
A nonprofit financial fraud investigation is a discreet, board-directed forensic inquiry into suspected misappropriation of charitable funds — executive or bookkeeper theft, grant and restricted-fund misuse, ghost vendors, reimbursement abuse, or related-party self-dealing. Its purpose is to establish what happened, quantify the loss, preserve evidence, and equip the board to meet its fiduciary duties while protecting donor trust and tax-exempt status. Honeybadger Solutions conducts these investigations in-house from its Arizona home command, nationwide and internationally.
Why are nonprofits uniquely vulnerable to internal fraud?
Charities are built on trust, and trust is precisely the condition fraud exploits. A mission-driven culture discourages the suspicion that healthy financial controls require. Founders and long-tenured executive directors accumulate unchecked authority. Bookkeeping is frequently handled by a single person — often part-time or a volunteer — who owns receipts, deposits, reconciliation, and reporting with no separation of duties. Boards are volunteer bodies that meet quarterly, read summarized financials, and defer to staff they like and respect.
The Association of Certified Fraud Examiners has long documented that organizations with fewer anti-fraud controls suffer disproportionately, and small and mid-sized nonprofits are the textbook case: high trust, thin oversight, and limited resources to detect a scheme once it starts. When the person who could catch the fraud is the person committing it, the deception can run for years. By the time a board notices — a bounced grant reimbursement, a vendor no one recognizes, a program budget that never adds up — the losses are often substantial and the paper trail has been actively managed.
What forms does nonprofit financial fraud typically take?
Charitable-sector fraud follows recognizable patterns. Understanding them helps a board articulate its concern precisely and helps investigators scope the inquiry.
- Executive or bookkeeper misappropriation — direct theft through unauthorized transfers, payroll manipulation, forged checks, or diversion of cash donations before they are recorded.
- Grant and restricted-fund misuse — spending donor- or grantor-restricted money on general operations, salaries, or unrelated programs, then obscuring it in the general ledger.
- Ghost vendors and fictitious invoices — a shell payee controlled by an insider, or inflated invoices from a real vendor kicking back the difference.
- Credit-card, expense, and reimbursement abuse — personal purchases run through the organization, duplicate reimbursements, or padded travel and entertainment.
- Related-party self-dealing — contracts, leases, or consulting fees steered to an insider, a family member, or a business the insider owns, without disclosure or arm’s-length pricing.
- Donation skimming — intercepting event cash, in-kind gifts, or online donations before they reach the accounts, a scheme that is invisible on the books because the money was never recorded.
How does restricted-fund misuse differ from ordinary theft?
Restricted funds are the fault line unique to the nonprofit world. When a donor or grantor designates money for a specific purpose — a scholarship endowment, a capital campaign, a disaster-relief program — that restriction is a legal obligation, not a suggestion. Spending it elsewhere is a breach even when the money stays inside the organization and funds legitimate work. Misuse can be outright (cash moved to cover payroll) or subtle (allocation methods quietly changed, timing manipulated, or expenses miscoded to draw down a restricted balance). A forensic examination of grant compliance reconstructs how each restricted dollar was received, tracked, and spent against its terms — a discipline distinct from spotting a stolen check, and one that requires reading grant agreements alongside the ledger.

What red flags on the Form 990 and in the books should a board notice?
The IRS Form 990 is a public accountability document, and its structure surfaces exactly the areas where fraud hides. A board reviewing its own filing — or a donor reading a charity’s public return — should treat the following as prompts for questions, not proof of wrongdoing.
- Undisclosed related-party transactions — Schedule L and the governance questions exist to capture insider dealings; blanks or vague entries where relationships are known are a signal.
- Compensation that outpaces the organization — executive pay, loans to officers, or first-class travel inconsistent with the mission’s scale.
- A single signer and no independent review — governance questions revealing no audit committee, no conflict-of-interest policy, or no board review of the 990 before filing.
- Program-to-overhead ratios that shift suddenly without a strategic explanation, or functional expense allocations that strain credulity.
- Restricted contributions that don’t reconcile — net-asset schedules where released restrictions don’t match program activity.
- Round-number or unfamiliar vendors in the highest-paid contractor disclosures, or payees no board member can identify.
- Late, amended, or inconsistent filings — a pattern of delay or restatement that keeps the true picture perpetually unsettled.
None of these confirms fraud. Each is a reason to ask a better question — and if the answers don’t satisfy the board’s duty of care, a reason to commission an independent look. The IRS publishes extensive guidance for the sector through its Charities and Nonprofits resources, and the National Council of Nonprofits offers practical governance frameworks worth measuring your controls against.
What are the board’s fiduciary duties when fraud is suspected?
Directors of a nonprofit owe the organization a duty of care, a duty of loyalty, and a duty of obedience to its charitable purpose. When a credible concern surfaces, the duty of care converts a suspicion into an obligation to act — deliberately, informedly, and without conflict. Inaction is itself a breach: a board that hears a warning and looks away exposes both the organization and its directors.
Acting well does not mean acting rashly. It means preserving evidence before it can be altered, avoiding tipping off the subject, insulating the inquiry from anyone who might be implicated, and engaging qualified independent help so the findings are credible to the parties who will eventually scrutinize them — auditors, state charity regulators, the IRS, insurers, and potentially prosecutors. An investigation run by the very executives who might be involved, or announced to staff before evidence is secured, is worse than none at all.
Why does independence matter so much here?
Independence protects two things at once: the integrity of the findings and the reputation of the board. Donors, grantors, and regulators discount conclusions reached by insiders with a stake in the outcome. An independent forensic investigation — ideally directed through legal counsel to preserve privilege — produces a record that withstands challenge. It also demonstrates, visibly and on the record, that the board took its duty seriously. When the story eventually reaches donors, “the board detected a concern and commissioned an independent investigation” is a fundamentally different narrative than “the fraud continued until it became impossible to ignore.”
How does the investigation build evidence for the board, regulators, and prosecutors?
A defensible investigation is built for multiple audiences, because the same findings may need to satisfy an audit committee this quarter, a state Attorney General’s charity division next quarter, and a criminal prosecutor after that. That means chain of custody from the first byte, source documentation for every conclusion, and analysis a skeptical third party can reproduce.
Forensic accounting reconstructs the financial reality: bank and card statements traced against the general ledger, vendor files tested for legitimacy, payroll and reimbursement patterns analyzed, and restricted-fund activity matched to grant terms. Digital forensics preserves and examines the electronic record — email, accounting-system audit logs, deleted files, and device artifacts — in a manner that keeps it admissible. Background intelligence and asset research establishes whether an insider controls a suspect vendor, holds undisclosed related-party interests, or has accumulated assets inconsistent with known income. Together these methods move a case from “something feels wrong” to a documented, quantified account of what occurred and who was responsible.
How does Honeybadger approach a nonprofit fraud investigation?
Honeybadger Solutions runs financial investigations, forensic accounting, digital forensics, and background intelligence as in-house, remote-by-design capabilities — not partner-dependent referrals. That matters for a nonprofit: one accountable team, coordinated from our Arizona home command, controls the evidence end to end, nationwide and internationally, wherever your programs, grantors, and vendors are located. Discretion is the default; most boards need the inquiry to proceed without staff, donors, or the subject knowing it exists.
A typical engagement follows a disciplined sequence built to protect both the mission and the board:
- Confidential intake and scoping — we work with the board or its counsel to define the concern, identify who must be walled off from the inquiry, and set objectives without alerting the subject.
- Evidence preservation — before anything else, we secure financial records, accounting-system data, email, and device images under proper chain of custody so nothing can be quietly deleted.
- Forensic reconstruction — we trace funds, test vendors and reimbursements, examine restricted-fund compliance, and quantify the loss with documented support.
- Corroboration — asset research and background intelligence connect insiders to shell entities, related parties, and unexplained assets.
- Reporting — we deliver findings the board can act on and that stand up to auditors, regulators, insurers, and, where warranted, law enforcement.
- Coordination and referral support — we support your counsel in engaging state charity regulators, the IRS, and prosecutors, and in meeting any mandatory-disclosure obligations.
Because these matters often begin as an ambiguous concern about one individual, boards frequently pair a fraud inquiry with a discreet background investigation, or find that the fund misuse mirrors patterns we address in business partner embezzlement investigations. Our full range of corporate work is outlined on our investigations overview.
Internal audit vs. forensic investigation: what’s the difference?
| Dimension | Routine / Internal Audit | Forensic Fraud Investigation |
|---|---|---|
| Objective | Test controls and confirm financial statements are reasonable | Determine whether specific fraud occurred, how, and by whom |
| Assumption | Records are broadly reliable; sampling is acceptable | Records may be manipulated; concealment is expected |
| Scope | Broad, standardized, periodic | Targeted, evidence-led, driven by the specific concern |
| Evidence standard | Materiality and reasonable assurance | Chain of custody; admissible, reproducible, defensible |
| Digital evidence | Rarely preserved forensically | Email, audit logs, and devices imaged and analyzed |
| Confidentiality | Known to management and staff | Discreet; subject and staff typically not informed |
| End use | Board assurance, 990 support | Board action, regulator referral, insurance, prosecution |
An audit and a forensic investigation are complementary, not interchangeable. An audit may raise the flag; it is not designed to catch a determined insider who controls the books. When the concern is fraud, the investigation must assume active concealment from the outset.
How is the organization’s tax-exempt status and donor trust protected?
Two assets are at stake beyond the stolen dollars: the charity’s tax-exempt status and its donor relationships. Related-party self-dealing and excess-benefit transactions can carry regulatory consequences, and undisclosed or misreported activity on the Form 990 compounds the exposure. Addressing fraud promptly, documenting it independently, correcting filings, and being able to show regulators a good-faith response is how organizations preserve their standing rather than surrender it.
Donor trust is protected the same way. Donors and grantors forgive organizations that were victimized and responded with rigor far more readily than those that appeared negligent or evasive. A completed, credible investigation lets the board control the narrative, honor restricted-gift obligations going forward, recover losses where possible, and rebuild the controls that failed — the difference between an isolated setback and an existential crisis.
Recovery is often part of the outcome. Documented findings support insurance claims under crime or fidelity policies, restitution demands, and, where an insider diverted funds into personal assets or shell entities, targeted asset research to identify what can realistically be recovered. The board’s obligation does not end at proving the fraud; it extends to making the organization and its restricted funds as whole as the facts allow. A rigorous, independent investigation is the foundation for every one of those remedies — which is why the quality of the inquiry, and the discretion with which it is conducted, ultimately determines how much of the mission survives the crisis.
Frequently asked questions
Should the board notify the suspected individual before investigating?
No. Notifying a subject before evidence is preserved invites destruction of records, coordination of stories, and asset movement. The board should quietly engage counsel and an independent investigator, secure financial and digital evidence under chain of custody, and only then decide on interviews or confrontation. Discretion early is what makes recovery and accountability possible later.
Do we have to report the fraud to regulators or the IRS?
Possibly. Nonprofits face disclosure obligations — including questions on the Form 990 and, in many states, reporting to the Attorney General’s charity division — and grant agreements may require notice. Those decisions belong with your legal counsel, informed by documented findings. An independent investigation gives counsel the factual foundation to advise on mandatory disclosure and any correcting filings.
Can restricted-fund misuse be proven if the money stayed inside the organization?
Yes. Restricted-fund misuse is proven by reconstructing each restricted contribution against its terms and tracing how it was recorded, allocated, and spent. Even when funds never left the organization, forensic accounting can show that restricted dollars were drawn down for unauthorized purposes — a documented breach independent of whether anyone personally profited.
Does Honeybadger work with nonprofits outside Arizona?
Yes. Our financial investigations, forensic accounting, digital forensics, and background intelligence are remote-by-design and run in-house from our Arizona home command — serving nonprofits and foundations throughout Arizona, nationwide, and internationally. Distributed programs, out-of-state grantors, and remote bookkeepers are routine; the evidence is handled by one accountable team regardless of geography.
About Honeybadger Solutions
Honeybadger Solutions is an Arizona-licensed security and investigations firm providing financial investigations, forensic accounting, digital forensics, cybersecurity, and background intelligence. These capabilities are in-house and remote-by-design — not partner-dependent — and run from our Arizona home command for clients across Arizona, nationwide, and internationally. We work discreetly alongside boards, executive directors, foundation counsel, and major donors to establish facts, preserve evidence, and protect both mission and tax-exempt status.
Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona. Confidential consultations: 602-725-2818.