Your board is responsible for safeguarding the association’s assets and reputation. There are two primary areas of concern: legal liability and financial loss.
While the risk of legal action against a nonprofit may seem small, it is possible that your association could be sued over any number of issues, such as inadvertent use of copyrighted or trademarked materials, defamation of character or reputation allegedly done by board members, sexual harassment of 3rd parties (contractors, etc) by members of board, breach of contract, or conflict of interest. While the organization may not be guilty of any of these charges, and some states have Good Samaritan laws protecting board member’s liability (except in cases of active malfeasance), you may still incur legal costs for defense and damage to your reputation. Your insurance broker can assist you in determining the appropriate insurance coverages.
There is a general attitude that nonprofits are unlikely to suffer diversion of funds because the amounts of money involved are relatively small, and, after all, who would steal from a nonprofit? We are inclined to trust board members who volunteer their time to act as Board Treasurer. However, cases of fraud or simple mismanagement of funds do occur in nonprofits. The loss or misuse of even a relatively small amount of money may cripple your association’s reputation and ability to raise funds or receive grants. For example, a nonprofit health organization received a large Federal grant for carrying out a specific program. When the organization diverted the funding and used it to pay general operating expenses, an audit uncovered the diversion. The organization was fined, forced to pay back the grant, and the entire management staff and board of directors were forced to resign.
Your board should have procedures in place to assure that the money you collect is used in the manner approved by the board and your members. These include:
Authorization and Segregation of Duties
- Avoid “self-dealing” ( see conflict of interest policy under policies above), where a board member plays a part in awarding payments to an entity in which they have a personal interest.
- Cash and checks received should be documented and deposited quickly (typically 24 hours)
- Access to bank accounts should be limited but involve more than one person
- Bank statements should be reconciled by someone other than the person that writes checks
- No single person should be responsible for receiving, depositing, recording, and reconciling the receipt of funds. No single person should be responsible for authorizing the purchase of goods/services, preparing the purchase order, receiving the goods, and performing the various steps in paying for the goods/services.
- For example, the Board Chair could be responsible for receiving, recording and depositing all income — checks or cash — while the Board Treasurer could handle disbursements and reconciling of bank statements. Some large organizations (like banks) require that any person handling money be periodically replaced in their duties (two or more weeks a year) by another person to prevent ongoing malfeasance.
- All check and cash disbursement requests should be accompanied by an invoice or other document showing that the payment or disbursement is in line with board approved spending guidelines and decisions.
- Set a limit for credit card expenditures above which you require prior written approval from two individuals. Require back-up documentation demonstrating the expenditures are appropriate. The person using the credit card should not be the same person who authorizes its use.
- All contracts should be approved by a person — another board member, for example — who is uninvolved and personally disinterested in the transaction (with approval levels depending on the size of the contract)
- Large contracts (size limit to be determined by the board) should be the product of competitive and transparent bidding. This will not only prevent “self-dealing” forbidden by IRS regulations, but open the organization to new ideas for services as well as help ensure more competitive pricing.
Audits and Security
- At least annually, have the financial records examined by an external party (an accounting firm or CPA who is not a board or association member) to ensure effectiveness of internal controls and accuracy of financial records.
- Keep all cash, checks, passwords in a locked area or storage device
- Be sure that all paper and financial records are backed up and secure – two or more copies of paper or electronic files stored in separate locations or on separate file servers, with access controlled by physical security (hard copies) or secure, encrypted electronic files using appropriate password protection, using two-factor authentication where appropriate.
- Minimize access to sensitive information and records to those who have a need to know — a small number of authorized persons (at least two for backup purposes).