Skip to main content
Organizational Management

Internal Controls for Nonprofits: A Practical Guide 

Meera Parmar
11 min read

Is your board treasurer asking about audit readiness? Maybe your auditor flagged a gap in your approval process. Or perhaps you’ve heard too many stories about nonprofit fraud and want to make sure your organization isn’t next. 

Internal controls for nonprofits are one of the most practical measures you can choose to implement at your organization. However, they are also one of the most misunderstood. 

This guide breaks down what internal controls for nonprofits are, which ones matter most, and how to build a sensible system whether you have two staff members or twenty. 

What Are Internal Controls for Nonprofits? 

Internal controls are the policies, procedures, and practices your organization uses to protect financial assets, ensure accurate reporting, and prevent fraud or error. Internal controls guide all nonprofits and businesses, despite their size or industry.  

Think of internal controls as the rules your organization follows so that no single person can make a financial mistake or commit fraud, without someone else catching it.  

Here are some common examples of internal controls for nonprofits: 

  • A policy that requires two signatures on a check 
  • A policy to lock the front office door when not in use 
  • A policy requiring employees may only be reimbursed for preapproved expenses 
  • A policy to conduct background checks of employees who process finances 
  • A policy to keep cash in a locked drawer 

At their core, internal controls address checks and balances on your staff, ensuring funds are not misappropriated at your nonprofit. 

Why Internal Controls Matter, at Any Organization Size 

Nonprofit fraud is more common than most boards want to believe. According to the Association of Certified Fraud Examiners, organizations with fewer than 100 employees are disproportionately affected by occupational fraud. Shockingly, the median loss per case runs into the six figures. 

Beyond preventing cases of fraud, internal controls protect your organization in two other important ways: 

  1. Honest mistakes. Internal controls prevent honest mistakes from happening at your nonprofit. Accounting errors happen, especially in organizations where staff wear multiple hats. Internal controls are created to catch the error before it becomes an audit finding. 
     
  1. Build trust. Internal controls build trust with funders. Donors, grantors, and government agencies all want to know their money is being managed responsibly. A well-documented set of controls signals that your organization takes stewardship seriously. 

The good news is that even basic controls make a significant difference. You do not need a full finance team to protect your organization. 

Core Internal Controls Every Nonprofit Should Have 

Regardless of your organization’s size, you should aim to include these foundational elements in your core internal controls:  

  • Segregation of duties. No single person should be able to authorize a transaction, record it, and reconcile it. At minimum, the person who writes checks should not be the same person who approves them. 
     
  • Dual signatures on checks. Require two authorized signatories on checks above a set threshold (for example, $500 to $1,000 for smaller organizations). This single control eliminates a large category of fraud. 
     
  • Monthly bank reconciliations. Someone independent of the person who handles day-to-day finances should review and sign off on monthly bank reconciliations. This control catches errors and unauthorized transactions quickly. 
     
  • Receipts and documentation for all disbursements. Every payment should have a corresponding invoice or receipt. Payments without documentation are a red flag in any audit. 
     
  • Board review of financial statements. Your board should receive and formally review financial statements at every meeting, not just at the year-end. This control keeps leadership informed and creates a documented oversight trail. 
     
  • Annual independent audit or review. Depending on your revenue size and funding sources, you may be required to have an annual audit. Even when it is not required, an independent financial review adds a valuable layer of accountability. 
     
  • Restricted and unrestricted fund tracking. Grant funds, designated donations, and program-specific revenue need to be tracked separately from general operating funds. Commingling restricted and unrestricted funds is one of the most common compliance issues in nonprofit audits. 

With these internal controls for nonprofits in place at your organization, your staff should be empowered to minimize the risk of misappropriated funds. 

Segregating Financial Duties with a Small Staff 

Often, small nonprofits get stuck because they have limited help and time. For example, when trying to “segregate duties,” how does a small nonprofit of one bookkeeper and an executive director do so to maintain internal controls? 

The answer is that board members and volunteers can fill in the gaps. Segregation of duties does not require paid staff for every role. It requires that different people handle different parts of a financial transaction. 

A practical model for a small or all-volunteer organization might look like this: 

  • The Executive director approves expenditures 
  • The Bookkeeper or office manager processes payments and records transactions 
  • The Board treasurer receives bank statements directly and reviews reconciliations 
  • The Finance committee or second board member provides a secondary review on transactions above a set amount 

This arrangement keeps the approval, execution, and review functions in different hands, even with a small team. 

Consider these additional safeguards for small organizations: 

  • Rotate who opens the mail, especially if checks are received.  
  • Have bank statements sent directly to someone other than the person who handles day-to-day bookkeeping.  
  • Require two board signatures on any check above your threshold. 
  • If possible, have your bank send automatic alerts for transactions above a certain dollar amount. 

None of these suggestions require additional staff, just intentionality. 

Internal Controls Checklist for Board Review 

Use this checklist to assess where your organization stands with internal controls. If your answer to any item is “no” or “unsure,” that is a priority to address at your nonprofit. 

Approvals and Authorization 

  • Expenditures above $[threshold] require documented approval before payment 
  • A second authorized signatory is required on checks above $[threshold] 
  • Capital expenditures and unbudgeted expenses require board approval 
  • Wire transfers require dual authorization 

Recording and Reconciliation 

  • Bank accounts are reconciled monthly 
  • Reconciliations are reviewed and signed off by someone independent of the bookkeeper 
  • Credit card statements are reconciled monthly with receipts attached 
  • Payroll is processed and reviewed by different individuals 

Cash and Revenue Handling 

  • Two people are present when cash is counted at events 
  • Cash and checks are deposited within [X] business days of receipt 
  • Donation acknowledgments are generated independently of cash handling 

Access and Oversight 

  • Online banking access is limited to staff who need it and reviewed annually 
  • Terminated employees are removed from financial systems immediately 
  • Petty cash has a maximum balance and is reconciled regularly 
  • The board receives and reviews financial statements at every meeting 

Grant and Restricted Fund Management 

  • Restricted funds are tracked separately in the accounting system 
  • Grant expenditures are reviewed against budget before reporting 
  • Time and effort records are maintained for grant-funded staff 

Common Internal Control Gaps and How to Fix Them 

It’s not uncommon for nonprofits to experience challenges with internal controls. Here are some of the most common internal control gaps and how you can address them at your organization: 

  • The same person handles all of finance. This is the most common gap in small nonprofits. The fix does not require a new hire; you can pull one function (typically reconciliation review or check signing) out to a board member or second staff person. 
     
  • Controls exist on paper but are not followed. A policy manual that isn’t used doesn’t count as a control. Build your procedures into workflows, checklists, and system settings rather than relying on staff to remember them. 
  • Board does not review financials regularly. Monthly financial review should be a standing agenda item, not a year-end exercise. Provide board members with a brief narrative alongside the numbers so they know what to look for. 
     
  • No independent review of bank statements. This is an easy one to fix. Have the bank statement delivered directly to the executive director or board treasurer rather than the bookkeeper and require a sign-off before it goes into the files. 
     
  • No formal policy for reimbursements. Personal reimbursements to staff and leadership, including the executive director, need a documented approval process. The ED should not approve their own reimbursements. 
     
  • System access is too broad. Review who has access to your accounting system, your bank’s online portal, and your payroll platform at least annually. Access should be limited to what each person actually needs. 

How Technology Strengthens Nonprofit Internal Controls 

You already know that having strong internal controls for your nonprofit is crucial. But if you have well-designed accounting software to match your controls, it makes it much harder for those controls to be bypassed. 

The most valuable technology features for internal controls are ones that make the right process the easy process.  
 
Here is what that looks like in practice: 

  • Approval workflows route transactions to the correct approver before they are posted, so dual-approval is built into the system rather than enforced by memory. 
  • Audit trails record who entered, approved, or modified every transaction. This documentation is invaluable during an audit and creates a deterrent against unauthorized changes. 
  • User permissions limit what each staff member can see and do in the system. A data entry person should not be able to post journal entries. A program manager should not be able to cut a check. 
  • Automated reconciliation alerts flag transactions that fall outside normal patterns, giving your finance staff early warning of potential errors or unauthorized activity. 
  • Restricted fund tracking keeps grant and designated funds separate within the system, so commingling is structurally difficult rather than just prohibited by policy. 

For nonprofits looking to put these controls into practice, MIP Accounting’s audit management capabilities are built specifically around the controls and documentation requirements nonprofits face.  

Learn more about MIP’s nonprofit accounting tools: Learn more about MIP Accounting’s audit management tools. 

FAQ 

What are the most important internal controls for a small nonprofit? 

Start with three priorities. Require two signatories on checks above a set threshold, have someone independent review and sign off on monthly bank reconciliations, and make sure your board reviews financial statements at every meeting. These three controls address the most common fraud vectors and audit findings in small nonprofits. 

How can a small nonprofit segregate duties with limited staff? 

Board members and volunteers can serve in oversight roles. The goal is to separate the functions of authorization, execution, and review. You do not necessarily need three paid staff to do it. Your board treasurer can review reconciliations. A finance committee member can serve as a second check signer. These arrangements are documented in your internal control policy and are fully acceptable to auditors. 

What is a good internal control policy for nonprofits? 

A good internal control policy covers cash handling, disbursement approval, reconciliation procedures, access controls, and restricted fund management. It should be written in plain language, reviewed by your board annually, and specific enough that a new staff member could follow it without additional guidance. 

How often should internal controls be reviewed? 

At minimum, conduct a formal internal control review once per year, ideally before your annual audit. It is also worth reviewing controls after any significant staff change (especially finance staff turnover), after any suspected fraud or error, and when you adopt new technology or significantly change financial processes. 

Can accounting software replace manual internal controls? 

No. Software enforces controls more consistently than manual processes, but it cannot replace the judgment and oversight that come from a board that reviews financials, an ED who is paying attention, and staff who understand why controls matter. Think of accounting software as providing the infrastructure that makes your controls easier to follow. 

Put Your Internal Controls to Work 

Strong internal controls protect your organization’s assets, satisfy your auditors, and give your board confidence that finances are being managed with care. The controls that matter most are not complicated. They require intention, documentation, and consistent follow-through. 

If you are looking to build or strengthen your financial controls, MIP Accounting’s audit management tools can help you automate approvals, maintain a complete audit trail, and manage restricted funds with the precision your funders expect.