Skip to content
Back to SOP Resources

Risk & Control Matrix

Your comprehensive control framework at a glance

A consolidated view of all risks and controls across your nonprofit's accounting operations, providing transparency, accountability, and audit readiness.

Understanding Your Control Environment

This matrix consolidates all documented risks and their corresponding controls from your 22 Standard Operating Procedures. Each risk/control pair is linked back to the source SOP(s), creating a transparent and traceable control framework.

Identify Gaps

Spot areas where controls may be missing or need strengthening across your processes.

Audit Readiness

Demonstrate your control environment to auditors with clear documentation and traceability.

Risk Mitigation

See which SOPs address each specific risk and ensure comprehensive coverage.

How to Use This Matrix

  • •Search: Find specific risks or controls using the search bar
  • •Filter: View risks by category (Financial Reporting, Cash Management, etc.)
  • •Navigate: Click on SOP badges to view the full procedure documentation
  • •Review: Use the metrics above the table to understand your control coverage
Showing 118 of 118 risk/control pairs
118
Total Risk/Control Pairs
5
Risk Categories
22
SOPs with Controls
1
Avg SOPs per Risk
RiskControlCategoryRelated SOPs
Delayed responses, audit noncompliance, missed vendor paymentsShared inbox is reviewed daily and categorized by function; all requests have defined response timeframes based on priority levelVendor Management
Duplicate, misclassified, or unpaid invoices; cash flow disruptionInvoices routed promptly and uploaded to payment system with initial coding and review checkpointsVendor Management
Incomplete, incorrect, or delayed audit responses; reputational and compliance exposureAll audit-related emails are flagged and routed to senior finance staff; supporting documentation is sourced from controlled locationsVendor Management
Missed deadlines or noncompliant filings; impact on program fundingInbox monitoring and direct routing to compliance program process owners with internal backup supportVendor Management
Unaddressed inquiries leading to delays in payments, audit breakdowns, or operational frictionAll unresolved items are logged in a standardized tracker and reviewed daily; aging requests are escalated within 48 hoursVendor Management
Missed or duplicate invoices; vendor service delays or reputational issuesAll invoices received are reviewed daily and logged/uploaded to the AP system with duplicates flagged for removalVendor Management
Incomplete or incorrect invoice data entry may result in late or over/under paymentsRequired fields are reviewed and invoice images attached before submission for approvalVendor Management
Improper coding can misstate financials and impair grant reportingAll invoice lines are coded to accounting system-integrated fields and reviewed by AP and Finance before syncVendor Management
Payments made without proper authorization; potential fraud or policy violationsAll invoices require assigned approvers before payment is scheduled; dual approval enforced for high-value or project-specific itemsVendor Management
Missed syncs lead to incomplete liability recognition in the general ledgerSync status monitored weekly; AP confirms invoice appears in GL before closeVendor Management
Inconsistent or missing AP data may impact cash flow planning or create missed paymentsAP summary is reconciled to open bills in the AP system and reflected in weekly cash forecastVendor Management
Carrying forward outdated cash data can distort cash position visibilityFresh copy created weekly using fixed structure; starting balance is pulled from verified bank feedFinancial Reporting
Missing open bills can lead to understated cash needs; duplicating invoices may cause overestimationCash flow forecast is reconciled to current accounts payable system open payables weeklyFinancial Reporting
Inaccurate cash timing may result in overdrafts, missed payments, or loss of funding controlsForecast categorized by payment type and reviewed before payment release each weekFinancial Reporting
Lack of real-time cash visibility may cause missed obligations or failed paymentsWeekly cash balance check ensures sufficient funds are available before payments proceedFinancial Reporting
Uncommunicated changes in cash flow may result in uncoordinated payments or missed issuesFinal cash flow forecast is saved, distributed, and archived weeklyFinancial Reporting
Misidentifying deposits may result in incorrect revenue classification or missing restricted designationsAll revenue deposits are tied to backup documentation and logged with source attribution before entryFinancial Reporting
Improper coding of revenue can distort program financials or violate donor restrictionsRevenue entries are matched to donor records and source documents are tagged with appropriate class/account; Senior Accountant or Controller reviews and approves all entries before posting to the general ledgerFinancial Reporting
Net deposits without fee breakout may understate income and overstate expensesWeekly payment processor entries are recorded gross, with fees posted separately for transparencyFinancial Reporting
Misapplied pledge payments can overstate revenue or misalign receivablesPledge receipts are reviewed and matched to customer balances weeklyFinancial Reporting
Incorrect or late time entry may result in inaccurate payroll or grant allocation errorsThe payroll system requires employee submission before approval workflow beginsPayroll & HR
Unapproved or improperly approved timesheets could result in unallowable payroll chargesThe payroll system prevents finalization of payroll until all required approvals are completePayroll & HR
Outdated allocation file leads to incorrect payroll reviews and grant compliance violationsQuarterly review of file accuracy and formal approval process for changesPayroll & HR
Charging inappropriate hours to grants may create audit compliance issuesAllocation review is tied to Master Allocation File and sensitive-time policy reviewPayroll & HR
Incorrect employee setup may cause payroll errors or misallocation of expensesAll employee changes require documented HR approval before system updatesPayroll & HR
Payroll may be processed based on unapproved or incorrect dataCorrections cannot be processed until approval workflow is re-completedPayroll & HR
Incorrect amounts processed may impact employee satisfaction and complianceSystem reports and pre-processing audit are reviewed before submissionPayroll & HR
Missing documentation reduces audit readinessAll payroll support is archived immediately after payroll runPayroll & HR
One-off exceptions may bypass standard allocations and cause misreported costsExceptions require Controller review before payroll is finalizedPayroll & HR
Incorrect grant reporting may lead to disallowed costs or loss of fundingMonthly review ties spend to approved budget and grant agreementGrant Management
Charging unallowable payroll hours creates compliance exposure and potential repaymentAllocation review compares Master Allocation expectations to timecard activity and grant rulesGrant Management
Miscoded expenses may distort reporting or cause billings to be incomplete or inaccurateMonthly reconciliation covers all expense types, not payroll aloneGrant Management
Missing or incomplete reconciliation weakens grant reporting and auditsWorkbook ties directly to general ledger, payroll summaries, and allocation fileGrant Management
Submitting unsupported or incorrect reports may jeopardize fundingAll reports include general ledger tie-outs, payroll detail, and controlled documentationGrant Management
Improper document storage leads to repeated requests and audit delaysAll grant support is centrally organized and version-controlledGrant Management
Budget errors or omissions may lead to funding shortfalls or rejected proposalsAll grant budgets are based on standardized templates and pulled from verified cost dataGrant Management
Misalignment between budget and program scope may cause downstream compliance issuesEach draft is jointly reviewed with program and development staff before submissionGrant Management
Submitting unapproved budgets may expose organization to compliance risk or inaccurate reportingNo budget is submitted externally without internal approval from Controller or Finance DirectorGrant Management
Entry discrepancies between Excel version and system entry may result in funding mismatchBudget entry is cross-checked against approved file and archived with submission evidenceGrant Management
Lack of documentation may make it difficult to track assumptions or reconcile future changesEach budget is logged and archived with standardized file structure and namingGrant Management
Inaccurate allocations may result in noncompliant labor charges or audit disallowanceTimekeeping system enforces timecard entry and supervisor sign-off prior to payroll processingGrant Management
Misalignment between timecard data and reported allocations may result in under- or over-reportingAllocation reports are archived and reviewed post-payroll before grant cost applicationGrant Management
Missing signatures or incomplete timecards may lead to questioned costs during auditSigned timecards are required monthly and stored centrally for all grant-funded staffGrant Management
Variances between documentation sources may indicate incorrect charging or accounting errorsPayroll allocations are reconciled across all documents (timecard, stub, journal entry) each cycleGrant Management
Incomplete or disorganized audit documentation may lead to disallowed costsSupport packets are assembled per grantor specifications and stored in structured foldersGrant Management
Invoices processed without appropriate signoff may result in unauthorized disbursements or compliance violationsApproval routing logic is embedded in AP system and verified during entryVendor Management
Delays in approval may stall payments, damage vendor relationships, or misalign with cash flowWeekly AP review includes aging analysis of unapproved invoices; escalation to Finance Director if neededVendor Management
Lack of documented approval may result in audit findings or failed internal controlsEvery invoice payment is tied to an AP system approval log or attached manual approvalVendor Management
Payment without final approval exposes organization to legal or reputational riskWeekly payment prep includes final review of approval trail for every invoiceVendor Management
Failure to log or track checks may lead to lost revenue or inaccurate donor recordsEvery physical check is logged, scanned, and backed up electronically upon receiptCash Management
Misapplied funds may create compliance issues or restricted fund misstatementAll designations are reviewed before deposit; sensitive funds are double-confirmedCash Management
Deposit errors or system failures may delay fund availability or lose documentationEach mobile deposit is backed by both a physical scan and a digital confirmation archived electronicallyCash Management
Unauthorized or undocumented disbursements may violate policy or create audit gapsTreasury payments require documented approval and system-confirmed trackingCash Management
Gaps between bank records and general ledger may result in missed income or inaccurate reportingAll treasury activity is reconciled monthly and documented in close folderCash Management
Unverified card syncs may introduce misclassified expenses or compliance issuesTransactions are synced only after full review of coding and receipt documentationFinancial Reporting
Missing syncs or timing lags may leave expenses off the books or duplicatedPost-sync reconciliation is performed monthly using system logs and expense reportsFinancial Reporting
Unclassified or misclassified deposits may distort revenue recognitionEach revenue item is tied to supporting docs and matched to receivables where applicableFinancial Reporting
Misclassified or unreviewed bank transactions may misstate program or administrative expensesEvery outgoing payment is manually classified with full context and backup cross-checkFinancial Reporting
Misaligned records across systems may result in audit flags or financial misstatementsAll synced and classified transactions are reconciled monthly as part of close processFinancial Reporting
Errors in payroll journal entries distort program cost reporting and grant allocationsAll payroll journal entries are supported by payroll system reports and reviewed by accounting leadershipFinancial Reporting
Sensitive or unallowable payroll charges may lead to questioned grant costsAllocation adjustments are documented and approved before the accrual processFinancial Reporting
Missing accruals understate expenses and misrepresent restricted vs unrestricted balancesAccrual is recalculated monthly and ties to payroll reports and allocation fileFinancial Reporting
Misclassification of special payroll items may distort program costs or violate grant restrictionsAll special items must be approved by Controller before postingFinancial Reporting
Not reversing accruals causes duplicated expense recognitionAutomated reminder in monthly close checklist ensures reversal is completedFinancial Reporting
Unreconciled differences undermine audit support and allocation accuracyMonthly tie-out is required before close is approvedFinancial Reporting
Delayed retrieval may lead to missed reconciliation deadlinesAll statements are saved by Day 2 of close cycleFinancial Reporting
Using outdated GL balance may cause inaccurate variance analysisExport date is always matched to bank statement end dateFinancial Reporting
Unexplained variances may mask errors or fraudAll differences must be fully explained and documentedFinancial Reporting
Unsupported reconciling items weaken audit trail and internal controlAll backup is stored with consistent naming in a central locationFinancial Reporting
Lack of oversight may result in uncorrected errors or stale itemsDual review ensures reconciliations are timely, accurate, and completeFinancial Reporting
Failure to record prepaids correctly may overstate current period expensesAll large, multi-month payments are reviewed for deferral at AP entryFinancial Reporting
Missing amortization may understate expenses and overstate assetsPrepaid tracker is reviewed monthly and tied to actual journal entry postingsFinancial Reporting
Overstated or stale prepaid balances may distort net assets or cost allocationsPrepaids are fully reconciled to support schedule each periodFinancial Reporting
Retaining fully amortized balances may clutter reports or impact analysisClosed prepaids are archived and excluded from active amortization logicFinancial Reporting
Missing capitalizable purchases may overstate expenses and understate assetsAP and card reviews include a fixed-asset flag step for large or durable purchasesFinancial Reporting
Improper reclassifying may misstate capital assets or distort program costsReclass entries are supported by invoices and reviewed by senior accounting staffFinancial Reporting
Incomplete register leads to missing depreciation or audit support gapsFixed asset register is updated monthly and reconciled to GL balancesFinancial Reporting
Missing or incorrect depreciation causes overstatement of assets and misstated expensesDepreciation is calculated from the register and posted monthly with support attachedFinancial Reporting
Retaining disposed assets inflates asset values and depreciation expensePeriodic review ensures register reflects only active assets and disposals are recorded timelyFinancial Reporting
Unrecorded leases lead to understated liabilities and noncompliant financial reportingCentral lease register ensures all active leases are documented and trackedFinancial Reporting
Incorrect initial measurement impacts ongoing lease expense and balance sheet accuracyInitial calculations are performed using standardized templates and reviewed by ControllerFinancial Reporting
Missing monthly entries misstate liabilities and expensesMonthly close checklist includes lease entry posting tied to lease scheduleFinancial Reporting
Unreconciled variances may compound over time and cause audit issuesLease accounts are reconciled monthly to controlled schedulesFinancial Reporting
Unrecorded modifications lead to misstated liabilities and incorrect expense timingAll lease changes require updated schedules and Controller-reviewed journal entriesFinancial Reporting
Failure to reverse accruals may double-count revenueAccrual reversal is a required first-step close task and tied to original JE referenceFinancial Reporting
Missing unbilled revenue understates grant income and receivablesGrant spend is reviewed monthly against billing cadence to identify timing gapsFinancial Reporting
Incorrect accruals may lead to overstated revenue or compliance issuesAccruals are derived from documented spend and reviewed by ControllerFinancial Reporting
Misstated deferred revenue can misalign revenue with performance obligationsDeferred revenue entries are supported by grant/donor schedules and reconciled monthlyFinancial Reporting
Misapplied pledge payments may overstate revenue or ARPledge activity is reconciled monthly between donor management system and accounting systemFinancial Reporting
Missing NPV adjustments can misstate long-term receivables and revenueAnnual NPV review is scheduled and supported by controlled pledge scheduleFinancial Reporting
Using mismatched report dates can create false variances and delay closeBoth reports are pulled using the identical month-end as of date and stored togetherFinancial Reporting
Unreconciled totals may indicate missing liabilities or duplicate postingsTotal-level tie-out is required before any close signoffFinancial Reporting
Vendor-level differences may hide duplicate bills, missing syncs, or coding errorsTargeted vendor tie-out ensures key liabilities are aligned across systemsFinancial Reporting
Unresolved discrepancies can result in misstated liabilities and audit exceptionsEvery mismatch must be traced to a specific cause and resolved or documentedFinancial Reporting
Carrying unresolved errors forward compounds GL inaccuraciesErrors are corrected before close; timing items are clearly flagged and trackedFinancial Reporting
Closing without AP tie-out may leave liabilities incompleteController review/signoff required prior to financial statement preparationFinancial Reporting
Missing platform reports may prevent complete revenue recognition and fee trackingMonthly close checklist requires report downloads and archivingFinancial Reporting
Without reconciliation, revenue could be understated (net-only) or duplicatedNet payouts are tied to bank deposits and gross receipts are verified monthlyFinancial Reporting
Recording net-only deposits understates revenue and obscures fee ratesDeposits are recorded gross with fees separated every monthFinancial Reporting
Misclassified campaigns may violate donor restrictions or distort project trackingMonthly cross-check ensures campaign metadata matches general ledger codingFinancial Reporting
Unreconciled balances may lead to audit exceptions or revenue misstatementController review and stored reconciliation package required before close completionFinancial Reporting
Incorrect starting balances may cascade into misstated net asset totalsNet asset schedules always begin with a Trial Balance export as of close dateFinancial Reporting
Misclassification between restricted/unrestricted may violate donor intent and distort reportingRollforward is updated monthly and fully tied to GL balancesFinancial Reporting
Improper restricted fund treatment can create compliance and audit findingsRestricted activity is reviewed monthly against donor/grant terms and codingFinancial Reporting
Missing schedules weaken audit trail and may delay reportingClose checklist identifies required schedules and templates are updated from GL exportsFinancial Reporting
Unreviewed schedules may carry errors into financial statementsController review and archive required before financial statement reporting beginsFinancial Reporting
Preparing statements before close completion can result in misstated or incomplete reportingFinancial statements are not generated until close checklist is fully completeFinancial Reporting
Incorrect report settings may cause missing transactions or misaligned periodsStandard report settings (accrual + month-end cutoff) are used consistently each monthFinancial Reporting
Undetected errors may pass into leadership reporting and auditsController tie-out review ensures all major balances reconcile to close supportFinancial Reporting
Lack of variance context reduces usefulness and may lead to misinterpretationMaterial variances are documented monthly with finance leadership reviewFinancial Reporting
Missing key schedules may weaken reporting completenessStandardized monthly package checklist ensures consistent contentsFinancial Reporting
Distributing unreviewed statements may harm trust and cause decisions based on errorsController approval required prior to any internal or board distributionFinancial Reporting
Missed tax credit reporting deadlines may create compliance exposure or investor concernWeekly monitoring of tax credit inbox requests ensures timely awareness and responseFinancial Reporting
Inaccurate weekly tracking may lead to errors in formal compliance submissionsWeekly tax credit reports are built from verified general ledger and bank activity and archived centrallyFinancial Reporting
Missing tax credit entries may misstate restricted balances or project costsTax credit journal entry review is a required close step led by tax credit process owner and reviewed by senior accountingFinancial Reporting
Missing tax credit documentation can result in audit findings or delayed investor reportingAll tax credit actions are paired with backup evidence stored in structured foldersFinancial Reporting
Incorrect or late compliance responses may damage program standing or fundingCompliance responses are reviewed by Controller/Finance Director before submissionFinancial Reporting
Without a deliverables calendar, tax credit deadlines may be missedTax credit tracker/calendar is updated continuously by process ownerFinancial Reporting

Your Expert

Kevin Collingsworth

Kevin Collingsworth

Partner

"I'm here to help you customize these controls for your organization's specific needs."

Need help implementing these SOPs?

Every organization is unique. Fill out the form below to connect with our team and discuss how to adapt these procedures for your systems.

Want a team to run them for you? See our nonprofit accounting & CFO services.