Facing Up to Fraud in the Flock
One out of three churches is defrauded. Nonprofits lose 5 percent of their revenue annually to embezzlement. What can be done?
We encourage congregations to trust – but verify – and protect themselves with bonding insurance.
Ministry Pacific Report: Facing Up to Fraud in the Flock
A practical guide to preventing internal fraud in houses of worship and nonprofit organizations.
You’ve probably heard the saying, “Charity begins at home.” Sadly, so does fraud. Financial fraud shares something in common with sexual misconduct: Organizations where these crimes take place usually believed “it can’t happen here.” Congregations and nonprofit boards often view their members and teams as people who share their wholehearted devotion and sacrifice to the cause. And nearly all the people do. But it only takes one individual to compromise the environment. Unfortunately, those people are well represented in the nonprofit world.
According to Church Procedures Audit, one out of every three churches experiences theft directly from its own ranks. That means financial misconduct is not an outlier, but an everyday risk confronting all congregations. A related statistic is that nonprofit organizations lose an average of five percent of their annual revenues to fraud. That adds up to billions of dollars siphoned from good causes.
Defining terms: What is fraud?
One word distinguishes fraud from other financial crimes: insider. A burglar breaks in. An embezzler has a key.
Fraud (also called embezzlement) is always an inside job. It’s when an organization’s finances are manipulated to provide personal gain for an employee, board member or volunteer. It can mean doctoring financial reports and expense accounts, opening unauthorized credit and bank accounts and more. It usually takes place slowly – often over a period of years – to avoid detection. Individuals can only defraud if they possess insider access and knowledge.
Did you know?
A common mistake is assuming internal theft occurs only when money is being collected. Nonprofit leaders and pastors naturally focus concern on the intake of funds during Sunday offerings, capital pledge drives or retail sales. They’re right to do this. But fraud is both incoming and outgoing. While someone may find a way to skim church offerings, an equal or greater opportunity is on the expenditure side. This includes bogus reimbursement requests, personal use of an official credit card or checks to fake vendors. Good money managers must guard the entrance and the exit.
The vulnerability paradox
Organizations established to do good are frequently victimized by their own people. How’s that? Men and women who serve in churches and charities are there to advance noble causes. This is a strength and a weakness. Why? This disposition does not lend itself toward internal scrutiny of finances.
The corporate world is much less idealistic. As a result, transactions are governed by internal controls, independent cross-checks and segregation of duties. Of course, corporate fraud still happens. In addition, small businesses – with less sophisticated accounting systems – are often compromised.
The native trust in the nonprofit world, however, can cause common safeguards to be ignored, bypassed or dismissed as unnecessary bureaucracy. Ministry leaders may feel that requiring receipts, demanding secondary signatures or auditing cash counts implies an unholy suspicion of their fellow believers.
Beyond the trust factor is the reality of lean resources. If only one person is willing to stay after a Sunday service to count the cash offerings, that individual is handed the task out of necessity. Or a church may rely on a single volunteer bookkeeper. In both instances, a dangerous single point of oversight is created. If only one domino must fall, there are no external deterrents to theft.
Even when resources exist, relational familiarity can undermine operational discipline. Inherent trust can become a substitute for administrative accountability. In reality, a valuable team member would welcome – and even ask for – accountability.
“Embezzlement by trusted church workers almost never starts as a cold-blooded, premeditated plot to rob the church of hundreds of thousands of dollars. ”
Rather, it begins as a small compromise that can be rationalized. A volunteer handling cash may face an urgent personal dilemma such as an overdue utility bill, an unexpected car repair, or a family medical bill. It’s easy to rationalize that no one will miss a mere $50 – and of course it’ll be paid back. But once that boundary is crossed, repayment rarely happens. The initial compromise is repeated, grows in magnitude and can snowball into a systemic, multi-year theft of catastrophic proportions.
The math of fraud
Jonathan Chang, an elder at a Bay Area California church, was sentenced to 48 months in prison for stealing more than $7.5 million from the church over a 12-year period.
Inside the head of an embezzler
When leaders learn of a theft within their ranks, their initial reaction is almost always total bewilderment. They struggle to comprehend why someone who appeared deeply committed to the cause would betray it. To explain the web of human motivations that drive insider deception, investigators and finance professionals have developed a theory expressed in the acronym MICE. It stands for Money, Ideology, Coercion and Ego.
While money is front and center, it would be overly simplistic to characterize this desire as simple greed. Within houses of worship and charities, the financial driver is often rooted in personal panic and financial desperation. A trusted bookkeeper may be drowning in unpayable medical debts, facing foreclosure or some other emergency. In their distress, embezzlers rationalize the diversion of funds as a private, justifiable survival measure rather than criminal theft.
Ego represents another often-overlooked motivator that mirrors dynamics observed in espionage. Embezzlers may harbor a deep-seated belief that they’re intellectually superior to the leaders around them. It’s satisfying to think that nobody is smart enough to catch them. In other instances, ego manifests as wounded pride. An employee or volunteer who has spent years working long hours for minimal pay or recognition may feel unappreciated and exploited. They view theft as fair compensation the church rightfully owes them for their sacrifices.
Ideology and coercion are also factors. Ideological motivation occurs when an individual convinces himself that church leadership is mismanaging sacred funds or allocating money to the wrong programs. He feels morally justified in redirecting those funds toward projects, individuals, or charitable causes that he deems more worthy. Coercion involves situations where external pressures – such as predatory loans, personal blackmail or other outside demands – make an insider desperate enough to exploit their access to institutional funds.
What does an embezzler look like?
Unfortunately, they have no tells (as in facial or physical expressions that betrays their actions). They don’t stand out. Perpetrators are regular, respected members of the flock. They may be tenured office administrators, longtime ministry directors – even 72-year-old grandmothers. As a result, leadership must never rely on personal impressions as a substitute for internal controls.
First lines of defense
Preventing most fraud does not require pastors and board members to master complex accounting principles. When accounting firms review fraud cases, they find time and again that the theft could have been prevented by basic controls. What are these?
The first indispensable safeguard is the two-person cash counting rule. Under no circumstances should a single individual ever be permitted to collect, handle or count cash offerings alone. Mandating that two unrelated individuals be present throughout the entire collection and counting process minimizes the opportunity for an individual to steal. Beyond preventing theft, a team approach can correct innocent counting errors.
The second essential is regular administrative review of monthly bank statements. A member of executive leadership – such as the senior pastor, board chairman or treasurer – must personally review these documents. This means examining transfers and payments and asking questions when necessary. If everyone understands that statements will be reviewed, that alone is a deterrent to fraud.
The third requirement is independent oversight and approval of payments and reimbursements. Organizations need strict policies requiring every expense claim to be accompanied by an itemized receipt that clearly indicates the purchase’s identity, date and purpose. Receipts should be individually reviewed before approval. This oversight – along with being responsible leadership – is another deterrent to fraud.
In addition, all volunteers and employees who work with finances must be screened and trained. Leaders must make time to know these individuals and grant access accordingly. Clear, written instructions should guide financial processes.
Under no circumstance should any single employee or volunteer be granted total, end-to-end control over an entire financial cycle. That’s an invitation to disaster. Financial tasks must be divided among multiple individuals so that no single person possesses the unchecked authority to execute and conceal a transaction.
“Inspect what you expect” is common leadership teaching. It applies here. Houses of worship must maintain up-to-date financial records and conduct monthly, rather than quarterly, administrative reviews. When a church relies on an overburdened volunteer who falls six months behind on bookkeeping, it becomes vulnerable. Attempting to review records on a delayed, catch-up schedule buries critical details beneath months of accumulated paperwork, making it nearly impossible to spot discrepancies. Monthly recordkeeping and reconciliations ensure that unusual transactions, unauthorized withdrawals or missing deposits are identified and investigated immediately.
Overcoming cultural resistance
While implementing basic internal controls appears straightforward, structural change within faith communities and volunteer-driven nonprofits is usually challenging. Unlike corporations where an executive can simply issue an order, churches operate within a sensitive relational ecosystem. In ministry life, issuing abrupt demands can hurt feelings, spark conflict and drive volunteers away.
When a volunteer who has faithfully counted offering money alone for five years is suddenly told that a second person will now join the count, he may feel insulted and wonder if he’s suspected of dishonesty. The key is to communicate that changes are not about individuals, but building a better, more accountable system. Internal safeguards are like the seatbelt in an automobile. Ninety percent of the time, fastening a seatbelt feels like an unnecessary, restrictive annoyance. But in the rare, sudden moment of a collision, seatbelts saves lives. While financial controls may feel like an inconvenience, knowing they prevent disruption makes them worthwhile.
Florida church faces $500,000 loss
A Florida church financial secretary was ordered to repay more than $500,000 she stole from her congregation over five years. Low bank balances raised eyebrows and led investigators to discover hundreds of thousands of dollars in personal expenses charged for personal use.
Procedural changes are more likely to succeed if they are overtly championed by executive leadership. If pastors leave financial reforms entirely to the church bookkeeper or accounting committee, volunteers will easily dismiss the new policies as the nitpicking of an overly rigid bean counter.
It’s also important for leaders to note that financial safeguards provide personal protection for the volunteers themselves. If a solo counter records $400 when $500 was expected, suspicion immediately falls on him. But if two people perform the count together, miscounts are caught and corrected, shielding the volunteer from suspicion.
Another point of persuasion is the solemn responsibility to guard dollars donated to faith-based causes. Donors sacrifice their personal earnings with the sacred trust that leadership will guard those funds with integrity. When financial controls are elevated from bureaucratic red tape to a noble act of stewardship, volunteers and staff can more readily embrace the changes.
If policy changes are carefully explained and thoughtfully enacted, most people will sign on. Beware of anyone who adamantly resists reasonable changes. If they are not willing to comply, they should be reassigned to non-financial duties.
The severe impact of inadequate oversight
Examples of nonprofit embezzlement are not difficult to find. One incident from Jitasa’s casefiles involves a nonprofit whose bookkeeper had been a tenured, highly respected employee for 14 years. Over her tenure, the organization developed complete trust in her, gradually granting her total, unchecked control over the entire accounting cycle – including a store that generated roughly half a million dollars in annual sales. Because the bookkeeper was deeply trusted, she was permitted to configure the sales software, control the transaction records, process customer payments and perform the monthly bank reconciliations with virtually zero independent oversight.
Exploiting this complete lack of checks and balances, the bookkeeper discovered an operational loophole: credit card transactions processed through American Express followed a slightly different settlement pathway than transactions processed through Visa or MasterCard. Capitalizing on this, she created a secret, unauthorized bank account in the organization's name to which all American Express proceeds were automatically directed. Once every month, she logged in and transferred the accumulated funds from this hidden account directly into her personal checking account. Because she alone reconciled the bank statements and compiled the board financial reports, no one in leadership ever knew the revenue was missing.
The scheme unravelled only when the organization engaged Jitasa to assume management of their bookkeeping. As Jitasa's accounting team took on the client and audited financial workflows, they traced the retail store's sales records and noticed that American Express transactions were conspicuously missing from the primary operating bank accounts. Investigating further, they uncovered the secret account. An audit covering merely the preceding two years revealed that the bookkeeper had siphoned away more than $200,000 for her personal use. Because the employee held unchecked control for 14 years, the total amount stolen was likely higher.
The organization turned the evidence over to law enforcement and the bookkeeper was criminally prosecuted. When questioned, she revealed her motivation was not lavish greed, but personal medical debts. As is usually the case in these matters, the financial loss was only a fraction of the damage. The discovery shattered the organization, caused emotional trauma and feelings of betrayal.
Other examples:
A board member of a New York church was accused of stealing more than $3.8 million from his congregation. The state alleges he directed funds into a secret account and doctored church financial reports to cover his tracks.
A Georgia United Methodist Church closed after its administrator was arrested for diverting more than $500,000 for personal use.
A former pastor of an AME Zion church pled guilty to taking more than $500,000 for personal use, including expenditures on firearms and gambling. Core to the deception was a bank account titled “administrative expenses” with the pastor as the exclusive signer.
Accounting options: in-house versus outsourcing
Most faith communities rely upon a traditional in-house structure consisting of a lone paid bookkeeper, a part-time financial administrator, or an unpaid volunteer treasurer. While this model appears cost-effective, it introduces risks. Relying solely on an internal individual can create a single point of operational failure.
Partnering with a specialized third-party nonprofit accounting firm can provide safeguards that an internal worker cannot duplicate. Reputable third-party accounting firms’ workflows are governed by rigorous external audits. An outsourced firm assigns a dedicated team of accounting professionals to every client. Work completed by one professional is reviewed by another.
When evaluating the financial break-even point between in-house staffing and outsourced accounting, leadership should look beyond simple hourly wages. A true cost comparison must factor in the total burden of an internal employee, including employer payroll taxes, healthcare coverage, retirement contributions, software licensing fees, paid time off and leadership’s oversight responsibilities. When all costs are calculated, outsourcing frequently proves more economical. This can be true of organizations both small and large.
The primary limitation of an outsourced arrangement is that services are strictly governed by a contract. When unexpected administrative tasks arise, an internal employee or volunteer can absorb the extra duties without additional expense. An accounting firm, however, may charge additional fees for out-of-scope work.
Evolving risks
While digital giving is common and popular, paper checks and cash are still common instruments of giving. This puts organizations in the challenging role of guarding “all the above.” While digital giving reduces the low-hanging fruit of pocketing cash, digital evolution has simply modernized embezzlement. In place of physical theft, churches now face sophisticated cyber fraud, payment card compromise, identity theft, ledger manipulations and the digital diversion of revenue. Fraud frequently occurs via the misappropriation of funds. This may not be as overtly malicious as it sounds. For example, if an organization collects contributions specifically designated for a capital building project, but quietly diverts the money into the general operating account to cover payroll deficits, fraud has occurred.
Online giving portals and accounting software are not self-policing systems. Technology only protects an organization when it is properly configured, maintained and reviewed. Without active human oversight, digital systems merely enable tech-savvy thieves to steal with greater speed and efficiency.
Which records to retain?
A related challenge is determining appropriate record retention standards. Leaders often wonder whether it is possible to maintain too much documentation by preserving duplicate physical and digital records. Regardless, documentation is only beneficial if leadership actively reviews it. Storing mountains of unorganized documents creates an overwhelming, mess that makes it easier for fraud to stay hidden.
Instead, organizations should establish a single, well-organized source of records (digital is ideal). While maintaining a physical backup is sound, it should also be organized and indexed. A purge of backups can be scheduled every five years.
Is there an insurance solution?
Even with internal controls and dedicated oversight, the risk of insider deception cannot be completely eliminated. Determined, dishonest individuals with inside knowledge can still find ways to game the system. To protect against losses of trust and resources, houses of worship and nonprofits can purchase financial bonding insurance. It’s a specialized form of liability insurance that protects organizations against losses from embezzlement.
Because employee theft frequently compounds over several years, accumulated losses routinely reach $100,000 or more. A few cases have resulted in more than $1 million stolen. Without financial bonding coverage, an organization may have to absorb all of these losses. If the embezzler is caught, repayment may be mandated as part of a court judgment. However, this is no guarantee: The money may be unrecoverable (already spent). Although bonding insurance can’t remove the loss of trust incurred by the theft, it can reduce the financial burden.
Embezzlement liability coverage, however, does not enable an organization to free itself from concern about financial oversight. An insurance policy is a legal contract. Bonding insurance is not an unconditional guarantee. An insurance claim will only be honored if the insured ministry complies with the policy's terms.
The first requirement is that the church or nonprofit must press criminal charges when embezzlement is discovered. In faith communities, leadership often feels a deep spiritual impulse to extend grace, forgive the offender, and quietly handle the matter internally. In the congregation’s view, this may be the best course of action. It’s certainly their right. But an insurance company will not issue a settlement without criminal charges being filed. If a congregation is conflicted about filing charges, it leaves them with a difficult choice.
Beyond this, bonding insurance operates by the principle of trust, but verify. Policyholders must demonstrate they are practicing financial controls such as dual cash counts, independent bank reconciliations and executive expense reviews.
Taking action: What’s your next step?
Protecting houses of worship and nonprofit organizations from internal fraud is not a cynical exercise in paranoia. It’s also not an unethical expression of distrust toward others. Rather, it’s evidence of leadership and personal responsibility.
We encourage you to note ideas for action and to promptly bring them to the attention of decision makers and leaders.
Some organizations may participate in group insurance plans that include some form of financial bonding insurance. While this is a good first step, insurance works best when it is customized for each organization and its unique risk profile. Annual consultation with a broker is advised to make sure the coverage level is appropriate.
Risk profile checklist
To assist in your review, here are common questions insurers ask applicants for financial bonding insurance:
Are bank accounts reconciled by someone who is not authorized to deposit or withdraw?
Is a secondary signature of checks required? If not, who is the signatory?
Are donated securities subject to joint control of two or more employees or volunteer leaders?
Are all officers and employees required to take annual vacations of at least five consecutive business days? (This is recommended to prevent one person form continually accessing finances.)
Is there a written policy regarding electronic fund transfers?
What is the largest single amount that can be transferred?
Do fund transfers require more than one person to authorize them?
Are hard copies of fund transfer confirmations received and reconciled?
What is the frequency of deposits?
Are detailed records of bank deposits made?
Are audits performed by a CPA?
At what frequency are audits completed?
Who reviews the completed audits?
Is the audit made in accordance with generally accepted auditing standards and certified?
Are new hires subject to background checks?
Are payroll systems audited annually to detect fraud from “ghost” employees?
Is a physical inventory made of church property?
Our subject matter expert: Christian Spearow of Jitasa
This guide from Ministry Pacific is based on a webinar interview with Christian Spearow, Senior Vice President of Sales at Jitasa, one of the nation’s leading accounting and bookkeeping firms for nonprofit organizations. A graduate of the University of Idaho, Christian has extensive experience in all aspects nonprofit accounting. At Jitasa, his responsibilities have included managing client accounting teams, serving as General Manager of Operations, and participating in hundreds of nonprofit financial audits.
Get information about protecting your congregation from financial fraud.
We’re pleased to provide a free consultation and answer your questions about fraud insurance. You can contact us through the form below or call us directly at 1.866.870.2700.
Facing Up to Fraud in the Flock: Interview with Christian Spearow of Jitasa
Christian Spearow is a vice president at Jitasa, the nation’s largest accounting firm exclusively serving nonprofit organizations.
AUDIO VERSION: FACING UP TO FRAUD IN THE FLOCK
Financial Bonding Insurance protects your church in the event of fraud-related losses
While creating a culture of accountability is the first line of defense, you may also want to consider a backup plan. If someone steals big sums from your church or ministry, you may not get any of it back. How will you cope? Financial bonding insurance can help churches and nonprofits recoup financial losses that result from criminal activity. An insurance payment won’t erase the memory or restore mistrust, but it can take the sting out of the financial and operating losses. That way you can focus on one problem at a time.