GivingArc Nonprofit accounting Service

Nonprofit Internal Controls: Simple Safeguards Every Small Nonprofit Needs

A small nonprofit's desk with a lockbox, bank statement, and a simple checklist representing internal controls and fraud safeguards

You have two people on staff. Maybe three. The idea of “nonprofit internal controls” sounds like something built for an organization with a finance department and a floor of cubicles — not for you, the person who already does the deposits, signs the checks, and reconciles the account at your kitchen table on Sunday night.

So it gets skipped. Not out of carelessness — out of math. There aren’t enough hands to split the work, so one trusted person does all of it. That feels like the only option a small nonprofit has.

Here’s the uncomfortable part, and then the hopeful part. The uncomfortable part: small doesn’t mean safe. The hopeful part: being small is actually the best time to build the safeguards — and the ones that matter most are nearly free.

Key Takeaways

  • Small doesn’t mean safe. In the ACFE’s 2024 fraud study, organizations with fewer than 100 employees had a median loss of $141,000 — in large part because smaller organizations have fewer anti-fraud controls in place.
  • The best time to build internal controls is while you’re small. Light habits set with two people grow with the organization, instead of being painfully retrofitted at fifteen.
  • Internal controls are not about distrusting your staff. They’re a seatbelt, not an accusation — they protect honest people and the organization at the same time.
  • When you genuinely can’t separate duties, compensating controls — a second set of eyes on the bank statement, board review — do the same job.
  • Five safeguards you can set up this week cost nothing but a habit. The most powerful one: make sure someone other than the bookkeeper opens the bank statement.

The myth that small means safe

There’s a quiet assumption that fraud is a big-organization problem — that you need real money on the table before anyone bothers to steal it. The data says the opposite. In the Association of Certified Fraud Examiners’ 2024 Report to the Nations, organizations with fewer than 100 employees had a median fraud loss of $141,000 — the second-largest of any size category. The reason the ACFE gives is not that small organizations attract worse people. It’s that they have fewer controls in place to catch a problem early.

That’s the part worth sitting with. The vulnerability isn’t the people. It’s the structure — one trusted person handling money start to finish, with no second set of eyes, not because anyone planned it that way but because there was no one else to ask.

And the cost, when something goes wrong at a small nonprofit, is rarely just the dollars. It’s a board that stops trusting the staff. A funder who reads about it. A founder who quietly leaves. For an organization running on reputation and goodwill, the damage outlasts the loss.

None of this is meant to scare you. It’s meant to retire one specific belief: that being small is its own protection. It isn’t. But being small is an advantage — just not the one you’d expect.

Small isn’t a reason to skip controls — it’s the best time to build them

Think about how a house gets its wiring. You run the wires before the walls go up, while everything is open and easy to reach. Nobody waits until the house is finished, the family has moved in, and the walls are painted — and then decides to tear them open to add outlets. That’s ten times the work and everybody hates it.

Internal controls are the wiring. When you’re small, the walls are still open. You have a handful of transactions, a couple of people, and no entrenched habits to undo. A control you set today — “the bank statement always goes to a board member first” — takes thirty seconds to establish and then simply becomes how things are done. It grows with you. By the time you’re fifteen people, it’s already load-bearing.

The organizations that struggle are the ones that wait. At five staff, the founder did everything and everyone trusted it. At twenty, no one can quite remember who approves what, the books have three years of improvised habits baked in, and untangling it means an outside review and a lot of awkward conversations. Retrofitting controls into a grown organization is the wall-tearing version. Building them now is the open-wall version.

You’re not too small for internal controls. You’re at the exact size where they’re easiest to build.

Two-person nonprofit team, one handing a bank statement to the other, illustrating segregation of duties with a small staff

What internal controls actually are

Strip away the audit-speak and nonprofit internal controls are just this: the small, repeatable habits that make sure your organization’s money and records are handled honestly and accurately — without depending on any single person being perfect.

The phrase makes people flinch because it sounds like surveillance. It sounds like you’re accusing your bookkeeper — often a devoted volunteer or your most loyal staffer — of being a thief. So here’s the reframe that matters:

A control is a seatbelt, not a lock. A lock says I don’t trust you. A seatbelt says I care what happens to you. You don’t put on a seatbelt because you plan to crash, and you don’t resent it on the days you don’t. It’s just there, quietly, for the day something goes wrong. Good controls protect your honest staff more than anyone — because the day a board member asks “how do we know the money’s handled right?” the person doing the books can point to the system instead of their own word. A control turns “trust me” into “here’s how you can see for yourself.” That protects the person, not just the money.

That single shift — from suspicion to protection — is what makes controls something a small, close-knit team can actually adopt without it feeling like an insult.

Why small nonprofits are the most vulnerable

Three things stack up at a small organization, and together they create the gap:

👥

Too few hands to split the work

One person receives the money, deposits it, records it, and reconciles the account. The whole cycle lives with one set of hands — the textbook condition for an error or a theft to go unnoticed.

🤝

A culture built on trust

Small nonprofits run on mission and loyalty. Asking to double-check a beloved colleague’s work feels like a betrayal — so no one asks, and the gap stays open for years.

🎓

No one was trained for this

The person keeping the books usually inherited the job, not chose it. Nonprofit accountingrestricted funds, functional expenses, the fund accounting logic underneath — is a real specialty, and the controls that go with it were never part of anyone’s job description.

If any of that describes your organization, you’re not behind — you’re normal. Most of the small nonprofits we’ve sat beside started exactly here. The point isn’t guilt. It’s that the gap is fixable, and cheaper to fix than you think. (If shaky books are part of the picture too, our guide to best practices for nonprofit bookkeeping and our bookkeeping and accounting service are good companions to this one.)

The “you can’t separate duties with two people” problem — solved

The gold standard of internal controls is segregation of duties — the principle that no single person should control an entire transaction from start to finish. The National Council of Nonprofits puts it plainly: the person who logs in the checks that arrive in the mail shouldn’t be the same person who deposits them, and the person who prepares payroll shouldn’t be the one who hands out the paychecks.

Which raises the obvious objection: that’s lovely, but I have two people. Sometimes one.

This is where small organizations give up — and they shouldn’t, because there’s a well-established answer. When you can’t fully separate duties, you use compensating controls: a different check that achieves the same goal — an independent set of eyes somewhere in the cycle. You can’t split the work three ways, but you can make sure someone outside the work sees it.

The most powerful compensating control costs nothing: a person who doesn’t touch the books — a board treasurer, a finance committee member — reviews the monthly bank statement and reconciliation directly. Not a summary the bookkeeper prepared. The actual statement, from the bank. That one habit closes most of the gap, because the whole point of separating duties is an independent look, and an independent look is exactly what that is.

5 simple safeguards you can set up this week

A simple checklist of five internal control safeguards on a clipboard, friendly flat illustration in lavender and cream

These are the nonprofit internal controls that actually move the needle for a small team — and none of them require new software, a bigger staff, or a consultant. Each is a habit you can put in place in an afternoon. Start with the first one — if you do nothing else, do that.

1

Someone other than the bookkeeper opens the bank statement

Have the monthly statement go to a board treasurer or a second staffer first — or arrive at a separate email or address — so a second person sees every transaction before it’s reconciled. This single habit is the highest-value control a small nonprofit can adopt, and it’s free.

2

Split the money cycle wherever you can

Even with two people, the one who receives or logs incoming checks shouldn’t be the only one who deposits them, and whoever prepares payroll shouldn’t be the one to distribute it. Hand off one step — that’s segregation of duties at small scale.

3

Set a dollar threshold that requires a second approval

Pick a number that fits your budget — say, any payment over $1,000 — and require a second person (a board officer is fine) to approve it before it goes out. It slows down exactly the transactions worth slowing down.

4

Put the financials in front of the board every month

A short, regular review by the board or finance committee — the statement, the reconciliation, anything unusual — turns oversight from an annual scramble into a steady habit, and creates the independent look that catches problems early.

5

Run an occasional surprise check

Once or twice a year, have someone pull a random month and trace a few transactions end to end — receipt, deposit, record. It’s quick, it’s not an accusation, and just knowing it happens is a deterrent on its own.

Write these down. A one-page document that says who does what, what gets reviewed, and by whom — that is your internal controls policy. It doesn’t need to be longer than a page to be real.

The board’s role in internal controls

For a small nonprofit, the board isn’t just where controls are approved — it’s often where they live. When you don’t have enough staff to separate duties, your board members are the independent eyes the structure needs. A treasurer who reviews the bank statement — and knows how to read the financial statements in front of them — is doing real internal-control work, not ceremony.

There’s also a compliance dimension worth knowing. The IRS’s Form 990, Part VI asks directly whether your organization has key governance policies — a conflict-of-interest policy, a whistleblower policy, a document-retention policy — and whether the board reviews the 990 before it’s filed. These aren’t internal controls in the accounting sense, but they’re part of the same family: documented practices that show the organization is governed with care. (They also overlap with what auditors look for — our nonprofit audit requirements guide covers when an audit comes into play.) And in April 2026, the Treasury Department signaled coming revisions to Form 990 aimed at clearer insight into how nonprofits receive, control, and deploy funds — a reminder that the direction of travel is toward more scrutiny of financial oversight, not less.

The takeaway for a small organization: a board that actually looks at the numbers each month is doing two jobs at once — strengthening your controls and building the governance record the IRS increasingly expects to see.

When to bring in outside help

Most of what’s above, you can do yourself this week. But there’s a specific limit to a small team: you can’t create a truly independent set of eyes from inside a two-person office. At some point, the most honest control is one that comes from outside.

That’s often the quiet reason organizations move their books to an outside accountant — not just for accuracy, but because an external bookkeeper or accounting firm is the segregation of duties a small staff can’t build alone. The person recording your transactions no longer reports to the person spending the money. The independence is structural. If you’re weighing that step, our guides on when to outsource nonprofit accounting and how to choose a nonprofit CPA walk through it — and our Form 990 and tax service is here when you’re ready. You can always reach out to us to talk it through.

You don’t have to outsource everything to get the benefit. Sometimes the right move is keeping the day-to-day in-house and having an outside professional do the monthly review — the independent look — while your board provides oversight. The structure matters more than who sits in which seat.

Want the independent set of eyes without hiring a second finance person?

GivingArc handles nonprofit bookkeeping, Form 990 prep, and monthly review for small 501(c)(3)s — the outside look your controls need. No pressure, just a conversation when you’re ready.

Talk to us →

Frequently Asked Questions

Common questions from small-nonprofit leaders and boards setting up internal controls.

Internal controls are the routine habits and checks that protect a nonprofit’s money and records — things like having a second person review the bank statement, requiring approval for larger payments, and separating who handles cash from who records it. Their purpose is to catch errors and prevent fraud without relying on any single person being perfect.

No. Smaller organizations actually face higher fraud risk, largely because they have fewer controls in place — in the ACFE’s 2024 study, organizations with under 100 employees had a median loss of $141,000. Being small also makes controls easier to build, since you have fewer transactions and no entrenched habits to undo. The most important safeguards, like a second set of eyes on the bank statement, cost nothing.

When you can’t fully separate duties, you use compensating controls — an independent check that achieves the same goal. The most effective one is having someone who doesn’t keep the books, such as a board treasurer, review the monthly bank statement and reconciliation directly. You can also hand off a single step in the money cycle and require board approval above a dollar threshold.

There’s no single federal law that mandates a specific set of internal controls for every nonprofit. However, the IRS Form 990, Part VI asks whether your organization has key governance policies — conflict-of-interest, whistleblower, and document-retention policies — and funders, grantmakers, and auditors routinely expect sound controls. Some states also impose audit and oversight requirements above certain revenue levels.

For a small nonprofit, the board often provides the independent oversight that a tiny staff can’t create internally. A treasurer or finance committee reviewing the monthly bank statement and financials is doing real internal-control work. The board is also responsible for adopting governance policies and, ideally, reviewing the Form 990 before it’s filed.

GivingArc provides bookkeeping, Form 990 preparation, and nonprofit-specialized accounting for small and mid-size 501(c)(3) organizations across the US. We’ve spent years in the seat next to the executive director. Reviewed by Min Kim, CPA.