BE Informed

Internal Controls for Small Nonprofits: Protecting Your Mission When Resources Are Thin

Written by Melissa Sikes | Oct 8, 2026, 12:00:02 PM

Thank you to everyone who joined us for our fall not-for-profit symposium, one of the three we hold each year. I'll be honest with you, as I was on the webinar: I set the agenda, and I put my session on internal controls first because I was fairly sure most of you were tuning in for the AI session that followed. For those who missed it, or who want a refresher, here is a recap of what we covered.

My session focused on internal controls for nonprofits, and especially for smaller nonprofits. We walked through the what and why of internal controls, the implications of fraud, key risk areas we see when we're out performing nonprofit audits, and how to establish controls when you have limited resources. We finished with a look at how AI features already built into many accounting platforms can help.

Start with the Nonprofit Cycle

Most of you know this cycle well, but it sets the stage for why controls matter. It starts with resources: donations, grants, sponsorships, and, for 501(c)(6) organizations, membership dues and assessments. Those resources fund your programs, which is where you carry out your mission. Your programs create impact in the community, and your measurable outcomes (how many pets were adopted, how many children were served) matter most. Doing good builds trust with donors, grantors, and the people who use your services. You earn that trust by being transparent and keeping good accounting records, and that trust brings in more resources, which in turn creates more impact.

Why Internal Controls Matter

When I talk about internal controls, I'm talking about prevention and detection. Fraud is part of that conversation, but more often than not the issue in an organization is errors, and errors are just as critical. Humans perform many of these processes, and humans make mistakes that can affect financial reporting or send resources out the door. Good controls help you:

  • Protect your resources, including cash, donations, and your people.
  • Keep your numbers accurate. A bank reconciliation that doesn't reflect what you actually have is no good to anyone.
  • Get information on time. I've seen nonprofits go months without reconciling their bank accounts, and you can't make informed decisions that way.
  • Stay accountable to stakeholders, including donors, grantors, and the families and individuals your mission serves.
  • Comply with laws. For example, if you go without filing your Form 990, you will have your exempt status revoked.
  • Make timely, well-informed decisions.

The Internal Control Framework

You may have seen the internal control framework as a diagram or a cube. It has been around since the early 1990s, but few people did much with it until after the Enron and WorldCom scandals and the creation of Sarbanes-Oxley. The components are numbered, but no single one is more important than the others:

  • Control environment: the tone at the top. A board that isn't active or meeting regularly, a CEO who doesn't hold staff meetings or encourage people to come forward, or the absence of a whistleblower policy can all signal a poor control environment.
  • Risk assessment: considering where things could go wrong when your organization - changes, such as turnover at a key level or new programs.
  • Control activities: the things you actually do, such as approvals, reconciliations, and IT access limits on who can make journal entries or record transactions.
  • Information and communication: getting the right data to the right people in a timely fashion.
  • Monitoring: confirming that your controls are actually working. Without monitoring, they may very well fail.

We polled attendees on which component is hardest to maintain, and responses were fairly even. My personal view is that control activities are one of the easier ones, because putting a process in place is straightforward. Making sure it works is much harder, and the control environment can sometimes sit a little outside your control.

Why Nonprofits Struggle More with Controls

  • Boards are voluntary and rotate, so you may have a strong chair or treasurer one year and lose them to term limits the next.
  • Staffing is limited. Many nonprofits have a one-person accounting department, maybe two if they're lucky.
  • Budgets are tight, and accounting doesn't drive the mission the way programs do, so money for new software is often scarce.
  • A culture of trust can become a block to setting up the right controls. People assume no one would steal from an organization doing good work, or from a church. Even if you trust someone completely, you still want controls in place, and written policies and procedures are invaluable for continuity when that person retires or something happens to them.
  • Informal systems, such as donor software that doesn't talk to the financial software.
  • Lack of IT oversight, including shared passwords that let anyone do anything in your system.
  • High turnover, especially in program areas.

Preventive vs. Detective Controls

Preventive controls stop wrongdoing, whether an unintentional error or fraud, from happening in the first place. Detective controls help you find something after it has occurred. From an IT perspective, password controls and module restrictions are preventive, while reviewing a user log and seeing that someone went into a module they shouldn't have at 5:56 p.m. is detective. Preventive controls are the ones we really want in place.

The Fraud Triangle and the Two Types of Fraud

The fraud triangle applies to all types of organizations, for-profit and nonprofit alike. Its three sides are:

  • Opportunity: where internal controls come into play. Missing, unenforced, or unmonitored controls, too much trust, and a poor tone at the top all create opportunity.
  • Rationalization: "I'm not getting paid what I'm worth," "Nobody's going to miss this," or "I'll pay it back."
  • Pressure and motivation: debt, greed, lifestyle needs, gambling or drugs, and internal pressure to earn a bonus, keep a job, or meet a budget. If someone's lifestyle changes, it's worth paying closer attention.

Fraud generally falls into two categories. Misappropriation of assets is theft: cash, checks, inventory (a thrift store, for example), payroll fraud through fictitious employees or unapproved pay rate changes, credit card misuse, expense reimbursement scams, and stolen intellectual property. On credit cards, not everyone in your organization needs one, and we've seen people, even at high levels, use them for personal purposes. Whether or not they intended to pay it back, that's a line better not crossed.

Fraudulent financial reporting includes fictitious revenue (for example, when a department fears its program will be cut if it misses budgeted revenue), shifting revenue or expenses between years, misstating asset values, underreporting liabilities, and, a big one for nonprofits, treating restricted donations as unrestricted. Sometimes that last one is an error, but when a restricted gift is intentionally moved to unrestricted because it's needed for operations, that is a form of fraud.

We also polled attendees on an Association of Certified Fraud Examiners survey question: which department accounts for the most fraud cases across all organization types? The answer was operations, because those employees often have access to many areas of the organization. Accounting came next, and purchasing was fairly high as well. Sales was a very small percentage.

Where Control Failures Concentrate, and What to Do About It

Based on what we see as auditors, control failures tend to concentrate in cash and donations, disbursements and credit cards, payroll, grants and restrictions, financial reporting, and IT. Here's what we discussed in each area.

Contributions revenue. (If you're a 501(c)(6), read this as membership revenue.) Contributions are often over- or under-reported, frequently because accounting and development aren't talking. Early in my career, on my first audit as the senior in charge, I asked whether there were any grant letters at year end and was told no. When I presented the draft financials, the executive director mentioned money that had just come in, opened his desk drawer, and pulled out two unconditional grants dated in May for a June 30 year end. Development had handed them to him, and the accountant had no idea. We had to take the statements back and fix them. Controls that help:

  • Reconcile development reports to accounting. Some differences, such as bequests that aren't recorded until the donor has passed, are known reconciling items and that's fine.
  • Every time development receives a grant, give accounting a copy. Development staff may not know the accounting nuances, such as conditions that affect when a grant is recorded.
  • Never write off pledges or grants receivable without proper authorization and approval. Accounting should not make that decision alone.

Cash receipts. Risks include skimming (which is admittedly hard to catch, especially when volunteers collect cash at events), delayed deposits around year end, check forgery, theft at events, and simply having too many ways to give. One client last year had seven different ways to donate, and the accountant was forgetting to reconcile one of them. Keep giving open enough for donors but not open for error. The classic control is for someone independent of accounting to open the mail, make a list, and stamp checks with a restrictive endorsement; accounting prepares the deposit; someone else takes it to the bank; and an independent person compares the deposit records to the mail log.

Years ago, when I volunteered to help at my church, I was asked to count the Sunday offering, and my husband and I were left alone to do it. I knew I wouldn't take anything, but I also knew I couldn't prove it if I were ever accused. I told them I wouldn't do it again unless there was a third person, dual sign-off, and a lockbox, and they changed the process. If you're a CFO or accountant, you should want internal controls. They protect you as well.

Cash disbursements and accounts payable. Watch for unauthorized payments, duplicate payments, fictitious vendors, and people running personal expenses (a mortgage or car payment) through the organization. In our poll, a majority of attendees were not using AP or bill pay software such as Bill.com or Ramp, while about 36% were. Controls that help:

  • Supervisory approval of invoices.
  • Payments only to approved vendors, with the ability to add vendors reserved for people who don't write the checks.
  • Two signatures on checks over a set amount, or a board signature. I have seen banks miss this and clear a check with one signature, but it's still a very good process.
  • Limited banking access and dual approval on any wires or ACH payments. Once money is wired out, it's next to impossible to get back. An attendee also asked about positive pay, which is very useful and used by many of our clients.

Credit cards and expense reports. We're not suggesting you stop giving program directors credit cards, but monitoring is essential. Risks include personal purchases, missing documentation of business purpose (if 60 pairs of shoes from DSW were a program expense, you need to be able to show that in an IRS audit), excessive spending, split transactions to stay under an approval threshold, and small recurring charges. Controls that help:

  • Not everyone needs a credit card.
  • Require receipts and the business purpose for every expense. Tools like Bill.com, Stampli, and Ramp make it easy to scan receipts.
  • Have someone independent review and approve statements and expense reports, including the CEO's, typically the treasurer or board chair.
  • Disable cash advances, and cancel cards when someone leaves.

Payroll. Fictitious employees are less common in small nonprofits where everyone knows everyone, but risks also include unapproved pay rate changes or bonuses, unsupported overtime, improper allocations, and incorrect tax calculations. One client told us they reviewed the payroll register before and after it went to the provider, but during our audit the CFO discovered the wrong amounts had been deducted. A digit had been mis-keyed, and no one had reviewed it beforehand. It was an unintentional error, but a mess to fix. Controls that help:

  • Document pay rates and bonuses in personnel files (electronic is fine).
  • Have upper management, or the board, approve the PTO policy.
  • Require supervisory approval of timesheets and overtime.
  • Have someone other than the person keying payroll review payroll change reports. Segregation of duties means no one person walks a transaction all the way through the organization.
  • Compare employee counts from one payroll to the next and review for unusual amounts.

IT. In an audit, we're mainly concerned with access. The famous exchange goes: Does the CEO have access to the accounting module? Yes, but he never uses it. But he could. That's where the control fails. If someone doesn't need access, don't give it. Also use multi-factor authentication where possible, discourage password sharing, limit administrator rights, remove access immediately when employees leave, adopt an acceptable use policy that covers IT and AI, carry cyber insurance, and have a disaster recovery plan that you actually test. Ongoing education, like the short periodic trainings from KnowBe4, helps people spot scams. Just last Friday I received an official-looking email, apparently from the board chair of a large Richmond nonprofit where I serve, asking for support for a new effort. I called him immediately. He hadn't sent it. These scams are getting more and more sophisticated.

Tidbits from Your Friendly Auditors

If you serve on a nonprofit board, there are signs that tell you whether the organization has good controls without having to ask:

  • An active board of directors, which usually demonstrates proper monitoring.
  • All accounts reconciled within a few weeks of month-end close.
  • Monthly financial statements delivered no later than the last day of the following month. Between the 15th and 20th is ideal. If you're a CEO or board member and you aren't receiving them, ask why. Your staff may simply need help, and it's better to step in now than let them fall a year behind.
  • Variances in the statement of activities that staff can explain. On the board I serve, I always review budget-to-actual and current-year-to-prior-year expense variances at finance committee meetings.
  • Very few year-end audit adjustments.
  • Reaching out to the audit firm before recording unusual transactions. I love it when clients send a new grant agreement and ask me to confirm the restrictions and period. It usually doesn't take long, and we'd rather get it right up front.

Doing More with Less

Nonprofits tend to be short-staffed. (I used a clip from Office Space here, which, I realized while building the slide, features a fraud scheme built on fractional cents that no one was supposed to notice.) If you're fully volunteer or have only one staff member, you'll likely need to pull in board members, ideally a few with financial backgrounds, for oversight rather than hours of accounting work:

  • Send bank statements directly to the treasurer, or have the treasurer review online activity for anything that doesn't look right.
  • Have the board regularly review budget-to-actual variances as part of the board package.
  • Use a lockbox or electronic deposits. Less cash is better, especially with one person in the office day to day.
  • Require board approval for major transactions such as fixed asset purchases, taking on debt, moving money into investments, or acquiring another organization.
  • Route second approvals for wires or large purchases, and the CEO's expense reports, to the treasurer.
  • Have the board review year-end financials and approve audited or reviewed statements, as well as the Form 990, which asks whether the board reviewed it before filing.

A Segue into AI

In our poll, the majority of attendees said they are not using AI in a significant way, about 35% said they are, and about 7% weren't sure. That's about what I expected, and I suspect the smaller the organization, the less AI is being used. But many of you may already have AI features you haven't explored:

  • QuickBooks Online often autofills and codes transactions based on prior activity, can match incoming bank items to existing donors, and has an AI chat feature for creating reports and donor communications. You still have to verify the output.
  • Sage Intacct offers similar features and flags odd general ledger transactions you may want to look into.
  • Bill.com, Ramp, and Stampli use AI to pre-fill information from scanned receipts, and they aren't terribly cost prohibitive.
  • Microsoft Copilot and Claude are very powerful. You can run ratio and variance analysis, search for duplicate invoice numbers or vendors with questionable addresses, and analyze credit card trends to see where spending has gotten out of hand.

From the Q&A

How can a small nonprofit with a budget around $200,000 get a low-cost review or audit? Reviews and audits are fairly expensive, and reviews typically run about half the cost of an audit. I have some ideas on this and took the question offline, so please reach out.

Is it okay for the CFO to approve the CEO's expenses and credit card? I think so, depending on the relationship. If the CFO is in tune with the board and would comfortably question the CEO or go to the board when something isn't right, that can work. It may not be as strong as board-level approval, but I have clients who do this where I've seen that comfort demonstrated.

If you think of a question later, even weeks or months from now, my contact information is in the session materials. I'm always happy to help.