• June 2026

NSGP Risk Documentation: What Reviewers Actually Score

Reviewers score what’s verifiable, and that starts with NSGP risk documentation built before a single word of the Investment Justification gets written. A Nonprofit Security Grant Program (NSGP) Investment Justification that describes a threat without a date, a source, or a named incident behind it reads as an opinion, not as documented risk, and it costs points in the section that carries the most weight in the whole application.

This guide walks through what NSGP scoring actually asks for in the Risk section, the kinds of evidence that hold up, where each kind comes from, and how to organize an NSGP risk documentation file before the Investment Justification (IJ) gets written. It doesn’t cover how to write the IJ itself. It covers the file that has to exist first.

Why Documented Risk Carries So Much Weight in NSGP Scoring

NSGP is a competitive FEMA grant program that funds physical security improvements at nonprofit organizations, including houses of worship, religious schools, and faith-affiliated nonprofits, that face an elevated risk of a terrorist or other extremist attack. Every applicant submits an Investment Justification, a scored federal form that walks through the organization’s background, its risk profile, the security investments it’s requesting, and how it plans to carry them out.

The Risk section is worth 15 of the IJ’s 40 possible points, the single largest scored category on the form, more than Facility Hardening, more than Background, more than any other section. It’s built around the federal government’s own definition of risk: the combination of Threat, Vulnerability, and Consequence. Threat is where documentation does the heaviest lifting, since it’s the part of the section reviewers can actually check against a source.

Applications don’t go straight to FEMA. Each state’s Administrating Agency (SAA) reviews and scores every submission first, ranks them, and forwards its top-ranked applications to FEMA for a second review focused on eligibility and allowability. A thin or unsourced Risk section can cost points at either stage, and it’s the stage most within an applicant’s control. Facility hardening choices matter, but they don’t matter if the risk documentation underneath them doesn’t hold up.

What Counts as a Qualifying Risk

The federal IJ asks applicants to substantiate risk connected to terrorism, extremism, or a hate-related motive. FEMA’s own guidance is explicit that local crime without any of those three connections, such as ordinary burglary or vandalism, can still provide contextual support for an application, even though it won’t carry the same weight as an incident tied to one of the three qualifying categories.

The IJ also explicitly permits applicants to draw on incidents that happened at closely related or similar organizations, not just their own facility, and not only domestically. An attack at a comparable organization overseas can support the case that this type of organization is a target, provided the applicant draws the connection explicitly rather than leaving the reviewer to infer it.

That’s a broader standard than “hate crime documentation” alone. Hate crime data is one of the strongest, most accessible sources of evidence available to most applicants, and it directly supports the hate-related nexus, but it’s a proxy for part of the risk picture, not the whole thing. A well-built NSGP risk documentation file draws on multiple categories of evidence and ties each one back to the specific facility and the specific nexus it supports.

The Kinds of Evidence NSGP Applications Draw On

Across the applications SGA has reviewed, the strongest Risk sections pull from several of the following categories, not just one. A file built entirely from national statistics, with nothing tying the pattern to this facility, tends to read thin no matter how well written the narrative is.

Federal Hate Crime Data

The FBI publishes hate crime data annually through its Uniform Crime Reporting (UCR) Program. The useful cut of that data for an NSGP filing is narrow: the bias-motivation category that matches the applicant’s community, filtered down to the state and, where the FBI’s Crime Data Explorer supports it, the county. A national total on its own doesn’t tell a reviewer anything about this facility. The same figure narrowed to the applicant’s county does, and it’s usually the single fastest entry to add to an NSGP risk documentation file.

The standard window is the three most recent full calendar years. Check the FBI’s hate crime page directly before citing a year. The release date for a given year’s data shifts from cycle to cycle and typically lands sometime in the second half of the following year, so confirm what’s current before you write the number down.

Local Police Reports

Reports involving the applicant’s own facility, whether vandalism, attempted entry, threatening communications, or harassment on the property, are generally the strongest single category of evidence because they’re specific to the site. Most departments will provide copies to the original reporting party, often at no cost, and these belong at the top of any risk documentation file once they’re in hand.

Incidents at peer organizations nearby also carry weight under the “closely related organization” standard the IJ allows, but only with a date, a source, and enough specificity for a reviewer to verify them. A vague reference to “several peer synagogues in the region” carries no weight on its own. A dated, sourced account of a specific incident at a specific type of facility does, especially when the applicant explains why that incident reflects a risk to their own organization too.

Threats Received Directly

Threatening mail, calls, emails, or social media messages sent to the organization are the most specific evidence available, and also the most fragile. A voicemail deleted from the office phone system is gone for good. A screenshot of an email without its headers can’t be authenticated, since the headers are what show where the message actually originated.

Preserve the original artifact, not just a description of it: the physical item or a full scan for mail, the exported audio file for voicemail, the message with full headers for email, and a screenshot with the URL and timestamp visible for social media. For each one, log the date, the channel, who handled it, and whether it was reported to law enforcement. This log is one of the most credible pieces an NSGP risk documentation file can contain — a clean, contemporaneous record is hard to fabricate after the fact, which is exactly why reviewers tend to find it convincing.

Public Statements by Extremist Groups

When an extremist group has made a public statement naming the applicant’s organization, denomination, or community, it establishes a distinct and specific threat picture rather than a generic ideological one. These aren’t always available. When they are, useful sources include tracking from the Anti-Defamation League and the Southern Poverty Law Center, published DHS threat assessments, the FBI’s civil rights and hate crimes resources, and DOJ or U.S. Attorney press releases tied to prosecuted cases.

The file should store a summary of what the statement said and who it named, along with the source and date, not a reproduction of the extremist material itself. A reviewer doesn’t need to see the original propaganda to credit that a documented, sourced statement exists.

Denominational Security Agency Reports

A number of faith communities operate their own security agencies that publish incident summaries and threat assessments for member organizations: Secure Community Network for Jewish institutions, Catholic Mutual Group and USCCB resources for Catholic parishes and dioceses, the Sikh Coalition, CAIR for mosques and Muslim community centers, and similar denominational offices for other traditions. Because these agencies have direct visibility into incidents reported by their own member organizations, they tend to carry more specific evidentiary value for a Risk section than a national advocacy report covering the same ground from a distance. Cite the agency, the publication date, and the specific finding, not just the organization’s name.

Local News Coverage of Peer Incidents

Local news fills the gap between national data and an applicant’s own police reports by documenting incidents at peer organizations that the applicant can’t obtain a police report for directly. Favor the original local outlet over an aggregator or a national reposting, since a direct link is easier for a reviewer to verify. If an article has been paywalled or taken down, the Internet Archive’s Wayback Machine can preserve an accessible copy of the original page.

Visibility Evidence

The last category isn’t about incidents. It documents how visible the organization is: exterior signage, public-facing events, media coverage, and online presence. This matters directly to NSGP scoring, since the IJ’s Background section separately asks applicants to address the symbolic value of the site as a recognized institution that could make it a possible target. A highly visible institution serving a large, publicly identifiable community reads as a more plausible target than a low-visibility one with the same incident history, and it’s worth documenting deliberately rather than assuming a reviewer will infer it.

Organizing Your NSGP Risk Documentation File

Whatever structure you use, the file needs to make two things easy to find fast: every dated, sourced piece of evidence, and exactly where it came from. A simple index, one row per artifact, with the date, source, category, and a link or file location, is usually enough to let whoever writes the IJ pull citations without re-researching them.

The goal isn’t a particular filing system. It’s being able to answer, for every claim that ends up in the Risk section, “what’s this based on, and can I show it to someone if they ask.” Building an NSGP risk documentation file for the first time, especially the peer-incident and denominational research, generally takes longer than organizations expect. Treat it as its own project with its own timeline, not a task squeezed into the final week before a deadline.

What Reviewers Discount

These are the gaps that show up most often in a thin NSGP risk documentation file, and each one costs points even when the underlying risk is real:

  • National-only references with no local tie. A national increase in incidents, with no state, county, or denominational breakdown, doesn’t tell a reviewer anything about this facility.
  • Expired data. Citing hate crime figures or denominational reports several cycles old when more current versions are available.
  • Unsourced language. Phrases like “unprecedented threats” with no incident behind them read as opinion, not risk.
  • Undated incidents. A reference to a peer organization “experiencing an attack” without a date or source can’t be verified and generally won’t be credited.
  • Reused boilerplate. Language and incident references that appear, close to word for word, in filings from other organizations in the same denomination or region. Write from your own file, not someone else’s.
  • Unpreserved claims. “Multiple members have expressed concern,” with no record of when, by whom, or how it was documented.

What Solid NSGP Risk Documentation Looks Like in Practice

You don’t need a prior attack at your own facility to build a credible Risk section. Federal hate crime data, denominational reports, peer incidents at closely related organizations, and visibility evidence can support a well-documented file even when the organization itself has no incident history of its own, as long as the connection back to your organization is drawn explicitly rather than left implied.

Given that Risk carries more scored points than any other section of the IJ, and that both the SAA and FEMA can weigh in on how well it’s substantiated, it’s worth treating the underlying documentation as seriously as the narrative built on top of it. Most organizations already own pieces of this file, scattered across emails, board minutes, and old police contact records. The work is less about generating new evidence from scratch and more about consolidating what already exists and filling the real gaps.

What SGA Does

SGA builds NSGP risk documentation files as part of its NSGP and state security grant engagements, pulling together the federal data, peer incident research, and denominational sourcing that support a well-documented Investment Justification, and structuring it so it holds up if a reviewer asks for backup.

Still have questions about what counts as documented risk for your organization? We’re happy to help you think it through.

You can book a free consultation with SGA here.

Official Sources

Every claim in this guide traces back to a primary federal source. Confirm the current cycle requirements at the official URLs below before submission.

State Administrative Agencies publish state-specific NOFOs and submission portals. Confirm the current SAA contact for your state through the FEMA grants portal above.

NSGP risk documentation categories: hate crime data, police reports, threats received.

Table of Contents

Is Your Nonprofit
NSGP-Ready?

Before you apply for up to $600,000 in federal security funding, make sure your application has every required element. 

More Resources

The equipment is installed. The final invoice is paid. The three-year period of performance has ended and the project is, in every practical sense, done.
NSGP Closeout Requirements: What to Submit and When
NSGP Reimbursement: What the SAA Needs to Pay You

Unlock Your Free PDF

Just one quick step! Fill in your details below and your PDF will be ready to download.