Internal Controls for Hybrid Nonprofits: What's Required in 2026

Melanie Kirton | Jul 01 2026 15:58

Educational guidance — not a substitute for advice from your CPA or auditor.

 

If your team is split between home offices and headquarters — someone approving expenses from a kitchen table, someone processing payments from the break room — your financial controls may not have caught up with how you actually work. That's not a criticism. It's one of the most common gaps we see in nonprofits right now.

 

Hybrid work solved a lot of problems. But it quietly removed some of the informal oversight that used to happen naturally: a supervisor glancing at a payment, a colleague noticing an unfamiliar vendor name, a manager walking past and asking why the petty cash tin looked light. That passive oversight is gone. The safeguards that replaced it need to be intentional — and documented.

 

This guide walks you through a practical, step-by-step internal controls review built for how nonprofits actually operate in 2026. No outside consultant required.

Why Internal Controls Matter More in a Hybrid World

 

What Controls Actually Do

 

Internal controls are the policies, processes, and checks that protect your nonprofit's money and reputation. They answer the question:   What would stop something from going wrong — and what would help us catch it if it did?

 

They protect against four things: honest mistakes, misuse of restricted funds, fraud, and audit surprises. For nonprofits there's a fifth: donor trust. When a control gap leads to a financial problem — even a small one — and it becomes public, the damage to donor confidence is often far larger than the dollar amount.

 

What Hybrid Work Changed

 

In a physical office, some controls happened informally — a supervisor glanced at a check, a colleague noticed a vendor name that looked off, the check stock was locked in a cabinet. Hybrid work removed that passive oversight. The same safeguards now need to be intentional and documented rather than accidental and ambient.

 

The 6-Step Hybrid Controls Review

 

1. Map Your Approval Workflow on Paper

 

Pick one transaction type — a vendor payment, for example. Write down who requests it, who approves it, who processes it, and who reconciles it. If the same name appears more than twice, that's where your gap lives.

 

Approval workflows that happen over email chains or informal texts leave no audit trail and no clear accountability.

 

What good looks like
 

A written policy that specifies who can approve what, up to what dollar threshold, and where approvals are recorded. Even one page is better than an unspoken understanding.

 

Hybrid-specific risk
 

The primary approver is traveling or remote, so payments get waved through by whoever is available that day — without a documented backup authorization process.

 

2. Identify Segregation of Duties Gaps

 

Segregation of duties means no single person controls every step of a financial transaction. In a small nonprofit, perfect segregation isn't realistic — but layered touchpoints are.

 

Map your current process: who initiates, who approves, who records, who reconciles. Wherever one person appears in all four steps — that's the gap to close first.

 

Compensating controls for small teams
 

Someone other than the bookkeeper reviews the bank statement monthly. The ED or board treasurer reviews reconciliations. New vendors require approval before first payment. A second person spot-checks vendor payments periodically.

 

3. Conduct a 30-Minute Access Audit

 

Who has login credentials to your accounting software, banking platform, credit cards, and payroll system? Is that list current? Departed employees whose access was never removed are one of the most commonly overlooked risks in hybrid organizations.

 

  • Pull the active user list for each financial system
  • Confirm every person still employed and still needs that level of access
  • Remove credentials for anyone who has left — contractors included
  • Confirm multi-factor authentication is enabled on banking and payroll platforms
  • Check that no financial accounts use shared passwords

4. Review Your Expense Management Process

 

Hybrid work often means expenses pile up in scattered inboxes: photos of receipts texted to a bookkeeper, personal cards used for work travel, reimbursements submitted weeks after the fact. Messy expense records create real problems: miscodings, missing documentation for restricted grant audits, and reimbursements that are hard to reconcile at year-end.

 

Your expense process needs to answer
 

Is there a written expense policy — what qualifies, what needs a receipt, what requires pre-approval? Are credit card holders submitting monthly statements with receipts attached? Are receipts stored somewhere retrievable — not just in someone's camera roll?

 

5. Confirm Board-Level Oversight Touchpoints

 

The board is your last line of oversight — and one of the most powerful compensating controls available to small teams. Board oversight doesn't mean micromanaging finance. It means at least one regular touchpoint per quarter that adds a set of independent eyes.

 

Three realistic board-level controls
 

Monthly or quarterly bank statement review by the treasurer. ED review of reconciliations before sign-off. Annual written policy review — even 30 minutes once a year to confirm documented controls still reflect how the organization actually operates.

 

6. Document What You Find

 

You don't need a formal controls manual. You need enough documentation that if someone asks "what controls are in place?" — a new ED, an auditor, a board member — you can answer the question clearly.

 

A one-page summary of your approval policy, a list of who has system access, a note on your expense process, and a record of your board oversight touchpoints is a meaningful starting point.

 

The key insight
 

Controls that exist but aren't documented aren't much better than controls that don't exist at all. If it's not written down, it's not a policy — it's a habit. And habits leave when people do.

 

Screenshot 2026-07-02 at 10.51.10 AM

 

Three Hybrid Control Mistakes That Create Audit Problems

 

Approving Payments Over Email Without a Record

 

Email is not an audit trail. When an auditor or a board member asks to see approval documentation for a payment, "I'll check my inbox from six months ago" is not a satisfying answer. The fix isn't a new software platform — it's a clear policy: approvals are documented in the accounting system, the bill-pay platform, or a shared folder with a timestamp. The platform matters less than the consistency.

 

Never Reviewing Who Has System Access

 

Staff and contractor turnover is higher in the nonprofit sector than most. Every departure creates a potential access gap that, if not closed, is an open door. This is the most commonly skipped control in hybrid organizations — not because it's hard, but because no one put it on the calendar. Add an access audit twice a year. It takes 30 minutes. It closes one of the easiest-to-exploit gaps in the control environment.

 

Treating "We Trust Our Team" as a Control

 

Trust is not a compensating control. It's a value — and an important one. But auditors don't test for trust. Funders don't rely on it. And when something goes wrong, the absence of documented controls makes it very difficult to determine whether a problem was accidental or intentional. The most trustworthy organizations are the ones that can demonstrate their trustworthiness through systems, not just through intention. Build both.

Your July Action Plan

 

You don't need to rebuild your entire control environment this month. Start with the six steps above — in order — and document what you find.

 

Six Things to Do This Month

  • Map one approval workflow end-to-end
  • Identify your single biggest segregation of duties gap
  • Pull the user list for your accounting and banking systems and remove stale access
  • Check whether a written expense policy exists — and whether it's being followed
  • Confirm at least one board-level oversight touchpoint is on the calendar
  • Write down what your controls are — one page is enough

Download the Internal Controls Checklist

 

A practical, small-team-friendly review tool covering all six areas above, plus a compensating controls guide for organizations that can't achieve full segregation of duties.

 

Get the Checklist →
"Strong controls aren't about distrust. They're about building an organization that can be trusted."
The Financial Affairs · thefinancialaffairs.com
 
Screenshot 2026-07-02 at 10.52.40 AM
 
This post is educational and not a substitute for accounting, audit, or tax advice specific to your organization. Contact a Financial Affairs advisor at   thefinancialaffairs.com/contact-us .