IN BRIEF

Fraud remains a serious risk for any entity, and not-for-profit organizations unfortunately make an easy target. This article explores the ways in which not-for-profit organizations may be particularly susceptible to fraud and highlights some helpful steps to take in preventing and—if necessary—addressing fraud within not-for-profit organizations.

***

Not-for-profit organizations are increasingly being targeted by fraudsters. They are often viewed as “cyber-poor but target-rich,” meaning that they collect valuable data from donors and beneficiaries, but generally lack the IT staff or resources to properly safeguard such information. This status puts an organization’s reputation, and the trust placed in it by stakeholders, at risk. Fraud exposure within not-for-profit organizations has never been more consequential or more complex.

What is Fraud?

Fraud has various definitions and can occur in many different ways. One classic definition of fraud is any intentional or deliberate act to deprive another of property or money by deceit, dishonesty, or other unfair means. Fraud may also include deception brought about by the misrepresentation of material facts, or silence when good faith requires disclosure, resulting in material damage to anyone who is entitled to read and rely upon the affected financial statements.

Occupational fraud, which is committed by individuals against the organizations that employ them, is a very common type of fraud. According to the Association of Certified Fraud Examiners’ (ACFE) Occupational Fraud 2024: A Report to the Nations, annual losses related to occupational fraud generally amount to approximately five percent of an organization’s revenues (https://tinyurl.com/39kwruwy).

The following results from the ACFE’s report are of particular interest to not-for-profit organizations:

  • Not-for-profit organizations (which represented 10% of entities in the study) had a median loss of $76,000, almost half the size of losses at other types of organizations.
  • Religious, charitable, and social service organizations had a median loss of $85,000.
  • Overall, an average occupational fraud takes approximately 12–18 months to detect. Fraud detection in not-for-profit organizations could take up to 24 months.
  • Not-for-profit organizations had the lowest implementation rate of fraud awareness training in the study, with approximately 49% of manager/executive training and 52% of employee training. Not-for-profit organizations that provided fraud awareness training uncovered frauds more than 2.5 times faster than organizations that did not.
  • The study determined that the primary factors leading to fraud included poor internal controls (32%), override of internal controls (19%), lack of management review (18%), lack of competent personnel in oversight roles (9%), and poor tone at the top (8%).

In the author’s experience, cyber fraud is another critical risk area for not-for-profit organizations. This area includes ransomware, phishing attacks, and email compromises (see John Alfonso, Nicole Stan, David Sun, and Vincenzo Toppi, “Cyber and Financial Fraud Is Rising—Is Your Not-for-Profit Ready?” Sept. 23, 2025, https://tinyurl.com/3pvr9x9k).

Why Are Not-for-Profits Especially Vulnerable to Fraud?

Operating with limited staffing, lean financial oversight, and a high degree of internal trust leaves not-for-profits especially vulnerable to fraud. In Microsoft’s 2024 Digital Defense Report, not-for-profit organizations are the fourth most targeted sector, and the education sector is the second most targeted by nation-state threat actors (https://tinyurl.com/4f557bm4). Many not-for-profit organizations are viewed as “cyber-poor but target-rich” because they collect sensitive donor and beneficiary data and frequently have limited cybersecurity budgets or dedicated IT staff to secure the information.

Common Fraud Schemes and Red Flags

Fraudulent activity in not-for-profit organizations is usually intermingled with valid daily operations. The challenge is early detection, particularly in organizations where resources and segregation of duties is limited. Fraud goes unnoticed because of limited resources and a culture of trust. Understanding common fraud schemes and red flags will help a not-for-profit organization better understand and identify fraud risks that could impact their organizations.

Check fraud. While many organizations have switched to electronic payment methods, check fraud remains common. Mailed checks are getting intercepted, altered, and deposited fraudulently. With the ability to make mobile check deposits, fraudsters can change the payee name and deposit these fraudulent checks into multiple accounts. Organizations should pay attention to red flags, including: unknown vendor names, vendor complaints about unpaid invoices, missing or duplicate check numbers during bank reconciliations, and copies of cleared checks with different logos, handwriting, or fonts.

Payroll fraud. Payroll fraud can occur more easily when an organization relies on one individual to perform the majority of payroll responsibilities; this can lead to various opportunities for fraud schemes, including ghost employees, unauthorized pay rate changes, and direct deposit diversion. With larger organizations, there are risks that inactive employees would remain on the payroll, allowing fraudsters to change bank details and continue to receive the inactive employee’s salary. Red flags to pay attention to include duplicate or fictitious employee names or bank accounts, employees frequently changing bank account details, and terminated employees appearing on payroll.

Billing and vendor fraud. This type of scheme often involves fake vendors or personal expenses disguised as business costs. For example, a not-for-profit executive charging expensive meals as “donor meetings” or personal vacations as “conference/business trips.” There have also been cases of employees creating a shell company to submit fake invoices.

In these scenarios, some red flags include duplicate invoices or multiple payments to a vendor below approval thresholds, vague descriptions of details on invoices, generic vendor email addresses, a lack of a physical address for a vendor, frequent reimbursements from high-end restaurants or hotels, and frequently changing bank account details.

Donor confidence can erode quickly after a fraud incident, and once trust is broken, rebuilding it can take years.

Grant and government funding fraud. Compared to the other frauds where an individual is taking money directly from the not-for-profit, grant and government funding fraud involves an individual or individuals using the organization’s name and manipulating information to get more funding from the government, either for personal use or organizational use. Recent cases of grant-related fraud include diverting funds for personal expenses and falsifying information, such as exaggerating the number of meals delivered to those in need. Not-for-profit organizations should remain alert and ensure reports and invoices are legitimate to avoid potential violations of the federal False Claims Act.

Red flags to pay attention to include frequent journal entries moving costs between programs without clear explanation, spending patterns inconsistent with grant budgets, late or incomplete grant reports, lack of supporting documentation for claimed expenses, and drawdowns that do not align with actual program activity.

Phishing and credential attacks. Since the pandemic, phishing emails have increased significantly due to the reliance on emails and electronic approvals. Phishing emails often look urgent and legitimate, asking the individual to process an invoice, send funds, or take another action immediately. Credential phishing is particularly dangerous as attackers use convincing messages to compromise login credentials. Red flags to pay attention to include emails arriving at odd hours, use of urgent language, and subtle character changes in email addresses.

Importance of Fraud Risk Assessments

Fraud can affect not-for-profit organizations on multiple levels. Financial loss is often the most significant impact, as stolen funds directly reduce the organization’s ability to operate and support its programs. This leads to operational disruptions, requiring additional staff time to review transactions and strengthen controls, stretching already limited resources.

But the reputational impact can be just as damaging for a not-for-profit organization. Donor confidence can erode quickly after a fraud incident, and once trust is broken, rebuilding it can take years. Not-for-profit organizations may also face increased regulatory scrutiny; city, state, and federal agencies may delay funding approvals or initiate deeper investigations to confirm that funds are spent appropriately. That is why conducting regular fraud risk assessments is essential to protecting the mission, resources, and long-term viability of any not-for-profit.

Fraud risk assessments identify vulnerabilities before fraud occur. Organizations should strive to be proactive, rather than reactive. Because not-for-profit organizations often operate with tight budgets, a fraud risk assessment will help prioritize resources and assist with identifying the areas that are high risk.

Fraud risk differs from organization to organization and is influenced by their size, structure, and operational complexity. In general, not-for-profit organizations should consider the following steps when performing a fraud risk assessment:

  • Establish objectives and scope. Define the purpose for conducting the assessment and determine which areas to include.
  • Gather information. Review organizational structure, policies, and procedures; understand funding sources, reporting requirements, and regulatory obligations; and interview key staff and volunteers to learn about operations.
  • Identify fraud risk areas. Determine processes where fraud could occur and research fraud cases from similar organizations.
  • Assess likelihood and impact. For each risk, evaluate the risk’s likelihood and impact (considering financial, operational, strategic, reputational, and regulatory perspectives).
  • Determine risk response. Review existing internal controls and identify gaps or weaknesses in current internal controls.
  • Develop mitigation strategies. Where gaps exist, strengthen internal controls via new policies and procedures, training, whistleblower channels, technological advances, additional insurance, and others.
  • Monitor. Review risk at least annually, as well as after major organizational changes.

Internal Controls: Preventive and Detective Measures

To reduce exposure, organizations must translate assessment findings into concrete, actionable safeguards. This is where strong preventive and detective internal controls come to the forefront.

Preventive controls. Preventive controls are the first line of defense, designed to stop errors, fraud, and misappropriation before they occur. The following are key preventive measures that can be used by not-for-profit organizations:

  • Segregation of duties, ensuring no single individual has control over all aspects of a transaction
  • Background checks to screen for potential risk indicators during the hiring process
  • Physical and access security over key assets such as inventory, cash, and sensitive documents
  • Formalized procurement processes, including purchase orders, contracts, receiving reports, and three-way matching
  • Dual approvals for high-value transactions, with explicit avoidance of email-based approvals
  • Limited corporate credit cards, with established limits and clear usage policies
  • Bank safeguards, such as Positive Pay and ACH Debit Blocks, to prevent unauthorized payments
  • Controlled setup and modification of customer, vendor, and employee records, requiring independent verification
  • Technology-driven protections, such as routine updates, multi-factor authentication, robust password policies, virtual private networks (VPN), cybersecurity training, and phishing simulations
  • Vendor and partner alignment with cyber policies, in order to manage third-party risk
  • Immediate removal of system access upon employee termination
  • Mandatory vacations, so that concealed irregularities can be uncovered when staff are out.

Detective controls. Detective controls help organizations identify issues that preventive measures may not fully eliminate. These controls play a critical role in alerting organizations to potential issues and prompting their timely investigation and remediation. The following are important detective controls:

  • Timely month-end account reconciliations and robust financial statement reviews
  • Careful examination of credit card statements, ensuring the completeness and legitimacy of charges
  • Regular payroll analysis to confirm the authenticity of employees and the accuracy of compensation
  • Vendor payment and Form 1099 reviews to spot anomalies
  • Annual external audits, offering independent assurance
  • Listening to stakeholders—employees, customers, vendors—for potential early warning signs
  • Monitoring banking alerts and Positive Pay exceptions, investigating any flagged activity
  • Daily review of bank activity, in order to promptly detect unauthorized transactions
  • Using analytics and AI to detect unusual transaction patterns or behavior
  • Review of IT general and application controls, such as access rights and change logs
  • Anonymous reporting mechanisms (e.g. whistleblower hotlines), to encourage the early escalation of concerns.

What to Do When Fraud Is Suspected

If the first time an organization is thinking about how to respond to fraud is after it has already occurred, then it is too late. Effective fraud management is about anticipating risks, building resilient processes, and preparing teams long before anything happens. When fraud is discovered in a not-for-profit organization, the immediate priority is to preserve evidence, contain further losses, and initiate a structured response. Management should promptly restrict access to relevant financial systems, secure documents or electronic records, and ensure no staff member involved in the allegation can alter information or influence the investigation. A response group, generally including finance, human resources, IT, and legal, should be established.

Management should inform the board or audit committee of the fraud when it occurs. Depending on the nature of the fraud, a not-for-profit organization may need to also notify funders, lenders, or governmental oversight bodies, and assess whether donor or beneficiary information was compromised. If an organization collects and maintains “personally identifiable information,” it is required to disclose any security breaches in accordance with applicable state law (https://tinyurl.com/4uypw456). Breaches involving protected health information require communication to the US Department of Health and Human Services. The authors recommend consulting with lawyers, accountants, and cybersecurity professionals before communicating with any external parties. Throughout the process, management should document the actions taken and evaluate root causes in order to strengthen internal controls and policies. While the incident may create immediate operational and reputational challenges, a disciplined and well-governed response can help restore trust.

Emerging Issues

Not-for-profit organizations face a growing set of emerging fraud risks driven by evolving criminal tactics. With the rise of online platforms and crowdfunding campaigns, digital fundraising has increased an organization’s exposure. Among other schemes, for example, fraudsters have been able to successfully create fake donation pages designed to mimic legitimate fundraising sites. Emerging artificial intelligence risks, such as deepfake videos of requests for urgent funds, require organizations to independently verify unusual requests through other channels. Finally, social media scams, including fraudulent accounts leveraging trending charity hashtags, can redirect donors to fraudulent links. Not-for-profit organizations should verify payment gateways, monitor social media, and verify URLs.

While not-for-profit organizations may never be able to fully prevent fraud from occurring, they should take steps to minimize the reputational and financial risks before an incident occurs. Today’s interconnected IT systems make organizations vulnerable to fraudsters anywhere in the world. Fraud prevention is a stewardship responsibility and, in the not-for-profit sector, protecting financial integrity directly protects the organization’s mission.

Vincenzo Toppi, CPA, CIRA, CFF, CCFE, is a partner in restructuring and dispute resolution services at CohnReznick LLP, New York, N.Y.
Allison Guttenplan is a CPA and CIA. She is a senior manager in risk advisory at CohnReznick Advisory LLC, New York, N.Y.
Mindy Ng is a CPA. She is a senior manager in not-for-profit and education assurance practice at CohnReznick Advisory LLC, New York, N.Y.