FAQ
Real answers about grant compliance training, cybersecurity assessments, and organizational readiness for tribal governments and grant-funded organizations.
General Questions
Ravenkey helps tribal governments, victim services programs, housing authorities, and nonprofits build operational capability through compliance training, cybersecurity assessments, and organizational readiness support. We focus on three areas: (1) grant compliance training and readiness support — so your team can manage federal grants, pass audits, and maintain funding eligibility, (2) cybersecurity and technology assessments — practical, NIST- and CIS-aligned evaluations that identify vulnerabilities before they become problems, and (3) organizational readiness and technical assistance — workshops, risk mapping, and 90-day remediation roadmaps that connect compliance requirements to daily operations. Our co-founder Kari developed the actual OVC compliance framework used by a tribal government, so we're not guessing — we've done this work in a tribal setting.
Tribal governments, tribal victim services programs (including OVC-funded programs), housing authorities, Native nonprofits, village councils, and municipalities across the country. Most of our clients are organizations serving communities with limited access to specialized compliance and IT support. Our focus and expertise is built around tribal organizations.
We're an Alaska-based company serving tribal organizations across the country. We understand the connectivity, logistics, and compliance conditions that tribal organizations face — because we live in them. This isn't abstract for us. We built our support model around serving organizations with unique infrastructure needs, so there's no learning curve on your end. We support clients nationwide for OVC compliance, grant program development, and cybersecurity services.
Reach out through our contact page, email us at info@ravenkey.org, or call 907-444-7150 or 907-290-1400. We'll schedule a free, no-obligation call to learn about your organization, your current compliance or IT situation, and what you need. From there we'll provide a clear scope of work with fixed pricing — no surprises, no pressure. We typically respond within 24 hours.
OVC Compliance & Grants
OVC compliance means meeting all the reporting, documentation, policy, and program requirements that come with Office for Victims of Crime (OVC) grant funding. If your organization receives VOCA or other OVC funds, you're required to demonstrate compliance with federal regulations including 2 CFR Part 200 (Uniform Guidance) and specific OVC terms and conditions. Non-compliance can mean funding suspensions, paybacks, or losing eligibility for future grants. We help organizations build and maintain the compliance framework they need so funding isn't at risk.
OVC funding through the VOCA formula grant program is available to all states and territories, and tribes may receive funding as subawards from their state or directly through the OVC Tribal set-aside program. Eligibility depends on whether your organization provides victim services and whether your state's administering agency includes tribes in their distribution plan. The best way to find out is to take our Organizational Readiness Assessment — 15 questions that will give you a clear picture of where you stand. We can also help you determine eligibility during a free consultation.
Grant writing is the process of applying for funding — writing narratives, preparing budgets, submitting applications. Grant compliance is what happens after you get funded: meeting reporting deadlines, maintaining proper documentation, following federal procurement rules, tracking allowable costs, and demonstrating that you're doing what you said you would. Many organizations can find a grant writer, but far fewer have the internal capacity to manage compliance once the award is made. We focus on compliance and program development — the ongoing work that keeps your funding safe. We can also help with grant program development as a standalone service if you need application support.
It varies by organization and grant, but typically it includes: developing and maintaining compliance policies (financial management, internal controls, conflict of interest, recordkeeping), setting up document management for evidence collection and audit readiness, preparing progress and financial reports, tracking allowable costs and cost allocation, managing subrecipient monitoring if you pass funds through, and staying current with federal regulatory changes. We scope this based on your specific grant portfolio — you don't pay for what you don't need. The actual time commitment from your staff is much lower than trying to do it alone because we handle the documentation and reporting structure.
Yes. Many of our clients already have someone writing grants — what they're missing is the compliance infrastructure to manage awards once they get them. Grant writing and grant compliance are different skill sets, and it's rare to find one person who excels at both. We can step in on the compliance side while your grant writer focuses on applications. Our compliance package includes policy development, evidence collection frameworks, reporting templates, and ongoing support to keep you audit-ready.
Training & Capability Building
We offer three capability areas, delivered as hands-on training and technical assistance — not slide decks: (1) Grant Compliance & Readiness Support — OVC and DOJ compliance alignment, policy gap analysis, documentation readiness for reporting, compliance risk assessments, and PMT/JustGrants/ASAP.gov reporting support. (2) Cybersecurity & Technology Assessment — NIST- and CIS-aligned security posture evaluations, data protection and access control review, MFA and account governance, Microsoft 365 / Google Workspace security audits, and incident response readiness assessments. (3) Organizational Readiness & Technical Assistance — compliance + IT operational readiness workshops, risk mapping and control identification, 90-day remediation and capability-building roadmaps, staff training on compliance operations, and executive and board-level reporting support. See the Training page for full details.
Program directors, grant managers, finance staff, compliance officers, executive directors, tribal administrators, and IT leads — anyone responsible for grant compliance, operational security, or technology governance. Training is designed for the staff who actually do the work, not external consultants. We also offer executive-level sessions for leadership and boards who need to understand compliance positions without the operational detail.
Training is delivered onsite at your location or remotely via video conference — whichever works best for your team. For remote sessions, we use video conference with screen sharing and documentation provided in advance. Sessions are recorded so staff can review later. We're experienced with the connectivity conditions tribal organizations face — variable bandwidth, intermittent access, satellite links. We structure sessions so they work with your actual connectivity, not against it. Materials are distributed as PDFs and shared documents that work offline for remote participants. If connectivity drops during a remote session, we pick up where we left off — no lost time, no frustration. Onsite training is available for organizations that prefer in-person engagement, and we work with your schedule and logistics to make it practical.
Every engagement is tailored to your specific grant portfolio, compliance obligations, technology environment, and operational structure. We don't deliver generic curriculum — we base the training on your actual policies, systems, reporting requirements, and funding landscape. Before we start, we review your grant agreements, compliance documentation, and IT environment so the training addresses real gaps, not theoretical ones. The outcome is capability your team can use immediately — not a certificate and a binder that sits on a shelf.
Yes. Staff training on compliance procedures, data protection, financial controls, cybersecurity awareness, and reporting requirements is often required under federal grant terms — including OVC and DOJ awards. Our training includes documentation you can include in your audit evidence package: session outlines, attendance records, competency checks, and training completion summaries. Auditors and grant monitors look for evidence that staff understand their compliance responsibilities — our training provides that evidence in a defensible format.
Cybersecurity
Yes, and here's why: small tribal offices are increasingly targeted by ransomware and phishing attacks because attackers know these organizations have limited defenses. A single ransomware incident can lock you out of all your grant files, financial records, and client data — potentially triggering a data breach notification requirement and putting your grant funding at risk. A cybersecurity assessment identifies your vulnerabilities before an attacker does. For OVC grant recipients, it's also increasingly expected as part of overall compliance. Our assessments include a vulnerability scan, policy gap analysis, and a prioritized remediation roadmap so you know exactly what to fix first.
A ransomware attack can lock you out of grant files, financial records, and victim data simultaneously — potentially triggering breach notification requirements under federal and state law. If those systems contain OVC-funded program data, you may face reporting obligations to OVC, your state administering agency, and possibly HHS or FBI. Beyond the immediate operational disruption, a breach can trigger audit findings, compliance remediation requirements, and in severe cases, funding suspension. With average tribal breach costs at $4.88 million per incident, the financial and compliance consequences can far exceed the cost of prevention. The good news: basic controls like MFA, offline encrypted backups, and an incident response plan prevent the majority of attacks, and every one of those is an allowable use of OVC grant funds.
Still have questions?
We answer every inquiry personally — usually within 24 hours.
Call us: 907-444-7150 or 907-290-1400 · info@ravenkey.org