Most nonprofit financial problems don’t start as problems. They start as small gaps that go unnoticed while the organization is still small, manageable, and run by a tight-knit team that trusts each other.
Then the organization grows.
Grants get larger. Programs multiply. New staff and volunteers join. And the informal systems that once worked perfectly well begin to strain under responsibilities they were never built to carry. The risk here isn’t bad intentions—it’s that financial responsibility tends to grow faster than the controls designed to support it.
What makes these gaps especially difficult is that they’re invisible during the good years. As long as nothing goes wrong, the organization has no reason to question how things are done. The bookkeeping gets done, the bills get paid, the reports get filed. It’s only when something unexpected happens—a staff departure, a funder’s audit request, a discrepancy in the bank account—that the missing controls suddenly become obvious. By then, the easy fix has become an expensive scramble.
Below are four internal control gaps we see most often in growing nonprofits. None of them require a finance department or expensive software to fix. They simply require intention.
1. Weak Segregation of Duties
Segregation of duties is exactly what it sounds like: making sure no single person controls an entire financial process from start to finish.
The classic warning sign is when one person can approve an invoice, issue the payment, and reconcile the bank account. When all three live with one individual, two things happen. First, honest errors can go undetected because no one else is positioned to catch them. Second, the opportunity for fraud quietly increases—not because that person is dishonest, but because the structure removes the natural checkpoints that protect everyone.
Small nonprofits often assume segregation of duties is a luxury reserved for larger organizations. It isn’t. Even with a team of two or three, you can separate key responsibilities. The person who approves a payment shouldn’t be the same person who reconciles the account. A board member or executive director can review reconciliations even if they don’t prepare them. The goal isn’t to slow things down—it’s to make sure no single point of failure can compromise the whole system.
When you genuinely can’t separate duties because the team is too small, the answer isn’t to give up on the control—it’s to introduce oversight from outside the daily process. A treasurer who reviews the monthly bank statement before it reaches the bookkeeper, a board member who receives a copy of every reconciliation, or an outsourced accounting partner who performs an independent review all accomplish the same protective purpose. The principle to remember is simple: the person who handles the money should never be the only person who checks the money.
2. Approvals Happen, But They Aren’t Documented
Most growing nonprofits do approve their spending. The problem is how those approvals happen.
Verbal sign-offs in the hallway, a quick “yes, go ahead” over text, scattered email threads buried in someone’s inbox—these all feel sufficient in the moment. And they work fine, right up until the moment someone asks who approved a specific payment six months ago. Suddenly no one can say for certain, and the organization is left reconstructing a decision from memory.
A documented approval trail solves this. It doesn’t have to be complicated: a consistent place where approvals are recorded, a clear threshold for what requires sign-off and from whom, and a simple record that connects each significant payment to the person who authorized it. This protects leadership during audits, reassures funders, and—just as importantly—protects the individuals making decisions. When the trail is clear, no one has to defend a choice based on recollection alone.
The most practical step here is to write down your approval thresholds and stick to them. Decide, for example, that any expense under $500 can be approved by the program manager, anything between $500 and $5,000 requires the executive director, and anything above that needs board or treasurer sign-off. Once those rules exist on paper, approvals stop being a matter of who happened to be in the room and become a consistent, defensible process. Auditors look favorably on organizations that can show not just that spending was approved, but that it was approved by the right person according to a documented policy.
3. Financial Reports Are Prepared But Not Discussed
Producing financial reports is not the same as governing with them.
It’s common for a board to receive a packet of financials before each meeting, file it away, and move on. The reports exist. They’re accurate. But they’re not actually being used. Good governance happens in the discussion—when leadership takes the time to review the numbers, ask why a particular expense category jumped, understand significant variances from the budget, and let those insights shape real decisions.
A financial report that no one questions is just paper. A financial report that prompts a board member to ask, “Why are program costs up 30% this quarter?” is oversight in action. The difference isn’t the quality of the report—it’s whether anyone engages with it. Building even fifteen minutes of genuine financial discussion into each board meeting transforms reporting from a formality into a decision-making tool.
Part of the problem is that financial reports are often presented in a format that’s hard for non-accountants to engage with. Pages of line items and account codes invite glazed eyes, not good questions. The organizations that govern well tend to pair their statements with a short, plain-language summary: three or four sentences explaining what changed since last period, what’s on track, and what deserves the board’s attention. When the numbers are framed in terms of the mission—”we’re spending faster than projected on the after-school program because enrollment doubled”—board members can actually exercise judgment instead of nodding along. Oversight only works when the people responsible for it understand what they’re looking at.
4. Financial Knowledge Lives With One Person
This may be the most underestimated risk of all.
In many nonprofits, the entire financial operation runs through a single person—one bookkeeper, one finance volunteer, one staff member who simply “knows how everything works.” Everyone trusts them, they’re good at their job, and so the organization comes to depend on them entirely.
The vulnerability shows up the moment that person is unavailable. They leave for a new role, go on extended leave, or step back unexpectedly—and suddenly no one knows the passwords, the processes, the relationships, or the reasoning behind how things are done. Operations stall. Continuity breaks. The organization discovers, too late, how much risk was concentrated in one individual.
Strong organizations build systems that outlast the people who run them. That means documenting processes, cross-training a second person on core financial tasks, and keeping critical information accessible to leadership rather than locked inside one person’s head. The objective isn’t to distrust your team—it’s to make sure the mission can survive any single departure.
A useful test is to ask a deceptively simple question: if your bookkeeper won the lottery and quit tomorrow, how long would it take someone else to keep the organization running? If the honest answer is “we have no idea,” you’ve found a gap worth closing. Start by writing down the recurring monthly tasks, where the accounts and logins live, which vendors and funders need to be paid and when, and how the books are actually closed each month. This documentation costs nothing but a few hours, and it converts fragile, person-dependent knowledge into a durable organizational asset. The same documentation also makes onboarding a new hire dramatically faster and reduces the leverage any single individual holds over operations.
Internal Controls Protect the Mission, Not the Bureaucracy
It’s worth being clear about what internal controls are for. They aren’t about adding red tape, slowing down decisions, or signaling distrust toward dedicated staff and volunteers. They exist to protect your mission, strengthen board oversight, and give leadership genuine confidence in every financial decision the organization makes.
There’s also a reputational dimension worth naming. Funders, major donors, and grantmakers increasingly want assurance that the organizations they support handle money responsibly. Demonstrating that you have segregation of duties, documented approvals, engaged financial governance, and resilient systems isn’t just good internal practice—it’s a competitive advantage when you’re asking someone to trust you with their contribution. Sound controls signal a well-run organization, and well-run organizations attract more support.
The good news is that closing these gaps rarely requires a major overhaul. It requires noticing where your systems have fallen behind your growth, and making a few deliberate adjustments before a small gap becomes a serious problem. Most of the fixes described here can be implemented in an afternoon and refined over time. What matters is starting before circumstances force your hand.
So here’s the question worth bringing to your next board meeting: Which of these four gaps deserves the most attention in your organization right now?
If you’re not sure where you stand—or you suspect you’ve outgrown the controls you currently have in place—a financial health check can surface the gaps that matter most before they create bigger problems.
