Approvalmax | Accounting, Finance and Technology Blog

Internal controls for nonprofits: why the risk is bigger than it looks

Written by ApprovalMax | 8/12/26, 11:24 AM

As a finance lead in the nonprofit space - what keeps you awake at night?

In our experience, working with prospects and customers in this sector, the general responses normally involve deadlines. A grant report due soon. Or the audit pack. Or the numbers needed by the treasurer before the next board call.

Each one of these concerns is asking the same underlying question: was this money spent the way it was supposed to be, and can we show it?

The main painpoint of each of these deadlines is that they focus on spending, asked long after the spending has happened. By the time the grant report is being written, you might discover a restricted fund had paid for something it shouldn't have, that was settled months earlier by whoever approved the payment.

And that's usually how it goes wrong. An ordinary payment, approved quickly, against a fund that wasn't there to cover it.

Two things make this harder than it would be in a business of the same size. Your accounts end up on public record, so the mistake is visible. And your finance team is two or three people, so there is rarely anyone spare to check.

How do you get around this? In our experience, it's not creating more policy. It's having the internal controls in place to stop these types of mistakes from happening in the first place.

What are internal controls for nonprofits? Internal controls for nonprofits are the checks that keep money spent as intended: segregation of duties, so no single person creates, approves and pays; documented financial policies; board or finance-committee oversight; and a clean approval trail for every transaction. Nonprofits face outsized exposure because they handle restricted funds and file a public annual return — the 990 in the US and the T3010 in Canada — on small teams. The most effective controls enforce approval before money leaves, not after.

Key takeaways

  • Nonprofits lose a median of $76,000 per fraud case (ACFE, 2024) - smaller in dollars than the private sector's ~$150,000, but far more damaging against a restricted program budget and a public annual return.
  • The single most effective control is enforced approval before payment: no bill reaches payment until a second authorized person has reviewed it, with the decision recorded as it happens rather than reconstructed from email.
  • Segregation of duties is about the sequence of a transaction, not headcount - a workflow system can require a different person to enter a bill than releases it, even in a finance team of two.

What financial risk really means for a nonprofit

Fraud is one of the outcomes of this risk that gets written about, but it's not the most likely thing to go wrong.

What more commonly happens is a restricted grant pays for something it wasn't meant to cover. Or a funder condition is missed because nobody flagged the spend at the point it happened. In some cases, a cost lands in the wrong period and the year-end numbers have to be reworked.

So rather than bad intent, risks usually come from an honest, overloaded team moving quickly without the proper processes in place to catch mistakes.

The problem is that the consequences land differently for nonprofits. In a commercial business, a coding error is an accounting problem. In a nonprofit, misused restricted funds can mean returning money, or an awkward conversation with a funder who has other places to put their grant next year.

That is why financial controls for nonprofits are worth more than their administrative cost. They are not there to slow spending down. They are there to keep the spending defensible.

Related reading: accounts payable controls

Why nonprofits are uniquely exposed

That's not to say fraud doesn't occur - and while nonprofits do not suffer the largest fraud losses, they carry a worse ratio.

A loss of $76,000 against a $2 million program budget is not the same event as a $150,000 loss inside a company with commercial reserves and no obligation to explain itself in public. One is a bad quarter. The other can be a canceled program, a broken funder relationship, or a board that has to disclose what happened.

Three things stack the exposure:

  • Restricted funds. Money arrives with conditions attached, which means "did we have the cash" is the easy question and "were we allowed to spend it on that" is the one that matters.
  • A public annual return. The 990 and the T3010 put a version of your finances on the record where donors, journalists, and grant assessors can read them.
  • Thin resource. Segregation of duties assumes enough people to segregate. Many finance functions here are one person, a part-time bookkeeper, and a volunteer treasurer with a day job.

So the picture is not a sector that loses more. It is a sector where the same loss does more damage, in front of a larger audience, with fewer hands available to prevent it.

What the data says

The Association of Certified Fraud Examiners tracks this across thousands of real cases, and the nonprofit numbers have been stubbornly consistent.

$76,000
Median loss per nonprofit fraud case (ACFE, 2024)
Roughly half the ~$150,000 median in the for-profit and government sectors - but against a restricted program budget and a public annual return, the same loss does far more damage.

Nonprofits account for around 10% of reported occupational fraud cases, which is broadly proportionate to their share of the economy. The more useful finding sits underneath the headline figure.

A large share of cases trace back to a control that was missing, or one that existed on paper and was overridden in practice. The fixes that come up again and again are the unglamorous ones: separating who requests from who authorizes, and giving oversight something concrete to look at.

Which tells you where to spend your attention. Not on detecting fraud faster, but on making the routine transaction harder to get wrong.

The controls that actually protect the mission

Most nonprofit internal controls checklists cover the same ground, and the ground is sound. Worth having, all of it:

  • Segregation of duties. No one person creates a payment, approves it, and releases it.
  • Documented financial policies. Written thresholds, delegated authorities, and a defined process for exceptions.
  • Board or finance-committee oversight. Regular review with enough detail to be meaningful, not just a summary page.
  • An external audit or independent review. Annual, and treated as a health check rather than a verdict.
  • A visible audit trail. Who approved what, when, and on what basis.

Every item on that list can be fully in place and still fail, because a policy is a statement of intent. It describes what should happen. It does nothing at the moment a payment is actually being made.

A policy describes what should happen. Enforcement makes it happen.
The gap between the two is where nonprofit finances quietly go wrong — a control that exists on paper but is overridden in practice.

That is the difference between having controls and enforcing them. Enforcement means the check runs on every transaction, automatically, whether or not anyone remembers it. The bill cannot move to payment until the right person has approved it. The approval is recorded as it happens rather than reconstructed later from email.

This is what approval control means in practice, and it is the layer most nonprofits are missing. They have the policy. What they lack is the mechanism that makes the policy true on a Thursday afternoon when three people are on leave.

Learn more: approval workflows and audit and fraud control

Audit-ready all year: the 990 and the T3010

Both countries require an annual public return. Form 990 in the US, the T3010 in Canada. Neither is only a tax exercise. Both are a public description of how your organization handles money, and both ask about governance and oversight directly.

Deadlines follow each organization's own fiscal year end, so the crunch is never one date in the calendar. What is constant is where the answers come from.

A team that records approvals as they happen produces the return from evidence that already exists. A team that does not spends weeks in inboxes reconstructing who said yes to what.

That is the whole principle. Audit readiness is not a project you run before filing season. It is a byproduct of how you approved money the rest of the year.

Control without the headcount

The objection is always the same, and it is fair. Segregation of duties sounds like advice for organizations with a finance department.

It is not, once you stop thinking about it as a staffing question.

Separation of duties is about the sequence of a transaction, not the size of the payroll. A system can hold the line where a rota cannot. The person who enters a bill is not the person who releases it, because the workflow will not let the same account do both, even in a team of two.

The same goes for oversight. A treasurer who reviews the numbers once a quarter is doing their best with a snapshot. A treasurer who approves specific transactions above a threshold, from their phone, in the moment, is exercising real oversight without attending a single extra meeting.

You are not hiring your way to control. You are moving the control from a person's memory into the process.

How ApprovalMax helps

The pattern we see most often in nonprofit finance is that one capable person ends up owning too much of the spend process, because that is what the resource allows, and everyone hopes the annual audit catches anything that slipped.

ApprovalMax sits on top of QuickBooks Online and Xero and enforces the approval step the accounting platform leaves open. Bills and expenses route to the right approver by amount, fund, or program. Nothing reaches payment without the authorization the policy requires, and every decision is captured with a timestamp and a name.

The result is not more admin. It is a finance function where the control is part of the process rather than an intention, and where audit readiness is a byproduct of working normally.

Free trial
See how ApprovalMax enforces approval controls automatically
No credit card required. Works with Xero, QuickBooks Online, and NetSuite.
Start free trial Book a demo

Where to start

The fastest way to find out whether your controls would hold up is to check them against what an auditor or a funder actually asks for.

It walks through segregation of duties, approval thresholds, restricted-fund checks and audit-trail completeness, with the small-team version of each.

Worth knowing on timing. Canadian charities with a 31 March year end file the T3010 by 30 September, and US organizations on extension face 15 November for the 990. If either of those is your deadline, the checklist is the quicker win.

Download the nonprofit audit-readiness checklist

Frequently asked questions

What are internal controls for a nonprofit?

They are the checks that make sure money is spent as intended and that the spending can be evidenced. In practice that means separating who requests, approves, and pays, documenting your financial policies, giving the board real oversight, and keeping an approval trail for every transaction.

What is the most important internal control for a small nonprofit?

Enforced approval before payment. If only one control is working, make it the one that stops money leaving without a second authorized person having reviewed it, with that decision recorded.

How do nonprofits prevent fraud with a small team?

By putting the separation into the system rather than the staffing. Workflow can require a different person to approve than to enter, and can escalate above set thresholds, even when very few people touch the books.

What is the difference between the 990 and the T3010?

Form 990 is the annual information return filed by tax-exempt organizations in the US. The T3010 is the equivalent registered charity information return in Canada. Both are public documents and both ask about governance and oversight, not only financial totals.

How often should a nonprofit review its internal controls?

At least annually, and always after a change in staff, systems, or funding structure. Turnover in the finance function is the most common moment for a control to quietly stop working.

Do internal controls slow down spending?

Well-designed ones speed it up. Clear thresholds and automatic routing remove the chasing, the "who signs this" questions, and the rework that comes from catching problems after payment.