Policies Don’t Prevent Fraud. Organizations That Follow Them Do.
Most nonprofits have policies. In fact, many organizations have binders or electronic folders filled with accounting policies, conflict of interest policies, employee handbooks, disaster recovery plans, procurement policies, and countless other governance documents. The problem isn’t usually the absence of policies, it’s that many of them were written years ago, no longer reflect how the organization operates, or simply aren’t followed consistently.
Over time, policies become outdated as staff changes, technology evolves, banking practices shift, and new risks emerge. Yet many organizations continue operating as though the policy is still relevant simply because it exists. Unfortunately, a policy that sits untouched on a shelf provides little protection when something goes wrong.
Policies Are One of Your Best Risk Management Tools
Policies should never be viewed as administrative paperwork created only to satisfy an auditor or check a governance box. Instead, they establish the framework for how an organization operates by defining expectations, assigning responsibilities, and promoting consistency throughout the organization.
Well-written policies help safeguard assets, support ethical decision-making, improve accountability, and preserve institutional knowledge when employees or board members leave. They also provide management and the board with a common understanding of how important decisions should be made.
However, none of those benefits are realized unless the policies are actually implemented.
Having a Policy Isn’t the Same as Following It
Imagine a nonprofit with policies covering online banking, procurement, credit card usage, expense reimbursements, and segregation of duties. On paper, the organization appears to have strong internal controls.
Now imagine that the long-time accounting manager retires. A new employee is hired, and in an effort to make the transition easier, that individual is granted administrator access to the online banking platform, authority to create new vendors, approval rights for ACH payments, and responsibility for reconciling the bank account.
Those responsibilities may directly contradict the organization’s written policies, but because no one reviews user access or compares actual practices to the policies, the changes go unnoticed. Months later, fraudulent payments are discovered, and the board is left asking a familiar question: “Didn’t we have policies that were supposed to prevent this?”
The answer is yes, but the organization stopped following them. The policy didn’t fail. The implementation did.
Why This Matters
This lesson applies to organizations of every size. Simply having policies and governance documents does not guarantee good oversight. Written policies have little value if leadership does not consistently follow them or ensure they are being enforced.
The same principle applies to every nonprofit, regardless of its size or budget. Whether your organization has five employees or five hundred, policies are only effective when they reflect current operations, employees understand them, and leadership actively reinforces them.
Policies Should Evolve as Your Organization Evolves
Many nonprofit policies were written before electronic banking became commonplace, before employees worked remotely, before cybersecurity became a daily concern, and before artificial intelligence entered the workplace. As organizations grow and technology changes, policies should be reviewed to ensure they still reflect reality.
A conflict-of-interest policy should be reviewed regularly to address evolving governance expectations. An online banking policy should reflect current fraud prevention practices such as multi-factor authentication and user access reviews. Employee handbooks should be updated to incorporate changes in employment laws and workplace practices. Even long-standing accounting policies may need revisions as accounting standards or organizational processes change.
Reviewing policies shouldn’t be viewed as an administrative exercise. It is an opportunity to identify gaps, strengthen internal controls, and ensure that the organization’s practices match its written expectations.
Where to Start
If your organization hasn’t reviewed its policies in several years, begin with a simple inventory. Identify every policy your organization maintains, note when it was last reviewed and approved, and compare it to the way your organization actually operates today.
Policies should be living documents that support your mission, not forgotten files that only come out during an audit.
Strong governance isn’t measured by the number of policies an organization has. It’s measured by whether those policies are current, understood, and consistently followed.
The most effective policies don’t simply document expectations, they shape day-to-day decisions, promote accountability, and reduce organizational risk. When boards, management, and employees understand that policies are practical operating tools rather than administrative paperwork, they become an essential part of protecting the organization and advancing its mission.
Contact Us
"*" indicates required fields