Quick answer: Fraud awareness means knowing the scams that target donor and grant funds: a faked executive-director email, a vendor’s changed bank details, or ACH account takeover. Your team also needs a written process designed to flag each one before money moves. A two-person team can’t watch every payment around the clock, so the fix combines dual approval, phone-verified bank changes, and automated monitoring that flags what a human might miss.
Key Takeaways
Why Are Nonprofits Specifically Targeted by Payment Fraud?
A nonprofit finance director in Des Moines usually runs a leaner operation than a similarly sized for-profit company. That’s not carelessness. Three factors make the structure a target:
- Public information. Staff names, board members, and program budgets are often listed on a website or a 990 filing, giving a scammer everything needed to write a convincing impersonation email.
- Concentrated approval. Payment authority often sits with one or two people, so there’s rarely a second set of eyes built into the everyday process.
- Grant-deadline pressure. Disbursement deadlines create the exact kind of urgency a fraud scheme depends on to push a payment through without a normal check.
What Does Payment Fraud Actually Look Like for a Nonprofit?
Most nonprofit payment fraud falls into a handful of repeatable patterns. Recognizing the pattern is more useful than memorizing a list of warning signs, because the same red flag (urgency, a changed bank detail, an off-channel request) shows up across all of them.
| Scheme | How It Shows Up | Red Flag |
|---|---|---|
| Business email compromise | An email that looks like it came from the executive director or board chair, asking for an urgent wire or ACH payment. | Pressure to skip the normal approval step “just this once.” |
| Vendor invoice fraud | A recurring supplier or grant sub-recipient emails new bank account details right before the next payment is due. | The bank change arrives by email only, with no phone call to confirm. |
| ACH account takeover | A fraudster compromises login credentials on a donor-giving platform, grant portal, or the organization’s own online banking. They then change the payout bank account on file, so the next scheduled deposit goes to the new account. | A deposit that normally lands on schedule doesn’t show up, or a login alert nobody recognizes. |
| Gift-card requests | A “leadership” text or email asks a staffer to buy gift cards for an event and send the redemption codes. | Any request to pay with gift cards instead of a normal payment method. |
What Internal Controls Actually Close the Gap for a Small Finance Team?
A two- or three-person finance team cannot add headcount every time a new fraud pattern shows up, so the controls that work best are the ones that fit inside the team that already exists.
- Separate who initiates a payment from who approves it, even if that means the executive director approves and the finance director initiates, or the other way around. Above a set dollar threshold, the same person should never do both. Approve through a verified channel, like a phone callback, not a reply on the same email thread that raised the request.
- Confirm any changed bank detail by phone, using a number already on file, never a number included in the email that requested the change.
- Set a rule that grant and donor-fund disbursements above a certain amount always get a second look before the payment is released, regardless of how familiar the vendor is.
- Write the process down. A one-page policy that a board treasurer or grant funder can review is worth more during an audit than an unwritten habit, even a good one.
- Have someone outside the initiate-and-approve chain, a board treasurer or an outside bookkeeper, independently review the bank statement and reconciliation every month. A two-person team can split initiating and approving, but it usually can’t also cover reconciliation on its own, so this outside check is what closes that gap.
- Let account-level monitoring catch what the team can’t watch around the clock. A dual-approval policy stops a colleague from acting alone, but it does not stop unusual account activity outside business hours. On Zil Money, that gap is covered by ACH transaction monitoring that restricts a transaction lacking normal documentation, plus an account-level score that can block activity automatically if repeated irregular entries push it past a threshold.
Iowa nonprofits can also file a report with the Iowa Attorney General’s Consumer Protection Division, in addition to their bank and payments platform, if a payment fraud attempt succeeds.
See What Zil Money’s Fraud Controls Actually Do
Account verification, transaction monitoring, and an automated fraud-score system work alongside your own approval policy.
What Should You Do in the First Hour If You Suspect a Payment Was Fraudulent?
- Stop any related pending payment immediately, including recurring payments to the same account. At the same time, lock down the login that was used: reset the password and revoke access if credentials may be compromised.
- Call your bank’s fraud line and your payments platform’s incident line. Do this by phone, not email, since email is often how the fraud started. For an ACH payment, a reversal can sometimes be requested if the funds are still in the receiving account, though it isn’t guaranteed. A completed wire is generally final once the receiving bank has credited it, and recovery from there depends entirely on that bank’s cooperation.
- Write down the timeline while it’s fresh: when the request arrived, who approved it, and what looked normal at the time. A board or auditor will ask for this later.
- File a report with local law enforcement and, for wire or ACH fraud, the FBI’s Internet Crime Complaint Center at ic3.gov.
- Tell your board or executive director the same day, not after the fact. Disclosing quickly is generally viewed more favorably by funders than a delayed or quiet fix.
A nonprofit’s operating account is a business account, not a personal one, so the consumer protections and error-resolution timelines that apply to personal bank accounts do not automatically extend to it. Check with your bank about the specific recovery options and deadlines that apply to your account.
Fewer logins means fewer places for a scammer to slip in a fake bank change. That’s the case for consolidating ACH and direct-deposit payments in one wallet instead of a mix of manual logins, and for routine bill payments too: a team that can automate recurring vendor and bill payments in one place has fewer places for a scammer to hide a fraudulent change.
Frequently Asked Questions
What does “fraud awareness” mean for a nonprofit finance team?
It means knowing the specific payment scams your organization is likely to see, such as business email compromise or vendor invoice fraud, and having a written approval process designed to catch each one before a payment goes out.
Why do nonprofits get targeted more than other small organizations?
Staff names, board members, and program budgets are often public on a website or a 990 filing, and approval usually sits with one or two people. Both make it easier for a scammer to write a convincing impersonation email and easier for it to slip through.
What if a fraudster gets into a staffer’s own payments-platform login instead of email?
Treat that login like any other financial account: use a unique password, turn on multi-factor authentication if it’s offered, and set up login alerts. Zil Money only emails from support@zilmoney.com, so contact support directly and change the password right away if a login looks compromised.
What should you do if a vendor’s bank details change?
Treat any changed bank detail as unverified until it’s confirmed by phone on a number you already had on file. Vendor invoice fraud almost always arrives by email only, with a new account number and no way to call and check.
Is dual approval enough to stop payment fraud on its own?
Not entirely. Dual approval stops one person from acting alone, but it depends on the approver actually looking closely rather than rubber-stamping. Pairing it with account-level transaction monitoring covers unusual activity a human approver might not catch, like activity outside business hours.
Who should review payment approvals if a nonprofit only has two finance staff?
The executive director or a board treasurer can serve as the second reviewer for payments above a set threshold, even without a dedicated compliance role. The point is a genuinely different person, not a second signature from the same desk.
What should a finance director have ready for a grant funder’s fraud-control questions?
A short, written policy covering who can initiate and approve a payment, how a changed bank detail gets verified, and what happens in the first hour after a suspected fraud event. Funders increasingly ask for this in writing.
What’s the first step if a payment already went to a fraudulent account?
Call your bank’s fraud line and your payments platform’s incident line right away, by phone rather than email. Acting within the first hour gives the best chance of stopping or reversing the payment before funds are picked up.
None of this needs more headcount. It needs a callback habit, one written policy, and a platform that’s awake when your finance director isn’t.
Zil Money is a financial technology company, not a bank. Banking and money movement services are provided through partner financial institutions and licensed service providers. FDIC insurance coverage applies only to eligible deposit products and accounts, and is subject to applicable terms, conditions, limitations, and requirements. Additional information regarding partner institutions, products, and services is available in the applicable terms and agreements.

