Embezzlement & Board’s Fiduciary Responsibility

A nonprofit board is entrusted with protecting the assets of the organization it serves. That responsibility includes providing appropriate financial oversight and helping protect the organization from both internal and external threats.

Putting the right safeguards in place can help boards fulfill their oversight responsibilities and identify potential problems sooner. If embezzlement or another diversion of assets occurs, board members are responsible for investigating what happened, protecting the organization’s remaining assets, meeting applicable reporting requirements, and taking appropriate steps to recover lost assets.

Financial oversight is a board responsibility

Board members should have enough access to the organization’s financial information to independently verify that its assets are being handled appropriately. They should also understand the policies and procedures governing how money enters and leaves the organization, rather than relying entirely on information from the people managing transactions.

Strong financial policies and clear internal controls can help reduce opportunities for fraud and provide the board with greater visibility into how the organization’s assets are handled. As part of that oversight, boards should pay particular attention to several areas in which charitable assets may be vulnerable.

Know where your organization is vulnerable

At a minimum, boards should pay particular attention to four areas of financial oversight:

  1. Bank statements — A board member, typically the treasurer, should have direct access to actual bank statements and review them monthly or, at minimum, quarterly rather than relying solely on financial reports prepared by staff.

  2. Contractors and vendors — Before approving payments, the board should verify that the business is legitimate and understand who owns or controls the company receiving the nonprofit’s funds.

  3. Incoming mail — The organization should establish a process for handling mail, particularly checks and other payments. Tools like USPS Informed Delivery can provide an additional record of what should be arriving at the organization.

  4. Online payments — The organization should establish verification procedures for electronic payments and changes to payment instructions. Requests to redirect payments should be independently confirmed with a known contact rather than accepted solely through email. Organizations may also consider safeguards like dual verification or bank-fraud prevention tools, such as Positive Pay.

Online transactions can expose an organization to threats from both inside and outside the nonprofit. Someone with administrative access may be able to redirect payments to another account, while phishing scams or compromised email accounts can make fraudulent payment instructions appear legitimate.

If embezzlement happens, the board must act

Policies and financial controls can reduce opportunities for embezzlement, but a person determined to divert funds may still find a way. Discovering the diversion does not end the board’s responsibility; it creates additional obligations for the organization.

IRS Form 990, Part VI, Section A, Line 5 asks whether the organization became aware of a significant diversion of its assets during the past year. If the organization is required to report the diversion, the Form 990 instructions call for additional information about what occurred and the organization’s response.

Returning the money does not erase the fact that a diversion occurred. Even if all the funds have been repaid by the end of the year, the diversion must still be addressed under the applicable reporting requirements.

When funds are misused, the organization must take appropriate steps based on the circumstances. In Oklahoma, that can include reporting the diversion to the Oklahoma Attorney General’s Office, Charity Enforcement Unit. Other reporting obligations may apply depending on the circumstances and the source of the funds involved. The organization must also make appropriate efforts to recover funds that have not been returned.

The board cannot overlook the situation simply because the person involved is a longtime employee, fellow board member, friend, or family member. Removing someone from the organization does not relieve the board of its responsibility to address the diversion.

Personal relationships may also create conflicts for individual board members. A board member with a close relationship to the person involved may need to abstain from voting or otherwise step away from decisions related to the matter.

Board members must also maintain the confidentiality of discussions held in executive session and not share that information with the person involved.

The board’s responsibility is to the nonprofit and the charitable assets entrusted to its care. That responsibility must guide its response even when the circumstances are personally difficult.

Protect your organization

Financial safeguards serve more than one purpose. They can make assets harder to divert and help the board identify irregularities sooner, but they can also protect employees and board members who handle the organization’s money. Clear procedures and independent verification create a record that can help resolve questions if a payment goes missing or a transaction is disputed.

No organization can eliminate every internal or external threat. The board can, however, establish appropriate policies and procedures, maintain meaningful financial oversight, and be prepared to act if something goes wrong.

At Nonprofit Solutions Law, we help nonprofit boards understand their fiduciary responsibilities, strengthen policies and procedures, and navigate situations involving the misuse or diversion of charitable assets.

Contact us to discuss how we can help your board protect the assets entrusted to your organization.

Next
Next

Beyond the Mission: Practical Considerations for Launching a Nonprofit