Internal Controls are a Must Have for Non-Profits

Nikki L. Walton, CPA, Principal

For nonprofits, strong internal controls are more than an accounting requirement. They help protect donor resources, preserve public trust, support accurate financial and grant reporting, and keep your organization focused on its mission. Yet nonprofits often must work within challenging realities of limited staffing, evolving programs, multiple and complex funding sources, and staff, volunteers and board members with varying levels of financial expertise. These realities can create control gaps—even when leadership is committed to doing the right thing. The good news is that effective internal controls do not require perfect systems or unlimited resources. What they do require is - clear accountability, thoughtful oversight, documented review processes, and consistent follow-through.

Why Internal Controls Can be Challenging for Nonprofits

A non-profit’s mission is its greatest strength, but a strong mission focus can sometimes place financial processes in the background. Rapid growth, new grants, staff turnover, new accounting systems, and banking changes can also introduce risk faster than procedures are updated.

Common challenges include:

  • Segregation of duties issues
  • Board literacy and focus
  • Complexity surrounding certain grant requirements
  • Incomplete or inconsistent policies
  • User access

Key Controls Areas – Designing Fraud Resistant Controls

Key Control Area: Cash Receipts

  • Two people open mail together; log all checks immediately upon receipt
  • Person receiving donations must not also post entries – no single handler
  • Same-day or next-day bank deposits; compare deposit slip to check log
  • Document donor intent at receipt; flag restrictions immediately
  • Reconcile online giving platform to the general ledger monthly

Key Control Area: Disbursements and Credit Cards

  • Segregate duties: requester, approver, and check releaser should be different people
  • Dual authorization: require dual authorization above defined dollar thresholds
  • Approved vendor list: maintain an approved vendor master list, and obtain board approval for new vendors
  • Positive pay: confirm each check electronically before it clears
  • Monthly reconciliations: reviewed by knowledgeable person outside the disbursement process
  • Credit cards: individual limits, prohibited categories, and monthly reviews

Key Control Area: Program and Grant Disbursements

  • Budget-to-actual review at grant level; flag variances over 10%
  • Require invoices and approval before payment release
  • Separate program expenses from accounting entry
  • Subrecipient monitoring: site visits, financial reports, and eligibility verification
  • Time and effort documentation for salary allocation (critical for federal grants)

Key Control Area: Payroll

  • Separate employee record maintenance, payroll processing, and payroll approval
  • Analytically review payroll expenses each period
  • Review change reports including new hires, terminations, pay rates, vacation balances and termination payouts

Key Control Area: Financial Reporting

  • Functional expense allocation: document and consistently apply methodology
  • Interfund transactions – require supporting schedules and formal elimination
  • Period-end checklist: assign ownership and require sign-off before reporting
  • Management review of draft financials vs prior period and budget
  • Net asset releases: require written authorization before recognizing

Key Control Area: IT Access Controls

  • System access review
  • Multifactor authentication, strong password policies, and phishing awareness
  • Incident response planning
  • Prompt removal of access after termination

Recognize the Warning Signs of Fraud

Fraud risk is often described through three connected conditions: pressure, opportunity, and rationalization. It is not possible to eliminate every pressure an employee may experience, but Management can reduce fraud opportunity by strengthening controls and making oversight visible.

Potential fraud warning signs may include resistance to oversight, refusal to take vacation, delayed reconciliations, repeated errors, missing support, duplicate vendors, round dollar transactions, or unusual activity that is difficult to explain. One red flag does not prove fraud. It does, however, warrant timely, documented follow-up (particularly if Management observes multiple red flags). A culture of accountability matters. Employees should know how to report concerns, who will respond, and that allegations will be handled seriously and appropriately.

What Active Board Oversight Looks Like

Boards and audit or finance committees can also play an additional role in strengthening the control environment by asking questions such as:

  • What could go wrong in this process, and where would we detect it?
  • Who approves, records, safeguards, and reconciles transactions?
  • What alternative procedures exist when staffing makes full segregation of duties impractical?
  • How are unusual transactions, allegations, exceptions, and management letter findings tracked?
  • Who owns each remediation step, what is the deadline, and what evidence will demonstrate completion?

Meeting minutes should reflect follow-up on unusual activity and control concerns. Oversight is stronger when it is tied to specific risks rather than general assurances that policies exist.

Start With the Top Three Gaps

The most effective remediation plan is not necessarily the longest one. Identify the three control gaps with the highest fraud or misstatement exposure at your organization. Then assign an owner, deadline, review method, and evidence expectation for each fix. After implementation, reassess whether the new control is operating as intended. A policy rewrite alone is not enough; the organization must be able to demonstrate that responsible personnel understand the control and are performing it consistently.

Strong internal controls protect more than financial statements. They protect the resources entrusted to the organization, reinforce confidence among donors and stakeholders, and give Management/Board and Committee members better information for making decisions. For nonprofits, that makes internal control a direct investment in mission continuity and public trust.

Connect With Us

Stay Connected!

Sign up to receive information on the latest government and non-profit industry insights, firm news, and upcoming events & seminars.

Jump to Page

Maher Duessel Cookie Preference Center

Your Privacy

When you visit our website, we use cookies on your browser to collect information. The information collected might relate to you, your preferences, or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. For more information about how we use Cookies, please see our Privacy Policy.

Strictly Necessary Cookies

Always Active

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Functional Cookies

Always Active

Some functions of the site require remembering user choices, for example your cookie preference, or keyword search highlighting. These do not store any personal information.

Form Submissions

Always Active

When submitting your data, for example on a contact form or event registration, a cookie might be used to monitor the state of your submission across pages.

Performance / Analytical Cookies

Analytical cookies help us improve our website by collecting and reporting information on its usage. We access and process information from these cookies at an aggregate level.

Powered by Firmseek