As a finance lead in the nonprofit space - what keeps you awake at night?
In our experience, working with prospects and customers in this sector, the general responses normally involve deadlines. A grant report due soon. Or the audit pack. Or the numbers needed by the treasurer before the next board call.
Each one of these concerns is asking the same underlying question: was this money spent the way it was supposed to be, and can we show it?
The main painpoint of each of these deadlines is that they focus on spending, asked long after the spending has happened. By the time the grant report is being written, you might discover a restricted fund had paid for something it shouldn't have, that was settled months earlier by whoever approved the payment.
And that's usually how it goes wrong. An ordinary payment, approved quickly, against a fund that wasn't there to cover it.
Two things make this harder than it would be in a business of the same size. Your accounts end up on public record, so the mistake is visible. And your finance team is two or three people, so there is rarely anyone spare to check.
How do you get around this? In our experience, it's not creating more policy. It's having the internal controls in place to stop these types of mistakes from happening in the first place.
What are internal controls for nonprofits? Internal controls for nonprofits are the checks that keep money spent as intended: segregation of duties, so no single person creates, approves and pays; documented financial policies; board or finance-committee oversight; and a clean approval trail for every transaction. Nonprofits face outsized exposure because they handle restricted funds and file a public annual return — the 990 in the US and the T3010 in Canada — on small teams. The most effective controls enforce approval before money leaves, not after.
Fraud is one of the outcomes of this risk that gets written about, but it's not the most likely thing to go wrong.
What more commonly happens is a restricted grant pays for something it wasn't meant to cover. Or a funder condition is missed because nobody flagged the spend at the point it happened. In some cases, a cost lands in the wrong period and the year-end numbers have to be reworked.
So rather than bad intent, risks usually come from an honest, overloaded team moving quickly without the proper processes in place to catch mistakes.
The problem is that the consequences land differently for nonprofits. In a commercial business, a coding error is an accounting problem. In a nonprofit, misused restricted funds can mean returning money, or an awkward conversation with a funder who has other places to put their grant next year.
That is why financial controls for nonprofits are worth more than their administrative cost. They are not there to slow spending down. They are there to keep the spending defensible.
Related reading: accounts payable controls
That's not to say fraud doesn't occur - and while nonprofits do not suffer the largest fraud losses, they carry a worse ratio.
A loss of $76,000 against a $2 million program budget is not the same event as a $150,000 loss inside a company with commercial reserves and no obligation to explain itself in public. One is a bad quarter. The other can be a canceled program, a broken funder relationship, or a board that has to disclose what happened.
Three things stack the exposure:
So the picture is not a sector that loses more. It is a sector where the same loss does more damage, in front of a larger audience, with fewer hands available to prevent it.
The Association of Certified Fraud Examiners tracks this across thousands of real cases, and the nonprofit numbers have been stubbornly consistent.
Nonprofits account for around 10% of reported occupational fraud cases, which is broadly proportionate to their share of the economy. The more useful finding sits underneath the headline figure.
A large share of cases trace back to a control that was missing, or one that existed on paper and was overridden in practice. The fixes that come up again and again are the unglamorous ones: separating who requests from who authorizes, and giving oversight something concrete to look at.
Which tells you where to spend your attention. Not on detecting fraud faster, but on making the routine transaction harder to get wrong.
Most nonprofit internal controls checklists cover the same ground, and the ground is sound. Worth having, all of it:
Every item on that list can be fully in place and still fail, because a policy is a statement of intent. It describes what should happen. It does nothing at the moment a payment is actually being made.
That is the difference between having controls and enforcing them. Enforcement means the check runs on every transaction, automatically, whether or not anyone remembers it. The bill cannot move to payment until the right person has approved it. The approval is recorded as it happens rather than reconstructed later from email.
This is what approval control means in practice, and it is the layer most nonprofits are missing. They have the policy. What they lack is the mechanism that makes the policy true on a Thursday afternoon when three people are on leave.
Learn more: approval workflows and audit and fraud control
Both countries require an annual public return. Form 990 in the US, the T3010 in Canada. Neither is only a tax exercise. Both are a public description of how your organization handles money, and both ask about governance and oversight directly.
Deadlines follow each organization's own fiscal year end, so the crunch is never one date in the calendar. What is constant is where the answers come from.
A team that records approvals as they happen produces the return from evidence that already exists. A team that does not spends weeks in inboxes reconstructing who said yes to what.
That is the whole principle. Audit readiness is not a project you run before filing season. It is a byproduct of how you approved money the rest of the year.
The objection is always the same, and it is fair. Segregation of duties sounds like advice for organizations with a finance department.
It is not, once you stop thinking about it as a staffing question.
Separation of duties is about the sequence of a transaction, not the size of the payroll. A system can hold the line where a rota cannot. The person who enters a bill is not the person who releases it, because the workflow will not let the same account do both, even in a team of two.
The same goes for oversight. A treasurer who reviews the numbers once a quarter is doing their best with a snapshot. A treasurer who approves specific transactions above a threshold, from their phone, in the moment, is exercising real oversight without attending a single extra meeting.
You are not hiring your way to control. You are moving the control from a person's memory into the process.
The pattern we see most often in nonprofit finance is that one capable person ends up owning too much of the spend process, because that is what the resource allows, and everyone hopes the annual audit catches anything that slipped.
ApprovalMax sits on top of QuickBooks Online and Xero and enforces the approval step the accounting platform leaves open. Bills and expenses route to the right approver by amount, fund, or program. Nothing reaches payment without the authorization the policy requires, and every decision is captured with a timestamp and a name.
The result is not more admin. It is a finance function where the control is part of the process rather than an intention, and where audit readiness is a byproduct of working normally.
The fastest way to find out whether your controls would hold up is to check them against what an auditor or a funder actually asks for.
It walks through segregation of duties, approval thresholds, restricted-fund checks and audit-trail completeness, with the small-team version of each.
Worth knowing on timing. Canadian charities with a 31 March year end file the T3010 by 30 September, and US organizations on extension face 15 November for the 990. If either of those is your deadline, the checklist is the quicker win.
They are the checks that make sure money is spent as intended and that the spending can be evidenced. In practice that means separating who requests, approves, and pays, documenting your financial policies, giving the board real oversight, and keeping an approval trail for every transaction.
Enforced approval before payment. If only one control is working, make it the one that stops money leaving without a second authorized person having reviewed it, with that decision recorded.
By putting the separation into the system rather than the staffing. Workflow can require a different person to approve than to enter, and can escalate above set thresholds, even when very few people touch the books.
Form 990 is the annual information return filed by tax-exempt organizations in the US. The T3010 is the equivalent registered charity information return in Canada. Both are public documents and both ask about governance and oversight, not only financial totals.
At least annually, and always after a change in staff, systems, or funding structure. Turnover in the finance function is the most common moment for a control to quietly stop working.
Well-designed ones speed it up. Clear thresholds and automatic routing remove the chasing, the "who signs this" questions, and the rework that comes from catching problems after payment.