A nonprofit internal controls policy for Form 990 is a single, board-adopted document that spells out how your organization authorizes transactions, safeguards assets, keeps records, and handles conflicts of interest, whistleblower reports, and document retention — the three governance policies the IRS asks about directly on Form 990 Part VI.1Internal Revenue Service. Form 990 Part VI – Report Policies of Filing Organization Only Your answers on that section of the return become part of the public record, so the policy needs to exist in writing before the filing goes out, and it needs to actually govern what happens inside the organization.
What Form 990 Actually Asks About Your Policies
Form 990 is the IRS’s primary information return for tax-exempt organizations, and most states use it for charitable oversight as well.2Internal Revenue Service. Form 990 Resources and Tools Organizations with gross receipts normally at or above $50,000 must file Form 990 or Form 990-EZ.3Internal Revenue Service. Exempt Organization Annual Filing Requirements Overview
Part VI of Form 990 asks three specific policy questions:
- Line 12: Does the organization have a written conflict of interest policy, do officers, directors, and key employees disclose annually, and does the organization monitor and enforce it?
- Line 13: Does the organization have a written whistleblower policy?
- Line 14: Does the organization have a written document retention and destruction policy?
Answering “no” to any of these is not itself a legal violation, but it invites scrutiny from the IRS, state charity regulators, and sophisticated donors who read 990s before writing checks.1Internal Revenue Service. Form 990 Part VI – Report Policies of Filing Organization Only The three governance policies below deserve their own sections in your controls document.
Conflict of Interest Policy
The IRS describes a conflict of interest as a situation where a person’s duty to further the organization’s charitable purposes clashes with their own financial interests. Common examples: a board member voting on a contract with a business they own, or insiders setting their own compensation. The IRS warns that serving private interests more than insubstantially can cost the organization its tax-exempt status.4Internal Revenue Service. Form 1023 – Purpose of Conflict of Interest Policy
Your policy should require annual written disclosure statements from all board members, officers, and key employees. It should set out a procedure where a conflicted individual leaves the room during discussion and does not vote on the matter, and it should require the board to document that recusal in the minutes.
Watch the Schedule L thresholds. Business transactions with interested persons must be disclosed on Schedule L when total annual payments exceed $100,000, or when a single transaction exceeds the greater of $10,000 or 1% of total revenue. Compensation paid to a family member of an officer or key employee triggers reporting at just $10,000.5Internal Revenue Service. Instructions for Schedule L (Form 990) The internal process that flags these transactions before the tax return is drafted belongs inside the conflict of interest policy.
Whistleblower Policy
The Sarbanes-Oxley Act’s whistleblower and document-destruction provisions apply to all corporations, nonprofits included. Retaliating against an employee who reports concerns about accounting practices, or destroying evidence tied to a federal investigation, is a federal crime regardless of organization size.
A workable policy establishes a reporting channel that lets employees bypass the person they might be reporting on. Usually that means reports go directly to the board chair, the audit committee chair, or an anonymous hotline. State clearly that retaliation is prohibited and describe the protections available to anyone who reports in good faith.
Document Retention and Destruction
The IRS requires exempt organizations to maintain records sufficient to document compliance with tax rules and to support the income, expenses, and credits reported on their annual returns.6Internal Revenue Service. EO Operational Requirements – Recordkeeping Requirements for Exempt Organizations IRS guidance for public charities is to keep records for as long as they may be needed to document compliance.7Internal Revenue Service. Publication 4221-PC – Compliance Guide for 501(c)(3) Public Charities
Set minimum retention periods for each category of record:
- Governing documents (articles of incorporation, bylaws, determination letters): permanently.
- Filed tax returns and supporting schedules: at least seven years.
- Employment tax records and payroll documentation: at least four years after the tax becomes due or is paid, whichever is later.
- Grant records: the period specified in the grant agreement, typically three years after final reporting.
The destruction side matters just as much. Documents should be destroyed on the stated schedule unless a litigation hold, audit, or investigation requires preservation.
Segregation of Duties
Segregation of duties is the structural spine of every other control in the policy. The rule: no single person controls more than one of the three core financial functions — authorizing transactions, holding custody of assets, and recording entries in the accounting system. When one person handles all three, both the opportunity to commit fraud and the ability to hide it exist together.
In practice, the policy should require separations like these:
- Cash receipts. The person who opens the mail and logs incoming checks is not the person who records the deposit in the general ledger.
- Disbursements. The person who approves a payment is not the person who signs the check or initiates the wire.
- Payroll. The person who prepares payroll does not distribute checks or hold custody of them.
- Vendor files. The employee who authorizes a vendor contract does not maintain the payment records for that vendor.
Small organizations often cannot achieve full separation. Compensating controls, covered further down, are how you close the gap.
Cash Receipts, Disbursements, and Reconciliations
Receipts
Incoming cash and checks should be opened and logged by two people who do not report to each other, both signing the log. That log goes to the accounting department as an independent record against which the deposit is later verified. Deposit funds intact and promptly, ideally within one business day. “Intact” means nothing gets peeled off to cover an office expense. Using incoming cash to pay bills destroys the audit trail and is one of the fastest paths to undetected theft.
Purchasing and Disbursements
An approval matrix sets the authorization required for each spending range. A common structure:
- Under $500: department manager approval.
- $500 to $10,000: executive director approval.
- Over $10,000: two signatures, including a board officer or finance committee member.
Before any payment is processed, the policy should require a three-way match: the approved purchase order, the vendor invoice, and documented evidence that the goods or services were received. Paying an invoice without confirming delivery is how fictitious vendor schemes succeed. Limit access to blank check stock if you still write physical checks, and never use a check-signing machine without dual controls.
Credit Cards and Petty Cash
Organizational credit cards need a written sub-policy. Keep the number of cards low, assign each a defined monthly limit, and issue only to approved employees. Cardholders submit original receipts and a brief expense report within a set number of business days after the statement closes — five days is a common benchmark. A supervisor who is independent of the cardholder reviews the statement and verifies the business purpose of every transaction. Prohibit cash advances and personal purchases outright.
Petty cash works well on the imprest system: cash on hand plus receipts must always equal the established fund amount. One designated custodian controls the fund and keeps it in a locked location. Submit receipts for replenishment when cash runs low; a supervisor approves each replenishment. Management should conduct unannounced spot counts at least once or twice a year. Never use petty cash for salaries, personal services, or expenses that belong in normal purchasing channels.
Bank Reconciliation
Reconcile every bank account to the general ledger monthly. The person doing the reconciliation cannot be someone who authorizes payments or handles cash, or they are checking their own work. The completed reconciliation and supporting documentation for any variances go to a manager who is independent of both cash handling and bookkeeping for review and sign-off. Set a resolution timeframe for material differences; 30 days is reasonable for most organizations. This step is where many frauds are eventually caught, so it deserves the attention.
Payroll Controls and Personal Liability
Payroll is high risk because it involves recurring, predictable outflows that can hide ghost employees or inflated hours for months. Separate payroll preparation from payroll distribution and from the authority to add or remove employees in the system. A manager outside the payroll function should review each run, comparing headcount and totals against the prior period.
If you outsource payroll, the organization remains legally responsible for all employment tax obligations. The IRS recommends enrolling in the Electronic Federal Tax Payment System (EFTPS) so you can independently verify that your provider is actually depositing taxes under your employer identification number.8Internal Revenue Service. Third Party Payer Arrangements – Payroll Service Providers and Reporting Agents
The stakes are personal. Under 26 U.S.C. § 6672, any person responsible for collecting and paying over employment taxes who willfully fails to do so faces a penalty equal to the full amount of the unpaid taxes. That penalty falls personally on whoever had authority over finances — typically the executive director, CFO, or treasurer. Volunteer board members who serve in an honorary capacity and do not participate in day-to-day financial operations are protected, but only if they had no actual knowledge of the failure.9Office of the Law Revision Counsel. 26 USC 6672 – Failure to Collect and Pay Over Tax, or Attempt to Evade or Defeat Tax
For grant-funded positions, require employees to certify time on specific grants after the work is performed, not from budgeted estimates. Federal grant rules require after-the-fact timesheets prepared at least monthly, signed by both the employee and a supervisor with firsthand knowledge of the work.10eCFR. 2 CFR 200.303 – Internal Controls
Non-Cash Assets and Fixed Asset Tracking
Set a capitalization threshold in the policy — the dollar amount above which a purchase becomes a fixed asset rather than an expense. Many nonprofits use $5,000 per item, which aligns with the IRS de minimis safe harbor for organizations that have an applicable financial statement. Organizations without an applicable financial statement can use a $2,500 threshold under the same safe harbor.11Internal Revenue Service. Tangible Property Final Regulations Tag every item above the threshold with an asset number, log it in a fixed asset ledger, and physically verify it on a regular schedule. Annually is ideal; every other year is the minimum.
Donated publicly traded securities present a specific risk. Most nonprofits are not investment managers, and holding donated stock exposes the organization to market risk unrelated to its mission. A common provision requires liquidating publicly traded securities immediately upon receipt, and communicating that policy to donors ahead of time.
Restrict physical access to inventory, equipment, and stored donations. Document transfers between locations or programs with signed transfer forms, and reconcile periodic physical counts against accounting records.
IT Access and Data Security
If someone can alter records in the accounting system without detection, no other control matters. Restrict access through unique user IDs and role-based permissions. A staff accountant does not need the ability to delete journal entries or modify the chart of accounts.
The policy should require a quarterly review of all user access covering employees, contractors, consultants, and any service accounts. Confirm that departed employees have been removed, that access levels match current responsibilities, and that no user has been granted conflicting permissions.
Back up financial data frequently, with copies stored securely off-site or in an encrypted cloud environment. Encrypt sensitive data — donor records, banking credentials, employee tax information — both in storage and during transmission. Organizations that process credit card donations must also comply with PCI DSS 4.0, which became mandatory in March 2025 and includes expanded encryption requirements.
Fraud Prevention Services Worth Requiring
Two bank services automate what manual review cannot reliably catch. Positive pay: your organization submits a file of issued checks to the bank each time checks go out, including check number, dollar amount, and payee. When a check is presented, the bank matches it against your file, and anything that does not match is flagged as an exception item for you to approve or reject before it clears.
ACH positive pay works the same way for electronic debits. You set up a list of approved vendors and can establish a maximum dollar threshold for each; any ACH debit from an unrecognized account requires manual approval before it posts. Require enrollment in both services in the policy, and designate who reviews exception items daily.
Compensating Controls When Staff Is Thin
Segregation assumes enough staff to separate financial roles. Many nonprofits do not have that. When one or two people handle everything financial, compensating controls close the gap. The most effective ones pull the board directly into oversight:
- Unopened bank statements to a board member. The bank sends monthly statements directly to the treasurer or finance committee chair, who reviews cancelled checks and withdrawals for anything unusual before passing the statement to the bookkeeper.
- Credit card statement review. Someone other than the cardholder or the bookkeeper reviews every transaction on the statement each month, watching for unfamiliar vendors, late fees, or foreign transactions.
- Mandatory consecutive time off. Anyone with financial access takes at least two consecutive weeks away each year. Fraud often surfaces when the perpetrator is not there to maintain the cover-up.
- Surprise cash counts. Unannounced counts of petty cash or any other funds on hand, done by a board member or outside accountant.
- Background and credit checks. Criminal background checks on anyone with financial access before they start, and a consent-based credit check on the bookkeeper or finance manager as a condition of the role.
The policy should explicitly identify which compensating controls are in place and tie each one to the segregation gap it addresses. Auditors expect to see this in writing, not assumed.
Adopting the Policy and Keeping It Current
Formal adoption means a board resolution passed at a scheduled meeting, referencing the specific policy document and version number. The policy itself should carry an effective date, a version number, and a revision history, so there is never confusion about which version governs.
After adoption, everyone with a financial role — staff and board — should complete mandatory training on the policy and sign a written acknowledgment that they have read, understood, and agree to follow it. Keep the acknowledgments in personnel files.
Require an annual review by the audit committee, or by an independent third party if the organization can afford it. The review checks whether the controls still match current size, operations, and risk profile. A nonprofit that doubled its grant funding needs different controls than it did twelve months earlier. Changes go back to the board for formal approval before implementation.
Build in a way to report control deficiencies to the audit committee throughout the year, not just at the annual review. Controls break down gradually, and waiting twelve months to surface a weakness can turn a procedural gap into a financial loss.