Goldenthal & Suss

Nonprofit Internal Controls That Stand Up to Scrutiny

Nonprofit internal controls protect funds, strengthen board oversight, and support reliable reporting, grant compliance, and audit readiness year-round.

A missing approval, an unreconciled grant account, or a single employee with authority to receive cash, record it, and make deposits can create far more than an audit finding. These gaps can distort financial reporting, place restricted funding at risk, and leave a board unable to demonstrate appropriate stewardship. Effective nonprofit internal controls give management and governing boards a disciplined way to protect assets, meet donor and regulatory obligations, and make decisions using reliable information.

For organizations subject to Uniform Guidance, Yellow Book requirements, HUD program rules, Medicaid reporting, or demanding funder contracts, internal control is not a generic finance exercise. Controls must reflect the organization’s actual funding streams, transaction volume, staffing structure, and compliance exposure. A policy copied from another organization is not a control unless it is understood, performed, documented, and reviewed.

What Nonprofit Internal Controls Are Designed to Do

Internal controls are the policies, procedures, approvals, reconciliations, system permissions, and oversight activities that help an organization achieve its financial and compliance objectives. They are not limited to preventing theft. Well-designed controls also reduce errors, identify issues before reports are submitted, preserve supporting documentation, and provide the clearest picture your board will ever get of how resources are managed.

A practical control framework should address five connected areas: the integrity of financial reporting, protection of cash and other assets, compliance with legal and grant requirements, operational accountability, and board oversight. The right balance depends on the organization. A large human-services provider with multiple federal awards needs a more formal structure than a small membership organization, but both need defined responsibilities and credible review.

Controls should also be proportionate. Requiring three signatures on a modest recurring payment may add delay without reducing meaningful risk. Allowing a single individual to create vendors, approve invoices, release payments, and reconcile the bank account creates a clear concentration of risk. The objective is not bureaucracy. It is appropriate separation, documented evidence, and timely review where risk is highest.

Start With the Risks That Matter Most

A control assessment should begin with the organization’s real exposure, not a checklist alone. Management should consider where funds enter the organization, how they move through payroll and purchasing, which activities are subject to restrictions, and what reports are relied upon by funders, regulators, lenders, and the board.

For many nonprofits, cash disbursements, payroll, restricted grants, revenue recognition, and information-system access deserve close attention. Organizations receiving federal awards should also evaluate procurement, allowable costs, time and effort documentation, subrecipient monitoring, program income, and reporting under 2 CFR Part 200. A control that works for unrestricted membership dues may not be sufficient for a reimbursement-based federal grant.

Risk assessment is most useful when it asks direct questions. Could an employee initiate and conceal an improper payment? Can management determine whether grant expenditures are allowable before they are charged? Are reconciliations completed promptly and reviewed by someone with sufficient authority? Does the board receive financial reports that explain significant variances, liquidity concerns, and restricted-fund activity?

The answers should lead to action. A risk register can be helpful, particularly for larger institutions, but it should result in assigned owners, specific control activities, and a timetable for correction. An unaddressed risk list is not a control environment.

Segregation of Duties Requires Judgment

Segregation of duties remains one of the most effective concepts in nonprofit financial management. Ideally, different people authorize transactions, maintain accounting records, hold assets, and perform reconciliations. This reduces the likelihood that one person can both make an error or improper transaction and conceal it.

Smaller organizations often cannot fully separate these duties. That does not mean the risk must be accepted without a response. Compensating controls can provide meaningful oversight. An executive director or board treasurer who is independent of transaction processing can review bank statements unopened, examine canceled checks and electronic payments, compare payroll reports to authorized compensation, and review monthly bank reconciliations with supporting detail.

Compensating controls must be substantive. A signature or initials added after a cursory review will not provide persuasive evidence of oversight. The reviewer should understand what is being reviewed, question unusual items, and retain documentation of the review. For example, a monthly bank reconciliation package might include the bank statement, reconciliation, outstanding-items detail, evidence of review, and explanations for old reconciling items.

Controls Over Revenue, Spending, and Restricted Funds

Revenue controls should establish who receives funds, how receipts are recorded, how quickly deposits are made, and how donor restrictions are captured in the accounting system. Contributions received through multiple channels - mail, events, online platforms, or third-party processors - require clear reconciliation between source records, deposit activity, and the general ledger.

On the disbursement side, organizations should distinguish between approval of a purchase, confirmation that goods or services were received, and authorization of payment. Vendor setup deserves particular care. Changes to vendor banking information should be independently verified using known contact information, not a phone number or email address included in a change request. This simple step can reduce exposure to payment-diversion fraud.

Restricted funding calls for controls that operate before, not after, an expenditure is recorded. Grant managers and finance personnel should understand the approved budget, period of performance, cost principles, required match, reporting deadlines, and documentation standards. Finance should not be expected to infer programmatic compliance from an invoice alone.

A useful monthly process compares actual grant activity with approved budgets and remaining award balances. It should also identify costs requiring follow-up, late reports, pending budget modifications, and restrictions that affect revenue recognition or net asset classification. These reviews are especially valuable when program staff, development staff, and finance staff each hold part of the information needed for accurate reporting.

Payroll and Technology Controls Need Equal Attention

Payroll is frequently the largest expense for nonprofit organizations and a recurring source of compliance exposure. Controls should require documented authorization for hiring, compensation changes, and termination; periodic review of payroll registers; and prompt removal of system access when an employee leaves. For organizations charging payroll to grants, time records and allocation methodologies must support the amounts charged and be consistent with actual work performed.

Technology controls are now inseparable from financial controls. User access should follow job responsibilities, with administrator privileges limited to those who need them. Organizations should periodically review accounting-system users, online banking rights, payroll-platform access, and approval workflows. Multifactor authentication, controlled password practices, and documented procedures for responding to suspicious payment requests are basic safeguards, not optional enhancements.

Cloud accounting platforms can improve visibility, but they can also allow a small number of users to perform too many functions. Management should understand system roles before assuming that automated workflows create adequate separation of duties.

Make Board Oversight Specific

The board does not need to approve every invoice to fulfill its governance role. It does need to establish expectations, receive meaningful information, and follow up on indicators of risk. The board treasurer or audit committee should understand the organization’s financial close process, significant control limitations, external audit results, management letter comments, and status of corrective actions.

Monthly board reporting should go beyond a statement of activities and statement of financial position. Depending on the organization, it may include budget-to-actual analysis, cash flow, days cash on hand, receivables aging, grant balances, debt covenant measures, and explanations of material variances. The goal is not to bury directors in detail. It is to make emerging issues visible early enough for oversight to matter.

Policies also need board-level attention. Conflict-of-interest, whistleblower, document retention, expense reimbursement, reserve, and investment policies should be current and applied consistently. A policy that is never acknowledged, tested, or revisited offers limited protection when a difficult situation arises.

Test Controls Before an Auditor Does

The strongest control environments include routine self-assessment. Management can select a sample of transactions each quarter and determine whether approvals, support, coding, and reconciliations occurred as intended. This work often identifies practical failures: approvals sitting in email without retention, outdated signatory lists, missing grant documentation, or reconciliations completed but never reviewed.

When a deficiency is identified, the response should address cause as well as correction. If invoices are consistently approved after payment, the organization may need a clearer workflow, different purchasing authority, or additional staffing support. If a key employee is carrying too many incompatible duties, a part-time controller, outsourced accounting support, or more active board review may be a better answer than another written policy.

Goldenthal & Suss approaches internal-control assessment as a governance and audit-readiness exercise, not a search for theoretical perfection. The right framework provides partner-level clarity about what management is doing, what the board is overseeing, and where compliance risk requires attention.

Internal controls are most valuable when they become part of the organization’s operating discipline: documented in real time, reviewed by the right people, and adjusted as funding, systems, and responsibilities change. That discipline protects more than the balance sheet. It protects the confidence that donors, regulators, employees, and boards place in the mission.

This article is general information, not accounting, audit, or tax advice, and it does not create a client relationship. Thresholds and filing requirements change. Confirm anything you intend to rely on against the current rules or speak with us directly.

Talk to an auditor

Goldenthal & Suss performs nonprofit audits, single audits, and Yellow Book government engagements from offices in Staten Island, NY and Freehold, NJ.

Request a Proposal

More insights