
The Top Findings We See in Not-for-Profit Audits
Year after year, the same handful of issues show up in not-for-profit audit reports. CFOs, executive directors, accountants, and grant managers don't need to be caught off guard by them. Below are the five findings we encounter most often, along with the practical steps that keep them off your next audit list.
Segregation of Duties Weaknesses
Many not-for-profits run lean on administrative staff, so more resources can go toward the mission. That's admirable, but it often means controls and segregation of duties take a back seat.
Building in proper review and approval steps goes a long way toward a strong control environment that prevents, and catches, both errors and fraud. Start by mapping your processes and asking:
Is there a step where someone currently uninvolved could add a layer of review?
As a rule of thumb, avoid letting one employee initiate, record, and reconcile the same transaction. If staff bandwidth is tight, look to your board; qualified members can often step in to provide the compensating controls a small staff can't offer alone.
Make control review an annual habit, not a one-time project, and revisit segregation of duties any time there's staff turnover.
Revenue Recognition
Not-for-profits follow uniquely complex GAAP rules for revenue recognition. Donor restrictions, conditional contributions, and the timing of grant notices all introduce complexity and are common sources of audit adjustments. To complicate matters further, development offices sometimes recognize donations on a different timeline than accounting rules require.
A few habits can help. First, make sure both management and accounting staff stay current on revenue recognition rules. Second, when there's ambiguity, go back to the donor: clarifying their intent creates a paper trail that makes the audit process smoother for everyone. Finally, having a trusted advisor to consult throughout the year, not just at audit time, helps ensure the right guidance is applied as situations arise, and builds your team's own capability over time.
Tracking of Net Assets
Donor-restricted contributions require careful tracking, and this is where many not-for-profits fall short. Audits frequently turn up thin documentation of the specific purpose behind restricted net assets, which not only creates findings, but leaves organizations unsure when they can actually release those funds.
Because donor restrictions can be time-based, purpose-based, or both, it's essential to have a consistent method for tracking and documenting each one, and to ask donors clarifying questions up front so their intent is clear from the start.
Some organizations track restrictions directly in their accounting system; others use a separate spreadsheet. There's no single right approach; what matters is choosing a methodology and applying it consistently.
Lack of Paper Trail
Solid documentation is the backbone of a smooth audit, but the way organizations organize their support files varies widely, and inconsistent filing is a frequent source of findings.
With most records now digital, a clear policy for organizing and retaining files is essential. Cloud storage and AI-powered search tools can now do much of the heavy lifting, reducing the burden on staff to manually track everything down.
But the best system only works if the right information actually makes it in. Tagging and access controls make it easier than ever to store relevant files securely, so there's little reason not to keep documentation complete and organized for auditors, donors, and, for federal fund recipients, government reviewers alike.
Retention policy matters too. Since cloud storage costs scale with volume, decide deliberately what needs to be kept permanently and what can eventually be purged.
IT and Cybersecurity Issues
For many not-for-profit organizations, a dedicated IT budget is a luxury. That often means someone with an already full plate is also managing technology, leaving gaps that create real risk: unauthorized access, weak backup procedures, missing multi-factor authentication, and other vulnerabilities that can put operations, donor data, and employee information at risk.
Cost-effective steps can still meaningfully reduce that risk: cybersecurity coverage, annual risk assessments, and periodic IT health check-ups all help surface weaknesses before they become incidents.
Don't overlook the human element, either. Cyber risk runs the gamut, from something as simple as an employee clicking on an unfamiliar link to increasingly sophisticated schemes, like an AI-generated impersonation of a leader within the organization, a tactic that's becoming more common and harder to detect. Ongoing training and awareness are what turn employees into your first line of defense rather than your biggest vulnerability.
How CSH Can Help with Not-for-Profit Audits
These five issues share a common thread: they're all preventable with the right processes in place before audit season arrives. Clark Schaefer Hackett works with not-for-profit leaders year-round, not just at audit time, to strengthen controls, clarify revenue recognition and net asset tracking, organize documentation, and assess cybersecurity risk. Whether you need a one-time controls assessment, a cybersecurity health check-up, or an ongoing advisor to call on as questions arise, our not-for-profit team is ready to help you stay audit-ready and focused on your mission.
Ready to get ahead of your next audit?
Contact CSH today to schedule a controls review or cybersecurity risk assessment tailored to your organization.



