Nonprofit fraud prevention: Practical steps to reduce risk

Consider a comprehensive approach to strengthening internal controls.

Key takeaways

  • Strong internal controls and separation of duties are among the most effective nonprofit fraud prevention measures.
  • Check fraud, business email compromise and ransomware remain some of the most common threats facing nonprofit organizations.
  • Board oversight, employee training and ongoing monitoring can help nonprofits detect fraud early and limit financial and reputational damage.

Nonprofit organizations exist to serve their communities, often operating with limited budgets and lean teams dedicated to advancing their missions. It’s an unfortunate reality that those same characteristics can make nonprofits attractive targets for fraudsters seeking access to funds, donor information and sensitive organizational data.

Nonprofit fraud prevention should be a priority for organizations of every size. According to a study by the Association of Certified Fraud Examiners, nearly one in 10 nonprofits experience fraud each year, with a median loss of $69,000. In many cases, fraud occurs because organizations lack sufficient internal controls, management oversight or safeguards designed to prevent employees from bypassing established procedures.

Beyond direct financial losses, fraud can damage donor confidence, strain stakeholder relationships and negatively impact an organization's reputation. Taking a proactive approach to fraud prevention can help nonprofits protect both their resources and the communities they serve.

Why nonprofits are vulnerable to fraud

Nonprofits face unique operational challenges. Limited staffing, budget constraints and the desire to maximize mission-focused spending can sometimes result in fewer resources dedicated to fraud prevention and cybersecurity.

Common risks that could potentially lead to system compromise or internal fraud at a nonprofit include:

  • Insufficient internal controls
  • Limited management review of financial activity
  • Inadequate segregation of duties
  • Override of established controls
  • Lack of employee or volunteer training
  • Weak cybersecurity practices

When too much responsibility is assigned to a single individual, the opportunity for fraud increases significantly.

How internal control failures can lead to fraud

Consider a common scenario.

A nonprofit hires a talented accounting professional who quickly earns the trust of executives and board members. As responsibilities expand, that individual gains control over invoice approval, payment processing, account reconciliations and financial reporting.

Initially, unauthorized transactions may seem small. Over time, however, the individual realizes no one is closely reviewing activity. Small personal purchases can escalate into falsified invoices, fraudulent payments and manipulated reports designed to conceal wrongdoing.

By the time questions arise, losses may have accumulated over several years.

Situations like this are not uncommon. The lesson is clear: nonprofit fraud prevention depends on creating systems that reduce opportunity, regardless of how trustworthy an employee may appear. Controls should protect both the organization and its people.

Common types of fraud affecting nonprofits

Check fraud

One of the oldest fraud schemes remains one of the most prevalent. Check fraud accounts for a significant percentage of fraud activity, including fraud involving related payment instruments such as debit cards.

Checks contain valuable information, including names, addresses, bank account numbers and routing numbers. If checks fall into the wrong hands, criminals may alter, counterfeit or forge them to steal funds.

According to Jeff Taylor, head of Commercial Fraud Forensics at Regions, fraudsters may “wash” existing checks, create counterfeits using blank check stock or forge the endorsement signature to steal money from nonprofit organizations.

5 best practices to help prevent check fraud

Taylor recommends the following actions:

  1. Reconcile accounts promptly to identify unusual activity.
  2. Place stop payments on checks that are lost or stolen.
  3. Convert paper payments to electronic payments whenever possible.
  4. Securely store and properly destroy check stock, deposit slips and bank statements.
  5. Use Positive Pay with Payee Name Verification to compare issued payment information against presented items.

As Taylor notes, “You want to convert to electronic payments anytime you can because it gives you more control over your transaction.”

Business email compromise

Business email compromise (BEC) continues to grow and can be especially damaging for nonprofits.

Common schemes include executive email intrusion, in which criminals impersonate senior leaders and request payments or gift card purchases; vendor email intrusion, in which criminals request changes to payment instructions or remittance information; and employee email intrusion, in which criminals attempt to redirect payroll payments or expense reimbursements.

These attacks often rely on urgency, trust and social engineering rather than technical sophistication.

Ransomware attacks

Ransomware occurs when criminals gain access to a network, encrypt critical systems and demand payment to restore access.

Attackers may gain entry through phishing emails, malicious links, infected software, compromised websites or vulnerable systems. For nonprofits that depend on continuous access to operational and donor data, ransomware can create significant financial and operational disruptions.

A modern nonprofit fraud prevention strategy

Taylor recommends the following steps when taking a proactive approach to fraud prevention in your organization.

Strengthen cybersecurity controls

A strong cybersecurity foundation helps reduce both fraud and operational risk.

Organizations should conduct regular IT vulnerability assessments, maintain properly configured firewalls and consistently install security updates and patches. Secure password requirements and multifactor authentication should also be standard practice.

Fraud prevention tools such as Positive Pay, ACH Positive Pay and Account Reconciliation services can provide additional layers of protection.

Train employees and volunteers

Fraud prevention is most effective when everyone understands their role.

Provide ongoing training for employees and volunteers who have access to systems, donor information or payment processes. Below are some examples of topics to include.

Password and Wi-Fi router security: Train employees and volunteers to create strong passwords, enable multifactor authentication and secure Wi-Fi networks to help prevent unauthorized access to systems and data.

Phishing awareness: They should learn to recognize suspicious emails, messages and links so they can avoid scams designed to steal credentials or data.

Social engineering tactics: They should know how to identify manipulation techniques used by fraudsters who attempt to gain trust and trick people into sharing confidential information.

Safe handling of sensitive information: They need to understand how to properly collect, store, share and dispose of data to reduce the risk of a breach.

Payment verification procedures: They should know how to follow approval and verification processes before handling payments or changing payment details.

Because nonprofit organizations often experience staff and volunteer turnover, training should be repeated regularly.

Create a fraud risk governance plan

A formal fraud governance framework can help organizations respond consistently and effectively to emerging threats.

Key elements may include defined risk tolerance levels, vendor management procedures, fraud response protocols, cybersecurity insurance review, payment verification requirements and documented internal controls.

Organizations should also establish callback procedures for payment changes and other high-risk transactions. Remember to Stop, Call and Confirm: A three-step fraud prevention method that helps organizations verify urgent or unexpected messages before taking action.

Increase board oversight

Effective nonprofit fraud prevention starts at the top.

Many organizations are elevating fraud and cybersecurity discussions to the board level and creating dedicated committees to oversee risk management activities. Active board engagement can strengthen accountability and support a culture of risk awareness throughout the organization.

Encourage reporting

Employees are often the first to identify suspicious activity.

Establishing an anti-fraud policy and implementing a fraud reporting hotline can create an environment where concerns are raised early. Fraud hotlines remain an important detection tool because a substantial number of fraud cases are identified through employee tips.

Review internal controls regularly

Strong internal controls remain one of the most important nonprofit fraud prevention measures.

Organizations should separate responsibilities whenever possible. Ideally, no single person should control the initiation, approval, payment and reconciliation of a transaction.

For example:

  • The person approving invoices should not issue payments.
  • The person reconciling accounts should not have access to the related assets.
  • Board members or finance committee representatives should provide oversight when executive-level transactions are involved.

Implement ongoing monitoring

Monitoring can help identify unusual activity before losses become significant.

Examples include monthly reviews of payroll changes, analysis of credit card activity, reviews of vendor additions or modifications, examination of refund activity and monitoring of high-risk transactions.

Even when staffing limitations make full segregation of duties difficult, monitoring activities can provide an important compensating control. The perception that transactions are being reviewed is often a powerful deterrent.

Larger nonprofits may also benefit from establishing an internal audit function to support ongoing monitoring efforts.

Building a strong foundation against fraud

Nonprofits play a critical role in supporting communities and advancing meaningful causes. Protecting those efforts requires more than good intentions. It requires deliberate safeguards.

By strengthening internal controls, improving cybersecurity, training employees and volunteers, increasing board oversight and actively monitoring financial activity, nonprofit organizations can significantly reduce fraud risk. A thoughtful nonprofit fraud prevention strategy helps protect financial resources, preserve donor trust and support long-term mission success.

If you’d like additional guidance, reach out to us or explore our nonprofits, endowments, and foundations capabilities.

FAQ

Nonprofit fraud prevention is the process of implementing policies, controls and monitoring practices designed to prevent, detect and respond to fraudulent activity within a nonprofit organization.

Nonprofits often operate with limited resources, small staffs and high levels of trust. These conditions can create opportunities for fraud when sufficient oversight and internal controls are not in place.

Common forms of nonprofit fraud include check fraud, employee embezzlement, business email compromise, vendor fraud, payroll fraud and ransomware attacks.

Some of the most important controls include segregation of duties, management review, board oversight, payment verification procedures, account reconciliations and ongoing monitoring of financial activity.

Organizations can reduce check fraud risk by reconciling accounts promptly, securing check stock, placing stop payments on lost checks, implementing Positive Pay services and transitioning to electronic payments whenever possible.

The board helps establish accountability, oversee risk management efforts, review fraud prevention policies and ensure appropriate controls are in place to protect organizational assets.