Thank you to everyone who joined us for our fall not-for-profit symposium, one of the three we hold each year. I'll be honest with you, as I was on the webinar: I set the agenda, and I put my session on internal controls first because I was fairly sure most of you were tuning in for the AI session that followed. For those who missed it, or who want a refresher, here is a recap of what we covered.
My session focused on internal controls for nonprofits, and especially for smaller nonprofits. We walked through the what and why of internal controls, the implications of fraud, key risk areas we see when we're out performing nonprofit audits, and how to establish controls when you have limited resources. We finished with a look at how AI features already built into many accounting platforms can help.
Most of you know this cycle well, but it sets the stage for why controls matter. It starts with resources: donations, grants, sponsorships, and, for 501(c)(6) organizations, membership dues and assessments. Those resources fund your programs, which is where you carry out your mission. Your programs create impact in the community, and your measurable outcomes (how many pets were adopted, how many children were served) matter most. Doing good builds trust with donors, grantors, and the people who use your services. You earn that trust by being transparent and keeping good accounting records, and that trust brings in more resources, which in turn creates more impact.
When I talk about internal controls, I'm talking about prevention and detection. Fraud is part of that conversation, but more often than not the issue in an organization is errors, and errors are just as critical. Humans perform many of these processes, and humans make mistakes that can affect financial reporting or send resources out the door. Good controls help you:
You may have seen the internal control framework as a diagram or a cube. It has been around since the early 1990s, but few people did much with it until after the Enron and WorldCom scandals and the creation of Sarbanes-Oxley. The components are numbered, but no single one is more important than the others:
We polled attendees on which component is hardest to maintain, and responses were fairly even. My personal view is that control activities are one of the easier ones, because putting a process in place is straightforward. Making sure it works is much harder, and the control environment can sometimes sit a little outside your control.
Preventive controls stop wrongdoing, whether an unintentional error or fraud, from happening in the first place. Detective controls help you find something after it has occurred. From an IT perspective, password controls and module restrictions are preventive, while reviewing a user log and seeing that someone went into a module they shouldn't have at 5:56 p.m. is detective. Preventive controls are the ones we really want in place.
The fraud triangle applies to all types of organizations, for-profit and nonprofit alike. Its three sides are:
Fraud generally falls into two categories. Misappropriation of assets is theft: cash, checks, inventory (a thrift store, for example), payroll fraud through fictitious employees or unapproved pay rate changes, credit card misuse, expense reimbursement scams, and stolen intellectual property. On credit cards, not everyone in your organization needs one, and we've seen people, even at high levels, use them for personal purposes. Whether or not they intended to pay it back, that's a line better not crossed.
Fraudulent financial reporting includes fictitious revenue (for example, when a department fears its program will be cut if it misses budgeted revenue), shifting revenue or expenses between years, misstating asset values, underreporting liabilities, and, a big one for nonprofits, treating restricted donations as unrestricted. Sometimes that last one is an error, but when a restricted gift is intentionally moved to unrestricted because it's needed for operations, that is a form of fraud.
We also polled attendees on an Association of Certified Fraud Examiners survey question: which department accounts for the most fraud cases across all organization types? The answer was operations, because those employees often have access to many areas of the organization. Accounting came next, and purchasing was fairly high as well. Sales was a very small percentage.
Based on what we see as auditors, control failures tend to concentrate in cash and donations, disbursements and credit cards, payroll, grants and restrictions, financial reporting, and IT. Here's what we discussed in each area.
Contributions revenue. (If you're a 501(c)(6), read this as membership revenue.) Contributions are often over- or under-reported, frequently because accounting and development aren't talking. Early in my career, on my first audit as the senior in charge, I asked whether there were any grant letters at year end and was told no. When I presented the draft financials, the executive director mentioned money that had just come in, opened his desk drawer, and pulled out two unconditional grants dated in May for a June 30 year end. Development had handed them to him, and the accountant had no idea. We had to take the statements back and fix them. Controls that help:
Cash receipts. Risks include skimming (which is admittedly hard to catch, especially when volunteers collect cash at events), delayed deposits around year end, check forgery, theft at events, and simply having too many ways to give. One client last year had seven different ways to donate, and the accountant was forgetting to reconcile one of them. Keep giving open enough for donors but not open for error. The classic control is for someone independent of accounting to open the mail, make a list, and stamp checks with a restrictive endorsement; accounting prepares the deposit; someone else takes it to the bank; and an independent person compares the deposit records to the mail log.
Years ago, when I volunteered to help at my church, I was asked to count the Sunday offering, and my husband and I were left alone to do it. I knew I wouldn't take anything, but I also knew I couldn't prove it if I were ever accused. I told them I wouldn't do it again unless there was a third person, dual sign-off, and a lockbox, and they changed the process. If you're a CFO or accountant, you should want internal controls. They protect you as well.
Cash disbursements and accounts payable. Watch for unauthorized payments, duplicate payments, fictitious vendors, and people running personal expenses (a mortgage or car payment) through the organization. In our poll, a majority of attendees were not using AP or bill pay software such as Bill.com or Ramp, while about 36% were. Controls that help:
Credit cards and expense reports. We're not suggesting you stop giving program directors credit cards, but monitoring is essential. Risks include personal purchases, missing documentation of business purpose (if 60 pairs of shoes from DSW were a program expense, you need to be able to show that in an IRS audit), excessive spending, split transactions to stay under an approval threshold, and small recurring charges. Controls that help:
Payroll. Fictitious employees are less common in small nonprofits where everyone knows everyone, but risks also include unapproved pay rate changes or bonuses, unsupported overtime, improper allocations, and incorrect tax calculations. One client told us they reviewed the payroll register before and after it went to the provider, but during our audit the CFO discovered the wrong amounts had been deducted. A digit had been mis-keyed, and no one had reviewed it beforehand. It was an unintentional error, but a mess to fix. Controls that help:
IT. In an audit, we're mainly concerned with access. The famous exchange goes: Does the CEO have access to the accounting module? Yes, but he never uses it. But he could. That's where the control fails. If someone doesn't need access, don't give it. Also use multi-factor authentication where possible, discourage password sharing, limit administrator rights, remove access immediately when employees leave, adopt an acceptable use policy that covers IT and AI, carry cyber insurance, and have a disaster recovery plan that you actually test. Ongoing education, like the short periodic trainings from KnowBe4, helps people spot scams. Just last Friday I received an official-looking email, apparently from the board chair of a large Richmond nonprofit where I serve, asking for support for a new effort. I called him immediately. He hadn't sent it. These scams are getting more and more sophisticated.
If you serve on a nonprofit board, there are signs that tell you whether the organization has good controls without having to ask:
Nonprofits tend to be short-staffed. (I used a clip from Office Space here, which, I realized while building the slide, features a fraud scheme built on fractional cents that no one was supposed to notice.) If you're fully volunteer or have only one staff member, you'll likely need to pull in board members, ideally a few with financial backgrounds, for oversight rather than hours of accounting work:
In our poll, the majority of attendees said they are not using AI in a significant way, about 35% said they are, and about 7% weren't sure. That's about what I expected, and I suspect the smaller the organization, the less AI is being used. But many of you may already have AI features you haven't explored:
How can a small nonprofit with a budget around $200,000 get a low-cost review or audit? Reviews and audits are fairly expensive, and reviews typically run about half the cost of an audit. I have some ideas on this and took the question offline, so please reach out.
Is it okay for the CFO to approve the CEO's expenses and credit card? I think so, depending on the relationship. If the CFO is in tune with the board and would comfortably question the CEO or go to the board when something isn't right, that can work. It may not be as strong as board-level approval, but I have clients who do this where I've seen that comfort demonstrated.
If you think of a question later, even weeks or months from now, my contact information is in the session materials. I'm always happy to help.