Back to Articles
    Finance & Operations

    Spotting Embezzlement Early: Anomaly Detection in Nonprofit Books

    Internal theft at a small nonprofit almost never announces itself. It arrives as a slightly odd vendor name, a check that cleared for a different amount than the one recorded, a run of purchases that all land just below the approval threshold. Those patterns sit in your accounting data right now, and the reason nobody finds them is not that they are invisible. It is that nobody has the hours to look. AI changes the economics of looking, which is a genuinely useful thing, as long as you understand exactly what an anomaly is and, far more importantly, what it is not.

    Published: September 23, 2026•17 min read•Finance & Operations
    A nonprofit finance staffer reviewing accounting records and transaction data on screen

    Nonprofit finance leaders tend to carry two beliefs about internal fraud at the same time, and the two do not sit comfortably together. The first is that it happens, often, to organizations that look a lot like theirs. The second is that it could not happen here, because the bookkeeper has been with us eleven years and her kids went to our summer program. Both beliefs are supported by experience, which is part of what makes this subject so difficult to talk about internally. The people who commit occupational fraud are, in the overwhelming majority of cases, trusted long-tenured insiders. That is not an unfortunate coincidence. It is the mechanism. Trust is what creates the access, and access is what creates the opportunity.

    The scale of the problem is well documented. The Association of Certified Fraud Examiners analyzed 2,402 real cases of occupational fraud across 143 countries for its Occupational Fraud 2026: A Report to the Nations, and found a median loss of $104,000 per case and a median scheme duration of 12 months before discovery. More than half of all cases involved either a lack of internal controls or an override of the controls that existed. Nonprofit losses tend to run lower in absolute terms, with CPA firm analyses of the same data putting the median for not-for-profit, charitable, and social service organizations around $76,000. That smaller number is misleading comfort. A $76,000 loss at an organization with a $900,000 budget is a program, a staff position, and frequently the organization's relationship with its largest funder.

    The twelve month median matters more than the dollar figure, because duration is the variable an organization can actually influence. Schemes caught within six months carried a median loss of $40,000 in the ACFE data, while schemes running beyond five years carried median losses above $1.1 million. Nothing about the perpetrator changes across that range. What changes is how long the organization took to notice. Detection speed is the lever, and it is a lever a small nonprofit can pull without hiring anybody, because the raw material for early detection is already sitting in QuickBooks.

    This article covers why small nonprofits are structurally more exposed than businesses of the same size, which schemes actually appear in a two-person finance office, what anomaly detection means in concrete terms when applied to a general ledger export, and how to run that analysis with AI when your data lives in an accounting package and a spreadsheet. It then spends real time on the part that most articles skip: an anomaly is a question, not an accusation, and the damage done by acting badly on a false positive against a colleague is severe and often irreversible. It closes with the human controls AI cannot replace, why your external financial audit was never designed to catch this, what to do in the first days after a credible concern, and the disclosure obligations that arrive with a confirmed diversion.

    One framing note before the detail. Nothing here is legal advice or forensic accounting advice, and neither this article nor any AI tool is a substitute for a Certified Fraud Examiner, an attorney, or your auditor. The goal is narrower and more achievable: to help a finance director, executive director, or board treasurer know what to look for, what the looking can and cannot tell them, and who to call the moment a question becomes a concern.

    Why the Nonprofit Structure Itself Creates the Opening

    A for-profit business of equivalent size usually has an owner whose personal wealth is tied to every dollar in the account, and that owner tends to look at the bank balance with an intensity no salaried employee matches. Nonprofits have no such person. Oversight is distributed across a volunteer board that meets six or eight times a year, reviews a summarized financial statement prepared by the very person best positioned to manipulate it, and asks few questions because asking questions of a dedicated colleague feels like an accusation. The absence of an owner is the single biggest structural difference, and it explains a great deal.

    Thin staffing compounds it. In an organization with one bookkeeper, that person frequently enters the bills, prepares the checks, records the payments, reconciles the bank account, and produces the report the board reviews. Every one of those steps is a control point in a properly designed system, and here they all sit with the same pair of hands. This is not negligence, it is arithmetic. You cannot segregate five duties across one person. The honest response is not to pretend the segregation exists but to compensate with review from outside the finance function, which is exactly where boards most often fall short.

    Volunteer treasurers introduce their own dynamic. The role often lands with whoever has the most financial background among the trustees, which may mean a retired banker, a small business owner, or someone whose actual expertise is tangential. Whatever their skill, they typically see the organization's numbers for an hour every other month, in a summarized form, with no access to the underlying detail and no realistic way to test anything. A treasurer who signs off on a financial statement they had no ability to verify is providing the appearance of oversight rather than the substance of it, and everyone in the room quietly knows this.

    Then there is the cash. Many nonprofit programs handle physical currency in ways almost no modern business does: donation boxes, event ticket tables, raffle proceeds, thrift shop tills, cash collections at services, petty cash for participant assistance. Cash that has not yet been recorded anywhere is the easiest thing in the world to take, because the theft leaves no trace in any system. Skimming at the point of collection is invisible to every analytical technique described in this article, which is why the controls around cash receipts have to be physical and procedural rather than analytical.

    Finally, the culture itself. Nonprofits select for people who believe in the work and who extend good faith to colleagues as a default posture. That is a strength, and it is also precisely what a person rationalizing their first small transfer is counting on. The uncomfortable truth is that a mission-driven culture and a control environment are not in tension only if leadership deliberately frames controls as protection for everyone, including the honest bookkeeper who deserves to be able to prove she did nothing wrong. Organizations that frame controls as suspicion get resistance. Organizations that frame them as mutual protection get cooperation.

    The structural conditions that raise exposure

    None of these are moral failings, and all of them are common

    • No owner: oversight rests with a volunteer board reviewing summaries prepared by the person being overseen
    • One set of hands: the same person enters, pays, records, and reconciles
    • Part-time treasurer: an hour every other month, on summarized data, with no ability to test
    • Unrecorded cash: donation boxes, event tables, and tills where theft leaves no system trace
    • Trust as default: a culture where verifying a colleague's work feels like an insult rather than a courtesy

    The Schemes That Actually Turn Up in a Small Shop

    Knowing the mechanics matters, because each scheme leaves a distinct fingerprint in the data, and you cannot look for a pattern you have never heard described. The dominant category in small organizations is asset misappropriation, which is to say ordinary theft rather than elaborate financial statement manipulation. Within that category, a handful of schemes account for most of what a nonprofit will encounter.

    Fictitious vendors are the classic. The bookkeeper sets up a vendor with a plausible name, often something generic like a consulting or maintenance company, and pays it. The vendor is a shell, sometimes a real bank account in a relative's name, sometimes simply a payee on a check deposited into a personal account. The data fingerprint is distinctive: a vendor with no W-9 on file, an address matching an employee address or a mailbox service, invoices with no purchase order or supporting detail, round-number amounts, and a payment history that begins abruptly at a meaningful dollar value rather than ramping up the way a genuine supplier relationship does.

    Check tampering and altered payees remain surprisingly current in a sector that still writes checks. A check is recorded in the ledger as payable to a legitimate vendor, but the physical check is made out to someone else, or a signed blank check is completed later, or a voided check is quietly cashed. The tell is a mismatch between what the books say and what the bank image shows, which is why reviewing cleared check images against the register is one of the highest-yield reviews a board member can perform. No amount of ledger analysis finds this on its own, because the ledger is the side that was falsified.

    Ghost employees and payroll manipulation show up as a person on payroll who does not work there, a terminated employee who keeps receiving deposits, inflated hours on a timesheet nobody countersigns, or unauthorized bonuses and rate changes applied by the person who administers payroll. Direct deposit accounts shared across multiple employee records are a strong signal, as are payroll records with no corresponding personnel file. Organizations that have tightened their payroll processes usually find that the fix is procedural, requiring a second person outside finance to approve every new hire, rate change, and bank detail change.

    Expense reimbursement padding is the most common and the least dramatic. Personal meals coded as program expenses, mileage claimed for trips not taken, the same receipt submitted twice across two months, conference costs claimed after a registration was comped. Individually these are small, which is exactly why they survive, and cumulatively over several years they add up to real money. This is a category where AI review of submitted receipts genuinely helps, and it overlaps with the ground covered in our piece on expense reports and receipts.

    Skimming is the theft of money before it ever enters the accounting system, and it is the hardest to detect because there is nothing to detect. Cash from a donation box, a portion of event ticket sales, proceeds from a raffle, currency in a thrift shop till. The only analytical handle is comparison: ratios of cash to card receipts that drift downward over time, event revenue per attendee that falls year over year without explanation, or collections that dip when one particular person counts them. Those comparisons are weak evidence on their own and strong prompts to improve the physical controls.

    Credit card personal use, unauthorized transfers, and lapping round out the list. Organizational cards used for personal purchases and coded to vague accounts like miscellaneous or program supplies are common, particularly where nobody outside finance reviews the statement line by line. Unauthorized bank transfers move money to a personal account and are then concealed in the reconciliation, which the same person performs. Lapping is subtler and applies where receivables exist: a payment from Donor A is taken, and Donor B's later payment is applied to A's balance to hide the gap, with the shortfall rolling forward indefinitely. Persistent unexplained timing differences between when money arrives and when it is recorded are the signature.

    Scheme to fingerprint

    What each scheme leaves behind in the records

    • Fictitious vendor: no W-9, address matching an employee, round amounts, payments starting large
    • Altered payee: cleared check image disagrees with the payee or amount in the register
    • Ghost employee: duplicate direct deposit accounts, payroll records with no personnel file
    • Reimbursement padding: repeat receipts, mileage without calendar support, personal meals in program codes
    • Skimming and lapping: drifting cash ratios, and recurring timing gaps between receipt and posting

    What Anomaly Detection Actually Means on a General Ledger

    Anomaly detection sounds like machine learning, and in a large enterprise it often is. At a small nonprofit it is something far more approachable: a defined set of specific tests, each of which asks a narrow question about the transaction data and returns a short list of items worth a human glance. You are not training a model. You are running the same dozen queries a forensic accountant would run, on your own data, quarterly, at a cost of an afternoon. Understanding each test individually is what lets you interpret the output sensibly instead of treating a list of flagged rows as a verdict.

    Duplicate payments are the simplest and most productive place to start. Look for the same vendor, same amount, and same or near-identical invoice number within a short window, and separately for the same amount paid to two similar vendor names. Most hits are genuine duplicates caused by ordinary error, and recovering those is itself worth the exercise. The ones that are not errors matter enormously.

    Round-dollar amounts deserve a look because invented numbers cluster on round figures in a way that genuine invoices do not. A real supplier invoice lands at $1,247.38. A fabricated one is far more likely to be $1,250.00 or $2,000.00. Round amounts are utterly normal for grants, transfers, retainers, and stipends, so the test is only meaningful within vendor categories where irregular amounts are the norm.

    Vendor and employee data overlaps are one of the strongest single signals available to a small organization. Compare the vendor master file against the employee list on address, bank account, phone number, and tax identification number. An exact address match between a vendor and a staff member is rarely innocent, though it can be, since some organizations legitimately reimburse a staff member set up as a vendor or contract with a relative under a properly disclosed related-party arrangement.

    Transactions just under an approval threshold reveal structuring. If purchases above $2,500 require the executive director's signature, a cluster of charges at $2,350 and $2,475 from the same requester is worth understanding. Plot the distribution of transaction amounts and look for a pile-up immediately below each of your policy thresholds, then look for the same purchase split across two or three invoices on consecutive days.

    Timing tests use metadata rather than amounts. Entries created on weekends, late at night, or on holidays are not wrong, but they are unusual for a nonprofit finance function that works weekdays, and they are worth explaining. Manual journal entries posted in the final days before a period closes, or backdated after the close, are one of the classic vehicles for concealment, and the QuickBooks audit log records who made each change and when even where the transaction itself was subsequently edited or deleted.

    New vendors with immediate large payments combine two ordinary facts into an unusual one. Genuine supplier relationships usually start small or start with a documented contract. A vendor created on the fifth of the month and paid four thousand dollars on the eighth, with no contract in the file, is a reasonable thing to ask about. Run this test every quarter against vendors added since the last run, which keeps the list short.

    Benford's Law is the test everyone has heard of and the one most often misapplied. Naturally occurring financial figures tend to follow a predictable distribution of leading digits, with roughly thirty percent beginning with one and progressively fewer beginning with each higher digit, and the ACFE explains why fraud examiners use it as a screening tool. A significant deviation can indicate fabricated entries. The caveats are serious and are laid out well in the Journal of Accountancy's guidance on using Benford's Law on journal entries. The test needs a large population of naturally varying amounts, it does not apply to data with built-in floors or ceilings such as amounts under a fixed limit, and it will never surface a single thirty thousand dollar theft hidden in ten thousand transactions. Conformity does not mean the books are clean, and deviation does not mean they are dirty. Treat it as a rough screen that suggests where to look, never as evidence of anything.

    A starter test set for a quarterly review

    Each test asks one narrow question and returns a short list

    • Duplicate or near-duplicate payments by vendor, amount, and invoice number
    • Round-dollar amounts within vendor categories where irregular invoices are normal
    • Vendor records matching employee addresses, phone numbers, or bank accounts
    • Amounts clustering just below each approval threshold, and split purchases
    • Weekend, after-hours, and near-close manual journal entries with no narrative
    • New vendors receiving a large payment within weeks of being created
    • Benford's first-digit screen on a large population, read as a hint and nothing more

    Running This With QuickBooks, a Spreadsheet, and a Model

    The practical question is how a finance director with no analytics background actually does this on a Tuesday afternoon. The answer is more mundane than people expect. You export a handful of reports, you clean them into flat tables, and you work through the test set with an AI assistant that writes the formulas and queries you would otherwise have to know. The model is not finding fraud. It is doing the data manipulation that has historically been the barrier, and it is explaining its reasoning so a non-specialist can check it.

    Start with the exports. From QuickBooks Online, the Transaction Detail by Account report under the accountant section gives you the general ledger detail, and it exports to Excel. Pull the vendor list with addresses and contact details, the check register, a transaction list by vendor, the payroll register, and the audit log, which records who created or changed each transaction and when and is available as a CSV covering a rolling two year window. The native report exports arrive with merged cells, subtotal rows, and blank lines that break every pivot table you try to build, so the first genuine task is flattening them into one clean row per transaction line. This is exactly the kind of tedious reshaping an AI assistant handles well, and the same skills covered in our guide to AI in spreadsheets apply directly.

    Think about what you are uploading before you upload it. A general ledger contains vendor names, employee names, donor names attached to restricted gifts, and sometimes client identifiers in program expense descriptions. Use a business-tier AI account with a contractual commitment that your inputs are not used for model training, keep personal data out of the file where the test does not need it, and consider replacing donor and client names with codes before analysis since almost none of these tests require a real name. Where the test genuinely needs identifying data, such as matching vendor addresses to employee addresses, run that comparison locally in the spreadsheet rather than pasting both lists into a chat window.

    Then work test by test rather than asking one sweeping question. A prompt like "find the fraud in this file" produces confident nonsense. A prompt like "here are the columns in my general ledger export. Write an Excel formula that flags any transaction where the same vendor and the same amount appear within a fourteen day window, and explain what the formula does line by line" produces something you can verify and reuse. Ask for the logic in plain language alongside the formula, run it yourself, and spot-check a handful of results against the source records by hand. If the model cannot explain why a row was flagged in terms you can trace back to the data, do not act on that row.

    Useful prompts follow that pattern across the test set. Ask it to summarize the distribution of transaction amounts and identify clustering immediately below stated thresholds. Ask it to compare two lists and report exact and fuzzy matches on address fields, with the fuzzy matches labeled as such. Ask it to list vendors that first appear in the ledger within the period and their first payment amount and date. Ask it to identify all manual journal entries in the final five days of each month, sorted by amount, with their memo text. Ask it to flag expense descriptions that are vague or generic across a threshold of dollar value. Each of these returns a list, and every list is a starting point for human review.

    Two accuracy warnings matter here. Language models are unreliable at arithmetic performed in their heads, so any test that involves summing, counting, or comparing numbers should be executed as a formula or a query rather than trusted as a directly stated answer. And models will happily produce a plausible-sounding explanation for a pattern that is actually a data artifact, such as a duplicate row created by your export rather than a duplicate payment. Reconcile your flattened file back to the trial balance totals before you analyze it, which is the same discipline that makes month-end close work reliable, and treat a clean tie-out as the precondition for the whole exercise.

    What to export before you start

    Five files that support most of the test set

    • General ledger detail: transaction detail by account for the full period, flattened to one row per line
    • Vendor master file: names, addresses, phone numbers, and tax identification where held
    • Check register and card statements: payee, amount, date, and coding for every disbursement
    • Payroll register: employees, rates, hours, and direct deposit destinations
    • Audit log: who created, edited, or deleted each transaction, and when

    An Anomaly Is a Question, Not an Accusation

    This is the most important section in the article, and it is the one most likely to be skimmed. Every test described above produces false positives, and at a small nonprofit the false positive rate will be overwhelming relative to the true positive rate, for a simple reason of base rates. In any given quarter, the probability that your bookkeeper is stealing is low. The probability that your data contains duplicate-looking entries, round numbers, weekend postings, and a vendor sharing an address with a staff member is close to certain, because all of those things happen constantly for innocent reasons.

    Consider how ordinary the explanations usually are. The duplicate payment was a genuine second invoice for a recurring monthly service. The round-dollar vendor is a consultant on a flat monthly retainer. The vendor sharing an address with an employee is the employee's spouse, contracted years ago through a documented conflict-of-interest process the board approved and everyone has since forgotten. The weekend entries are from a part-time bookkeeper who works Saturdays because that is when her childcare allows. The charges just under the threshold are a program manager who knows the threshold and splits orders to avoid bothering the executive director during a busy week, which is a policy problem and not a theft.

    The harm from mishandling this is real and asymmetric. If you quietly investigate a colleague and find nothing, you have still changed how you look at that person, and they will often sense it. If you raise it clumsily in a meeting, or mention it to one board member who mentions it to another, you have created a rumor about a specific named employee that cannot be recalled. People have left the sector over accusations that turned out to be a data export artifact. The person you flag is, statistically, almost certainly innocent, and they are also the person who has kept your books straight for a decade on a below-market salary.

    Handle it the way a good auditor does, which is as a routine inquiry rather than a confrontation. Ask about the transaction, not the person. "I am doing a quarterly data review and these six items came up. Can you help me understand this one." Do the review on a schedule so it is not obviously targeted at anyone, and include items you already understand so the list is visibly a process rather than a suspicion. Document the explanation you receive and, critically, verify the ones that matter against an independent source rather than accepting an account at face value, because an explanation that cannot be corroborated is itself a finding. Most items resolve at this stage, and the ones that do not are the ones that matter.

    There is one hard exception to the routine-inquiry posture. If a pattern is specific and serious enough that you would be unable to explain to a board why you had warned the person it concerned, stop asking questions and go to the guidance in the response section below. The line is not a feeling. It is whether continuing the conversation risks giving someone the opportunity to alter or destroy records, and that risk is why the standard advice is to preserve first and inquire later once a concern becomes credible.

    How to hold a flagged item responsibly

    Discipline that protects colleagues and the organization at once

    • Assume a benign explanation first, because on base rates that is usually correct
    • Run the review on a fixed schedule so it never looks targeted at an individual
    • Ask about the transaction, never about the person, and keep the tone administrative
    • Corroborate material explanations against independent records rather than accepting them
    • Never share an unresolved flag with anyone who does not need it, in writing or otherwise

    The Human Controls No Analysis Can Replace

    Analytical review is detective. It finds things after they have happened, which is valuable, and it is strictly second best to the preventive controls that stop the scheme from starting. Every test in this article looks at data that the person under review may have created, and a determined insider who controls both the transaction and the record can make the data tell whatever story they choose. This is the fundamental ceiling on ledger analysis, and it is why the controls below are not optional extras.

    Segregation of duties is the foundation, and the standard objection is that a three-person organization cannot segregate anything. The National Council of Nonprofits addresses this directly in its guidance on internal controls for nonprofits, and the answer is that separating authorization, execution, and review does not require three finance employees. It requires three people, and a board member or a program director can hold the review role. The single most important separation is that whoever reconciles the bank account must not also be able to create and sign payments.

    Independent review of the bank statement is the control with the best return on effort in the entire list. A board member receives the statement unopened, or is given read-only online access, and reviews the actual cleared check images and the electronic transfers before anyone in finance touches it. This catches altered payees, unauthorized transfers, and unfamiliar vendors in a way no ledger analysis can, because it looks at the bank's record rather than the organization's. The Oregon Department of Justice includes this among its financial control recommendations for small nonprofits, and it costs an hour a month.

    Mandatory vacation and cross-training work on a simple principle: most ongoing schemes require continuous maintenance to stay concealed, and the person maintaining them cannot be away. Requiring finance staff to take consecutive time off, with someone else genuinely covering their duties rather than letting the work pile up, is why banks have imposed this on tellers and officers for generations. The employee who has not taken a full week off in four years and who insists on handling the reconciliation from home while on leave is exhibiting a pattern worth noticing, though it is worth saying plainly that most such employees are simply conscientious and overworked.

    Surprise reviews add the deterrent element that scheduled procedures lack. A scheduled annual review can be prepared for. An unannounced examination of how cash moves through an event, or a spot check of three months of credit card statements against receipts, or an unexpected request to see supporting documentation for ten payments cannot. Blue Avocado's rundown of five internal controls for the very small nonprofit makes the case that even tiny organizations can do this, and the deterrent value comes from the possibility rather than the frequency.

    The reporting channel deserves particular attention given how fraud actually surfaces. Tips accounted for forty-three percent of the cases in the ACFE study, roughly three times the next most common detection method, and over half of those tips came from employees. That means your most effective detection mechanism is a colleague who notices something and has a way to say so without career risk. A named third party who receives concerns, a board chair contact published in the handbook, or a low-cost hotline service all work. What does not work is a policy that routes concerns through the executive director when the concern may be about the executive director. Boards that take financial oversight seriously own this channel directly.

    Controls a three-person organization can actually run

    Preventive measures that beat any detective analysis

    • Whoever reconciles the bank account cannot also create and sign payments
    • A board member reviews cleared check images and transfers before finance does
    • Two signatures or two approvals above a stated dollar threshold, enforced by the bank
    • Consecutive mandatory time off, with duties genuinely covered by someone else
    • A reporting channel that does not pass through the people it might concern

    Your Audit Was Never Designed to Catch This

    Many nonprofit boards believe the annual financial audit is their fraud control. It is a reasonable assumption given the cost, and it is wrong in a way that matters. An audit under generally accepted auditing standards is designed to provide reasonable assurance that the financial statements as a whole are free from material misstatement. Every word in that sentence is doing work. Reasonable is not absolute. Material means large enough to change the judgment of a reader of the statements. As a whole means at the level of the financial statements, not at the level of any individual transaction.

    The auditing standard governing this, AU-C 240, does require auditors to consider fraud risk, to test journal entries, and to address the risk of management override. But as CPA firm explanations of fraud in a financial statement audit make clear, the standard also acknowledges inherent limitations: fraud involving collusion, forged documentation, or deliberate management override can remain undetected even in an audit properly planned and performed. Procedures effective at detecting error are frequently ineffective against concealment by someone who knows what the auditors test.

    Materiality is the practical crux for a small organization. If your materiality threshold is set around sixty thousand dollars, a scheme taking two thousand dollars a month is below the level the audit is engineered to find, and it can run for years inside the noise. Audits also work on samples rather than populations, selecting a subset of transactions for testing, and a well-concealed scheme distributed across many small entries has a low probability of being sampled. The external audit's low ranking as a detection method in fraud studies is not an indictment of auditors. It is an accurate reflection of what the engagement was scoped to do.

    The distinction worth understanding is between an audit and a forensic engagement. An audit asks whether the financial statements are fairly presented. A forensic accountant asks whether a specific person took specific money, examines populations rather than samples, and produces work intended to support a claim or a prosecution. They are different products at different prices, and you engage the second only when you have a credible concern. Some organizations also add an agreed-upon procedures engagement, which is a middle option where you direct the accountant to perform a defined set of tests, including several described in this article, and report the results without an opinion.

    None of this argues against the audit. It argues for accurate expectations and for a conversation with your auditor that most boards never have: ask what materiality they used, what fraud risks they identified, what they tested, and what a scheme would have to look like to escape their procedures. Those answers tell you precisely where your own detective work needs to sit. Preparing that conversation well is part of getting value from the engagement, which we cover in more depth in our guide to audit preparation.

    Questions to put to your auditor this year

    Answers that show you where your own gap sits

    • What materiality threshold did you apply, and what does that mean we would not see
    • Which fraud risks did you identify for an organization of our size and structure
    • What journal entry testing did you perform, and over what population
    • Which of our control deficiencies would you consider significant, in writing
    • Would an agreed-upon procedures engagement close the gap you are describing

    When a Question Becomes a Credible Concern

    There is a moment when an item stops being an anomaly and becomes something you cannot explain away: a vendor that does not exist at the address on file, a cleared check image with a payee nobody recognizes, a reconciliation that only balances because of a recurring adjusting entry with no support. What you do in the next few days shapes whether the organization recovers its money, keeps its insurance coverage, and survives the governance consequences. The instinct of almost every leader in this position is exactly wrong, so it is worth being explicit about the sequence. This is general guidance drawn from published legal commentary, not legal advice, and step four is where the real advice starts.

    Do not confront the person. This is the instinct, and it is the most damaging available action. A confrontation gives notice, and notice gives an opportunity to delete records, alter entries, empty an account, or construct an explanation. It also risks an unlawful accusation against someone who may be innocent, and it can compromise a later investigation by tainting the sequence of events. Say nothing to the person, and say nothing to colleagues.

    Preserve everything immediately. Take a complete backup of the accounting file, export the audit log before the two year window rolls, secure bank statements and cleared check images, and issue a litigation hold instructing that no records, emails, or files be deleted or altered. Venable's guidance on investigating and responding to allegations of fraud and embezzlement emphasizes preserving emails, notes, calendar entries, and financial documents, and doing so before anyone is aware an inquiry is underway. Preservation costs nothing and its absence is unrecoverable.

    Tell exactly one or two people. Normally the board chair and the audit or finance committee chair. If the concern involves the executive director, go directly to the board chair and do not route it through the executive. If it involves the board chair, go to the vice chair or the audit committee. Keep the circle as small as it can be until counsel advises otherwise, because every additional person increases the chance the subject learns of it and the chance that an innocent person's reputation is damaged.

    Engage independent counsel, then a forensic accountant if counsel advises. Independent matters. Your regular counsel may have conflicts, and an attorney engaged specifically for this can direct the investigation in a way that supports privilege over the work product. Counsel will advise on whether and when to engage a Certified Fraud Examiner or forensic accountant, whether to place anyone on administrative leave, when and how to suspend system and banking access, and whether and when to involve law enforcement or notify your state charity regulator, which some states require.

    Notify your insurer promptly. Employee dishonesty coverage, sometimes still called a fidelity bond, and commercial crime policies typically carry strict notice requirements and discovery windows, and late notice is one of the most common reasons a legitimate claim is denied. Read the policy for the notice deadline and the definition of discovery, and have counsel review the notice before it goes out. This is also where organizations discover the coverage they assumed they had was never purchased, which is a conversation worth having before you need it, alongside the wider review of nonprofit insurance exclusions.

    Worth noting that external fraud follows a different playbook. A payment diverted by a spoofed email from someone impersonating a vendor or the executive director is a criminal act by an outsider exploiting your process, and the immediate steps involve the bank's fraud desk and law enforcement rather than an internal investigation. We cover that scenario separately in our piece on phishing and wire fraud, and the two are easy to confuse in the first hours.

    The first days, in order

    General guidance, not legal advice, and counsel comes early

    • Say nothing to the person concerned, and nothing to colleagues
    • Back up the accounting file and audit log, and issue a hold on record deletion
    • Notify the board chair or audit committee chair, and no one else yet
    • Engage independent counsel, who directs any forensic engagement and access changes
    • Give the insurer notice inside the policy window, with counsel reviewing the notice

    The Disclosure Obligations Nobody Reads Until They Need To

    A confirmed theft is not only an operational and legal problem. It triggers reporting obligations that many boards learn about for the first time while drafting the return, and getting them wrong compounds a bad year considerably. Start with Form 990, Part VI, Section A, line 5, which asks whether the organization became aware during the year of a significant diversion of its assets. A diversion is any unauthorized conversion or use of assets other than for authorized purposes, which expressly includes embezzlement and theft, and it can be committed by an officer, director, employee, or an unrelated third party.

    Significance is defined by a threshold, and it is lower than most people expect. A diversion is significant if the total of diversions for the year exceeds the lesser of $250,000, five percent of gross receipts for the year, or five percent of total assets. For an organization with a million dollars in revenue, five percent is fifty thousand dollars, so the operative number is not a quarter of a million. It is whichever of those three figures is smallest, which for most small nonprofits means the five percent test governs. Answering yes requires an explanation on Schedule O describing the nature of the diversion, the amounts or property involved, corrective actions taken, and pertinent circumstances, as summarized in long-standing commentary on reporting diversions of nonprofit assets.

    Schedule L enters when the person involved is a disqualified person, broadly meaning someone in a position to exercise substantial influence over the organization, which typically covers officers, directors, key employees, and certain family members and related entities. Theft by such a person is generally treated as an excess benefit transaction under the intermediate sanctions rules, reportable through Part IV and Schedule L, and carrying excise tax exposure for the individual and potentially for organization managers who knowingly approved it. This is squarely territory for your tax adviser rather than for a finance director working from the instructions, and it is one reason the counsel conversation should happen long before the return is due.

    Other obligations often run in parallel. Several states require charities to notify the attorney general or charity regulator when assets are misappropriated, independently of anything the IRS requires. Federal award recipients have mandatory disclosure obligations relating to certain violations of criminal law involving fraud in connection with a federal award, with short deadlines. Private funders frequently impose their own notice requirements in grant agreements, and a foundation that reads about a diversion in a news report before hearing from you will react very differently than one you called. The 990 is a public document, and the disclosure will be read by funders, watchdog sites, and journalists, so drafting the Schedule O narrative deliberately matters. Our guidance on working through Form 990 covers the mechanics of the return, though a disclosure of this kind should be drafted with counsel and reviewed by the full board before filing.

    There is a version of this that goes well. Organizations that disclose clearly, describe the control failure honestly, explain what changed, and can point to a strengthened control environment frequently retain their funders and their donors. What damages an organization is not the disclosure. It is the impression of concealment, a vague Schedule O narrative that raises more questions than it answers, or a funder learning about it secondhand. Treat the disclosure as the first act of rebuilding credibility rather than as the final indignity of a bad year.

    Reporting obligations to review with counsel

    Several run in parallel and carry different deadlines

    • Form 990 Part VI line 5: significant diversion, with a Schedule O narrative
    • The threshold test: the lesser of $250,000, five percent of gross receipts, or five percent of assets
    • Schedule L: excess benefit treatment where a disqualified person was involved
    • State charity regulator: notification requirements that vary considerably by state
    • Funders: federal award disclosure duties and private grant agreement notice clauses

    Building the Rhythm Into a Normal Quarter

    A review that happens once, in a moment of anxiety, is worse than useless, because it will look targeted and it will teach the organization nothing about its own baseline. The value comes from repetition. Put the analytical review on the calendar quarterly, assign it to someone outside the transaction-processing function, and give the output a standing place on the finance committee agenda so that reporting no findings is as routine as reporting findings.

    Who runs it matters more than what tools they use. The ideal owner is the finance committee chair or a board member with financial literacy, working from exports that a staff member provides on request. The second best is an executive director reviewing the bookkeeper's data, which is acceptable in a small shop but leaves the executive director unreviewed. The arrangement to avoid is the bookkeeper running the review on their own work, which converts a control into a formality. If your organization has no realistic reviewer on the board, this is a strong argument for adding one, and it is a more useful recruitment criterion than the vague call for financial background that most boards use.

    Keep a written record of each quarter's run: which tests were executed, how many items each returned, which were reviewed, what the explanations were, and what was verified independently. This does three things. It demonstrates to your auditor and your board that a detective control exists and operates, which matters for the control environment assessment. It creates the baseline that makes next quarter's numbers interpretable, because a jump from four flagged items to nineteen is itself information. And it protects the reviewer, because a documented routine process is defensible in a way an undocumented inquiry into a colleague is not.

    Expect the early quarters to surface housekeeping rather than crime. The first run typically finds duplicate payments made in error and worth recovering, vendors that should have been deactivated years ago, coding inconsistencies that distort program reporting, missing W-9s, and approval thresholds that no longer match the organization's spending. That is a genuinely good outcome and a much more likely one than catching a thief. Cleaning that up improves the quality of everything downstream, from your chart of accounts to the reports your board relies on to make decisions, and it tightens the environment that a would-be scheme would have to survive.

    A quarterly review that survives contact with a busy month

    Scheduled, owned outside finance, and documented

    • A fixed calendar date, so the review is never a response to a suspicion
    • An owner outside the transaction-processing function, ideally a finance committee member
    • The same test set each quarter, so counts become comparable over time
    • A written record of tests run, items returned, explanations, and verifications
    • A standing agenda slot where a report of no findings is entirely normal

    Conclusion

    The uncomfortable arithmetic of nonprofit embezzlement is that the conditions producing it are the same conditions that make small nonprofits work at all. One trusted person handling the money is efficient. A board that extends good faith to its staff is healthy. A culture where nobody double-checks a colleague is pleasant to work in. Each of those is also the opening, and pretending otherwise has not protected a single organization. The realistic goal is not to build a control environment a determined insider could never beat, because a three-person organization cannot. It is to shorten the time between a scheme starting and somebody noticing, because duration is what turns a painful loss into an existential one.

    AI genuinely moves that needle, and it is worth being precise about how. It does not detect fraud. It removes the technical barrier that has kept a defined set of forensic tests out of reach for organizations without a data analyst, by flattening messy exports, writing the formulas, and explaining the logic in language a finance director can verify. That converts an analysis that used to require a consultant into an afternoon a board treasurer can spend quarterly. Run alongside honest exports from your accounting system and a sensible approach to the bookkeeping tools you already use, it closes a real gap.

    What the technology cannot supply is judgment, and the judgment required here is unusually delicate. Every flagged row is a question about a named human being who is, on any reasonable reading of the base rates, innocent. The discipline of treating anomalies as routine inquiries, of asking about the transaction rather than the person, of corroborating explanations quietly and keeping unresolved items inside the smallest possible circle, is not softness. It is what makes the practice sustainable, because a review process that damages good colleagues will be abandoned within a year, and rightly so.

    And when a question does harden into a credible concern, the sequence is the opposite of instinct. Do not confront. Preserve the records, tell the board chair or audit committee, bring in independent counsel, give your insurer notice inside the window, and let counsel direct any forensic work and any decision about law enforcement, your state regulator, and the disclosures on Form 990. None of this is legal or forensic accounting advice, and the whole point of understanding it in advance is that the phone call you make on the worst morning of your professional life should be to the right person, early, with your records intact.

    Want a Quarterly Review Your Board Can Actually Run?

    We help nonprofits turn accounting exports into a repeatable anomaly review, with the test set, the prompts, the documentation template, and the judgment guardrails that keep it fair to the people whose work it examines.