• June 2026

What Counts as Documented Risk for NSGP: Building the Risk Documentation File

Documented risk is the foundation of the Nonprofit Security Grant Program (NSGP) Investment Justification (IJ). Reviewers score what is verifiable. They do not score what an applicant states about its own threat picture without a source attached. An IJ that claims a credible threat without a dated incident, a named entity, or a citation reads to a scorer as a personal opinion, not as documented risk.

This guide covers the file that has to exist before the IJ is written: the risk documentation library. It walks through the seven categories of source material NSGP reviewers recognize, where each source comes from, how to preserve and cite each one, and how to structure the file so the IJ author (internal or external) can pull from it without delay.

The IJ writing itself is covered separately. This article is about the package of evidence that sits behind every sentence of a fundable risk section.

The Seven Categories of Risk Documentation NSGP Reviewers Recognize

NSGP scorers read the risk section against the current Notice of Funding Opportunity (NOFO) rubric published at https://www.fema.gov/grants/preparedness/nonprofit-security. The rubric does not list source types by name. It does, however, reward specificity, geographic relevance, recency, and verifiability. Across funded IJs, seven categories of source material recur:

  1. Federal hate crime data (FBI Uniform Crime Reporting program)
  2. Local police reports filed by the applicant or by peer organizations in a defined radius
  3. Documented threats received directly by the organization (mail, phone, email, social media)
  4. Public statements by extremist groups naming the organization, denomination, or community
  5. Denominational security agency reports (Secure Community Network, Catholic Mutual Group, others)
  6. Local news coverage of peer incidents within a defined radius and time window
  7. Symbolic and operational visibility evidence (signage, public events, media coverage, online presence)

A funded risk file usually contains documentation from at least four of these categories. Files built from only one category (typically FBI national data) score in the lower half of the funding distribution because reviewers cannot tie the national pattern to the specific facility.

The rest of this article walks through each of the seven sources: where it comes from, how to extract the parts NSGP cares about, and how to preserve the artifact so it can be cited.

Source 1: FBI Hate Crime Statistics (How to Pull the Report for Your Bias-Motivation Category and County)

The Federal Bureau of Investigation publishes annual hate crime statistics through the Uniform Crime Reporting (UCR) program at https://www.fbi.gov/services/cjis/ucr/hate-crime. The data is reported by participating local and state law enforcement agencies and aggregated nationally, by state, and by reporting agency.

For NSGP, the relevant data extraction has three components:

Bias-motivation category. Pull the rows that match the applicant’s faith, ethnic, or ideological category (anti-Jewish, anti-Catholic, anti-Muslim, anti-Sikh, anti-Hindu, anti-Black, anti-LGBTQ, anti-other-Christian, and so on). The published categories are listed on the FBI hate crime page.

Geographic scope. Pull data for the applicant’s state and, where available through the FBI Crime Data Explorer (linked from the FBI Hate Crime hub), the applicant’s county or metropolitan statistical area. County-level data carries more weight than state-level data in an NSGP risk section.

Time window. Pull the most recent three full calendar years of data. NSGP reviewers in a 2026 cycle expect 2022, 2023, and 2024 figures, since 2025 data is typically released in late 2026. Always confirm the most recent published year at the FBI page before citing.

To preserve the artifact, save the report or data export as a PDF with the URL and access date visible. The Crime Data Explorer allows direct CSV downloads. Keep both the human-readable PDF and the raw CSV in the documentation file.

Common mistake: citing the national total without the state and county breakouts. A 2024 figure of “10,000+ hate crime incidents nationally” is true but unscored. The same data filtered to the applicant’s bias-motivation category, state, and county produces a number a reviewer can attach to the facility.

Source 2: Local Police Reports (Filed by Your Organization or Peer Organizations Within a Defined Radius)

Local police reports are the highest-weighted source category in NSGP risk documentation when the incident occurred at the applicant facility or at a denominationally or symbolically similar peer facility within a defined radius (commonly 25 to 50 miles for urban applicants, 50 to 100 miles for rural).

Two types belong in the file:

Reports filed by the applicant organization. Every report the organization has filed in the past five years, regardless of disposition. Vandalism, trespass, suspicious-person observations, threatening communications, attempted entry, attempted theft of religious items, harassment of members on the property, all qualify. Pull report numbers, dates, and one-line summaries directly from the police department records division. Most agencies provide certified copies for a small fee or free of charge to the original reporting party.

Reports filed by peer organizations. These require more effort. Three working channels:

  • Direct contact with the security committee chair of nearby peer organizations (often the same denomination or community network)
  • The local Joint Terrorism Task Force (JTTF) liaison through the FBI field office (https://www.fbi.gov/contact-us/field-offices)
  • Local law enforcement community-relations officers who track bias-incident calls by location type

For each peer incident cited, the file should contain the date, the responding agency, the incident category, the peer organization’s name (or a redacted identifier if the peer requests confidentiality), and the source channel.

Reviewers discount peer incidents cited without dates or without a verifiable source channel. A statement that “several peer synagogues in the region have experienced incidents” carries no weight. A statement that “between January 2024 and December 2025, four bias-motivated incidents were reported at Jewish facilities within a 35-mile radius (sources: [agency name] community-relations log, peer organization security committees)” carries full weight.

If your organization has fragments of risk documentation across emails, board minutes, and police contact records but no consolidated file, the time-cost to assemble it is the largest single block in most internal NSGP timelines. We build risk documentation files as part of every IJ engagement. Book a free consultation with SGA here.

Source 3: Documented Threats Received (Mail, Phone, Email, Social Media): How to Preserve and Cite

Threats received directly by the organization are the most specific category of evidence available. They are also the most fragile. A threatening voicemail deleted from the office phone is unrecoverable. A threatening email forwarded only as a screenshot without headers cannot be authenticated.

Standard preservation protocol:

Mail. Photograph the envelope and contents at receipt. Bag in clear plastic. Log the date received, the staff member who opened it, and the postmark. File the original with the law enforcement report (if filed). Keep a high-resolution scan in the risk documentation file.

Phone. Most VoIP and modern landline systems retain voicemail audio. Export the audio file (typically WAV or MP3) along with the caller ID metadata. For calls answered live, the staff member who took the call writes a contemporaneous note (within 24 hours) with date, time, caller ID if displayed, and verbatim language as best recalled.

Email. Save the message in its original format with full headers (in Gmail, “Show original”; in Outlook, “View source”). Headers contain the originating IP and routing path, which authenticate the message. A screenshot alone is not enough.

Social media. Use the platform’s built-in reporting and archive features. Screenshot with URL and timestamp visible. Capture the originating account handle and any prior posts by the same account that establish the threat context. Platforms regularly delete accounts that post threats; the local copy is what survives.

For every preserved threat, the file should contain: date received, channel, preserved artifact, staff member who handled, whether reported to law enforcement (and report number if so), and current status. A clean threat log is one of the strongest single artifacts in an NSGP risk file because it is impossible to fabricate retroactively and easy for a reviewer to verify.

Source 4: Public Statements by Extremist Groups (Where to Find and How to Document Responsibly)

Extremist group statements that name the applicant organization, its denomination, its leaders, or its community establish a documented threat picture distinct from generic ideological hostility. They are not always available, but when they exist they carry significant weight.

Working sources:

  • Anti-Defamation League (ADL) extremism tracking, accessible through the ADL Center on Extremism public reporting
  • Southern Poverty Law Center (SPLC) hate group and extremist activity tracking
  • The Department of Homeland Security publishes periodic threat assessments at https://www.dhs.gov/ that summarize extremist movement activity by ideology and region
  • The FBI civil rights and hate crimes resources at https://www.fbi.gov/investigate/civil-rights/hate-crimes
  • Local U.S. Attorney’s Office press releases for indictments involving extremist activity in the region
  • Court records and DOJ press releases for prosecuted threats

Documentation responsibility matters here. The file should never amplify the extremist content itself. The artifact stored is a redacted summary or a third-party report describing the statement, not a direct copy of propaganda. For each citation, record: source organization, publication date, URL, what the statement said in summary form, and the named target (community, denomination, region, or individual organization).

Reviewers do not need to read the source extremist material to score the risk section. They need a verifiable citation showing the documented public statement exists and ties to the applicant.

A balanced risk file typically contains one to three extremist-statement citations when the underlying material is available, and zero when it is not. Padding this section with weak national references hurts the score.

Source 5: Denominational Security Agency Reports (Secure Community Network, Catholic Mutual Group, Others)

Several faith communities and ethnic groups operate dedicated security agencies that publish threat assessments, incident summaries, and trend reports for member organizations. Reviewers recognize these agencies as authoritative for their respective communities.

The most commonly cited:

  • Secure Community Network (SCN) for Jewish institutions. Publishes regional threat assessments and incident reports through its member portal and public briefings.
  • Catholic Mutual Group / USCCB security resources for Catholic parishes, schools, and dioceses.
  • Sikh Coalition for Sikh gurdwaras.
  • Council on American-Islamic Relations (CAIR) civil rights reports for mosques and Muslim community centers.
  • National Council of Churches security resources for member Protestant denominations.
  • Hindu American Foundation for Hindu temples and community organizations.
  • Diocesan, synod, or denominational security offices that publish regional briefings.

For each citation: source agency, publication date, report title, URL or member-portal reference, and the specific paragraph or finding referenced. If the source is a member-portal document, save a PDF copy in the risk file with the access date.

Denominational reports are particularly useful for establishing trends a single applicant cannot document alone (for example, a 40 percent increase in reported incidents at peer synagogues in a region over the prior calendar year). Reviewers weigh denominational reports more heavily than national advocacy organization reports because the issuing body has direct visibility into member organization incidents.

Source 6: Local News Coverage of Peer Incidents (Radius, Recency, Formatting Citations)

Local news coverage fills the gap between national hate crime data and applicant-specific police reports. It documents that incidents occurred at peer organizations even when the applicant cannot obtain the peer’s police report directly.

Working parameters:

Radius. Use the same radius applied to peer police reports (25 to 50 miles urban, 50 to 100 miles rural). State or regional incidents outside that radius can be cited briefly but should not dominate the section.

Recency. Two-year and three-year windows are standard. Incidents older than five years lose weight unless the incident itself was severe enough to remain regionally significant.

Source quality. Local newspaper, regional TV station, and established local news website coverage carries more weight than aggregator reposts or social media summaries. A direct link to the original local outlet is preferred. If the outlet has paywalled or removed the original article, archive it through the Internet Archive (https://web.archive.org/) and cite the archived URL.

Citation format for the risk documentation file:

[Date of incident] | [Peer organization name or descriptor] | [City, State] | [Brief incident summary] | [Source outlet] | [URL or archive URL] | [Date accessed]

A consolidated peer-incident table with eight to twelve entries covering the prior three years is a common feature of funded IJs. The same table built without dates, without URLs, or with national outlets standing in for local ones scores noticeably lower.

Source 7: Symbolic and Operational Visibility (Signage, Public Events, Media Coverage, Online Presence)

The seventh source category is internal to the applicant organization and documents visibility, not incidents. Reviewers consider visibility because a more visible organization carries a higher risk profile than a less visible one within the same denomination or community.

Components of a visibility file:

Signage. Photographs of exterior signage identifying the organization, denomination, or community. Include date of photograph, facing direction (north-facing, south-facing), and approximate distance from the nearest public roadway.

Public events. A calendar of the prior twelve months of public-facing events with attendance figures, public-promotion channels used (social media, press releases, denominational newsletters), and whether the event was open to the general public or restricted to members.

Media coverage. Press mentions, interviews, op-eds, or news features involving the organization or its leaders in the prior two to three years. Include date, outlet, headline, and URL.

Online presence. Website URL, public social media accounts with follower counts, and any online directories or denominational rosters that publicly identify the facility.

Recurring religious or community events. Identify high-occupancy dates that elevate consequences and visibility simultaneously (High Holy Days, Christmas Eve, Eid prayers, Vaisakhi, major festivals, graduation ceremonies).

Visibility documentation establishes why the facility is a plausible target relative to similar facilities. It does not replace the other six source categories, but it links them: a high-visibility Reform synagogue serving 400 families in a metropolitan area with documented regional antisemitic incidents reads as a higher-risk target than the same incident pattern around a low-visibility chavurah that meets in members’ homes.

How to Structure the Risk Documentation File (Folder Structure, Naming Convention, Citation Format)

A clean risk documentation file makes the IJ writing faster and the SAA or FEMA verification (if requested) immediate. A messy file slows internal drafting by days and creates uncertainty about whether a claim has a source behind it.

Recommended folder structure:

/risk_documentation_file/
  /01_fbi_hate_crime_data/
  /02_local_police_reports/
    /our_facility/
    /peer_facilities/
  /03_documented_threats/
    /mail/
    /phone/
    /email/
    /social_media/
  /04_extremist_statements/
  /05_denominational_reports/
  /06_local_news_peer_incidents/
  /07_visibility_evidence/
    /signage_photos/
    /event_calendar/
    /media_coverage/
    /online_presence/
  /00_master_citation_index.xlsx

Naming convention for individual files:

[YYYY-MM-DD]_[source_category]_[descriptor]_[organization_or_outlet].pdf

Example: 2024-11-12_police_report_threatening_letter_ourfacility.pdf

The master citation index is a single spreadsheet with one row per artifact. Columns: ID, date, category (1 through 7), source, descriptor, file path, URL (if applicable), date accessed, scored relevance (high/medium/low), and notes. The IJ author pulls from this index when writing the risk section, citing artifacts by ID.

A risk file structured this way takes one experienced person roughly 40 to 80 hours to assemble for a single-site applicant, more for multi-site applicants. Internal teams typically underestimate this by half.

What Reviewers Discount

Across denial pattern analysis, the same risk-file weaknesses recur in applications that scored above eligibility but below the funded line:

National-only references without a local tie. “Hate crimes against [community] increased nationally in [year]” with no county, state, or denominational-regional breakout.

Expired data. FBI figures cited from five or six years prior when current data is published. Denominational reports cited from cycles two or three NOFOs old.

Exaggerated language without source. “Our community faces unprecedented threats” with no incident behind the adjective. Adjectives without citations are scored as opinion.

Undated incidents. “A peer organization in our region experienced an attack” without a date, location, or source. Reviewers treat undated incidents as unverifiable.

Peer incidents borrowed verbatim from another applicant. Reviewers see identical paragraphs in multiple applications from the same denomination or region. The narrative reads as boilerplate, and the score drops accordingly.

Internal communications cited without preservation. “Multiple members have expressed concern” with no documentation of when, by whom, or in what form. Reviewers do not score impressions.

Social media screenshots without URL or timestamp visible. Unverifiable and easily fabricated. The platform’s built-in archive or share-link feature produces a citable URL; the screenshot alone does not.

The risk file is built to anticipate these discount patterns. Every artifact in the file should be traceable to a date, a source, and a preservation method that lets a reviewer verify the claim if asked.

Frequently Asked Questions

Does every claim in the risk section need to cite a file in the documentation library?

Yes. The IJ character limit makes inline citations difficult to format densely, but every named threat, every dated incident, every statistic, and every peer reference should map to an artifact in the documentation file. Reviewers do not require the file at submission, but SAAs occasionally request supporting documentation during their review, and applicants who cannot produce it are downgraded or removed from the SAA-forwarded pool.

How recent does the documentation need to be?

The standard window is the prior three calendar years for incident data and the most recently published year for federal statistics. Older incidents can be cited when they are severe enough to remain regionally significant (a fatal attack at a peer organization seven years prior is still relevant; minor vandalism seven years prior is not). The visibility documentation (Source 7) does not have a recency requirement beyond reflecting the current operational profile of the facility.

Can we use the same risk documentation file for federal NSGP and state programs?

The underlying artifacts transfer. The structure of the risk narrative changes per program because state applications (NY SCAHC, CA CSNSGP, NJ NSGP, IL NSGP-IL, and others) have their own character limits and section structures. The file itself is portable; the writing built on top of it is rebuilt per program. Federal cycle artifacts pulled in the spring can support state cycle applications later the same year without re-pulling, as long as the citations are still within the recency window.

What if our organization has never experienced an incident and has no police reports of its own?

Source 1 (FBI data) does not require a prior incident at the facility. Sources 4, 5, 6, and 7 also do not require a prior incident at the facility. A funded risk file can be built entirely from federal data, denominational reports, peer news coverage, and visibility evidence when the facility itself has no incident history. The risk section explains why the facility is plausibly at risk based on community-level pattern and denominational visibility, not why it has already been attacked.

Who in the organization should own the risk documentation file?

Most commonly the security committee chair, executive director, or facilities manager, with support from the rabbi/pastor/imam/leader for the visibility section and from the office administrator for the threat log. The file is built once in detail, then maintained quarterly. The maintenance overhead is roughly four to eight hours per quarter once the initial file is built.

How much of the file does a grant writer or consultant rebuild versus pull from what we provide?

A specialist working with an applicant that has no existing file rebuilds the whole library. A specialist working with an applicant that has a partial file (typically the police-report and visibility components) pulls the federal data, denominational reports, and peer news coverage, then formats everything into the master citation index. Either pattern produces the same scored result; the time allocation differs.

What We Do

Security Grant Advisors builds risk documentation files for nonprofits applying to federal NSGP and state security grant programs. The work covers all seven source categories: federal hate crime data extraction by bias-motivation and county, peer police report sourcing, threat preservation and logging protocol, extremist-statement citation, denominational report aggregation, local news radius mapping, and visibility evidence assembly.

The file is built to survive scoring (named threats, dated incidents, sourced citations, denominational visibility, location-specific peer events) and to support the IJ author through the writing stage and any post-submission verification requests from the State Administrative Agency.

If your nonprofit is building a risk documentation file for a 2026 or 2027 NSGP application and wants the package structured to survive scoring (named threats, dated incidents, sourced citations, denominational visibility, location-specific peer events), SGA assembles the risk file alongside the IJ draft. You can book a free consultation with SGA here.

Official Sources

Every claim in this guide traces back to a primary federal source. Confirm the current cycle requirements at the official URLs below before submission.

  • FBI Hate Crime Statistics (UCR): https://www.fbi.gov/services/cjis/ucr/hate-crime
  • FBI Civil Rights and Hate Crimes: https://www.fbi.gov/investigate/civil-rights/hate-crimes
  • FBI Field Offices (JTTF and community-relations contact): https://www.fbi.gov/contact-us/field-offices
  • FEMA Nonprofit Security Grant Program (NSGP): https://www.fema.gov/grants/preparedness/nonprofit-security
  • U.S. Department of Homeland Security: https://www.dhs.gov/
  • Internet Archive (for preserving paywalled or removed local news coverage): https://web.archive.org/

State Administrative Agencies publish state-specific NOFOs and submission portals. Confirm the current SAA contact for your state through the FEMA grants portal above.

Table of Contents

Is Your Nonprofit
NSGP-Ready?

Before you apply for up to $600,000 in federal security funding, make sure your application has every required element. 

More Resources

How to Appeal an NSGP Denial: What Works and What Does Not
Church Security Grants: Federal NSGP + State Programs for Christian Congregations in 2026

Unlock Your Free PDF

Just one quick step! Fill in your details below and your PDF will be ready to download.