loader image

Every nonprofit board member and executive director eventually asks the same question: “How do we protect our organization when we only have two or three people handling the money?” It’s a fair concern. Segregation of duties — the classic control that separates who authorizes, who handles, and who records financial transactions — was designed with larger staffs in mind. But a lean team doesn’t mean you have to accept weak controls. It means being intentional about how you fill the gaps.

This issue looks at practical, low-cost ways small nonprofits can strengthen internal controls, reduce the risk of error or fraud, and give donors, grantors, and board members confidence that resources are being safeguarded responsibly.

Tips on segregation of duties, even with a smaller staff

WHY THIS MATTERS MORE THAN YOU THINK

Nonprofits are especially vulnerable to control gaps because trust often substitutes for process. Long-tenured staff, close-knit teams, and a shared sense of mission can make it uncomfortable to ask “who’s checking this?” Unfortunately, that same trust is exactly what allows errors and misappropriation to go unnoticed for years. A modest, well-designed set of controls protects your staff as much as your assets — it removes opportunity and it removes suspicion.

THE THREE FUNCTIONS TO KEEP APART

Segregation of duties rests on separating three roles for any given transaction:

•      Authorization — approving that a transaction should happen (e.g., approving a bill or a new vendor).

•      Custody — physical or system access to the asset (e.g., signing checks, handling cash, accessing the bank portal).

•      Recordkeeping — entering and reconciling the transaction in the books.

In a well-staffed organization, three different people hold these roles. In a two- or three-person shop, that’s often impossible — which is where compensating controls come in.

PRACTICAL TIPS FOR A SMALL STAFF

•      Bring the board or treasurer into the loop. Have a board member or treasurer — someone outside daily operations — review and approve check runs, sign checks over a set dollar threshold, or review the monthly bank statement before staff can act on it.

•      Separate the bank reconciliation from cash handling. Whoever deposits money or pays bills should not be the same person who reconciles the bank statement each month. If staffing doesn’t allow this, have a board member or outside bookkeeper perform the reconciliation.

•      Require dual approval for larger disbursements. Set a dollar threshold above which two signatures, or one signature plus documented board approval, are required. This single step closes one of the most common fraud pathways.

•      Use your accounting software’s permission settings. Most cloud accounting platforms let you restrict who can create vendors, edit historical entries, or issue payments. Configure access by role, not by convenience.

•      Turn on bank and card alerts. Real-time alerts for large transactions, new payees, or failed login attempts give oversight even when staff are stretched thin.

•      Rotate responsibilities periodically. Where possible, rotate who processes deposits, reconciles accounts, or reviews expense reports every few months. Fresh eyes catch what routine misses.

•      Require documented approval for payroll changes. Changes to pay rates, new hires, or direct deposit information should require sign-off from someone other than the person who processes payroll.

•      Schedule an independent annual review. An outside CPA can review your controls, walk through key processes, and flag gaps before they become problems — often as part of your annual financial statement engagement.

A QUICK SELF-ASSESSMENT

Ask your finance team and board these five questions this month:

•      Can any single person both approve and process a payment without a second set of eyes?

•      Who reconciles the bank statement, and are they independent of cash handling?

•      Is there a dollar threshold that triggers board or treasurer approval?

•      Are accounting system permissions reviewed at least annually?

•      Would a new board member be able to explain your controls in plain language?

If any answer gives you pause, that’s a good place to start — not a reason for alarm. Most small nonprofits find that one or two targeted changes close the majority of their exposure.

THE BOTTOM LINE
You don’t need a large staff to have strong controls — you need clear roles, an engaged board, and a few well-placed checkpoints. Small, consistent habits protect your mission and your reputation.

Leave a Reply

Your email address will not be published. Required fields are marked *