Internal Control Checklist - NPO
Internal Control Checklist - NPO
Internal Control Checklist - NPO
Organization: ________________________________________________________
Introduction
The purpose of this checklist is to analyze the sufficiency of the organization’s internal controls,
document those controls, and make recommendations for improvement. Management should
update this checklist at least annually.
Position Name
Treasurer _______________________________________
Chief Financial Officer _______________________________________
Controller _______________________________________
Accountants: _______________________________________
_______________________________________
_______________________________________
Payroll Supervisor _______________________________________
Payroll Clerk _______________________________________
Accounts Payable Supervisor _______________________________________
Accounts Payable Clerks _______________________________________
_______________________________________
Accounts Receivable Supervisor _______________________________________
Accounts Receivable Clerks _______________________________________
_______________________________________
Others:
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Page 1 of 30
Internal Control Checklist - Nonprofit
_______________________________ _______________________________________
List the names and titles of employees who prepare the bank deposit:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are controls surrounding the preparation of bank deposits adequate? _____ Yes _____ No
Examples: segregation of duties, review procedures, checks received are restrictively endorsed
immediately upon receipt, cash receipts logs.
List names and titles of employees who are responsible for making bank deposits:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are controls surrounding the deposit of receipts and employee safety adequate? _____Yes
_____ No
Page 2 of 30
Internal Control Checklist - Nonprofit
Are the original bank statements sent to, opened by and reviewed by the Treasurer or to a
manager who does not have the responsibility for reconciling the statement to the general ledger?
_____ Yes _____ No
List names and titles of employees who are responsible for reconciling bank statements, next to
the account(s) they are responsible for:
Are all bank statements reconciled from the bank statement to the general ledger monthly and
promptly? Are reconciling differences, negative balances, and/or unsupported transactions
investigated and corrected timely? _____ Yes _____ No
Are checks that are noted as outstanding on the prior year-end bank statement reconciliations
investigated thoroughly (endorsement comparisons, double payments, etc.) by the auditors, the
internal audit committee or management, before the start of the following year’s audit? _____
Yes _____ No
Are financial reports comparing actual financial results to budgeted amounts generated and
reviewed by appropriate management on a monthly basis? Are budget variances sufficiently
explained? _____ Yes _____ No
Page 3 of 30
Internal Control Checklist - Nonprofit
Are copies of bank reconciliations attached to monthly internal financial statements, and
reviewed by management? _____ Yes _____ No
If no, detail that it has been explained to management that this is a recommended procedure to
reduce embezzlement through manipulation of bank statement reconciliations:
Are the individuals responsible for reconciling bank statements different from those responsible
for check preparation? _____ Yes _____ No
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
List names and titles of employees recording accounts receivable and general receipts:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
List names and titles of employees who open and distribute the mail:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Page 4 of 30
Internal Control Checklist - Nonprofit
Are full explanations required for all journal entries? _____ Yes _____ No
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
List names and titles of employees responsible for reviewing and approving journal entries:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are procedures surrounding the review and approval of journal entries adequate? _____ Yes
_____ No
Page 5 of 30
Internal Control Checklist - Nonprofit
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are controls surrounding petty cash fund disbursements and security adequate? _____ Yes
_____ No
Examples: supporting documentation obtained for all disbursements, petty cash log,
reconcilement to general ledger, surprise audits.
Are there adequate job descriptions for all accounting or finance positions? Are the level of
competence and the requisite knowledge and skills carefully defined for each job in the
accounting or finance department? _____ Yes _____ No
Does the organization have a written Accounting / Financial Policies and Procedures Manual, is
the manual current and thorough, and do all employees have a copy? _____ Yes _____ No
Page 6 of 30
Internal Control Checklist - Nonprofit
Are policies and procedures in place for hiring, training, promoting and compensating employees
in the accounting or finance department? _____ Yes _____ No
Has the accounting or finance staff been appropriately trained in the use of the accounting
system, including the chart of accounts, edits, and other system controls? _____ Yes _____ No
When employees assigned to financial or accounting duties are on vacation, does another
employee assume their responsibilities? _____ Yes _____ No
Does the organization require all individuals working in finance or accounting to take a full,
uninterrupted week of vacation per year? _____ Yes _____ No
Have all accounting personnel signed a Conflict of Interest agreement? _____ Yes _____ No
Page 7 of 30
Internal Control Checklist - Nonprofit
Does the organization require thorough background checks for all finance personnel and key
positions? _____ Yes _____ No
Is there a written policy whereby employees are required to report suspicious activities, conflicts
of interest, or unethical behavior to the appropriate level of management? _____ Yes _____ No
Does the organization have a whistleblower protection policy prohibiting retaliation against
whistleblowers? _____ Yes _____ No
Does the organization have a policy whereby terminated employees are subject to an exit
interview? _____ Yes _____ No
Does the organization have an Insurance or Risk Management Committee to ensure that all
insurance policies are adequate? _____ Yes _____ No
Page 8 of 30
Internal Control Checklist - Nonprofit
Does the organization have a code of ethics, a code of conduct or other policies addressing
acceptable business practice and expected standards of ethical and moral behavior for all
employees, including financial management? _____ Yes _____ No
Are controls over wire transfers and other electronic payments adequate? _____ Yes _____ No
Has the bank been made aware that any changes regarding authorized signatures on check
signature cards, wire transfer contracts, activations on lines of credit, and loans require the
approval of the appropriate level of management? _____ Yes _____ No
Page 9 of 30
Internal Control Checklist - Nonprofit
Comment on any specific financial and accounting administration issues that indicate that the
system and controls are not adequate, with recommendations for improvement:
List resources available to assess if any of the organization’s line item expenses are out of line
with those of similar organizations:
If any line items were determined to be out of line, what analytical action was taken to determine
if fraud might be present?
Employee Interviews
It is recommended that internal audit committees or other committees of the board interview
employees to discuss fraud risk and internal control strengths and weaknesses. The following
interview questions can be asked during each interview:
Page 10 of 30
Internal Control Checklist - Nonprofit
Results of Interviews:
The employee interviews and results should be documented. After the interviews, the results
should be discussed among the committee members. The risks should be analyzed and a plan of
action should be formulated.
Summarize results of implementing the plan of action and further action warranted, if necessary:
Are copies of credit card statements mailed by the credit card issuer to a secured post office box
accessible only by the following?
Yes No N/A
The CEO or Executive Director ____ ____ ____
Page 11 of 30
Internal Control Checklist - Nonprofit
Is the use of debit cards prohibited in your organization? _____ Yes _____ No _____ N/A
Are employees who have been issued organization credit cards aware of immediate steps to take
to report lost or stolen cards? _____ Yes _____ No
If the organization reimburses employees for purchases made on behalf of the organization, are
controls adequate? _____ Yes _____ No
Examples: approval and review procedures, use of expense reports, timeliness of submission,
limits on $ advances, attachment of all receipts to expense reports.
Payroll
List the names and titles of personnel who process payroll for your organization. (If an outside
payroll services is used, put “N/A”, and see additional questions below.)
Page 12 of 30
Internal Control Checklist - Nonprofit
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are payroll checks signed by individuals not involved in processing payroll? _____ Yes _____
No
If any outside payroll preparation service is used, are controls and reviews adequate? _____ Yes
_____ No
Page 13 of 30
Internal Control Checklist - Nonprofit
E-mail: ________________________________________
Is there a random check on payroll during the year to ensure that wages are accurate and there
are no ghosts on the payroll? _____ Yes _____ No
Are the calculations of the federal and state tax deposits checked or reviewed by management on
random basis? _____ Yes _____ No
Is the payroll account reconciled from the bank statement to the general ledger promptly at the
end of each month by someone not involved in the processing of payroll? _____ Yes _____ No
Are payroll checks or direct deposit receipts distributed to employees by someone not involved
in processing payroll? _____ Yes _____ No
Page 14 of 30
Internal Control Checklist - Nonprofit
Does the organization use time sheets for employees covered by the Fair Labor Standards Act
(FLSA), and are they signed by the employee and approved by the employee’s direct supervisor?
_____ Yes _____ No
If employee loans or advances are allowed, are controls, procedures and approvals adequate?
_____ Yes _____ No
Comment on any specific payroll-processing issues that indicate that controls are not adequate,
with recommendations for improvement:
Does the organization use a bank’s Lockbox Service for cash receipts that come through the
mail? _____ Yes _____ No _____ N/A
Page 15 of 30
Internal Control Checklist - Nonprofit
Are the checks that come into the organization via the mail endorsed with the organization’s
restrictive endorsement stamp immediately after receipt? _____ Yes _____ No
Once checks have been endorsed, are they forwarded directly to finance for processing? _____
Yes _____ No
Is a log of checks received maintained by the person who opens the mail, for audit trail
purposes? _____ Yes _____ No
Does the organization compile an accounts receivable aging schedule monthly? _____ Yes
_____ No
Does the organization have adequate procedures to follow up on aging accounts receivable and
delinquent accounts? _____ Yes _____ No
Page 16 of 30
Internal Control Checklist - Nonprofit
Are customer statements reviewed and controlled by an employee other than the accounts
receivable clerk? _____ Yes _____ No
Note the organization’s procedures for writing off uncollectible accounts receivable:
Are the procedures concerning writing off uncollectible accounts receivable adequate? _____
Yes _____ No
List the names and titles of employees authorized to approve accounts receivable write-offs:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Note the names and titles of employees authorized to issue credit memos to customers:
Page 17 of 30
Internal Control Checklist - Nonprofit
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are the controls concerning offering credits to customers and issuing credit memos adequate?
_____ Yes _____ No _____ N/A
Comment on specific issues concerning recording accounts receivable, securing proper write-off
approvals, issuing credits to customers, etc., that indicate controls are not adequate, and record
recommendations for improvement:
Is the check supply under lock and key? _____ Yes _____ No
Does the organization utilize a bank’s Positive Pay service? _____ Yes _____ No
Page 18 of 30
Internal Control Checklist - Nonprofit
If the organization does not utilize Positive Pay, have the benefits of this service been explored
and explained to the appropriate level of management? _____ Yes _____ No
Are individuals involved in the accounting function or the recording of transactions prohibited
from signing checks? _____ Yes _____ No
Does the organization use a purchase order system, and are procedures adequate? _____ Yes
_____ No
Are two signatures required on some or all disbursements? _____ Yes _____ No
Are there periodic comparisons of witnessed check-signing signatures against canceled checks?
_____ Yes _____ No
Page 19 of 30
Internal Control Checklist - Nonprofit
If handwritten or typed checks are ever prepared, is the amount protected with a check imprinter
machine? _____ Yes _____ No
Other than petty cash, are all disbursements made by check or wire transfer? _____ Yes _____
No
Are voided checks voided properly (cutting off signature lines) and are they accounted for
properly? _____ Yes _____ No
Does the organization prohibit authorized signers from signing checks in advance? _____ Yes
_____ No
Page 20 of 30
Internal Control Checklist - Nonprofit
List out the names and titles of all authorized wire transfer agents:
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
_______________________________ _______________________________________
Are two signatures required on all wire transfers? _____ Yes _____ No
Comment on any specific disbursement issues that indicate that controls are not adequate, with
recommendations for improvement:
Travel Expenses
Page 21 of 30
Internal Control Checklist - Nonprofit
Does the organization have a written travel policy, and is it included with the financial policies
and procedures? _____ Yes _____ No
Does the organization require original receipts for travel expenses? _____ Yes _____ No
Are travel expense policies current, documented, and communicated properly? _____ Yes _____
No
Does the organization use the per diem method for meal allowances? _____ Yes _____ No
If yes, describe procedures below, and note if the organization’s per diem policy is in compliance
with Internal Revenue Service rules and regulations:
Does the organization monitor air fare rates to ensure that it is benefiting from the best available
rates? _____ Yes _____ No
Page 22 of 30
Internal Control Checklist - Nonprofit
Are the organization’s travel expense forms current, complete, and compliant with the
organization’s travel policies? _____ Yes _____ No
Comment on any specific travel expense issues that indicate that controls and policies are not
adequate, and record recommendations for improvement:
Are policies and controls over access to postage meters and accounts adequate to prevent
unauthorized use? _____ Yes _____ No
Page 23 of 30
Internal Control Checklist - Nonprofit
Address: _____________________________________________________________________
Are the procedures surrounding utilization of the organization’s mail / shipping service
adequate? _____ Yes _____ No
Comment on any specific issues that indicate that controls and policies surrounding postal
meters, postal accounts, and shipping services are not adequate, and record recommendations for
improvement:
Are the purchases of budgeted and nonbudgeted fixed assets approved by the appropriate level of
management? _____ Yes _____ No
Page 24 of 30
Internal Control Checklist - Nonprofit
What type of depreciation method(s) does the organization use? Tax method: ______________
Book method: __________________________
Does the organization apply fixed asset control numbers to equipment? _____ Yes _____ No
Are the fixed assets records complete and current? _____ Yes _____ No
How often are fixed asset accounting records verified against fixed assets on hand?
Describe fixed asset retirement procedures and recommendations for improvement, if applicable:
Comment on any fixed asset procedures that you feel are inadequate, and suggest
recommendations for improvement:
Page 25 of 30
Internal Control Checklist - Nonprofit
Fidelity Bonds
Does the organization have a Fidelity Bond and/or employee dishonesty coverage? _____ Yes
_____ No
If the organization has a Fidelity Bond and/or employee dishonesty coverage, note the following:
Address: _____________________________________________________________________
_____________________________________________________________________________
Deductible: $__________________________
Is the amount of bond adequate, and has it been reviewed recently? _____ Yes _____ No
Are there any Fidelity Bond requirements due to line of credit agreements, grants, mortgages,
notes, etc.? _____ Yes _____ No
Page 26 of 30
Internal Control Checklist - Nonprofit
Are all employees who handle cash, checks, and credit card transactions included in the Fidelity
Bond and/or employee dishonesty coverage? _____ Yes _____ No
Has it been explained to management that corporate officers and directors are excluded from
Fidelity Bond coverage? _____ Yes _____ No
Does the organization have Directors and Officers liability insurance coverage? _____ Yes
_____ No
Comment on any specific Fidelity Bond, employee dishonesty coverage or Directors and
Officers liability insurance issues that indicate the coverage is inadequate, and note
recommendations for improvement:
Page 27 of 30
Internal Control Checklist - Nonprofit
Is the security of investments adequate (e.g., safe deposit box, safe, with custodian, etc.)? _____
Yes _____ No
Name Title
_______________________________ _______________________________________
_______________________________ _______________________________________
Page 28 of 30
Internal Control Checklist - Nonprofit
_______________________________ _______________________________________
Are investments examined routinely by responsible parties? _____ Yes _____ No _____N/A
Does the organization have an adequate written investment policy approved by the board of
directors? _____ Yes _____ No _____ N/A
Comment on any specific cash, cash equivalents, or investment procedures or issues that indicate
that the system and controls are inadequate, and suggest recommendations for improvement:
Does the organization have an action plan of steps to take in the event of fraud or embezzlement,
and has the organization identified a position within the organization to “own” the fraud
prevention plan? _____ Yes _____ No
Page 29 of 30
Internal Control Checklist - Nonprofit
Taking detailed notes with the perpetrator, in the event of fraud? _____ Yes _____ No
Contacting the bank(s) immediately, in the event of fraud? _____ Yes _____ No
Comment on any specific embezzlement and fraud action plan issues that indicate that more
study and communication with management / employees is needed:
Note any other internal control issues and recommendations for improvement not addressed in
this document:
For additional information on internal controls, or if you would like to have our CPA firm
perform an internal control study for your organization, please contact:
Page 30 of 30