3 Dangerous Assumptions Nonprofits Make About Internal Controls
Oct 01, 2026
I’ve worked with nonprofits long enough to have seen fraud up close.
Not in theory. Not in a textbook.
On my watch, with controls in place, at organizations full of good people doing good work.
And here’s what I’ve learned: you can’t control what motivates someone to steal. You can’t control how they justify it to themselves. But you can control whether the opportunity exists.
That’s the piece that belongs to you.
Motivation and rationalization live inside a person. Opportunity lives inside your systems. And every time I’ve seen fraud happen, it found a gap that no one thought was there—or that everyone assumed someone else was watching.
So when I tell you that some of the biggest financial risks I see in nonprofits don’t begin with dishonest people, I mean it.
They begin with trust.
“We’ve known her for years.”
“He would never do something like that.”
“We’re a small organization. Someone would notice.”
I understand why nonprofit leaders think this way. Our organizations are built around relationships. We hire people who believe in the mission. In churches especially, we may work alongside people we’ve known and served with for years.
But trust is not an internal control.
And good internal controls aren’t an accusation that someone is untrustworthy. They protect the organization, but they also protect the trustworthy people who serve it.
So let’s look at three dangerous assumptions I see nonprofits make about internal controls—and what I want you to do instead.
Assumption #1: “We Trust the Person”
I see this all the time.
One person has handled the finances for years. Everyone loves her. She knows where everything is. She receives the money, enters the transactions, pays the bills, reconciles the bank account, and prepares the reports.
And when someone suggests separating some of those responsibilities, the response is:
“But we trust her.”
That’s not the question.
You can trust someone completely and still build appropriate internal controls around their work.
In fact, you should.
And fraud isn’t the only reason.
Suppose there’s an error. A deposit goes missing. A transaction gets entered incorrectly. Something doesn’t reconcile.
If only one person has been involved in the entire process, you’ve created a problem for the organization and for that person.
There may be no independent record showing what happened.
Good internal controls protect good people.
They create documentation. They create verification. They make responsibilities clear. And they make it much easier to identify an innocent mistake before it becomes a significant problem.
So don’t build your financial processes around how much you trust a particular person.
Build processes that would still be appropriate no matter who occupied the position.
Assumption #2: “Someone Would Notice”
This one sounds incredibly reasonable.
“We’re a small nonprofit.”
“We all work closely together.”
“Our board knows what’s going on.”
“If something were wrong, somebody would notice.”
Okay.
Who?
That’s the question I want you to answer.
Who opens or independently reviews the bank statement?
Who verifies changes to payroll?
Who reviews credit card transactions and supporting documentation?
Who confirms that deposits recorded by the organization actually reached the bank?
Who reviews transactions entered or approved by the person responsible for the accounting?
If the answer is some version of “the board” or “leadership,” I want you to go one step further.
Which person?
And then:
How often?
And finally:
Where is that review documented?
Because “someone would notice” isn’t an internal control.
A control has an owner.
It has a process.
And there should be evidence that the process actually happened.
This is where small nonprofits can get into trouble. Everyone assumes someone else is looking.
The bookkeeper assumes the treasurer is reviewing it.
The treasurer assumes the Executive Director or Senior Pastor is reviewing it.
Leadership assumes the finance committee is reviewing it.
And the finance committee assumes the reports they’re receiving have already been reviewed.
Suddenly, you can have a room full of responsible people—and nobody actually performed the control.
Opportunity often exists in the space between “I thought you were checking that” and “I thought you were.”
Assumption #3: “This Process Has Always Worked”
This may be the most deceptive assumption because sometimes the process has worked.
Maybe it worked beautifully when your organization had a $300,000 budget, five employees, one credit card, and a handful of programs.
But now you have more employees.
More transactions.
More credit cards.
More vendors.
More restricted funds.
More programs.
Maybe you’ve added a second location or campus.
Nobody did anything wrong.
The organization simply outgrew the process.
Internal controls have to grow with the organization.
A process that was perfectly reasonable when you were small can become a significant vulnerability as financial complexity increases.
That’s why I don’t want you asking only:
“Has this worked?”
I want you asking:
“Does this still work for the organization we are today?”
And ideally, you should also be asking whether it will work for the organization you’re becoming.
Growth changes risk.
Your internal controls should change with it.
Trust and Accountability Belong Together
Here’s the distinction I want you to remember:
Trust is relational. Internal control is structural.
You need both.
Healthy organizations don’t replace trust with policies and procedures. They build structures that allow trust and accountability to coexist.
You can trust your bookkeeper and have someone else review the bank statement.
You can trust your Executive Director or Senior Pastor and still require receipts.
You can trust your finance team and separate authorization, custody, recordkeeping, and reconciliation wherever practical.
You can trust your board and still clearly assign who is responsible for reviewing what.
That’s not distrust.
That’s stewardship.
And for small nonprofits, this does not mean you need to hire five more people so every financial task can be performed by someone different.
You may need to get creative.
A board member may perform an independent review. Someone outside the accounting function may approve certain transactions. Bank alerts or accounting-system permissions can add another layer of oversight.
The goal isn’t bureaucracy.
The goal is to intentionally answer the question:
Who is checking the person who is doing the work?
Because you cannot control someone else’s motivation.
You cannot control what someone may someday rationalize.
But you can control the opportunity your systems give them.
Try This With One Financial Process
So here’s what I want you to do.
Pick one financial process in your organization.
It could be:
- Deposits
- Payroll
- Credit cards
- Expense reimbursements
- Bill payments
- Bank reconciliations
Then ask three questions:
Who does it?
Who independently verifies it?
What evidence shows that verification happened?
If you get to the second question and your answer is:
“Well, we really trust the person doing the first one…”
You’ve found a control gap.
And that’s where I would start.
You don’t have to fix everything today. Start with this one thing.
Build Stronger Internal Controls
If you’ve identified a gap, our Internal Controls for Small Nonprofits playlist walks through practical safeguards you can put in place—even with a small team.
Trust your people. Build systems that protect them. And inspect what you expect.
Sign Up to Receive Financial Tips in Your In Box
We hate SPAM. We will never sell your information, for any reason.
