Small nonprofits often depend on one trusted employee to handle nearly every financial task.
That person may receive checks, make deposits, enter transactions, pay invoices, reconcile bank statements and prepare reports for the board. The arrangement may seem efficient, especially when staffing is limited. It also creates a serious control weakness.
The risk is not limited to deliberate fraud. Errors can remain hidden, undocumented workarounds can become permanent and the organization may be unable to continue basic financial operations when that employee is absent.
Document How Money Moves
A nonprofit should be able to explain each step from receiving money to reporting it.
That includes:
- Who opens mail and records incoming checks
- Who makes deposits
- Who approves purchases
- Who enters bills
- Who authorizes payments
- Who has access to bank accounts
- Who controls credit cards
- Who processes payroll
- Who reconciles statements
- Who reviews financial reports
- Who creates and approves vendors
The IRS describes segregation of duties as fundamental to internal controls. Its examination guidance looks for separation among the authorization, execution and recording of transactions. (IRS)
When those responsibilities cannot be fully separated because the nonprofit has few employees, the organization needs compensating controls.
Small Organizations Still Have Options
A nonprofit does not necessarily need a large finance department to create meaningful checks and balances.
Possible controls include:
- A board treasurer reviewing bank statements
- A second person approving payments above a threshold
- Monthly review of new vendors
- Independent review of reconciliations
- Limits on credit-card access
- Written reimbursement requirements
- Required documentation for every payment
- Periodic review by an outside accountant
- Temporary reassignment of duties during vacations
The National Council of Nonprofits recommends starting with controls governing access to bank accounts and authority to spend money. It also recommends having someone other than the bookkeeper review bank statements and periodically examining vendors and cash activity. (National Council of Nonprofits)
An annual audit should not be treated as the organization’s only fraud-prevention measure. Audits may test controls, but they are not guaranteed to uncover every instance of fraud. Strong daily procedures remain essential. (National Council of Nonprofits)
Preserve the Procedure, Not One Person’s Workaround
SharePoint should serve as the organized knowledge source for approved purchasing procedures, reimbursement rules, approval limits, responsibility charts and blank financial forms.
Copilot Studio provides the conversational layer. Through Maisy, authorized employees could ask:
- Who may approve this expense?
- What documentation is required?
- Who reviews the bank reconciliation?
- What is the payment approval threshold?
- Who has authority to add a vendor?
- What happens when the finance manager is unavailable?
This helps the nonprofit retain institutional knowledge about financial procedures without exposing bank credentials, payroll records or sensitive transaction details.
The accounting system remains authoritative for transactions. The bank remains authoritative for balances and account activity. Payroll and donor systems remain authoritative for their respective records.
Maisy should not approve payments, interpret accounting rules or determine whether suspicious activity constitutes fraud. Accountants, auditors, leadership and the board remain responsible for financial oversight and investigation.
Make Controls Match Actual Practice
A written policy has little value when employees routinely bypass it.
The nonprofit should compare approved procedures with actual workflows. It should identify where staff share passwords, approve their own expenses, create undocumented vendors or rely on verbal authorization.
Changes should be realistic enough to follow consistently. Controls that are excessively complicated may encourage employees to work around them.
How Maisy Helps
Pixeldust begins by tracing how money moves through the organization, identifying repeated questions, undocumented responsibilities, conflicting procedures and activities controlled by one employee.
Pixeldust then organizes approved financial guidance in SharePoint, assigns content owners, maps permissions and configures Maisy through Copilot Studio. Testing uses realistic questions about purchasing, payments, reimbursements, reconciliation and backup responsibilities.
This helps the nonprofit retain institutional knowledge about financial controls while keeping transactions, approvals, accounting judgment and oversight with the appropriate human authorities.





