally.

However, many legitimate benefits can qualify for exclusions.

For example, qualifying working condition fringe benefits, certain de minimis fringe benefits, and some other benefits can be excluded when IRS requirements are satisfied.

That is why the correct question isn’t simply, “Did we give employees any perks?”

Instead, ask: Did we provide anything of value to an employee that hasn’t already been reviewed for tax treatment?

Don’t wait until January

The timing rules make this review especially important.

Employers generally must determine the value of fringe benefits no later than January 31 of the following year. Before then, they may reasonably estimate their value for timely withholding and deposits. 

IRS Publication 15-B, Employer’s Tax Guide to Fringe Benefits, provides detailed guidance on these rules. The IRS issued the current 2026 edition specifically for benefits provided during 2026. 

A simple year-end church payroll checklist

Before closing out the year, church finance leaders should ask:

ReviewWhat to verify
Housing allowanceHas next year’s allowances been formally designated before payment?
CompensationHave salary and compensation changes been approved and documented?
BonusesWill year-end bonuses be processed correctly through payroll?
ReimbursementsAre reimbursements being handled correctly under the church’s plan?
Fringe benefitsHas the church identified benefits that may constitute taxable compensation?
VehiclesHas personal use of church-owned vehicles been reviewed?
PayrollDoes payroll have everything needed for accurate reporting?
RecordsAre board resolutions, minutes, and other compensation records complete?

A short review now can prevent a much more difficult cleanup later.

Frequently asked questions about year-end church payroll and tax planning

When should a church approve next year’s clergy housing allowances?

The church must officially designate parsonage and housing allowances before payments are made. Therefore, churches commonly address the coming year’s designation during year-end budgeting and compensation planning. 

Can a church retroactively designate a pastor’s housing allowance?

No. IRS Publication 517 states that the employer must designate the payment before making it and cannot determine the housing allowance amount later. 

Is a Christmas bonus to a church employee taxable?

Yes. Bonuses are taxable wages for federal employment tax purposes. 

Are all fringe benefits provided by a church taxable?

No. Some benefits qualify for specific exclusions. However, taxable fringe benefits generally must be included in wages. Churches should evaluate each benefit under the applicable IRS rules rather than assuming a benefit is tax-free. 

Get year-end church tax decisions right

Year-end is more than a bookkeeping deadline. Church leaders can use this time to designate next year’s housing allowances, make deliberate compensation decisions, and identify taxable fringe benefits before they create payroll problems. A coordinated review by church leadership, payroll personnel, and qualified tax professionals can help the church enter the new year with cleaner records and fewer surprises.


Editor’s Note: This content was created using a combination of AI and human review.

AI Policy for Churches: What’s New in Version 2.0

The updated Artificial Intelligence Use in the Church Workplace Policy Template helps churches address agentic AI, sensitive data, employment decisions, deepfakes, cybersecurity, and other emerging AI risks.

Churches are no longer dealing only with employees opening ChatGPT to draft an email or brainstorm ideas. AI is increasingly embedded in software churches already use, while newer agentic AI tools can connect to systems, access information, automate workflows, and take actions with limited human intervention. 

At the same time, churches must consider how AI may affect sensitive and confidential information, employment decisions, cybersecurity, copyright, meeting transcription, records retention, and even fraud attempts involving AI-generated voices, images, or video.

That’s why Church Law & Tax and Gloo have released Version 2.0 of the Artificial Intelligence Use in the Church Workplace Policy Template.


Church Law & Tax Advantage Members: Access Version 2.0 now.

Not a member? Complete this
brief form to get free access.


What’s new in the 2.0 AI policy template?

The first template provided churches with a framework for approving AI tools, establishing acceptable and unacceptable uses, protecting confidential information, maintaining human oversight, training personnel, and regularly reviewing AI practices.

Version 2.0 goes even further. Among other updates, it:

  • Expands the policy to cover embedded AI features and agentic AI, not just standalone generative AI tools.
  • Establishes a more robust AI tool and provider risk-review process, including data retention, subprocessors, integrations, access controls, security safeguards, and incident notification. 
  • Introduces “Protected Data Terms” for AI tools that may handle sensitive or confidential church information.
  • Adds safeguards for AI recording, transcription, summarization, and note-taking involving pastoral care, counseling, personnel matters, children and youth, legal matters, and other sensitive communications. 
  • Broadens protections involving AI-assisted hiring, compensation, promotion, performance evaluation, discipline, termination, and other employment decisions. 
  • Addresses AI-generated impersonation, deepfakes, and fraud, including independent verification of unusual requests involving payments, credentials, data transfers, or account changes.
  • Requires additional safeguards when AI agents and automated workflows can access church systems or take consequential actions. 
  • Strengthens procedures for AI-related security incidents, records retention, training, and ongoing policy review. 

Does your church need an AI policy—or an update?

You don’t need to know the answer before getting started.

Take Church Law & Tax’s free 2-Minute check-up to evaluate how your church is using AI, where potential gaps may exist, and whether your existing AI policy needs attention.

  • Already have an AI policy? Use the check-up to see whether it still addresses today’s AI tools and risks.
  • Don’t have an AI policy? The check-up can help identify ways AI may already be used in your church workplace—even if your church has never formally adopted an AI tool.

AI will continue to change. The goal isn’t to predict every new tool. It’s to give church leaders a practical framework for responsible AI use, human oversight, sensitive-data protection, and ongoing review as the technology—and the legal landscape surrounding it—continues to evolve.

The editorial team of Church Law & Tax is made up of Matthew Branaugh, attorney-at-law, and Rick Spruill, digital content manager.

Clergy Act Would Let Ministers Opt Back Into Social Security

The Clergy Act would create a rare two-year window for eligible ministers to reverse a previous Social Security exemption. Here’s what clergy need to know about the 2029–2030 opt-in period, Social Security credits, retirement benefits, and what happens next.

The U.S. Senate unanimously passed the Clergy Act on September 30, following House passage earlier this year. It now goes to President Trump for his signature.

If signed into law, the Clergy Act will create a temporary, two-year window for eligible clergy to re-enter Social Security during tax years 2029 and 2030.

Why the Clergy Act matters

Under current law, qualifying ministers may opt out of Social Security coverage for their ministerial earnings based on religious opposition to accepting certain public insurance benefits.

But that decision is generally irrevocable. A minister who later changes his or her mind cannot simply elect to participate again.

The Clergy Act would provide a temporary exception.

Clergy who use the new opt-in window will begin paying Social Security taxes on their ministerial earnings. Consistent with current eligibility requirements, they generally will need to earn 40 Social Security credits—typically requiring about 10 years of covered work—to qualify for Social Security retirement benefits.

Congress has provided similar opportunities for clergy to re-enter Social Security in the past, including in 1977, 1986, and 1999.


Advantage Members: Go deeper on Social Security for ministers in Chapter 10 of the online Church & Clergy Tax Guide. 


What happens next?

The law  also directs the IRS, in consultation with the Social Security Administration, to develop a plan for informing eligible clergy about the opportunity to opt back in.

Within 90 days after enactment, the IRS must submit that plan to the House Ways and Means Committee and Senate Finance Committee. The IRS also will develop the forms clergy will use to revoke their previous exemptions.

The Clergy Act resulted from several years of work by the Church Alliance, which advocates on benefits issues for 35 denominational benefit organizations representing a broad range of Judeo-Christian faith traditions.

The bipartisan legislation was led by Reps. Vince Fong (R-Calif.) and Mike Thompson (D-Calif.) in the House and Sens. Katie Britt (R-Ala.) and Maggie Hassan (D-N.H.) in the Senate.

For ministers who previously opted out of Social Security, the key dates to remember are 2029 and 2030.

What This Means for Ministers

The IRS and Social Security Administration are expected to provide additional guidance explaining how eligible ministers can opt back into Social Security under the Clergy Act.

Meanwhile, ministers should understand several key points addressed below.

When can ministers opt back into Social Security?

Eligible ministers will need to make the election during the 2029 or 2030 tax years.

The deadline is expected to run through the due date for the 2030 federal income tax return, including extensions.

Additional IRS and Social Security guidance should clarify:

  • What form ministers must file.
  • Whether the opt-in election requires formal approval.
  • Whether simply filing the required opt-in election will establish participation.

How many Social Security credits will ministers need?

Ministers generally will need 40 Social Security credits, often described as 40 quarters of covered work, to qualify for Social Security retirement benefits.

That is typically the equivalent of about 10 years of covered employment.

Importantly, prior non-ministerial work may count toward those 40 credits.

Examples may include:

  • Jobs held during high school or college.
  • Non-ministerial employment (such as jobs held while attending seminary or working bivocationally in ministry).
  • Other jobs for which FICA taxes were paid.

A minister who already has Social Security credits from earlier employment may therefore need fewer additional years of covered work after opting back in.

When can retirement benefits begin?

Qualifying for Social Security retirement benefits and reaching retirement age are separate requirements.

Generally:

  • Reduced retirement benefits may begin as early as age 62.
  • Full retirement benefits generally begin at a minister’s full retirement age, currently between ages 66 and 67 depending on birth year.
  • Delaying benefits beyond full retirement age can increase monthly benefits, up to age 70.

How do Social Security disability benefits differ?

Social Security Disability Insurance, or SSDI, uses different credit requirements.

Eligibility depends partly on age and how recently the credits were earned.

In general:

  • Age 31 or older: Usually 40 credits are required, with 20 earned during the 10 years before disability begins.
  • Age 24 to 31: The minister generally needs credits covering about half the time between age 21 and the onset of disability.
  • Under age 24: Generally 6 credits earned during the three years before disability begins are required.

Because SSDI rules are more complex, ministers considering the Clergy Act opt-in should review their individual Social Security earnings record.

How will Social Security retirement benefits be calculated?

Social Security retirement benefits are based on a worker’s lifetime covered earnings.

The Social Security Administration generally:

  • Adjusts prior earnings to account for changes in average wages.
  • Uses the worker’s 35 highest years of indexed earnings.
  • Applies a formula to determine the monthly retirement benefit.

For ministers, an important point is that qualifying clergy housing allowance generally remains included in net earnings from self-employment for Social Security purposes, even though it is excluded from federal income tax.

What should ministers do now?

Ministers who previously opted out of Social Security should begin gathering information about their existing Social Security credits and earnings history.

They should also watch for forthcoming guidance from the IRS and Social Security Administration explaining exactly how the opt-in window will work for the 2029 and 2030 tax years.


Church Law & Tax will continue monitoring the Clergy Act, including the President’s action on the bill and forthcoming IRS guidance about how eligible clergy can opt back into Social Security.

G. Daniel (Danny) Miller is of counsel with McAfee & Taft.

Is your church using AI safely? Download our 2-minute check-up

Answer 10 practical questions to uncover potential gaps in how your church’s pastors, employees, contractors, and volunteers use AI—and where stronger safeguards may be needed.

AI has transformed the way people work, and churches are no exception. From writing and meeting transcription to HR, communications, finance, and administration, AI now plays a growing role in everyday church operations.

But AI use in churches can also create privacy, confidentiality, employment, copyright, and cybersecurity risks when clear safeguards aren’t in place.


Stay ahead of emerging risks. Sign up for Church Law & Tax newsletters for practical guidance on AI, cybersecurity, tax, legal, finance, and other issues affecting churches.


This free 2-Minute Church AI Use Check-Up helps church leaders quickly identify potential gaps in how pastors, employees, contractors, and volunteers use AI tools. It covers 10 practical questions involving approved AI tools, personal accounts, sensitive church information, human review, higher-risk uses, training, and oversight. Church Law & Tax AI Workplace 2… Church Law & Tax AI Workplace 2…

Download and take our 2-minute AI check-up now: 

Then compare your results with Church Law & Tax’s AI Use in the Church Workplace Policy Template. This product, designed especially for Advantage Members, will help your church establish safeguards, clarify responsibilities, train personnel, and create a regular review process.

Do you know other church leaders who could use this check-up? Share it with them today!

Matthew Branaugh is an attorney and editor for Church Law & Tax.

Church Cybersecurity Risks: 6 Trends Leaders Need to Watch

AI-powered scams, vulnerable software, third-party vendors, and sensitive data are changing the cybersecurity landscape for churches. Here’s what leaders should watch.

Church cybersecurity risks extend far beyond suspicious emails. AI, human error, vulnerable software, data privacy, vendors, and insurance are changing the threat landscape.

And, while cybersecurity can sound like an IT problem, it is increasingly a financial, legal, operational, and governance issue for churches.

Key takeaways:

  • AI is making fraudulent communications harder to recognize.
  • Software vulnerabilities are becoming a bigger entry point for attackers.
  • Staff members remain an important line of defense.
  • Churches hold sensitive information that needs protection.
  • Third-party vendors can create additional cybersecurity exposure.
  • Cyberliability insurance should complement—not replace—strong cybersecurity practices.

What are the biggest cybersecurity risks churches should watch? Church leaders should pay particular attention to AI-enhanced fraud, phishing and social engineering, software vulnerabilities, sensitive data, third-party vendors, and the financial consequences of cyber incidents.


Protect your church with guidance for churches

Cybersecurity is only one of the legal, financial, tax, and risk-management challenges church leaders face.

Church Law & Tax members get deeper access to trusted guidance from attorneys, CPAs, risk-management professionals, and church technology experts.


1. AI is changing church cybersecurity risks

Bottom line: Artificial intelligence can make cyberattacks faster and more convincing. Churches should no longer assume obvious spelling errors or strange wording will expose a fraudulent message.

For years, spotting phishing emails sometimes meant looking for obvious mistakes, but that method is becoming less reliable.

Generative AI can help attackers produce polished emails, text messages, and other communications. Moreover, attackers can imitate familiar communication styles and create convincing requests.

Church IT consultant Jonathan Smith, a Church Law & Tax editorial advisor, warns that AI has made low-tech attacks appear increasingly credible.

In Why 2FA Matters More than Ever in the Age of AI, Smith recommends using two-factor authentication (2FA) or multifactor authentication (MFA) wherever possible.

The federal government’s guidance is similar. 

The Cybersecurity and Infrastructure Security Agency’s (CISA) Secure Our World initiative recommends four foundational practices: recognize phishing, use strong passwords, turn on MFA, and update software. For churches, MFA is particularly important for accounts involving:

  • Email;
  • Online banking;
  • Giving platforms;
  • Payroll;
  • Church management systems;
  • Cloud storage;
  • Social media; and
  • Website administration.

However, MFA isn’t foolproof. Staff members must understand that an unexpected authentication request can itself be a warning.

Go deeper: Why 2FA Matters More than Ever in the Age of AI

Bottom line: Cybersecurity isn’t only about firewalls and software. A church employee who clicks the wrong link or approves the wrong transaction can bypass strong technical safeguards.

A pastor emails the finance office asking for an urgent payment.

A vendor suddenly changes its banking information.

A staff member receives a text requesting gift cards.

These situations may look routine and it’s why they can be so risky.

Church Law & Tax has examined scams involving churches where attackers used normal human behavior, rather than sophisticated computer hacking.

As Hacking a Church Is About Exploiting Its Weakest Link explains, generative AI can make these attempts even harder to identify. 

Therefore, churches need controls around high-risk actions.

For example:

  • Independently verify requests to change banking information, ideally by initiating a live conversation or through a separate communication channel with the requesting person.
  • Require additional approval for large transfers.
  • Never send passwords or authentication codes by email.
  • Train employees to challenge unusual requests.
  • Create a clear process for reporting suspicious communications.

The Federal Trade Commission (FTC) also recommends regular employee training and phishing simulations. In addition, organizations should give employees a simple way to report suspicious messages. 

Technology matters. However, so does the person sitting at the keyboard.

Go deeper: Hacking a Church Is About Exploiting Its Weakest Link

3. Your church needs a human firewall

Bottom line: Staff training should be an ongoing part of church cybersecurity. Employees should know how attackers operate and what to do when something doesn’t look right.

One cybersecurity seminar isn’t enough—threats change and church volunteers often have access to the same systems that employees have–but without the same training

Churches should create what cybersecurity professionals sometimes call a human firewall.

That means building habits that make people part of the church’s cybersecurity defenses.

Church Law & Tax has documented how attackers can learn the rhythms of a church and use those routines against employees.

For instance, a fraudulent request appearing to come from a pastor can arrive shortly before a worship service—when staff members are busy and less likely to stop and verify it.

Training should address:

  • Phishing emails;
  • Fraudulent text messages;
  • Unexpected MFA requests;
  • Gift card scams;
  • Payment-change requests;
  • Password security;
  • Suspicious attachments; and
  • Reporting procedures.

Most importantly, employees should feel comfortable slowing down a transaction.

A five-minute verification can be far less costly than recovering from fraud.

Go deeper: Church Cybersecurity Starts With the Human Firewall


Stay ahead of risks affecting your church

Cyber threats, laws, tax rules, and church management practices continue to change.

Get practical Church Law & Tax guidance delivered directly to your inbox with our free weekly newsletters.


4. Attackers are increasingly exploiting vulnerable technology

Bottom line: Training alone won’t protect a church. Software updates, access controls, backups, and basic technology management have become equally important.

One significant trend deserves church leaders’ attention.

Verizon’s 2026 Data Breach Investigations Report  (DBIR) found that 31 percent of breaches began with exploitation of software vulnerabilities. For the first time in the report’s 19-year history, that surpassed stolen credentials as the leading breach entry point. 

In other words, the person using the computer isn’t always the vulnerability.

Sometimes the computer is.

AI is also helping attackers find and exploit weaknesses faster, according to Verizon’s analysis. 

Consequently, churches should regularly:

  • Install security updates and patches;
  • Replace unsupported software;
  • Back up critical information;
  • Restrict administrator privileges;
  • Remove accounts belonging to former employees;
  • Review who can access sensitive systems; and
  • Inventory important hardware, software, and cloud services.

The FTC likewise recommends regularly updating security software, encrypting sensitive data, controlling access, and maintaining backups. 

Churches needing a broader framework can also use the NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide. NIST specifically says the resource can assist smaller organizations, including nonprofits. 

Go deeper: Is Your Data Security Up to Speed? A Checklist for Churches

5. Sensitive church data creates privacy and liability concerns

Bottom line: Churches collect more sensitive information than leaders sometimes realize. Protecting that information requires knowing what the church has, where it is stored, and who can access it.

Think about the information flowing through a typical church.

It may include:

  • Donor names and giving histories;
  • Employee Social Security numbers;
  • Payroll information;
  • Background-check information;
  • Children’s ministry records;
  • Member contact information;
  • Counseling information;
  • Prayer requests; and
  • Bank and payment information.

That information can create risk even without a sophisticated cyberattack.

For instance, something as routine as publishing a prayer request can raise privacy concerns.

Attorney and CPA Richard Hammar notes that churches can reduce the risk associated with public prayer lists by obtaining consent before identifying individuals and their needs online. Express consent is stronger than assuming consent because someone didn’t opt out. Cybersecurity and privacy, therefore, increasingly overlap.

Churches should ask:

Do we need this information?

Where are we storing it?

Who has access to it?

How long are we keeping it?

What happens if someone obtains it?

Those questions also matter after a breach.

The FTC notes that every state, the District of Columbia, Puerto Rico, and the Virgin Islands have laws addressing notification following certain security breaches involving personal information. Specific obligations depend on the information involved and applicable law. 

Therefore, churches experiencing a data breach should promptly consult qualified legal and cybersecurity professionals about their response and notification obligations.

Go deeper: Are Public Prayer Lists an Invasion of Privacy?

6. Third-party vendors are part of your cybersecurity perimeter

Bottom line: Outsourcing technology doesn’t outsource risk. Churches should understand how vendors access, store, and protect church information.

Churches depend heavily on outside platforms.

Giving processors, payroll providers, accounting systems, church management platforms, email providers, background-check companies, cloud storage services, and other vendors may possess church information.

That creates another potential entry point.

The 2026 Verizon DBIR found third-party involvement in breaches increased substantially. Verizon reported that breaches involving third parties accounted for 48 percent of breaches in its dataset. 

That doesn’t mean churches should abandon cloud services. But it does mean vendor selection becomes a very important part of a church cybersecurity plan.

Before granting a vendor access to church systems or sensitive information, consider asking:

  • Does the vendor require MFA?
  • How does it encrypt sensitive information?
  • Who can access the church’s data?
  • Does it use subcontractors?
  • How does it respond to a breach?
  • How quickly will it notify the church?
  • What protocols will the vendor follow to comply with notify federal and state authorities?
  • What happens to church data when the relationship ends?

The FTC recommends including security requirements in vendor contracts and limiting vendor access to only the information needed to perform the work. 

7. Cyberliability insurance is becoming part of risk management

Bottom line: A general liability policy should not be assumed to cover cyber incidents. Churches should review available cyberliability coverage and understand exclusions, limits, and conditions.

Even strong cybersecurity cannot eliminate every threat, which is why cyberliability insurance should be considered..

Cyber coverage can address expenses that traditional insurance may not cover.

Depending on the policy, first-party coverage can potentially address costs involving:

  • Data recovery;
  • Forensic investigations;
  • Business interruption;
  • Required notifications;
  • Crisis management;
  • Cyberextortion; and
  • Fraud.

Third-party coverage can potentially address liability arising from claims made by others after an incident. 

However, policies differ considerably.

Church Law & Tax’s review of cyberliability insurance also cautions churches against assuming their general liability policy covers cyber-related claims. Coverage limits, exclusions, premiums, and policy requirements all deserve careful attention. 

Before purchasing or renewing coverage, ask the church’s insurance professional:

  • What cyber events are covered?
  • What exclusions apply?
  • What are the coverage limits?
  • Is ransomware covered?
  • Does coverage include data recovery?
  • Are notification expenses covered?
  • Does the policy provide access to cybersecurity or legal professionals after an incident?
  • What cybersecurity controls must the church maintain for coverage to apply?

Insurance transfers some financial risk. It doesn’t replace prevention.

Go deeper: Navigating Cyberliability Insurance

A church cybersecurity checklist

Church leaders don’t need to become cybersecurity engineers. However, they should know whether fundamental safeguards are in place.

Risk areaQuestion church leaders should ask
MFADo all critical systems support and require multifactor authentication?
StaffDo employees know how to recognize and report suspicious requests?
SoftwareAre systems patched and updated promptly?
AccessCan only necessary people access sensitive information?
DataDo we know what sensitive information we collect and where it is stored?
BackupsCan critical systems and data be restored after an attack?
VendorsHave we reviewed the security practices of key providers?
PaymentsDo financial transactions require appropriate verification and approval?
ResponseDo we know who to contact immediately after a suspected breach?
InsuranceDo we understand what our policies do—and don’t—cover?

Cybersecurity doesn’t have to begin with an expensive new technology platform.

Start by identifying the church’s most important information and systems. Then determine what would happen if those systems became unavailable or that information was stolen.

From there, prioritize the biggest risks.

Frequently asked questions about church cybersecurity risks

What are the biggest cybersecurity risks facing churches?

Churches face risks from phishing, social engineering, compromised credentials, software vulnerabilities, ransomware, data breaches, and third-party vendors. AI is also helping attackers create more convincing scams and accelerate some attacks. 

Should churches require multifactor authentication?

MFA is one of the foundational cybersecurity practices recommended by both CISA and the FTC. Churches should strongly consider requiring it for systems containing financial, personal, administrative, or other sensitive information. 

Does a church need cyberliability insurance?

A church should evaluate its specific cyber risks with a knowledgeable insurance professional. General liability insurance should not automatically be assumed to cover cyber incidents, and cyber policies vary in their coverage, exclusions, and limits. 

What should a church do first to improve cybersecurity?

Start with the fundamentals. Identify critical systems and sensitive data, require MFA, update software, use strong unique passwords, maintain backups, train staff, review vendor access, and establish an incident-response plan. The NIST Cybersecurity Framework provides a structured approach built around Govern, Identify, Protect, Detect, Respond, and Recover. 

Make cybersecurity part of church risk management

Church cybersecurity risks are changing, but the fundamentals remain remarkably consistent. Protect accounts, update technology, train people, safeguard sensitive information, evaluate vendors, prepare for incidents, and understand your insurance. Most importantly, church boards and leaders should treat cybersecurity as an organizational risk—not simply something delegated to the person who manages the computers.

This resource was created with a combination of AI and human review.

The editorial team of Church Law & Tax is made up of Matthew Branaugh, attorney-at-law, and Rick Spruill, digital content manager.

3 Important Questions Every Church Should Ask About Risk and Compliance

Strong church risk management starts with asking the right questions. Evaluate your church’s governance, financial controls, employment practices, and compliance safeguards to identify vulnerabilities before they become costly problems.

Important Question 1:
How can your church reduce risk, strengthen governance, and protect your tax-exempt status? 

There are multiple things that can be done for each of these areas such as performing a risk assessment and providing governance training for your board. Think about each of these areas and consider 1) what you need to improve and have the resources to do so, 2) what you need to improve, but don’t know where to start, and 3) what areas you don’t know if they are a problem or not. Usinh the Annual Church Legal Checklist may be a good place to start.

Important Question 2:
Where are churches most susceptible to fraud and is your church protected? 

Thinking that you trust your staff and not going further than that is a big red flag. You must still have good internal controls in place involving more than one person in each process. The most likely places for problems are donations that never get counted and deposited, inappropriate expense reports, and payroll fraud. Church Law & Tax  has resources available from simple checklists to training for all levels within your church. Check out this resource.


Protect your church with trusted guidance.

From governance and fraud prevention to employment practices and tax compliance, church leaders face decisions that carry real legal and financial consequences. A Church Law & Tax membership gives you practical checklists, expert guidance, training, and in-depth resources to help you identify risks and take action with confidence.

Become a member today and give your church the tools it needs to stay compliant, financially sound, and prepared.


Important Question 3:
What employment practices do you have in place to meet the breadth of requirements that apply to your church? 

Just because it is easier to pay someone as an independent contractor or as a salaried employee instead of an hourly employee, does not mean it will be compliant with state and federal laws. Documentation is also key from performance reviews to employee files. Review Do We Follow Sound Employment Practices checklist to determine areas that may need your attention.


Stay informed. Stay ahead of the risks.

Church laws, tax rules, employment requirements, and financial best practices keep changing. Church Law & Tax’s free newsletters deliver timely, practical guidance to your inbox so you can spot emerging issues and make better-informed decisions for your church.

Sign up for our free newsletters and get trusted church legal, tax, finance, and risk-management insights delivered to you.


Vonna Laue has worked with ministries and churches for more than 20 years. Vonna was a partner with a national CPA firm serving not-for-profit entities through audit, review, tax, and advisory services. Most recently, she held the role of executive vice president for a Christian ministry that works to enhance trust in the church and ministry community.

What the Respect for Marriage Act Means for Churches

The Respect for Marriage Act recognizes qualifying marriages under federal law while preserving important protections for churches and other religious organizations. Here’s what church leaders need to know about weddings, facilities, tax-exempt status, and the law’s limits.

The Respect for Marriage Act (RMA), passed into law in 2022, preserves important religious-liberty rights while requiring federal and state recognition of certain legally valid marriages. 

Questions still occasionally circulate about protections churches receive under the Act. Here is what church leaders need to know.


Get trusted guidance for your church

Church leaders face legal questions that rarely have simple answers. Church Law & Tax members get trusted guidance from leading attorneys, CPAs, tax experts, and other professionals who understand the unique legal and financial challenges churches face.

Become a Church Law & Tax member today and get the guidance you need to make informed decisions for your church.


Key takeaways:

  • The RMA became federal law in December 2022.
  • The law requires the federal government to recognize a marriage if it was valid where entered into.
  • It also requires states to recognize valid out-of-state marriages regardless of the sex, race, ethnicity, or national origin of the spouses. .
  • Churches and certain other nonprofit religious organizations cannot be required under the Act to perform or host marriage celebrations.
  • A refusal covered by the Act’s religious-organization protection does not create a civil claim or cause of action under that provision.
  • The Act says it cannot be used to deny or alter tax-exempt status or certain other benefits that do not arise from marriage.
  • The law does not eliminate other federal, state, or local legal issues churches may encounter involving employment, facilities, public accommodations, or other activities.

The short answer for church leaders is that the RMA recognizes same-sex and interracial marriages under federal law while preserving specified protections for churches and other nonprofit religious organizations.

What is the Respect for Marriage Act?

Bottom line: The Act addresses government recognition of marriages. It also contains express religious-liberty protections for churches and other qualifying religious organizations.

President Joe Biden signed the RMA into law on December 13, 2022.

The law repealed the remaining provisions of the 1996 Defense of Marriage Act (DOMA). It also established federal rules for recognizing marriages.

For purposes of federal law, a marriage between two individuals is recognized when it was valid where it was entered into.

States must also recognize legally valid marriages from other states, regardless of the spouses’ sex, race, ethnicity, or national origin.

However, the law does more than establish marriage-recognition requirements. Congress also added specific protections addressing religious organizations and people with religious objections to same-sex marriage.

What Respect for Marriage Act church protections does the law provide?

Bottom line: The RMA expressly states that existing federal religious-liberty and conscience protections remain intact. It also creates specific protections for nonprofit religious organizations concerning marriage ceremonies and celebrations.

Section 6 of the Act is particularly important for churches.

First, Section 6(a) says the Act cannot be interpreted to diminish or eliminate religious-liberty or conscience protections already available under the First Amendment or other federal law.

In other words, Congress did not replace existing constitutional religious-liberty protections. Instead, the statute expressly says those protections remain available.

Moreover, Section 6(b) specifically identifies religious organizations protected by the law. These include:

  • churches;
  • mosques;
  • synagogues;
  • temples;
  • nondenominational ministries;
  • interdenominational and ecumenical organizations;
  • mission organizations;
  • faith-based social agencies;
  • religious educational institutions; and
  • nonprofit organizations whose principal purpose is studying, practicing, or advancing religion.

The protection also extends to employees of these organizations in the circumstances addressed by Section 6(b).


Stay informed about legal and tax issues affecting churches

Church law, tax rules, court decisions, and compliance requirements continue to change. Our free weekly newsletters help church leaders keep up with developments that matter.

Subscribe to Church Law & Tax’s free weekly newsletters and get practical updates delivered directly to your inbox.


Churches cannot be required under the Act to host or provide services for certain weddings

Bottom line: Section 6(b) says qualifying nonprofit religious organizations cannot be required to provide specified goods, facilities, or services for the solemnization or celebration of a marriage.

This is one of the RMA’s most important protections for local churches.

Section 6(b) says covered religious organizations cannot be required to provide:

  • services;
  • accommodations;
  • advantages;
  • facilities;
  • goods; or
  • privileges

for the solemnization or celebration of a marriage.

Therefore, the Act itself does not require a covered church to make its sanctuary or other facilities available for a wedding that conflicts with the church’s religious beliefs.

Likewise, the statute says a covered refusal does not create a civil claim or cause of action under this provision.

That distinction matters. The protection is not merely a statement of congressional intent. Congress placed specific language protecting covered religious organizations directly into the law.

Does the Respect for Marriage Act threaten a church’s tax-exempt status?

Bottom line: The RMA itself cannot be used as the statutory basis for stripping an otherwise eligible religious organization of its tax-exempt status because of its position regarding marriage.

The law says nothing in the RMA may be interpreted to deny or alter a benefit, status, or right of an otherwise eligible organization or person when it does not arise from a marriage.

Congress specifically listed:

  • tax-exempt status;
  • tax treatment;
  • educational funding;
  • grants;
  • contracts;
  • agreements;
  • guarantees;
  • loans;
  • scholarships;
  • licenses;
  • certifications;
  • accreditation;
  • claims; and
  • defenses.

Therefore, the RMA itself cannot be used to strip an otherwise eligible church of its federal tax-exempt status simply because of the Act’s marriage-recognition provisions.

However, church leaders should understand the limits of that statement. Section 7 restricts what can be done under the RMA. It does not mean every possible dispute involving marriage has been resolved, whether involving religious liberty concerns, tax, employment, or public accommodations.

Congress also recognized differing religious beliefs about marriage

Bottom line: Congress expressly acknowledged that sincere disagreements about marriage exist and said those beliefs are entitled to respect.

The RMA contains a congressional finding that is particularly relevant to religious organizations.

In Section 2, Congress recognized that people hold different beliefs about gender and marriage based on sincere religious or philosophical premises. Congress further stated that these people and beliefs are due proper respect.

This language echoes an important point from Obergefell v. Hodges, 576 U.S. 644 (2015).

In Obergefell, the US Supreme Court held that same-sex couples have a constitutional right to marry. At the same time, the majority opinion recognized that many people oppose same-sex marriage based on religious teachings and principles.

The RMA subsequently placed a congressional recognition of sincere differing beliefs about marriage into federal statutory law.

What the Respect for Marriage Act does not protect

Bottom line: Church leaders should not interpret the RMA as a blanket exemption from every law involving sexual orientation, marriage, employment, facilities, or public accommodations.

The scope of the statute matters.

For example, Section 6(b) specifically addresses goods, services, accommodations, facilities, and similar resources connected with the solemnization or celebration of a marriage.

That does not necessarily answer unrelated legal questions involving a church’s activities.

A church could still encounter legal questions involving:

  • employment decisions;
  • employee benefits;
  • facility use outside of weddings;
  • commercial activities;
  • state or local public-accommodation laws;
  • contracts with government agencies; or
  • state religious-freedom protections.

Those questions may involve the First Amendment’s Free Exercise and Establishment Clauses, the ministerial exception, federal employment laws, state religious-freedom laws, and other legal doctrines.

Therefore, churches should not assume the Act resolves every legal question involving their beliefs about marriage.

Bottom line: Written policies matter. Churches should clearly document their religious beliefs and consistently connect their practices to those beliefs.

The Act gives churches meaningful statutory protection. However, churches should still maintain clear governing documents.

Church leaders should consider reviewing their:

  • statement of faith;
  • definition of marriage;
  • bylaws;
  • wedding and marriage policies;
  • facility-use policies;
  • employment policies;
  • membership standards; and
  • policies governing ministers and other religious leaders.

Most importantly, these documents should be consistent with one another.

For example, a church that restricts weddings based on its theological definition of marriage should clearly state that doctrine in its governing documents. Its wedding and facility-use policies should then reflect the same belief.

The church also must evaluate whether its policy includes collecting revenue from private parties in exchange for using its building for weddings. If so, local and state public accommodations laws should be closely evaluated to determine if the church’s policies regarding marriage, coupled with revenue-generating activities, will create potential legal liability.

Church leaders should also work with qualified legal counsel before a dispute arises. State and local laws vary significantly. Therefore, a policy appropriate for one church may not address another church’s legal environment.

Respect for Marriage Act church protections at a glance

IssueWhat the RMA says
Recognition of marriagesFederal and state actors generally must recognize qualifying marriages valid where entered into.
Existing religious libertyThe Act cannot diminish religious-liberty or conscience protections otherwise available under the Constitution or federal law.
Church wedding facilitiesCovered nonprofit religious organizations cannot be required under the Act to provide facilities for the solemnization or celebration of a marriage.
Wedding-related servicesCovered religious organizations and their employees cannot be required under the Act to provide specified services, accommodations, goods, or privileges for a marriage celebration.
Civil claimsA refusal protected by Section 6(b) does not create a civil claim or cause of action under that subsection.
Tax-exempt statusAn otherwise eligible religious organization cannot be stripped of its tax-exempt status because of its position regarding marriage.
Other church legal issuesThe RMA does not create a blanket exemption from unrelated federal, state, or local laws.

Frequently asked questions about the Respect for Marriage Act

Does the Respect for Marriage Act require churches to perform same-sex weddings?

No. Section 6(b) expressly protects covered nonprofit religious organizations, including churches, from being required under the Act to provide specified services, facilities, accommodations, goods, or privileges for the solemnization or celebration of a marriage.

Can a church refuse to allow its sanctuary to be used for a same-sex wedding?

The RMA expressly protects covered nonprofit religious organizations from being required under the Act to provide facilities for the solemnization or celebration of a marriage. However, churches should also review applicable state and local laws with qualified counsel.

Can a church lose its tax-exempt status because it believes marriage is between a man and a woman?

The RMA says the Act cannot be interpreted to deny or alter an otherwise eligible organization’s tax-exempt status when that status does not arise from a marriage. However, that protection does not resolve every possible tax-law issue outside the RFMA.

Does the Respect for Marriage Act override the First Amendment?

No. Section 6(a) expressly states that the Act cannot be interpreted to diminish or abrogate religious-liberty or conscience protections otherwise available under the US Constitution or federal law.

For church leaders, the practical lesson is straightforward: the RMA recognizes qualifying marriages while also providing meaningful statutory protections for religious organizations. Churches should understand those protections without overstating them. Clear doctrine, consistent governing documents, thoughtful facility and wedding policies, and advice from qualified local counsel remain important parts of managing legal risk.

A combination of human editors, attorneys, and AI was used to create this article.

The editorial team of Church Law & Tax is made up of Matthew Branaugh, attorney-at-law, and Rick Spruill, digital content manager.

Webinar

Webinar: Getting Agile With Your Church Budget

CPA Ken Tan explains how church leaders can build more flexible, responsive budgets while maintaining strong financial controls, accountability, and stewardship.

Church budgets rarely unfold exactly as planned. Giving levels change, expenses shift, ministry opportunities emerge, and unexpected costs can quickly make even the most carefully constructed annual budget feel outdated.

In this free, on-demand webinar, Getting Agile With Your Church Budget, CPA Ken Tan shares practical ways church leaders can build greater flexibility into budgeting and financial decision-making without sacrificing accountability or good stewardship.


Strong church finances require more than an annual budget—they require trusted guidance for the financial, tax, legal, and governance decisions your leaders face throughout the year. Become a Church Law & Tax member or join our free weekly newsletter for expert guidance, practical tools, downloadable resources, and insights designed to help your church make informed decisions and steward its resources well.


Tan, a Church Law & Tax editorial advisor, explores how churches can think differently about budgeting, reserves, cash flow, capital expenses, and changing ministry priorities.

He also addresses real-world questions church leaders routinely face: Should a church budget to break even or plan for a surplus? How should depreciation and major capital replacements factor into the budget? When should excess contributions be moved into reserves? And when might a church need an external audit?

The conversation also examines the important role communication plays when financial circumstances require leaders to make difficult decisions or adjust established plans.

Whether you’re a pastor, executive pastor, treasurer, finance committee member, or church administrator, this webinar offers practical insights for creating a budget that provides direction without becoming a constraint.

Watch the webinar and learn how to make your church budget more responsive, resilient, and useful throughout the year.

Loading the player...

Download the presentation slides:

Why Every Church Needs a Gift Acceptance Policy

Not every charitable gift is right for every church. A well-designed gift acceptance policy helps leaders evaluate complex donations, protect the ministry from unnecessary risk, and make consistent decisions that honor both donors and the church’s mission.

Churches are called to receive generosity with gratitude and steward it faithfully. Generous giving fuels ministry. 

Every week, churches receive charitable donations–whether cash, real estate, or personal property–that support worship, outreach, discipleship, missions, benevolence, education, and countless other ministries.

Many of these gifts are straightforward. Others are not.


Get the tools and trusted guidance your church needs to make wise decisions about complex gifts and reduce unnecessary risk. Become an Advantage Member today to access our Gift Acceptance Policy template and other attorney- and CPA-developed resources.


Stewardship extends beyond how contributions are spent. It also includes discerning whether certain gifts should be accepted in the first place.

More than just cash

While most gifts involve cash or routine online giving, church leaders increasingly encounter more complex gifts, including:

  • appreciated securities;
  • closely held business interests;
  • cryptocurrency;
  • intellectual property;
  • vehicles;
  • real estate;
  • donor-advised fund grants;
  • planned gifts through estates and trusts.

While these gifts can provide tremendous opportunities, they can also expose a church to unexpected legal, financial, tax, environmental, operational, and reputational risks if not carefully evaluated.

Unexpected questions

These gifts often involve issues unfamiliar to many church leaders, triggering questions like:

  • Does accepting this gift create ongoing financial obligations?
  • Will this property require expensive maintenance?
  • Could environmental contamination become the church’s responsibility?
  • Are there tax consequences?
  • Can the donor legally require the church to use the gift in a particular way?
  • Should the church accept ownership of a struggling business?
  • Does accepting this gift advance—or distract from—the church’s mission?

A thoughtful gift acceptance policy helps answer these questions before problems arise. It also communicates to donors that the church is committed to honoring generosity while faithfully stewarding the resources entrusted to its care.

Equally important, a written policy allows church leaders to make difficult decisions consistently. Rather than responding differently depending upon the donor or the amount involved, leaders can point to an established process that treats every proposed gift fairly and objectively.

Declining an unsuitable gift should never be viewed as rejecting generosity. Sometimes the most faithful act of stewardship is recognizing that accepting a particular gift would ultimately burden the church rather than strengthen its ministry.

Church Gift Acceptance Policy and Procedures Template 

Church Law & Tax’s policy template (download your copy) guides church leaders through these questions and considerations. It’s designed to help churches:

  • establish consistent gift acceptance procedures;
  • reduce unnecessary legal and financial risk;
  • protect donor intent whenever practical and lawful;
  • clarify decision-making responsibilities;
  • promote good governance;
  • encourage thoughtful stewardship.

Strengthening the mission

Every charitable gift represents an act of generosity and trust.

Receiving that generosity faithfully requires more than gratitude—it requires wisdom, discernment, accountability, and stewardship.

A thoughtfully developed gift acceptance policy helps church leaders evaluate opportunities consistently, communicate clearly with donors, reduce unnecessary risk, and ensure that every accepted gift strengthens the church’s mission for years to come.

Whether a church receives a weekly offering, a gift of appreciated stock, a parcel of real estate, or a transformational estate gift, the principles remain the same: honor the donor, protect the ministry, and steward every resource for God’s glory.


Editor’s Note: This article was created using a combination of artificial intelligence and a human editor and attorney.


Gift Review Checklist

Before accepting a complex gift, consider the following questions:

Mission

☐ Does this gift advance the Church’s mission and tax-exempt purposes?

☐ Is acceptance consistent with our theological convictions?


Ownership

☐ Has ownership been verified?

☐ Are transfer documents complete?

☐ Are there liens or encumbrances?


Financial

☐ Estimated value reviewed

☐ Carrying costs evaluated

☐ Insurance reviewed

☐ Marketability considered


☐ Legal counsel consulted (if appropriate)

☐ Contracts reviewed

☐ Environmental issues evaluated (if applicable)

☐ Tax implications considered


Operational

☐ Storage

☐ Maintenance

☐ Staffing

☐ Transportation

☐ Security


Governance

☐ Appropriate approvals obtained

☐ Restrictions documented

☐ Board minutes completed


Gift Acceptance Matrix

Gift TypeDesignated AuthorityBoard ApprovalProfessional Review
Cash✓NoNo
Checks✓NoNo
Online Giving✓NoNo
Publicly Traded Securities✓Usually NoSometimes
Closely Held Business InterestsRecommendationYesYes
LLC InterestsRecommendationYesYes
Partnership InterestsRecommendationYesYes
CryptocurrencyRecommendationUsually YesYes
NFTs/Digital CollectiblesRecommendationYesYes
VehiclesUsuallySometimesSometimes
ArtworkUsuallySometimesAppraisal Recommended
Intellectual PropertyRecommendationYesYes
Real EstateRecommendationYesYes
Planned GiftsUsuallySometimesSometimes

IRS Quick Reference for Church Leaders

Remember:

✓ Donors who itemize charitable contributions must follow IRS rules for substantiating them. As a courtesy, the Church provides donors with contemporaneous written acknowledgements for individual cash contributions of $250 or more. The church also substantiates noncash gifts, but provides only description of noncash gifts (not their dollar values). 

✓ Acknowledgements must include a statement that no goods or services, other than intangible religious benefits, were provided by the Church, if that was the case. If the Church provides any goods or services in return for the gift, it must include a description and good-faith estimate of their values.

✓ Donors—not the Church—are responsible for obtaining qualified appraisals when required.

✓ When a donor values a noncash gift at $5,000 or more, the Church will provide a designated person to sign Part V of Section B of the donor’s required Form 8283. 

✓ The Church shall complete and/or file applicable IRS forms when required by law, including Form 8282 for property valued by the donor at $5,000 or more and disposed of by the Church within three years of the contribution date.

✓ The Church should keep complete documentation supporting every significant gift.


Practice Tip

Establish a standard receipting process for every contribution, regardless of size. Consistency strengthens both donor confidence and financial accountability.

Matthew Branaugh is an attorney and editor for Church Law & Tax.

Advantage Member Template: Gift Acceptance Policy and Sample Board Resolution

This template is provided by Church Law & Tax and Gloo for informational and general guidance purposes only.

Disclaimer

This template is provided by Church Law & Tax and Gloo for informational and general guidance purposes only. It does not constitute legal advice, and Church Law & Tax and Gloo are not law firms. No attorney-client relationship is created by your use of this template.

Laws and regulations governing artificial intelligence, data privacy, employment, and related matters vary by jurisdiction and change frequently. This template is not tailored to the specific circumstances, legal obligations, or operational needs of any particular church or religious organization.

Church Law & Tax and Gloo make no representations or warranties, express or implied, regarding the accuracy, completeness, suitability, or legal sufficiency of this template. Use of this template is at your own risk. Church Law & Tax and Gloo shall not be liable for any damages, losses, or liabilities arising from your use of, or reliance on, this template.

This template reflects general guidance as of the date of publication and may not account for developments in law or technology occurring after that date.


Can Church Employees Volunteer at Their Own Church?

A new Department of Labor opinion letter clarifies when nonprofit employees may volunteer for their employers—and offers churches a practical framework for determining when an employee’s volunteer service could become compensable work.

The U.S. Department of Labor’s Wage and Hour Division (WHD) has addressed an important question that often arises in church workplaces: When may a church employee volunteer additional time for the church without that time becoming compensable work under the Fair Labor Standards Act (FLSA)? 

In Opinion Letter FLSA2026-12, WHD reviewed a specific case involving exempt employees of a nonprofit that breeds and trains service dogs who want to volunteer outside normal work hours as puppy caretakers in their homes. 


Church employment rules can get complicated quickly—and getting them wrong can expose your church to back wages, overtime, and other costly liabilities. Become a Church Law & Tax member for trusted guidance on employment, tax, legal, and financial issues, or subscribe to our free weekly newsletter to stay informed about developments affecting your church.


The department explains that nonprofit employees—whether exempt or nonexempt—may volunteer for their employer if the services are:

  • Offered freely, 
  • without direct or implied coercion, 
  • without an expectation of compensation, and 
  • are not the same or similar to the work they are employed to perform. 

An employee cannot simply “volunteer” to perform essentially the same duties they normally perform for pay. Whether duties are sufficiently different depends on the facts and circumstances, including how closely the volunteer activities relate to the employee’s regular responsibilities. 

“Put another way, a nonprofit employee cannot be both a paid employee and a non-paid volunteer while performing the same type of work for the same employer,” the department said.

The analysis

Applying this standard, WHD concluded that veterinarians and directors could potentially volunteer as puppy caretakers because their regular duties were assumed to differ substantially from routine canine care and socialization. 

Trainers, however, generally could not volunteer for such work because training and caring for dogs substantially overlap with their paid duties. 

WHD referenced five past cases put before the department to help further illustrate the way the analysis works:

  • A hospital office employee could volunteer to sit with patients during off-duty hours;
  • A school district bus driver could volunteer as a school basketball coach;
  • A secretary for a nonprofit serving at-risk youth could chaperone a trip because the secretary’s primary employment duties did not involve supervising children. 
  • A school district bus driver could not volunteer to drive a school’s basketball team to away games because it overlapped with his primary employed duties.
  • Detention officers could not volunteer as reserve peace officers for the same public employer because duties between the roles overlapped.

For properly exempt employees, WHD clarified that improperly characterized “volunteer” work may not require additional compensation if their primary duties remain exempt work and they continue to satisfy all exemption requirements. 

Caution: The department nevertheless cautions nonprofits that misclassifying “volunteer” time can affect the analysis of an employee’s status as an exempt employee and can create liability for back wages, overtime, liquidated damages, and attorneys’ fees for employees that are classified as nonexempt.

What this means for churches

Churches often face situations in which exempt and nonexempt employees want to volunteer for church events, ministries, and activities.

The WHD guidance suggests room for such volunteering. 

However, churches should use the WHD’s analysis before approving any volunteering. 

When an employee desires to volunteer, the churches should:

  • Review all employee job descriptions to ensure they are detailed and accurate and such duties do not overlap with the requested volunteer areas;
  • Review wage classifications for ministerial exception, exempt, and nonexempt employees to ensure they are correct;
  • Outline specific duties a volunteer role entails and then review how those may overlap with an employee’s primary paid duties;
  • Verify the employee freely wishes to volunteer, without appearance of coercion; and
  • Verify the employee does not expect compensation for the volunteer work. 

Tip: Special consideration should be given when an employee will be volunteering in roles supervised by the same person as the employee’s regular supervisor as this may indicate the duties are more “work” duties than “volunteer” duties.


We used AI to help generate this content, which Frank Sommerville, Attorney and CPA, and Elaine Sommerville, CPA, peer-reviewed.

Matthew Branaugh is an attorney and editor for Church Law & Tax.
Frank Sommerville is both a CPA and attorney, and a longtime Editorial Advisor for Church Law & Tax.
Elaine L. Sommerville is licensed as a certified public accountant by the State of Texas. She has worked in public accounting since 1985.

Can Churches Get Political? What Church Leaders Need to Know

Churches and pastors have constitutional rights to political speech—but tax-exempt status comes with restrictions. Here’s what leaders should consider before candidates, causes, and elections enter the conversation.

Can churches get political?

The question feels especially loaded for pastors as the heat of our political landscape seemingly burns hotter than ever. 

Some want to see their churches take a stand for or against specific candidates or causes. Others wonder whether any stands taken by their churches should occur at all. 


Stay informed on the legal, tax, finance, and risk issues affecting churches. Sign up for a free Church Law & Tax newsletter or become a member today for trusted guidance and practical resources from leading experts.


Many pastors feel caught in the middle.

To help, Church Law & Tax put together a free guide to help churches and pastors navigate political activities. 

Video: Can Our Church Get Political?

Loading the player...

The goal is to help leaders understand where lines exist, and how they should thoughtfully consider them before deciding how to act. 

Thankfully, while the political landscape offers a lot of heat to our cultural moment, pastors and church leaders have an opportunity to bring light. 

A fuller picture

Technically speaking, churches can get political. The Constitution’s Free Exercise and Free Speech clauses offer robust protections for churches and pastors to speak and act as they feel called based on their theological convictions. 

Whether it’s endorsing a candidate for Congress or lobbying against a ballot measure involving, say, the legalization of marijuana, they can respond as they feel led. 

But there’s more to consider. 

Specifically, the Internal Revenue Service (IRS) lays out two requirements for nonprofits and churches in order to maintain their tax-exempt statuses. 

One requirement, based on the controversial 1954 adoption of the “Johnson Amendment,” says tax-exempt entities cannot support or oppose political candidates, even to an insubstantial degree. 

The other, based on an act of Congress from 1934, says churches can support or oppose ballot measures, or lobby for or against legislative matters—but only if these activities represent “no substantial part” of their overall operations. Defining “substantial” has proven elusive over the years. 

Status quo

Adding to the ambiguity: Limited enforcement by the IRS. Only a handful of violations have ever been openly pursued by the agency. 

An executive order issued by President Donald Trump in 2018 attempted to undo the Johnson Amendment but lacked any substantive legal effect. 

A 2024 lawsuit brought by two Texas churches and the National Religious Broadcasters appeared destined to bring change when the IRS agreed to a settlement statement offering churches and religious organizations more leeway. But a federal judge dismissed the case on jurisdictional grounds. 

The IRS listed updated guidance on the Johnson Amendment as a 2025-2026 priority, but until anything is issued, the status quo remains. 

That leaves pastors and churches facing continued uncertainty. Should they support or opposed candidates? What stands should they take? Is risking their tax-exempt statuses worth it? Should tax exemption even influence a decision to begin with?

Room to advocate

Pastors and church leaders should first examine how God is calling their church to act, whether it involves a candidate or an issue. 

For some, they are resolute about issues affecting their communities—or the country as a whole—and they believe they need to engage, as is their right. 

The Constitution protects churches and pastors who wish to speak into these issues, and whether it comes from the pastor’s preaching, a pastor testifying on behalf of the church before a legislative committee, or other forms of advocacy, there is room to act. 

Those actions won’t likely trigger IRS scrutiny, either, unless the time, money, and resources expended become a substantial part of the church’s operations. 

While the constitutional protections remain when it comes to political candidates, the assurances of tax-exempt protection do not. 

Even with relatively nonexistent IRS enforcement, pastors and church leaders must contemplate what a loss of exemption could mean for their congregations. Among the potential impacts:

  • property tax exemptions; 
  • sales tax exemptions; 
  • charitable contributions deductions for donors; 
  • eligibility for certain types of retirement plans;
  • availability of unemployment taxes.

More importantly, though, a church’s stand for or against a candidate or issue may invite division within the congregation itself. A 2024 survey by the National Association of Evangelicals reinforced these concerns, with 98 percent of pastors saying candidate endorsements should be avoided—largely because of the divisions they can cause. 

A force for civic good

While there is an opportunity to bring light on key political issues during this election season, churches and pastors also have an opportunity to shine in another important way: they can support our country’s democratic processes. 

For instance:

  • Hosting nonpartisan forums inviting all candidates;
  • Serving as a precinct location for elections;
  • Compiling and distributing voting records (without commentary) of candidates on major issues;
  • Conducting nonpartisan voter registration drives; and,
  • Providing educational materials and hosting educational meetings about community issues, such as drug legalization, education reform, health care access, and economic development.

Can churches get political? Constitutionally speaking, yes.

Should churches get political? That’s a more nuanced question for every pastor and church, but one worth answering. There’s an opportunity to bring light, even in the heat of an election season.

Matthew Branaugh is attorney and editor of Church Law & Tax. Don’t miss Church Law & Tax’s free guide on churches and political activities and its “Politics and the Church: Activism, Speech, and the Tax Code” Recommended Reading page.

Matthew Branaugh is an attorney and editor for Church Law & Tax.

Advantage Member Template: Artificial Intelligence use Policy for Churches

This template is provided by Church Law & Tax and Gloo for informational and general guidance purposes only.

Last Reviewed: October 2, 2026

Use this policy template to provide guidance regarding any uses of artificial intelligence within church work

Disclaimer

This template is provided by Church Law & Tax and Gloo for informational and general guidance purposes only. It does not constitute legal advice, and Church Law & Tax and Gloo are not law firms. No attorney-client relationship is created by your use of this template.

Laws and regulations governing artificial intelligence, data privacy, employment, and related matters vary by jurisdiction and change frequently. This template is not tailored to the specific circumstances, legal obligations, or operational needs of any particular church or religious organization.

Church Law & Tax and Gloo make no representations or warranties, express or implied, regarding the accuracy, completeness, suitability, or legal sufficiency of this template. Use of this template is at your own risk. Church Law & Tax and Gloo shall not be liable for any damages, losses, or liabilities arising from your use of, or reliance on, this template.

This template reflects general guidance as of the date of publication and may not account for developments in law or technology occurring after that date.


When to Use This Template

  • To create a workplace culture demonstrating commitments to biblical integrity, and legal, ethical, and responsible uses of artificial intelligence (AI) 
  • To provide acceptable and unacceptable uses of AI for church work, including examples
  • To establish an ongoing process for church leaders to examine current and potential AI uses and potential policy changes as AI and the legal landscape surrounding it continue to evolve

How to Use This Template

  1. Review this template with qualified legal counsel familiar with applicable federal, state, and local laws, as well as the specific laws governing nonprofit and religious organizations in your jurisdiction
  2. Consult with relevant advisors (including HR, finance, and technology professionals) as appropriate
  3. Customize bracketed sections of this template to reflect your church’s actual practices, structure, and values
  4. Approve through a process consistent with your church’s governing bylaws, such as a board-approved action
  5. Communicate to all personnel
  6. Apply consistently
  7. Review at least once a year and amend as needed

Best For

  • Church Board
  • Technology Committee
  • Church IT Leader/Department
  • Executive Pastor

Editor’s Note

Churches often handle sensitive or confidential information. Examples of sensitive or confidential information include, but are not limited to, pastoral care records, prayer requests, information about children and youth, employment-related matters, donor information, membership records, volunteer screening data, disciplinary matters, family crisis details, and financial assistance request details.

Some churches locally store the information. Others store it in cloud-based arrangements, typically through enterprise agreements with third-party providers that include provisions regarding related protections. This policy template should be customized to align with a church’s existing practices, including related safeguards and protections associated with sensitive or confidential information.

Download a .pdf copy:


How Churches Can Prevent AI-Powered Fraud

Artificial intelligence is making church scams more convincing than ever. From fake pastor emails to AI-generated invoices and voice messages, ministry leaders need stronger safeguards to protect church finances, sensitive data, and their congregations. Here are practical steps every church should take to reduce fraud risk before an attack occurs.

Artificial intelligence (AI) is changing ministry operations, but it is also creating new risks for churches. Today’s scams are no longer easy to spot. AI-generated emails, voice messages, invoices, and fake receipts can look and sound legitimate enough to fool even experienced church staff members.

As a result, churches should strengthen financial controls, improve verification practices, and require stronger online security measures before fraud occurs.

Bottom line: Churches that rely on trust, fast approvals, and informal communication processes are increasingly vulnerable to AI-driven scams targeting finances, payroll, and sensitive ministry data.

Why AI Fraud Risks Are Growing for Churches

Criminals now use AI tools to create:

  • Convincing phishing emails
  • Fake pastor voice messages
  • Fraudulent invoices and receipts
  • Vendor payment scams
  • Impersonation texts and emails

For example, a church staff member may receive a message that appears to come directly from a pastor requesting an urgent payment or reimbursement. Meanwhile, AI-generated financial documents can look polished enough to move through busy church workflows unnoticed.


Become a member today.


Churches are especially vulnerable because ministry environments depend heavily on trust, responsiveness, and distributed communication among staff and volunteers.

Simple Safeguards Churches Should Implement Now

Fortunately, churches can reduce fraud risks significantly with practical safeguards and stronger oversight.

Most importantly, churches should normalize verification rather than treattreating it as distrust. A quick phone call or secondary confirmation process can prevent significant financial loss.

Likewise, written response plans help churches act quickly if fraud occurs.

As AI technology advances, ministry leaders must view cybersecurity and fraud prevention as part of faithful stewardship.


Subscribe to Free Church Law & Tax Newsletters

Stay informed on the latest legal, financial, tax, and risk-management developments affecting churches nationwide.

Subscribe to our free weekly newsletters.


Matthew Branaugh is an attorney and editor for Church Law & Tax.
Rick Spruill is digital content manager for Church Law & Tax/Gloo.

Who Should Handle Church Payroll During a Sabbatical?

When the only person who knows how to process payroll goes on sabbatical, churches face more than a scheduling challenge—they expose a critical internal control weakness. Here are practical ways to ensure payroll and IRS filings continue without interruption while improving financial oversight for the future.

Q: I’m taking a monthlong sabbatical soon. The church has two payroll cycles to process and a quarterly withholding to file with the IRS. I am not supposed to come into work, but no one else knows how to do these tasks. In terms of compensation information, the only individuals who know who gets paid what (besides me) are church board members. And no one on staff seems willing to cover these tasks. How can these tasks get done?


A: CPA Tim Samuel, a longtime Church Law & Tax editorial advisor, offers this advice:

I would encourage the board to revisit the assumption that payroll can only be handled by one person based on the idea of keeping compensation information confidential.

But, this is a significant internal control concern. When only one person has access to payroll, the organization becomes vulnerable to errors, fraud, and operational disruption. Every church should have at least one trained backup person or an outside professional who can step in when needed.

Confidentiality is important, but it should not prevent proper oversight and cross-training. Payroll companies, bookkeepers, accountants, finance staff, and other designated leaders routinely handle compensation information as part of their responsibilities.

For this sabbatical, I would recommend one of several practical options:

• Train a trusted staff member before the sabbatical begins.

• Delegate the responsibility to the treasurer, finance committee chair, or another authorized board member.

• Engage an outside CPA, bookkeeper, or payroll specialist for the month.

• Work with your payroll provider to identify a temporary administrator who can process payroll and submit the required filings.

• Create written procedures and a payroll calendar so another individual can follow the process while you are away.

A sabbatical often reveals where an organization has become too dependent on one individual. In this case, the church has identified an opportunity to strengthen its internal controls, reduce fraud risk, and ensure critical financial functions can continue even when a key employee is unavailable.

Tim Samuel is a CPA and the chief financial officer of Bridgeway Community Church, a nondenominational, multicultural church in Columbia, Maryland, that draws more than 4,000 people each week.

Legal Risks of AI for Churches: What Church Leaders Need to Know

Church leaders must understand the legal, privacy, and governance risks tied to artificial intelligence before adopting AI tools in ministry operations.

Church leaders increasingly use artificial intelligence (AI) tools for communication, administration, and ministry support. However, understanding the legal risks of AI for churches is essential before adopting these technologies.

  • AI tools can create privacy and data security risks
  • Copyright ownership issues may affect AI-generated content
  • Churches should establish written AI usage policies
  • Federal and state laws may apply to AI-related decisions
  • Proper oversight helps reduce liability and reputational harm

Churches can use AI legally and responsibly, but only when leaders understand the risks, establish policies, and maintain human oversight. Most importantly, church leaders should never assume AI-generated content is legally safe simply because it is easy to produce.

Bottom line: AI can improve church operations. However, churches that fail to establish safeguards may expose themselves to legal, financial, reputational, and cybersecurity risks. 


Are you already an Advantage Member? Download your AI policy template today and browse our growing church policy and sample board resolution templates knowledge hub.


Churches should prohibit staff and volunteers from using personal AI accounts for church-related business. Instead, churches should carefully select the AI tools that their employees and volunteers can use for church business to help minimize risks and maximize their effectiveness.


Your staff is probably already using AI. Download our free “AI in the Church Workplace” policy template today!


Why Churches Are Rapidly Adopting AI Tools

Many churches now use AI for:

  • Sermon research assistance
  • Email drafting
  • Social media content
  • Volunteer communication
  • Budget summaries
  • Church administration
  • Website chat support

For example, AI platforms can quickly generate outlines, summarize large amounts of text, and create ministry graphics. However, speed does not eliminate legal and ethical responsibilities.

Above all, church leaders must remain accountable for every decision, communication, and content piece produced using AI systems.

Privacy and Data Security Risks

Bottom line: Churches should never allow staff and volunteers to upload sensitive or confidential information into AI tools without first understanding how that information may be stored, used, or shared.

One of the largest legal risks of AI for churches involves privacy and data protection.

Many AI tools collect and retain user-submitted information. Consequently, sensitive church data entered into these systems may become vulnerable, subjecting the church to legal risk.

Sensitive or confidential information may include:

  • Prayer requests
  • Counseling notes
  • Financial records
  • Employee information
  • Children’s ministry data
  • Donor information

Churches should pay close attention to state privacy laws and cybersecurity obligations. In addition, leaders should review vendor terms of service carefully to ensure no church-submitted data is used to train the vendor’s system or can be otherwise accessed by the vendor’s personnel. 

The Federal Trade Commission has issued guidance regarding deceptive data practices and AI-related risks. Review FTC privacy and security guidance here.

Practical Steps Churches Should Take

  • Create a written AI usage policy
  • Prohibit uses that violate laws or the church’s mission and values
  • Require vendor terms protecting privacy and security
  • Restrict sensitive data uploads
  • Train employees and volunteers at least annually
  • Review cybersecurity insurance coverage
  • Limit AI access permissions
Risk AreaPotential ConcernRecommended Action
Member DataUnauthorized disclosureRestrict uploads into AI systems unless vendor terms outline data security and confidentiality protections (seek legal counsel before final decision)
Financial RecordsCybersecurity exposureUse secure internal systems unless vendor terms outline data security and confidentiality protections (seek legal counsel before final decision)
Pastoral CounselingConfidentiality concernsAvoid AI processing entirely unless vendor terms outline data security and confidentiality protections (seek legal counsel before final decision)
Children’s DataLegal compliance risksAvoid AI processing entirely unless vendor terms outline data security and confidentiality protections (seek legal counsel before final decision)

Bottom line: AI-generated content may create ownership disputes and copyright infringement concerns if churches do not verify sources carefully.

Churches using AI-generated graphics, music, videos, or written content should understand potential copyright risks.

For example, some AI systems generate content based on existing copyrighted materials. As a result, churches may unknowingly publish infringing material.

The US Copyright Office has also clarified that purely AI-generated works may not qualify for copyright protection under current law. Read the U.S. Copyright Office guidance on AI here.

In other words, churches may not fully own certain AI-generated ministry content.

Common Intellectual Property Issues

  • Using copyrighted images unknowingly
  • Publishing AI-generated devotionals without review
  • Creating sermon graphics that resemble protected works
  • Uploading copyrighted church materials into AI tools

Most importantly: 

  • Church leaders should maintain human review processes before publishing AI-created materials to avoid potential copyright violations.
  • Churches that prioritize copyright ownership of works created by employees and independent contractors should clarify when AI uses are or aren’t appropriate.
  • Church leaders should disclose when AI is used to create content shared publicly.

Employment and HR Risks

Bottom line: Churches should never rely solely on AI systems to make employment decisions involving hiring, discipline, or termination.

Employment laws apply when AI tools influence workplace decisions. Some states even require disclosures about AI uses for employment practices as well as regularized bias testing.

Laws implicated by AI uses include:

  • Title VII of the Civil Rights Act
  • Americans with Disabilities Act (ADA)
  • Age Discrimination in Employment Act (ADEA)

AI systems can unintentionally create discriminatory outcomes if leaders fail to monitor results carefully.

Accordingly, churches should require human oversight for all employment-related decisions.

AI UsagePotential RiskSafer Practice
Resume screeningDiscrimination claimsHuman review required
Performance scoringBias concernsHuman review required
Scheduling automationWage-hour violationsReview labor law compliance

Governance and Policy Considerations

Bottom line: Every church using AI should adopt a written governance policy before staff members and volunteers begin widespread use.

Church boards should proactively address AI governance now rather than waiting for a problem to occur.

A written AI policy should define:

  • Approved AI tools
  • Review and approval procedures for tools 
  • Acceptable and unacceptable uses
  • Employee and volunteer responsibilities
  • Content approval standards
  • Cybersecurity expectations

Likewise, churches should evaluate whether their insurance policies cover AI-related claims.

Board members should also document oversight discussions in meeting minutes. This demonstrates responsible governance practices.


Advantage Members: Click here to access our downloadable AI Policy Template for your church.


Questions Every Church Board Should Ask

  • Do church-approved vendors provide adequate privacy and legal protections?
  • Who approves AI tools for the church and monitors vendor terms of service at least once a year?
  • What data should be shared with AI platforms?
  • Who approves AI-generated content?
  • How does the church disclose AI uses for content created and shared publicly?
  • How should employees and volunteers use AI for content that the church expects to own the copyright for?
  • Does the church’s insurance policy cover cyber incidents?
  • Do employees receive ongoing AI training?

Ethical and Ministry Reputation Risks

Bottom line: Even legally permissible AI usage can damage trust if churches use these tools carelessly or deceptively.

Church leaders should recognize that AI risks extend beyond lawsuits.

For example, members may react negatively if they discover sermons, devotionals, or counseling materials relied heavily on undisclosed AI assistance.

In addition, deepfake technology and AI-generated misinformation can harm ministry credibility quickly.

Accordingly, transparency and human review remain essential.

Frequently Asked Questions

Can churches legally use AI tools?

Yes. Churches can legally use AI tools for many administrative and communication purposes. However, leaders must still comply with privacy, employment, copyright, and cybersecurity laws.

Should churches create an AI-use policy?

Absolutely. A written AI policy helps reduce confusion, improve oversight, and limit legal exposure.

Can AI-generated content be copyrighted?

The US Copyright Office has stated that purely AI-generated content may not qualify for copyright protection without sufficient human authorship. Questions also remain with respect to human-created works that involve AI-generated components.

What is the biggest AI risk for churches?

Privacy and data security risks currently represent one of the largest concerns, especially when sensitive ministry information is entered into AI systems.

AI can help churches operate more efficiently, but ministry leaders should approach these tools carefully. Churches that establish clear policies, maintain strong oversight, and prioritize legal compliance will place themselves in a far stronger position as AI technology continues evolving.


Become a Church Law & Tax Member

Access trusted legal, tax, financial, and risk-management guidance designed specifically for churches. Church Law & Tax members receive expert analysis, practical templates, exclusive training, and timely updates that help churches lead confidently in a changing legal environment.

Become a member today.

Subscribe to Church Law & Tax Newsletters

Stay informed on the latest legal, tax, HR, and risk-management developments affecting churches nationwide. Get practical insights delivered directly to your inbox each week.

Subscribe to the free weekly newsletters.

Matthew Branaugh is an attorney and editor for Church Law & Tax.
Rick Spruill is digital content manager for Church Law & Tax/Gloo.

Can Exempt Church Employees Be Paid for a Second Role?

Church employees often serve in multiple capacities, such as administrative staff who also participate in worship ministry. Understanding how exempt and nonexempt classifications interact is critical for avoiding wage-and-hour compliance issues.

Q: We have full-time exempt employees whose working days are Sundays through Thursdays because the church is closed on Fridays and Saturdays. These employees frequently play in the praise and worship band, meaning they attend rehearsals middays on Tuesdays during working hours and they get paid from the worship budget for playing on Sundays. 

Is it a problem when an exempt employee gets paid from two different line items like this?


A: This is a good question. Questions about dual roles come up frequently in church settings. Exempt church employees can get paid for a separate nonexempt role, but the church needs to closely evaluate the duties for the roles and any implications for overtime. Here is a good decision matrix:

Nonexempt and Nonexempt. Minimum wage and overtime apply using a blended hourly rate. 

Exempt and Exempt. No issues with overtime or minimum wage.

Exempt and Nonexempt. The situation is delicate because the government does not want employers to avoid overtime by simply combining an exempt position with a nonexempt position. We look at how much time is spent in each position. While 2004 regulations removed any bright-line test, the older test is still used as a guideline: 

  • The older test is that the employee must be performing “exempt” duties at least 80 percent of their total work time. Exempt duties are those duties that allow the position to be classified as exempt. If the nonexempt duties require more than 20 percent of their work time, they are nonexempt for all hours worked. 
  • Under the 2004 regulations, the test is a “primary duty test.” The key question to evaluate: What is the employee’s principal, main, major, or most important duty, considering the position is treated as one? If the employee’s primary duty qualifies for exempt classification, then the employee is exempt. Primary is defined as the main, major, or most important duty. To determine the primary duty, the US Department of Labor (DOL) will also examine the time spent in each job, the degree of supervision, the relative compensation allocated to each position, and the relative importance of the two positions to the employer.   

Under the older test, if the exempt employee performed exempt duties for 40 hours per week and worked for the praise and worship band 10 hours per week, the employee is likely nonexempt. But if the employee performed exempt duties for 50 hours per week and worked for the band 8 hours per week, the employee is likely exempt. Since these hours likely fluctuate, the DOL uses an annual average. 


Get answers to your toughest HR and employment questions. Upgrade to an Advantage Membership for expert guidance on complex issues like exempt vs. nonexempt classifications, dual-role employees, overtime rules, and other compliance challenges. Access trusted, practical insights that help your church make informed decisions and reduce legal and financial risk.


Under the newer test based on the 2004 regulations, the main, major, or most important duty will be the focus. Let’s say the employee is classified as exempt under the administrative classification because the employee is the church’s chief financial officer (CFO). The employee also plays an instrument in the worship band, which has six instrumental players. Since the CFO’s administrative duties are the main, most important duty, the CFO is likely classified as exempt.

If the exempt employee does not turn in time sheets, the employee and the DOL get to estimate the time worked if the employee is reclassified as nonexempt.  

I assumed two jobs here based on the question, but the principles work regardless of the number of jobs held.


Related: Wondering how to handle compensation when a pastor leaves unexpectedly? Read our guidance on paying a pastor after resignation to understand key legal and payroll considerations.


Frank Sommerville is both a CPA and attorney, and a longtime Editorial Advisor for Church Law & Tax.

Does a Church Have to Keep Paying a Pastor After an Immediate Resignation?

A pastor resigns without notice and requests pay through the end of the month. Here’s what churches need to know about compensation obligations, employment contracts, accrued PTO, and potential separation agreements.

Q: Our church was in the process of reviewing its pastor’s compensation to determine if it is reasonable when the pastor abruptly quit, effective immediately. 

However, the pastor requested he still receive compensation for the remainder of this month. What is the church obligated to do? 


A: Unexpected resignations are difficult situations for churches to navigate. On top of the relational and logistical challenges of a pastoral vacancy, the church must carefully fulfill its legal obligations to a departing employee. 

What does ‘at-will’ mean?

Most states in the US are “at-will employment” states. While employment is not guaranteed by the employer for any length of time, employees are also not required to provide notice before resigning. 

This means employees can quit or be terminated at any time. 

In these states, the church is only obligated to pay compensation up to and including the last day of work for any employee. In addition to earned compensation, the church may also need to pay the pastor any accrued vacation or paid time off (PTO) that the pastor has not used. This depends on state law and the church’s own policies. 


When a Pastor Resigns Unexpectedly, Every Decision Matters.

Questions about final pay, severance, employment contracts, and legal obligations can expose your church to unnecessary risk if handled incorrectly. With an Advantage Membership, you’ll gain access to expert guidance, in-depth legal insights, and practical resources that help you respond confidently when employment issues arise.

Upgrade to Advantage Membership and equip your church with the trusted support needed to handle today’s most challenging personnel and governance decisions.


The church’s obligations may be different if they have entered into a contract with the departing pastor. Employment contracts are the most common exception to at-will employment. If this church has entered into a contract with the pastor–for example, one specifying that the pastor is paid on a month-to-month basis, or is otherwise entitled to full monthly payment–then the terms of that contract would control. 

If there is no contractual obligation to continue payment, the church may still choose to continue paying the pastor through the end of the month (or longer) as a gesture of goodwill. The compensation should be reasonable. 

If the church does plans to pay any additional compensation, itthey should consider executing a separation agreement before making any payments. 

Spell it out in the separation agreement

A separation agreement can specify a severance amount in exchange for a release of all claims the departing pastor may have against the church. This provides the church some legal protection even in an amicable departure. Many churches pay a reasonable amount of severance to departing employees, even those who have voluntarily resigned.  

The church should consult local counsel before executing a separation agreement. 


Related: Wondering how to handle compensation when an exempt employee has more than one role in the church? Read our guidance on this important tax-related topic.

How Churches Can Manage the Hidden Costs and Risks of AI

Many churches are already using AI through staff, volunteers, and software platforms—but often without oversight. An AI inventory, clear policies, and regular reviews can help church leaders manage legal, ethical, and financial risks while taking advantage of AI’s ministry benefits.

Many churches are using generative artificial intelligence (AI)–whether leaders realize it or not. 

Consider these common scenarios:

  • A communications director uses a free version of ChatGPT to draft a newsletter.
  • A youth pastor accesses an AI image tool for event graphics. 
  • A finance team member pays for a  subscription to an AI tool summarizing reports and writing Microsoft Excel formulas. 
  • A volunteer uploads volunteer data into a free AI tool while coordinating schedules and resources to serve the community.

These uses raise a variety of questions and concerns, including legal, ethical, and financial ones.


Are you in the market for values-aligned AI with a mind toward human flourishing? Look no further than Gloo AI Studio.


Most churches do not handle these considerations well, though, because they do not address them in the first place. And most do not formally adopt AI through a board-approved strategy, missing an opportunity to effectively manage these important considerations. 

Instead, their AI use arrives through employee- and volunteer-created free trials and personal subscriptions, plus church-paid software platforms that quietly add AI tools and features—often at additional expense. 

Many churches do not approve of these uses, much less purchases, for AI tools or AI-related upgrades. These activities go on undetected; even ones with charges often run low enough to go unnoticed in monthly financial reviews.

So what should a church leader do?

Churches should begin with an AI inventory. 

Doing so can go a long way toward reducing key legal, ethical, and financial risks.

A comprehensive inventory can be done through a combination of reviewing expense reimbursements, credit card charges, and software platform uses, and also by surveying staff and volunteers on the tools they’re using for church work. 

The goal is to understand what is already happening before costs and risks spread. 

This inventory should list each AI tool, who uses it, what it costs, and what information is entered into it. 


Secure your Advantage Membership today and start seeing the benefits immediately, including this AI Policy for Churches crafted by some of the brightest legal minds in the religious nonprofit and church space.


Evaluate the financial, legal, and ethical considerations. Have AI uses received reviews and approvals through some type of formal process? If not, a formal process should be created, starting with an AI policy for the church workplace. The church’s board should initiate this work, and appropriate departments, such as finance and IT, should administer it. Qualified legal counsel should be involved initially, since legal and ethical questions must be answered. 

Establish clear rules for sensitive information. Churches should strictly prohibit the use of free AI tools or trial offers of premium tools for any church work involving sensitive or personal information. Even if a premium tool is approved, staff and volunteers should not enter donor names, giving history, payroll data, counseling notes, benevolence requests, HR and personnel matters, or confidential financial information into AI tools unless the tool’s premium version provides written assurances that submitted data is not used to train models or become publicly accessible in any way. Additionally, use of any premium tool for sensitive or personal information should require additional vetting and approval first by the church to ensure, among other things, that the AI provider meets state law requirements related to cybersecurity protocols and bias prevention.

Treat AI as its own budget category. AI should not disappear inside miscellaneous software expenses. Some tools charge per user, while others charge by usage, credits, images, documents, or processing volume. A tool that seems inexpensive during an introductory offer can become costly when usage expands across the staff.

Run short pilots. A 30- to 60-day pilot can help determine whether a tool saves time, improves quality, reduces cost, or strengthens ministry. Success should be defined before the pilot begins. Above all, avoid long-term agreements as much as possible.

Review AI tools at least quarterly. Leaders should ask what tools are being used, whether they are still needed, whether costs have changed, whether sensitive information is protected, and whether any tools should be canceled, consolidated, or expanded.

Recognize hidden rewards

Remember, too, that AI can be a helpful tool for churches when wisely used. 

It can help busy ministry teams save time, communicate more clearly, organize information, improve first drafts, summarize meetings, and reduce administrative burden. 

For churches with limited staff and growing demands, the right tools can create capacity for deeper ministry, better planning, and more thoughtful leadership.

Churches still must pay attention to the relational risks. AI can quietly reduce human conversations when staff rely too heavily on generated messages, automated follow-ups, or chatbot-style interactions. 

Recent research and media reports have raised concerns about people forming unhealthy emotional attachments to chatbots, receiving affirmation of harmful thinking, or being discouraged from seeking help from real people in moments of crisis. 

Broad acceptance of AI for personal and spiritual-related matters exists among those attending churches, too. A survey of practicing Christians by Barna Group and Gloo (Church Law & Tax’s parent company) show 61 percent would completely or somewhat trust AI on financial matters, and nearly half say the same when it comes to growing spiritually.

For churches, this matters because it shows AI has become commonplace even among their ranks. 

Using it as a staff can create efficiencies. It also shouldn’t replace the way staff meet real ministry needs in ways that technology cannot. 

Ministry is built on presence, prayer, wisdom, counsel, and trusted relationships. AI can help draft a message or organize notes, but churches should preserve pastoral care, parental involvement, small group community, counseling referrals, phone calls, visits, meals, and face-to-face conversations.

Leading with hope

AI emerged into the mainstream in 2022 and remains relatively new. 

But the stewardship principle is ancient. 

Churches are called to manage resources faithfully, protect the people they serve, and ensure every tool–including AI–supports the mission.

With proper planning, decision-making, and supervision, AI can strengthen ministry.

Tim Samuel is a CPA and the chief financial officer of Bridgeway Community Church, a nondenominational, multicultural church in Columbia, Maryland, that draws more than 4,000 people each week.

Ask Richie

👋 Hello! I'm Richie, your AI assistant. How can I help you today?
ajax-loader-largecaret-downcloseHamburger Menuicon_amazonApple PodcastsBio Iconicon_cards_grid_caretChild Abuse Reporting Laws by State IconChurchSalary Iconicon_facebookGoogle Podcastsicon_instagramLegal Library IconLegal Library Iconicon_linkedinLock IconMegaphone IconOnline Learning IconPodcast IconRecent Legal Developments IconRecommended Reading IconRSS IconSubmiticon_select-arrowSpotify IconAlaska State MapAlabama State MapArkansas State MapArizona State MapCalifornia State MapColorado State MapConnecticut State MapWashington DC State MapDelaware State MapFederal MapFlorida State MapGeorgia State MapHawaii State MapIowa State MapIdaho State MapIllinois State MapIndiana State MapKansas State MapKentucky State MapLouisiana State MapMassachusetts State MapMaryland State MapMaine State MapMichigan State MapMinnesota State MapMissouri State MapMississippi State MapMontana State MapMulti State MapNorth Carolina State MapNorth Dakota State MapNebraska State MapNew Hampshire State MapNew Jersey State MapNew Mexico IconNevada State MapNew York State MapOhio State MapOklahoma State MapOregon State MapPennsylvania State MapRhode Island State MapSouth Carolina State MapSouth Dakota State MapTennessee State MapTexas State MapUtah State MapVirginia State MapVermont State MapWashington State MapWisconsin State MapWest Virginia State MapWyoming State IconShopping Cart IconTax Calendar Iconicon_twitteryoutubepauseplay
caret-downclosefacebook-squarehamburgerinstagram-squarelinkedin-squarepauseplaytwitter-square