What Internal Controls Should a Small Nonprofit Have?
Nonprofits often have a particular internal-control challenge: there may not be enough people to separate every financial responsibility cleanly.
That does not mean strong internal controls are impossible.
The goal is not to create bureaucracy for bureaucracy’s sake. It is to build a practical system of approvals, reconciliations, access controls, documentation, oversight, and compensating controls that matches the organization’s size, staffing, systems, and risk.
Good controls should make it harder for errors or misuse to occur—and easier to detect them quickly if they do.
Start With the Highest-Risk Areas
Small nonprofits do not need a complicated control framework to get started.
Focus first on areas where money moves or where financial reporting can be manipulated or misunderstood.
Common high-risk areas include:
cash receipts;
electronic payments;
credit cards;
payroll;
vendor setup;
expense reimbursements;
grants;
donor restrictions;
online banking;
financial reporting; and
accounting-system access.
The controls around those areas should be clear, documented, and consistently followed.
Separate Duties Where You Can
Segregation of duties means dividing key financial responsibilities among different people so one person does not control an entire transaction from beginning to end.
Ideally, different people would be responsible for:
authorizing transactions;
processing transactions;
recording transactions; and
reviewing or reconciling transactions.
For example, the person approving a vendor payment ideally should not also create the vendor, release the payment, and reconcile the bank account.
Nonprofits may not have enough staff to separate every function.
That is where compensating controls become important.
Use Compensating Controls When Staffing Is Limited
A compensating control provides additional oversight when traditional segregation of duties is not practical.
For example, if one employee processes most accounting activity, another person could independently review:
monthly bank reconciliations;
bank statements;
payroll reports;
credit card activity;
new vendors;
unusual journal entries; and
financial statements.
That reviewer might be an executive director, board treasurer, finance committee member, or another appropriately qualified person.
The key is that the review is independent, timely, and documented.
Simply receiving a financial report is not the same as reviewing it.
Require Appropriate Payment Approvals
Organizations should establish clear rules for who can approve spending.
That may include:
approval thresholds;
dual approval for larger payments;
board approval for significant commitments;
independent approval of executive-director expenses;
documentation supporting each payment; and
restrictions on self-approval.
Electronic payment systems should be configured to support these controls whenever possible.
For example, one person may prepare an ACH payment while another authorized person releases it.
Control Vendor Creation
Vendor fraud can occur when someone creates a fictitious or unauthorized vendor and then directs payments to that account.
Organizations should consider controls such as:
requiring approval for new vendors;
verifying vendor banking information independently;
reviewing changes to vendor payment instructions;
limiting who can create or modify vendors;
reviewing vendor master files periodically; and
separating vendor creation from payment approval when possible.
Changes to banking instructions deserve particular attention.
Fraudulent email requests to change payment information are common.
Reconcile Bank Accounts Every Month
Monthly bank reconciliation is one of the most important basic controls.
Every bank and investment account should be reconciled promptly.
The reconciliation should identify:
outstanding checks;
deposits in transit;
unusual transactions;
bank fees;
transfers;
stale items; and
differences between the bank and accounting system.
Whenever possible, someone other than the person processing cash transactions should review the completed reconciliation and bank statement.
Review Bank Statements Independently
A useful compensating control for a small organization is having someone independent of routine bookkeeping review bank activity.
The reviewer should look for:
unfamiliar vendors;
unusual transfers;
large payments;
unexpected cash withdrawals;
altered checks;
payments to employees;
duplicate payments; and
transactions outside normal operations.
That review should happen regularly, not only when something appears wrong.
Strengthen Credit Card Controls
Credit cards are convenient but can create control problems if documentation and approval are weak.
A nonprofit should consider requiring:
named cardholders;
written spending limits;
receipts for every transaction;
documented business purpose;
supervisory approval;
independent review of executive expenses; and
timely reconciliation.
The cardholder should generally not be the only person reviewing their own activity.
Protect Payroll
Payroll is often one of the largest expenses in a nonprofit.
Controls should address:
new employees;
compensation changes;
bonuses;
payroll deductions;
terminated employees;
direct-deposit changes; and
payroll tax filings.
Changes to compensation should be formally approved.
Executive compensation should receive appropriate board oversight.
Someone independent of payroll processing should periodically review payroll registers for unexpected employees, changes, or unusual payments.
Limit Accounting-System Access
Not every employee needs administrative access.
Permissions should be based on job responsibilities.
For example:
accounts payable staff may enter bills;
managers may approve expenses;
finance leadership may post journal entries;
only limited personnel may add users or change system settings.
Administrative rights should be tightly controlled.
Organizations should also use:
unique user accounts;
multifactor authentication;
strong passwords;
prompt removal of former employees;
periodic access reviews; and
audit logs when available.
Shared logins make accountability much harder.
Protect Online Banking Access
Online banking should receive particularly strong controls.
Consider:
multifactor authentication;
separate user credentials;
transaction limits;
dual approval;
alerts for significant transfers;
restrictions on new payees; and
periodic user-access reviews.
Former employees should lose access immediately.
Banking permissions should also be reviewed whenever roles change.
Maintain Good Supporting Documentation
Every significant financial transaction should tell a clear story.
Supporting documentation may include:
invoices;
receipts;
contracts;
grant agreements;
approval records;
purchase orders;
payroll support;
donor correspondence; and
reimbursement forms.
The organization should be able to show:
what happened, why it happened, who approved it, and how it was recorded.
Strong documentation supports both internal control and audit readiness.
Monitor Grants and Restricted Funds
For nonprofits, internal controls extend beyond cash.
Grant and restricted-fund controls should help ensure:
spending is allowable;
expenses are charged to the correct program;
donor restrictions are followed;
grant periods are respected;
reimbursement requests are accurate;
matching requirements are monitored; and
remaining balances are understood.
Grant accounting should be reconciled regularly to the general ledger.
Related Resource: How Should Nonprofits Track Restricted Funds? →
Review Journal Entries
Journal entries can change financial results without moving cash, so they deserve oversight.
Higher-risk entries may include:
manual revenue entries;
large year-end adjustments;
entries to cash;
entries involving restricted funds;
unusual reclassifications;
entries posted by administrators; and
entries made after the books were initially closed.
Depending on staffing, an independent reviewer may approve or periodically review significant manual journal entries.
Produce and Review Financial Statements Regularly
Financial reporting is itself an important control.
Management and the board should receive timely financial information that allows them to identify unusual trends.
That may include:
statement of financial position;
statement of activities;
budget-to-actual results;
cash position;
restricted-fund balances;
grant performance; and
cash-flow forecasts.
Unexpected variances should be investigated.
Financial statements are more useful as a control when someone is actively asking questions about them.
Give the Board Meaningful Oversight
The board should provide governance—not operate the accounting department.
But appropriate board oversight can be an important compensating control for smaller organizations.
Depending on the organization, the board or finance committee may review:
monthly or quarterly financial statements;
bank reconciliations;
major expenditures;
executive expenses;
budget performance;
cash reserves;
debt;
significant contracts;
related-party transactions; and
audit findings.
The level of oversight should be proportionate to the organization’s size and risk.
Manage Conflicts of Interest
Nonprofits should have a written conflict-of-interest policy and a process for identifying potential conflicts.
Related-party transactions should be:
disclosed;
evaluated;
approved by disinterested decision-makers;
documented in meeting minutes; and
supported as reasonable and in the organization’s best interests.
The objective is transparency and appropriate governance.
Create a Fraud-Reporting Process
Employees and volunteers should have a way to raise concerns without having to report directly to the person involved.
Even a small organization can establish a simple process such as:
direct access to the board chair;
access to the audit or finance committee;
a designated independent contact; or
another confidential reporting mechanism.
A whistleblower policy can help formalize this process.
Review Controls When People Leave
Staff turnover creates control risk.
When an employee or contractor leaves, the organization should promptly review:
email access;
accounting-system access;
payroll access;
banking access;
credit cards;
vendor portals;
cloud storage;
passwords;
physical keys; and
other financial systems.
Access should be removed immediately when no longer needed.
This sounds basic, but it is frequently overlooked.
Document Who Owns What
A simple responsibility matrix can significantly strengthen controls.
For major processes, identify who:
prepares;
approves;
records;
reconciles; and
reviews.
The exact assignments will differ by organization.
The point is to make accountability visible.
Internal Controls Do Not Need to Be Complicated
A nonprofit can build meaningful controls with relatively simple practices.
For example:
Every expenditure requires documentation.
Large payments require a second approval.
Bank accounts are reconciled monthly.
Someone independent reviews bank activity.
Payroll changes require documented approval.
Executive expenses receive independent review.
Accounting and banking access is limited by role.
Grant activity is reconciled regularly.
Financial statements are reviewed against budget.
Unusual transactions are investigated.
Consistency matters more than creating a long policy manual that no one follows.
Internal Control Checklist for a Small Nonprofit
A nonprofit should ideally be able to answer yes to questions such as:
Are bank accounts reconciled every month?
Does someone independently review the reconciliations?
Are significant payments approved by someone other than the preparer?
Are executive expenses independently approved?
Are payroll changes documented?
Are new vendors reviewed?
Are changes to vendor banking information independently verified?
Are system permissions limited based on responsibility?
Is multifactor authentication enabled?
Are former employees removed from systems promptly?
Are grant expenditures reconciled regularly?
Are restricted funds tracked?
Are significant journal entries reviewed?
Does the board receive timely financial reports?
Are conflicts of interest disclosed and documented?
Is there a way to report suspected fraud?
Are financial responsibilities clearly assigned?
A few “no” answers do not necessarily mean the organization has a serious control problem.
They do identify areas worth evaluating.
The Bottom Line
Small nonprofits may not have enough people to create perfect segregation of duties.
They can still have strong internal controls.
The most effective systems usually combine:
clear approvals
independent review
monthly reconciliations
limited system access
good documentation
board oversight
and
compensating controls where staffing is limited.
The objective is not to eliminate every possible financial risk.
It is to make risks visible, reduce the likelihood of errors or misuse, and create processes that allow issues to be identified and addressed quickly.
How Bilotta & Company Can Help
Bilotta & Company, CPAs, LLC works with nonprofit organizations on audits, reviews, Single Audits, accounting, internal controls, financial reporting, tax compliance, and ongoing financial stewardship.
Through our Nonprofit Navigator® Financial Stewardship program, we help organizations design practical accounting and control processes appropriate for their size and complexity—including approvals, reconciliations, reporting, grant tracking, system permissions, and board oversight.
The goal is not more process.
It is better accountability, stronger financial information, and greater confidence in how organizational resources are being managed.
Related Resource: How Should Nonprofits Track Restricted Funds? →
Related Resource: What Should a Nonprofit Board Financial Dashboard Include? →
Explore Nonprofit Navigator® →
Visit the Nonprofit Financial Resource Center →
This article is provided for general educational purposes and should not be considered accounting, legal, cybersecurity, fraud-prevention, or internal-control advice for a specific organization.