# Nonprofit Payment Fraud: Controls That Catch Both Risks | RankShield Financial

> ACFE data shows nonprofits suffer outsized fraud losses with the weakest controls. Here are payment controls that catch insiders and outside impostors.
>
> Source: https://rankshieldfinancial.com/resources/nonprofit-payment-fraud-controls/ · RankShield Financial (verifiable pre-settlement payment security)

RankShield Network · Financial · Payment Fraud
# Nonprofit Payment Fraud: Why Small Organizations Lose the Most and the Controls That Catch Insiders and Impostors Alike

Nonprofits lose an outsized share of their budgets to fraud, and the money leaves through two different doors: a trusted insider and an outside impostor. The controls that catch the first often do nothing about the second. Here is the minimum control set for a small finance office, and the one verification step that covers both.
   By  Jamie Kloncz  Founder, RankShield Financial    July 24, 2026 · 12 min read               Key takeaways
- Nonprofits lose a median $69,000 per occupational fraud case per ACFE 2026, and on a small budget that is a program, not a line item. Small organizations are hit hardest because controls are the hardest thing to staff.
- The money leaves through two doors: a trusted insider with broad access, and an outside impostor posing as a vendor or grantee. Segregation of duties catches the first and does nothing about the second.
- The annual audit is not the safety net it is assumed to be. Audits test whether statements are materially accurate and sample transactions; ACFE found 43 percent of frauds are caught by tips, with a median 12 months before detection.
- When a finance office is too small to fully segregate duties, verification is the compensating control: confirm the payee and the approval before release, and no single person can move money to the wrong account unchecked.
- One control covers both risks: verifying the payee before release and recording a named approver stops the insider paying themselves and the impostor posing as a vendor. That is what RankShield Financial is built to do.

Nonprofit payment fraud lands harder on small organizations than almost anywhere else, because the same tight budgets that make every dollar count also make real financial controls hard to staff. The Association of Certified Fraud Examiners’ 2026 study found that nonprofits accounted for about 10 percent of occupational fraud cases with a median loss of $69,000, and religious, charitable, and social-services organizations at a $76,000 median 1 . Against a six-figure annual budget, a $69,000 loss is not a line item; it is a program cut, a grant not renewed, or a staff position gone. The harder part is that this money leaves through two different doors most nonprofit guidance treats as one. An insider, a trusted bookkeeper or treasurer with access to everything, is one threat. An outside impostor posing as a vendor or a grantee is the other, and the controls that catch the first often do nothing about the second. This guide sets out the minimum control set for a small finance office, explains why the annual audit is not the safety net it is assumed to be, covers the vendor and grantee impersonation most nonprofit advice ignores, and shows how a single verification step covers both the insider and the impostor.

## The control set for a three-person finance office

The baseline controls for a small nonprofit are the ones that stop any single person from owning a payment end to end. In order of impact: segregation of duties, so the person who requests a payment is not the person who approves it or reconciles the bank statement; dual approval on every disbursement above a low threshold; and an independent review of the bank statement by someone who cannot move money, often a board treasurer. Each control targets the insider risk, the trusted person who can both create a payment and hide it.

The problem every small nonprofit hits is that pure segregation needs people it does not have. On a three-person team, the same person often requests, approves, and records, not out of negligence but out of headcount. That is not a reason to skip controls; it is the reason to add verification as a compensating control, covered below, so the payment itself cannot proceed unchecked even when one person touches all of it. The one-page control matrix in this guide maps each control against the two risks it does and does not cover, so a board can see at a glance where a gap remains.

- Segregation of duties: request, approval, and reconciliation sit with different people wherever headcount allows.
- Dual approval: a second authorized person must release any payment over a low, defined threshold.
- Independent reconciliation: someone who cannot initiate payments reviews the bank statement each month.
- Payee verification before release: the account being paid belongs to the vendor, grantee, or employee entitled to it.
- Named approver on record: every release is attributable to a specific person and provable afterward.

## Why audits miss it and tips catch it

The most common false comfort in the sector is that the annual audit will catch fraud. It usually will not. A financial-statement audit is designed to test whether the statements are materially accurate, not to hunt for fraud, and it examines a sample of transactions rather than all of them. A determined insider taking modest amounts below the materiality threshold, or spreading theft across many small payments, is exactly the pattern an audit is least likely to surface. Treating the audit as a fraud control is how boards end up surprised.

The data shows where fraud actually gets caught. ACFE’s 2026 study found that 43 percent of occupational frauds are detected by tips, far more than by audit, with a median scheme lasting 12 months before anyone catches it 1 . That points to two practical moves a nonprofit can make that an audit cannot: give staff and volunteers a real way to report concerns, and put controls at the moment of payment rather than relying on detection after the money is gone. A tip tells you fraud happened; a payment control stops it from happening. The board’s job is to fund the second, not just commission the first.

## The outside impostor: vendor and grantee payment fraud

The insider is only half the problem, and it is the half nonprofit guidance overwhelmingly focuses on. Nonprofits also pay vendors, contractors, and grantees, and every one of those payments is a target for the same impersonation that hits businesses. A spoofed email changes a vendor’s bank details before a payment run, or a fraudulent grantee-disbursement instruction reroutes program funds to an account no one verified. None of the internal segregation controls touch this, because the fraud is not an insider abusing access; it is an outsider wearing a trusted counterparty’s identity.

The scale of the external threat is set by business email compromise, which took $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH 2 , the rails nonprofits use for vendor and grantee payments. The same mechanics that drive losses in [public-trust payments](https://rankshieldfinancial.com/resources/school-district-vendor-payment-fraud/) at districts and municipalities apply to a nonprofit disbursing a grant: the payee’s banking details arrive by message, and whether the money reaches the real party depends entirely on whether anyone confirmed the change through an independent channel before release.

## Verification as the compensating control

When a finance office is too small to fully segregate duties, verification is the control that compensates for the missing headcount. Instead of relying on three separate people to check each other, you make the payment itself unable to proceed until the payee and the approval are confirmed. Any new or changed bank detail is verified out of band on a channel the requester did not provide, the first payment to new details is held until that confirmation lands, and a named person is on record approving it. That single discipline neutralizes both threats at once: the insider cannot quietly redirect a payment to themselves, and the impostor cannot pass a forged banking change.

This is increasingly the expected baseline, not just good practice. Nacha’s fraud-monitoring rules, whose second phase took effect on June 19, 2026 for all non-consumer ACH originators 4 , expect any organization originating ACH credits, nonprofits included, to screen for payments induced under false pretenses. A grant rerouted on a fake disbursement instruction, or a vendor payment sent on a spoofed bank change, is exactly that. Verification before release is how a small organization gets the protection of a much larger finance department without the headcount.

- Verify every new or changed bank detail out of band, on a contact you already had, not one supplied in the request.
- Confirm the account belongs to the vendor, grantee, or employee named, not just that a change was requested.
- Hold the first payment to new details until that confirmation is complete.
- Record a named approver, so a diverted payment can be traced and the control shown to the board and the auditor.

## The gate in front of a small nonprofit’s payments

Every control above works, and every one fails the same way: on a small team, under grant deadlines, when confirming a payment feels like bureaucracy the organization cannot afford. The durable version is structural. Before a payment is released, the payee is verified against the party entitled to it, a changed account is held until confirmed out of band, and a named approver is on record, so the finance office has evidence of the control and not just a policy on paper.

This is where RankShield Financial fits for nonprofit and grantee payments. It is a verification and attestation layer in the authorization path, not a bank or a payment processor, and it never takes custody of funds; your existing bank and rails still move the money. It holds a changed or unverified payee before a payment is released, requires proof that an authorized person approved it, and seals a signed, tamper-evident record of that decision that a board, an auditor, or a grantor can independently verify rather than take on faith. That shared signal compounds as members join, rather than claiming a scale we have not yet reached. The honest boundary: verification does not replace segregation of duties where you can staff it, or the [invoice controls](https://rankshieldfinancial.com/invoice-fraud-prevention/) your bookkeeper already runs; it makes the unsafe payment impossible to action casually and produces evidence of who approved what. If your organization runs payments on a small team and wants that gate, you can [see how it works](https://rankshieldfinancial.com/how-it-works/) or [request access](https://rankshieldfinancial.com/contact/).

## The change that protects donor money

If a nonprofit finance office takes one action after reading this, make every banking-detail change a verified event confirmed on a known channel, and hold the first payment to new details until that verification is done. That single procedure closes both doors: the insider who can no longer redirect a payment unchecked, and the impostor who can no longer pass a forged vendor or grantee change. The audit will still test your statements, the tip line will still catch what slips through, but neither stops the money from leaving the way a payment control does. The only question a board needs answered is whether a payment can leave this organization to an account nobody independently verified. If the answer is provably no, donor money reaches the mission instead of the fraud.
        Operate it
## Verify a payment before it settles

Compose a payment and the conditions around it, then run the same check the product runs on a live rail. The verdict comes back before the money would move.
      Pay to     Amount (USD)     Conditions around this payment      Bank details changed by email       First-time payee       Amount over approval policy       Approver signature verifies       PRE-SETTLEMENT VERDICT  RANKSHIELD NETWORK
Compose a payment on the left and run the check. The verdict is returned before the money moves, the way the product returns it on a live rail.

Sandbox demo · reproduces the product’s verdict logic and signing metadata · not a live network call
        Downloadable · SVG
Nonprofit payment fraud leaves through two doors, and most controls only close one. Segregation of duties, dual approval, and independent reconciliation catch the trusted insider but not the outside impostor; out-of-band verification catches the impostor but not the insider. The two controls that cover both are verifying the payee before release and recording a named approver, which is the compensating control a small finance office needs when it cannot fully separate duties.
      FAQ
## Frequently asked questions

Every question buyers ask before they trust a payment-security platform, answered directly.
           JAMIE KLONCZ · RANKSHIELD FINANCIAL           ONLINE
Pick a question on the left, or search above. You will get the direct answer, the way an answer engine would give it.
      REQUEST ACCESS →           Self-check
## How exposed are your payments?

Five controls decide whether an authorized-payment scam gets through on a fast rail. Answer them honestly to see where you stand.

- 01 Do you send payments on instant or same-day rails (RTP, FedNow, same-day ACH)?
- 02 Can one person both change a vendor’s bank details and approve the payment?
- 03 Do you always confirm a bank-detail change on a number from your own files, not the request?
- 04 Is the first payment to a new or changed payee held for verification before it goes out?
- 05 Do you keep a signed record of exactly who approved each payment?

Answer all five to see where you stand · 0/5
        References
- [ACFE, Occupational Fraud 2026 (nonprofits ~10% of cases, median $69,000; religious/charitable/social-services $76,000; 43% caught by tips; median 12 months to detect)](https://www.acfe.com/-/media/files/acfe/pdfs/rttn/2026/2026-report-to-the-nations.pdf)
- [FBI IC3, 2025 Internet Crime Report (BEC $3.046B; 86% via wire or ACH)](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
- [Association for Financial Professionals, 2026 AFP Payments Fraud and Control Survey](https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud)
- [Nacha, Risk Management Topics: Fraud Monitoring Phase 2 (effective June 19, 2026, all non-consumer originators)](https://www.nacha.org/rules/risk-management-topics-fraud-monitoring-phase-2)

         About the author
## [Jamie Kloncz](https://rankshieldfinancial.com/about/) Founder, RankShield Financial

Jamie founded RankShield Financial to verify a payment’s intent and authority before it settles on instant and tokenized rails. These guides are written from building that product and reading the primary sources directly: every statistic here links to its original filing or report, never a secondhand summary.

- Primary sources only: each figure links to the original filing
- Honest boundaries: what verification can and cannot do is stated plainly
- Last verified July 24, 2026

  How RankShield Financial verifies →  Request access →            Verify, then settle
## See your payments verified before they settle.

RankShield Financial is rolling out with design partners on instant and tokenized rails. Request access and we’ll map it to your settlement flow.
  Request access  How it works

## Frequently asked questions

### Why do nonprofits lose so much to payment fraud?

Because the controls that prevent it are the hardest thing for a small organization to staff. ACFE’s 2026 study puts the median occupational fraud loss for nonprofits at $69,000 per case, and at $76,000 for religious, charitable, and social-services organizations, which on a six-figure budget is a program rather than a line item. Small finance teams often cannot fully separate who requests, approves, and reconciles payments, so a single trusted person can both create a payment and conceal it. Add the outside impostor posing as a vendor or grantee, and a nonprofit faces both an insider and an external threat with fewer people to catch either. The fix is verification at the payment, which compensates for the missing headcount.

### What internal controls should a small nonprofit have?

Start with the controls that stop one person from owning a payment end to end: segregation of duties so the requester is not the approver or the reconciler, dual approval on every disbursement above a low threshold, and an independent monthly review of the bank statement by someone who cannot move money, often a board treasurer. Where a three-person team cannot fully separate those roles, add verification as a compensating control: confirm any new or changed bank detail out of band, hold the first payment to new details until confirmed, and record a named approver. Together these cover both the insider who abuses access and the outside impostor posing as a vendor or grantee.

### Will our annual audit catch fraud?

Usually not. A financial-statement audit is designed to test whether the statements are materially accurate, not to hunt for fraud, and it samples transactions rather than examining all of them. A determined insider taking amounts below the materiality threshold, or spreading theft across many small payments, is exactly what an audit is least likely to surface. ACFE’s 2026 data shows the real detection channel: 43 percent of occupational frauds are caught by tips, with a median 12 months before detection. Treat the audit as a check on your statements, not as a fraud control. The protection comes from controls at the moment of payment plus a genuine way for staff and volunteers to report concerns.

### Do nonprofits get targeted by vendor impersonation scams?

Yes, and it is the half of the problem most nonprofit guidance ignores. Nonprofits pay vendors, contractors, and grantees, and every one of those payments is a target for the same business email compromise that hits companies. A spoofed email changes a vendor’s bank details before a payment run, or a fraudulent grantee-disbursement instruction reroutes program funds. Business email compromise took $3.046 billion in 2025, with 86 percent of the money moving by wire or ACH, the rails nonprofits use. Internal segregation controls do nothing here, because the fraud is an outsider wearing a trusted counterparty’s identity. The defense is verifying the payee and any banking change out of band before release.

### What if we are too small to separate financial duties?

Then verification becomes your primary control. When you cannot rely on three separate people checking each other, you make the payment itself unable to proceed until the payee and the approval are confirmed. Verify any new or changed bank detail out of band on a channel the requester did not provide, hold the first payment to new details until that confirmation lands, and keep a named approver on record. This neutralizes both threats: the insider cannot quietly redirect a payment, and the impostor cannot pass a forged banking change. Nacha’s June 2026 fraud-monitoring rules now expect organizations originating ACH credits, nonprofits included, to screen for payments induced under false pretenses, which this approach satisfies.
