Sunil Kumar, FCAFCA · Governance Frameworks & Books
Assess

Find out where your governance actually stands.

Most boards assume their governance is fine until a funder audit, leadership transition or compliance notice proves otherwise. IGMA™ assessments score your organisation against a five-level maturity scale, with automated dashboards and a prioritised action list — not another checklist to file away.

L1Vulnerable
L2Reactive
L3Defined
L4Managed
L5Optimised

Every IGMA™ assessment scores your organisation against this scale, then gives your board a dashboard and a prioritised action list to move up a level. Not sure which level you're at? The free briefing is a good starting read before you commit to a full assessment.

Which toolkit is right for you?

Start from the question your Board, funder or regulator is asking.


Who built IGMA™, and why

IGMA™ was created by CA Sunil Kumar, FCA — a Chartered Accountant and social-sector CFO with 30+ years in NGO and development-sector finance, audit and governance. It grew out of work he has done repeatedly: managing a USD 60 million donor-funded portfolio, reporting to Board Audit Committees, building sub-recipient risk frameworks, clearing audit findings to nil observations, and carrying out audit and grant-monitoring visits in every state of India. The toolkits package that experience as self-assessments your own team can run. More about the author.

IGMA™ (Institutional Governance Maturity Assessment) is a methodology created by CA Sunil Kumar, FCA, in public use since June 2026.


See how it works

Watch the method explained and demonstrated before you buy. More free videos.

Can Institutional Governance Be Objectively Measured? — Evidence-Based Governance AssessmentA short demonstration of evidence-based governance assessment: the question is not whether an organisation says it has good governance, but what evidence supports it.Watch on YouTube
Can Institutional Governance Be Measured? — IGMA™ Founder Edition WebinarIntroduces the Institutional Governance Maturity Assessment and shows how governance can be assessed systematically across Board governance, strategy, financial stewardship and risk, rather than by opinion alone.Watch on YouTube
FCRA Governance Assurance: A Practical Approach to Strengthening NGO GovernanceExplains FCRA Governance Assurance and demonstrates how a structured governance assessment helps an NGO identify gaps and strengthen oversight of foreign contribution.Watch on YouTube


The assessments

Choose the scope that matches your immediate risk — FCRA compliance, data protection, or full institutional governance.

Looking for the FCRA Governance Maturity Framework book? It's on the Books page.

IGMA™ DPDP Compliance Assessment Toolkit

Excel-based, automated. Take control of your India DPDP Act compliance assessment.

Format: Excel workbook, automated scoring.
What's inside
India's DPDP Act shifts data-protection accountability onto the board and management, not just IT — and most NGOs and small organisations have no structured way to demonstrate compliance if asked. This toolkit walks you through the Act's actual requirements as an automated Excel assessment: answer the questions, and it scores your current compliance position and flags the specific gaps to close, rather than leaving you to interpret the law yourself. At $100, it's the lowest-cost way to get an evidence-based DPDP position on record before a regulator, funder or board asks for one.

IGMA™ FCRA Compliance Assessment Toolkit

A structured, organisation-wide assessment of your FCRA compliance position — so you know where you stand, not just assume it.

Format: automated Excel assessment tool.
What's inside
Filings done and documents on file don't always add up to a clear view of FCRA compliance — the work is spread across Finance, Programmes, Administration, Legal and the board. This toolkit brings it into one assessment across four modules (Registration Readiness, Current Compliance, Governance Integration and Future Regulatory Readiness) and six governance pillars. Rather than asking only "has this been done?", it asks whether each requirement is backed by a process, a control, evidence and a named owner. The outputs support management review, board reporting and a prioritised action plan. It works on its own or alongside the FCRA Governance and DPDP toolkits, and is a management tool, not a substitute for legal or regulatory advice.

IGMA™ FCRA Governance Assessment Toolkit — Professional Edition

The FCRA Governance Assurance Framework — an 8-pillar, 200-point automated Excel assessment, for organisations that need audit-ready documentation.

Format: 8-pillar, 200-point automated Excel assessment tool.
What's inside
FCRA compliance failures are rarely about one missing document — they're usually about governance gaps that only surface under audit: unclear approval trails, informal board oversight, inconsistent utilisation records. This toolkit scores your organisation across 8 governance pillars and 200 specific points, producing the kind of structured, evidence-based documentation an FCRA audit or funder due-diligence review actually looks for. It's built for the moment before that scrutiny happens, not after.

IGMA™ Professional Edition — Institutional Governance Maturity Assessment Toolkit

A structured, evidence-based governance diagnostic covering the full institution: 60 questions across 8 pillars, 646 evidence-based criteria, Board-ready outputs.

Format: 14-tab Excel workbook (Excel 2016+, no macros). Read the FAQ.
What's inside
Most governance reviews stop at "do you have a policy?" This toolkit goes further: it scores your entire institution — board oversight, financial sustainability, donor confidence, operational resilience — against the five-level IGMA™ Governance Maturity Scale (L1 Vulnerable to L5 Optimised), and returns an executive dashboard your board can actually act on, with a prioritised list of what to fix first. It's the full-institution counterpart to the narrower FCRA and DPDP assessments, for boards who want one clear, evidence-based read on where they stand rather than a patchwork of compliance checks.

Bundle

The three compliance toolkits together — FCRA compliance, FCRA governance and DPDP — for $700 instead of $900 bought separately.

IGMA™ Compliance Toolkits Bundle Best value

FCRA Compliance + FCRA Governance (Professional Edition) + DPDP Compliance, in one purchase.

Who it's for
For organisations that want to look at more than one compliance area with the same method, rather than a patchwork of separate checks. FCRA compliance, FCRA governance and data protection overlap — the same processes, controls, evidence and owners sit underneath all three — and assessing them together makes those connections visible. Useful for periodic compliance reviews, board-level assessments, audit preparation, and following up on gaps found earlier. Each toolkit is also available separately above. For a wider read on the whole institution, see the Institutional Governance Maturity Toolkit.

"Very useful document and compilation of checklists for Governance. Must buy for each and every NGO Board members and key functionaries. Excellent work by the author Mr. Sunil Kumar."

— Bhushan Mehta, verified Gumroad buyer, India, on the IGMA™ toolkits

Frequently asked questions

Mainly about the Institutional Governance Maturity toolkit. The licence and support answers apply to every IGMA™ toolkit.

About the Institutional toolkit

What is the IGMA™ Institutional Governance Maturity Assessment Toolkit?

An automated Excel workbook that measures how mature your organisation's governance is, on a 1.0–5.0 scale. You answer evidence-based Yes/No criteria. The workbook scores them and produces a dashboard, a Board-ready summary, gap recommendations and an action plan.

Who is it for?

NGOs, foundations, trusts and other mission-driven organisations. It is built for Boards, CEOs, CFOs, governance and compliance leads, and internal audit — anyone who needs to show funders, regulators or their own Board where governance stands.

Who created it?

CA Sunil Kumar, FCA — a Chartered Accountant and social-sector CFO with 30+ years in NGO and development-sector finance, audit and governance. He has led finance and grants for large donor-funded programmes, including a USD 60 million donor-funded portfolio, and supported the closure of a USD 60 million donor-funded programme with zero disallowance. More about the author.

IGMA™ has been in public use since June 2026.

How is this different from a free governance checklist?

A checklist tells you what to have. IGMA™ tells you how mature each practice is, weights the results by pillar, and lists your specific gaps from your own "No" answers. It then turns those gaps into a 30-60-90 day plan and a Board pack. Scoring is deliberately conservative: anything below 4.0 is flagged as meaningful exposure, not "room to improve".

Is it only for Indian organisations?

No. 58 of the 60 questions apply to any mission-driven organisation. Two refer to Indian law. Outside India:

  • Answer Q28 (Legal, including FCRA) against your country's rules on foreign funding and charities.
  • Answer Q47 (DPDP / Data Privacy) against your local data-protection law, such as GDPR.

The criteria for these two questions are worded for India, so a local expert should review your answers.

What's inside

What does the assessment cover?

60 questions across 8 governance pillars, assessed through 646 Yes/No criteria:

PillarQuestions
Board Governance & Strategic Oversight8
Risk, Resilience & Continuity8
Financial Stewardship & Sustainability10
Compliance, Ethics & Legal Protection8
Leadership, Talent & Succession6
Operational Excellence & Delivery6
Digital Governance & Data Protection6
Stakeholder Trust & Institutional Credibility8

Topics include Board independence; enterprise risk and donor dependency; reserves and internal financial controls; conflict of interest, whistleblowing and safeguarding; CEO succession; cybersecurity; and donor confidence.

Are all pillars weighted equally?

No. Financial Stewardship carries the highest weight. Leadership, Operations and Digital Governance carry the least. The overall score is a weighted average of the pillars you have answered.

What do I actually receive?

One Excel workbook (.xlsx) with 14 tabs:

  • Guidance: Cover & README, About the Author, Instructions, Question Index
  • Input: Criteria Input (646 criteria) and Scores View
  • Results: Pillar Summary, Results Dashboard, Board Summary (with chart), Print View
  • Follow-up: Assurance Report, Action Tracker, Year-on-Year Trend, Audit Log
Do I need any other software or add-ins?

No. Microsoft Excel 2016 or later, or a fully compatible spreadsheet application, is all you need. There are no macros to enable.

Using it

How do I complete the assessment?

There are two routes:

RouteWhat you doResponsesWhat it measuresBest for
Detailed (recommended)Answer Yes/No criteria per question646Demonstrated maturity — what the evidence supportsBoard, funder or external audit use
ConciseEnter one 1–5 score per question60Perceived maturity — what leadership believesA quick scan, workshop or Board discussion

For each question, the workbook scores whichever route you actually filled in and records which one it used.

Why might the two routes give different scores?

Leadership may rate a practice at Level 4 because a process exists, while the criteria show it is not applied consistently. IGMA™ calls this difference the Governance Perception Gap™. The gap is a finding in itself, so investigate it rather than forcing the scores to agree.

How long does it take?

As a guide: self-assessment 2–3 hours; facilitated workshop 4–6 hours; independent review 1–2 days. You can also complete it in stages.

Who should take part?

One governance, compliance or finance lead usually prepares it. For a full assessment, we recommend involving the Board Chair, CEO, CFO, COO and the risk, compliance and HR leads. Disagreements between them are useful. If the CEO says Level 4 and the CFO says Level 2, you have found a governance gap that a clean audit will not show.

Do I have to answer every question?

No. Unanswered questions are excluded from scoring, not penalised. You can produce results from a partial assessment and complete the rest later.

What does "Yes" mean for a criterion?

Yes means the statement is clearly and consistently true right now, with evidence. Partly true or uncertain counts as No. Each criterion has a Notes/Evidence column to record what supports the answer.

What counts as good evidence?

Formal documents are strongest: approved policies, Board minutes, registers and audit reports. Operational reports are moderate evidence. Verbal confirmation alone is weak. Where evidence is weak or conflicting, choose the lower level you can support.

Can I break the formulas by accident?

No. Only the yellow cells are for input; every other cell is locked. No password is needed for normal use. For structural changes, such as relabelling a pillar or adding rows, contact support for unlock guidance.

Will it catch inconsistent answers?

Yes. A built-in consistency check flags questions where a basic weakness is confirmed alongside a higher-maturity practice, so you can review before finalising.

Can I override a score?

Yes. Enter a 1–5 score in Scores View to apply professional judgment where context changes the picture. The override then takes priority in all calculations.

Results

How is maturity scored?

Every question starts at 1.0 and gains up to 1 point for each of Levels 2–5, in proportion to how many of that level's criteria you meet. Scores map to five maturity levels:

ScoreMaturity levelRisk rating
4.50–5.00Level 5 – OptimisedVery low
3.50–4.49Level 4 – ManagedLow
2.50–3.49Level 3 – DefinedModerate
1.50–2.49Level 2 – ReactiveHigh
1.00–1.49Level 1 – VulnerableCritical
What reports does it produce?

All outputs update automatically from your answers:

  • Results Dashboard — overall score, maturity level, pillar breakdown and 12 key governance risk indicators rated Green/Amber/Red
  • Board Summary — an executive one-pager with a pillar chart, 30-60-90 day plan and narrative
  • Print View — a print-ready Board and CEO pack, from executive summary down to question-level actions
  • Assurance Report — a question-level tracker for CFO, management and internal audit follow-up
Are the recommendations generic?

No. Recommendations are built from your own "No" answers above your current level. Each gap also shows the governance risk if it persists.

How do I turn results into action?

Gaps are phased into a roadmap:

ScoreTimeframe
1–2Within 0–30 days
Around 2–3Within 31–90 days
Around 3–4Over 3–12 months

The Action Tracker assigns an owner, target date and status to every question.

Can I compare against other organisations?

Optionally. The main benchmark is your own trend over time, measured against a fixed floor of 4.0. If you have real peer data, you can enter it per question and the gap is calculated automatically. There is no live external data feed.

Can I track progress year on year?

Yes. The Year-on-Year Trend tab logs each assessment's scores. The Audit Log records who prepared, reviewed and approved it.

How often should we reassess?

We recommend reassessing every 12 months for the leadership team and annually for the Board, with independent validation every 2–3 years.

Buying any IGMA™ toolkit: licence and support

How is it delivered?

Digitally, by download or email link straight after purchase. Nothing physical is shipped. Please keep your own backup copy.

What does the licence allow?

A single-organisation, perpetual licence. Your organisation can install and use the workbook on any number of its own devices for internal governance use, with no expiry.

Can I share it with another organisation, or use it for clients?

No. Redistribution, resale, sub-licensing or sharing outside the purchasing organisation requires prior written consent from the publisher. Consultants who want to use it with clients should email casunilkumarfca@gmail.com about a separate consultant licence before buying.

Do I own the methodology?

No. The licence covers use of the workbook. Copyright in the methodology, criteria and workbook design stays with the publisher.

Is it a one-time payment or a subscription?

A one-time purchase with a perpetual licence, with no renewal fees.

Will I get future updates?

Updates within version 1 (v1.x) are free for existing buyers and are delivered through your Gumroad library. A future major version (v2.0) would be a separate product. Any discount for existing buyers will be announced at release.

Is there a bundle?

The Institutional toolkit is sold on its own. The IGMA™ Compliance Toolkits Bundle ($700) combines the three compliance toolkits — FCRA Compliance, FCRA Governance (Professional Edition) and DPDP Compliance — for less than buying them separately. The IGMA™ FCRA Governance Maturity Framework book explains the thinking behind the FCRA toolkits.

Is the assessment professional advice?

No. IGMA™ is a structured self-assessment tool, not legal, accounting or other professional advice. Where you need expert assistance, consult a qualified professional.

How do I get support?

Email CA Sunil Kumar, FCA at casunilkumarfca@gmail.com. We aim to reply within 2 business days (India time). Support covers using the workbook, fixing errors and unlock guidance. It does not include governance advice on your answers or results.


Not ready for a full assessment?

Start with the free executive briefing, or one of the books, to see the thinking behind IGMA™ before you commit to a scored diagnostic.

Good to know before you buy