← University
Financial Oversight and Accountability
0 of 6

A management letter from the external auditor arrived in early spring, addressed to the board chair of a registered charity that provides housing support and employment services to individuals experiencing homelessness across 3 locations in a mid-sized Canadian city. The letter, delivered alongside the draft audited financial statements for the fiscal year just ended, identified several matters requiring the board's attention: a material variance between budgeted and actual program expenditures that management had not reported during the year, questions about the segregation of duties in the accounts payable function, and a recommendation that the organization formalize its process for board approval of unbudgeted expenditures exceeding $10,000. The auditor requested a meeting with the board, without management present, to discuss these observations before the financial statements were finalized.

The charity operates with an annual budget of approximately $4.2 million, funded through a combination of government contracts, foundation grants, and individual donations. Its 9-member board includes professionals from accounting, law, and healthcare backgrounds alongside several community members who bring lived experience relevant to the organization's mission. A treasurer serves on the board, and a 3-person finance committee meets monthly to review financial reports before they reach the full board. The organization employs a full-time executive director and a part-time bookkeeper who reports to the executive director; there is no internal finance director or controller.

Over the preceding 18 months, the charity had expanded its programs significantly, adding a new transitional housing facility and doubling its employment counselling staff. These expansions had been approved by the board based on management projections that anticipated corresponding increases in grant funding. The auditor's letter noted that while the new programs had launched on schedule, the anticipated funding had not materialized at the projected levels, leaving the organization with an operating deficit of $187,000 for the year just ended and drawing down its accumulated reserves to approximately $94,000. The board had received quarterly financial reports throughout the year, but the reports had consistently shown expenditures as "within acceptable variance" of budget without flagging the cumulative shortfall or the reserve depletion.

The board chair circulated the management letter to all directors and scheduled an emergency meeting for the following week. In preparation, the chair asked the treasurer and finance committee to review the prior year's quarterly reports, the approved budget, and the organization's policies regarding financial reporting to the board and management's expenditure authority.

Internal Controls and Financial Risk: The Board's Oversight Role

Every organization, regardless of its size or sector, operates within an environment of uncertainty. Financial transactions flow through multiple hands, assets require protection, and the potential for error, fraud, or mismanagement exists in even the most well-intentioned operations. Internal controls represent the systems, policies, and procedures that organizations put in place to safeguard assets, ensure the accuracy of financial information, promote operational efficiency, and encourage adherence to established policies and legal requirements. For boards of directors across Canada, understanding internal controls and financial risk is not merely a matter of operational curiosity but rather a fundamental governance obligation that flows directly from fiduciary duties and statutory responsibilities.

The concept of internal control has evolved considerably over the past century, moving from a narrow focus on preventing employee theft to a comprehensive framework encompassing all aspects of organizational risk management. Modern internal control theory recognizes that effective controls serve multiple purposes simultaneously. They protect an organization from losses due to fraud or error, but they also provide reasonable assurance that financial statements accurately reflect the organization's true financial position. They help ensure compliance with applicable laws and regulations while supporting efficient and effective operations. For board members, this multifaceted nature of internal controls means that oversight responsibility extends beyond simply asking whether the organization has controls in place to examining whether those controls are appropriate, functioning as intended, and adequate for the risks the organization actually faces.

The legal foundation for board oversight of internal controls in Canada emerges from multiple sources, though the specific articulation varies depending on organizational type and jurisdiction. Under the Canada Business Corporations Act, directors of federally incorporated companies have statutory duties of care that require them to exercise the care, diligence, and skill of a reasonably prudent person in comparable circumstances. While the statute does not explicitly mandate internal controls, courts and governance authorities have consistently interpreted this duty as including reasonable oversight of financial systems and risk management processes. The Canada Not-for-profit Corporations Act, as of the date of authorship, imposes similar duties on directors of federally incorporated non-profit organizations, requiring them to act honestly, in good faith, and with a view to the best interests of the corporation while exercising the care, diligence, and skill that a reasonably prudent person would exercise in comparable circumstances.

Provincial corporate and societies legislation across Canada establishes comparable expectations, though with variations in specific language and emphasis. The Business Corporations Acts of British Columbia, Alberta, Saskatchewan, and Ontario all contain duty of care provisions that implicitly require attention to internal controls as part of competent governance. Provincial societies and non-profit legislation similarly imposes fiduciary and care obligations that encompass financial oversight. In Quebec, the Civil Code of Quebec governs the duties of directors and administrators under its civil law framework, establishing obligations of prudence, diligence, honesty, and loyalty that parallel common law fiduciary duties while arising from distinct legal traditions. Quebec's framework emphasizes the administrator's duty to act within the limits of their powers with care, prudence, and due diligence, and these obligations extend naturally to ensuring that the organization maintains appropriate systems for financial control and risk management.

The alignment across Canadian jurisdictions on the fundamental principle is notable despite differences in specific statutory language. Whether an organization operates as a federal corporation, a provincial society, a credit union governed by specialized legislation, or a co-operative subject to its own regulatory framework, the board bears ultimate responsibility for ensuring that management has implemented adequate systems to protect organizational assets and produce reliable financial information. This does not mean that board members must personally design or operate internal control systems, but it does mean they must satisfy themselves that appropriate systems exist, function effectively, and receive adequate management attention.

Understanding how internal controls work in practice requires distinguishing between different types of controls and recognizing how they interact within an organizational context. Preventive controls aim to stop errors or irregularities before they occur. These include segregation of duties, authorization requirements for transactions above certain thresholds, physical security measures for assets, and hiring practices that include background verification. Detective controls, by contrast, are designed to identify errors or irregularities that have already occurred. Examples include bank reconciliations, variance analyses comparing actual results to budgets, inventory counts, and internal audit activities. Corrective controls address problems once detected, ensuring that errors are fixed and that systemic issues receive appropriate remediation. A well-designed internal control system incorporates all three types, creating multiple layers of protection against financial loss and misstatement.

The concept of segregation of duties deserves particular attention because it represents one of the most fundamental and yet most frequently compromised control principles. The basic premise holds that no single individual should have complete control over any significant transaction or process. Ideally, the person who authorizes a transaction should differ from the person who records it, who should differ from the person who maintains custody of the related assets. In a larger organization, this segregation occurs naturally through departmental structures and specialized roles. A purchasing department initiates orders, accounts payable processes invoices, and treasury handles payments. The challenges become acute in smaller organizations where limited staff may require individuals to perform multiple functions. Canadian non-profits, small businesses, and community organizations frequently operate with only one or two administrative staff members, making traditional segregation of duties impossible. In these contexts, compensating controls become essential. Board members or volunteers may need to participate in certain control functions, such as signing cheques above certain amounts, reviewing bank statements directly, or conducting periodic surprise reviews of financial records.

Financial risk management intersects with internal controls but extends beyond them to encompass the broader strategic question of what risks the organization is willing to accept and how those risks are monitored and managed. Every organization faces financial risks, including revenue volatility, cost pressures, liquidity constraints, interest rate and currency exposures, and counterparty risks with key customers, donors, or funders. The board's role includes ensuring that management has identified significant financial risks, that appropriate policies exist for managing those risks, and that the board receives adequate information to evaluate whether risk management practices remain effective. This oversight function requires boards to ask probing questions about risk assessment processes, to understand the assumptions underlying financial projections, and to consider whether the organization's risk tolerance aligns with its actual risk exposures.

The relationship between internal controls, financial risk, and financial reporting connects directly to the board's oversight of audited financial statements. External auditors provide an independent opinion on whether financial statements present fairly the organization's financial position and results of operations. However, auditors do not examine every transaction, and an unqualified audit opinion does not guarantee that no errors or fraud exist within the financial records. Auditors rely heavily on their assessment of internal controls to determine the nature and extent of their testing procedures. When controls are weak, auditors must perform more extensive substantive testing to achieve reasonable assurance about financial statement accuracy. When controls are strong and functioning effectively, auditors may rely more heavily on those controls and perform less detailed transaction testing. For board members, this means that attention to internal controls serves not only to protect the organization but also to support the integrity of the financial reporting on which the board relies for its own oversight and decision-making.

Consider the experience of a regional environmental advocacy organization based in Edmonton with annual revenues of approximately $1.2 million and a staff of eight full-time employees. The organization had operated successfully for over fifteen years, building a strong reputation and maintaining generally positive relationships with its major funders, which included a combination of government grants, foundation support, and individual donors. The board consisted of eleven members, including several senior professionals with backgrounds in law, accounting, and environmental science. The organization had established an audit committee that met twice annually to review the audited financial statements and meet with the external auditors, and board members generally felt confident in the financial management of the organization.

In early January 2025, the executive director announced her retirement after twelve years of service. The board undertook a search process and hired a new executive director who began work in April 2025. Within three months of starting, the new executive director expressed concerns to the board chair about certain financial practices she had observed. Specifically, she noted that the former executive director had maintained sole signing authority on the organization's operating account, that expense reimbursements had been processed without supporting receipts in multiple instances, that the organization had been carrying a line of credit balance of approximately $85,000 that had not been disclosed in board financial reports, and that a contractor who provided communications services had been paid approximately $78,000 over the previous two years without any written contract or competitive selection process.

The board chair immediately convened an emergency meeting of the audit committee to discuss these concerns. Upon investigation, the audit committee discovered that internal controls had weakened considerably over time without the board's awareness. The financial manager who reported to the executive director had prepared monthly financial reports for the board that consistently showed the organization in a favorable position, but these reports had excluded the line of credit from the summary presentation, showing it only in detailed supporting schedules that board members rarely examined closely. The external auditors had flagged the line of credit in the audited statements, but the notes described it as an operating facility available for use rather than highlighting that it had been drawn upon. No board member had thought to inquire about whether the credit facility was actually being used.

The expense reimbursement issues proved more troubling upon closer examination. Over a three-year period, the former executive director had submitted approximately $34,000 in expense reimbursements for travel, meals, and professional development that lacked adequate documentation. Many receipts were missing entirely, and in some cases the claimed expenses appeared inconsistent with the executive director's calendar or with organizational activities. The financial manager had processed these reimbursements without question, apparently feeling that challenging the executive director would jeopardize her employment. The board had never reviewed detailed expense reports or established policies requiring periodic review of executive expenses.

The contractor payments raised additional concerns about potential conflicts of interest. Investigation revealed that the communications contractor was a personal acquaintance of the former executive director who had been engaged without any formal procurement process. While the work appeared to have been performed, the rates paid exceeded market norms for comparable services, and no written contract defined deliverables or performance standards. The board had received no information about this contractor relationship through routine reporting processes.

The implications of this situation for governance practice are significant and extend beyond the specific facts involved. First, the scenario illustrates how internal controls can erode gradually over time, particularly when a trusted executive accumulates influence without adequate oversight structures. The former executive director had served successfully for twelve years and had earned the board's confidence through demonstrated performance. That confidence, however, translated into reduced scrutiny rather than continued verification. The board had effectively delegated financial oversight entirely to management without maintaining the independent verification mechanisms that serve as essential checks on executive authority.

Second, the scenario demonstrates the critical importance of multiple individuals having visibility into financial transactions and records. The concentration of signing authority in a single person, the lack of independent review of executive expenses, and the financial manager's reluctance to question her supervisor all contributed to an environment where problematic practices could continue undetected. Effective internal control systems assume that people may act improperly and build in redundant checks that make impropriety more difficult and detection more likely.

Third, the scenario reveals how financial reporting to the board can obscure rather than illuminate organizational reality if the board does not understand reporting limitations and does not ask sufficiently probing questions. Monthly financial reports are management documents, prepared by management according to management's judgments about what information matters and how to present it. Boards must approach these reports with appropriate professional skepticism, not assuming bad faith but recognizing that summarization inherently involves choices about emphasis and detail. The line of credit disclosure failure occurred not because management explicitly lied but because the reporting format made the information easy to overlook.

Fourth, the scenario highlights the relationship between control failures and organizational vulnerability to misconduct. Whether the former executive director engaged in actual fraud or simply maintained sloppy practices enabled by weak controls, the organization faced potential liability, reputational damage, and financial loss. Several of the government funders for this organization had explicit requirements in their contribution agreements regarding financial management and reporting. The line of credit borrowing, undertaken without board approval, arguably breached covenants in certain funding agreements and could expose the organization to demands for repayment of grant funds. The contractor payments, if deemed inappropriately procured, might need to be disclosed to certain funders with potential consequences for future funding eligibility.

For board members across Canada, this scenario and others like it point toward concrete governance practices that strengthen internal control oversight. Before assuming that controls are adequate, boards should request and review documentation of key control procedures, including authorization limits, segregation of duties, reconciliation processes, and exception reporting. This review should occur not only at audit committee meetings but also when significant organizational changes occur, such as executive transitions, major system implementations, or shifts in funding composition. The board should understand which individuals have authority over various transaction types and how that authority is monitored.

Boards should establish clear expectations for executive expense oversight. At minimum, this typically includes a policy requiring that executive expenses be reviewed and approved by someone other than the executive incurring them. Board chairs or audit committee chairs commonly perform this function for chief executive expenses, reviewing detailed expense reports at least quarterly and providing written approval. The policy should specify documentation requirements, reimbursement limits, and consequences for non-compliance.

Financial reports to the board should explicitly disclose credit facility usage, covenant compliance status, and any departures from budget or policy that require explanation. Boards should periodically review the format of financial reports to ensure that key information is presented prominently rather than buried in appendices. Asking management to walk through where specific items appear in the reports can reveal gaps in reporting coverage.

Procurement and contracting practices merit board attention, particularly for larger expenditures or ongoing service relationships. Policies should require competitive processes above reasonable thresholds, conflict of interest disclosure by those involved in vendor selection, and written contracts for material engagements. For organizations with related party transactions involving board members, executives, or their family members, enhanced disclosure and approval requirements provide essential protection.

The relationship with external auditors requires active board engagement. Audit committees should meet privately with auditors without management present at least annually to discuss any concerns about management practices, control weaknesses, or areas where auditors encountered resistance or difficulty obtaining information. The management letter issued by auditors after completing their engagement often contains observations about control weaknesses that warrant board attention and remediation follow-up.

Internal audit functions, where organizational size permits, provide independent assurance that controls operate as designed. Smaller organizations that cannot support dedicated internal audit resources might engage external consultants periodically to perform control assessments or might establish board-level oversight mechanisms such as periodic review of transaction samples by audit committee members.

Documentation of control-related decisions and oversight activities protects both the organization and individual directors. Board minutes should reflect that internal control matters received appropriate attention, that management reported on control status and any identified issues, and that the board directed remediation of any significant weaknesses. Directors who later face questions about governance performance benefit from contemporaneous records demonstrating their attention to these responsibilities.

The connection between internal controls and organizational culture warrants acknowledgment. Controls function best in environments where integrity and accountability are valued throughout the organization. Technical control mechanisms can be circumvented by determined wrongdoers, and excessive reliance on controls without attention to culture may create organizations where people follow rules mechanically without understanding or commitment to underlying values. Effective governance attention to controls therefore extends beyond procedural verification to include consideration of how the organization promotes ethical behavior, responds to concerns raised by employees, and demonstrates accountability at all levels.

Financial risk oversight similarly requires ongoing board attention. At least annually, boards should review management's assessment of significant financial risks facing the organization, evaluate the adequacy of policies and procedures for managing those risks, and consider whether risk exposures have changed since the previous assessment. For organizations with significant investment assets, this includes reviewing investment policies and monitoring compliance with policy parameters. For organizations with significant debt, it includes understanding covenant requirements and monitoring compliance margins. For organizations dependent on a small number of funders or revenue sources, it includes considering concentration risk and potential diversification strategies.

The board's role in internal control and financial risk oversight represents neither micromanagement nor passive trust but rather engaged verification. Directors fulfill their governance responsibilities by ensuring that appropriate systems exist, by monitoring whether those systems function effectively, by responding to identified weaknesses with appropriate urgency, and by maintaining awareness of the financial risks their organizations face. This oversight responsibility applies across organizational types and sizes, though the specific mechanisms will appropriately vary based on organizational complexity and resources. A community service organization with $200,000 in annual revenue and two part-time staff members will necessarily implement controls differently than a national charity with $50 million in revenue and hundreds of employees, but both require board attention to control adequacy and financial risk management. The fundamental governance obligation remains constant even as its practical expression adapts to organizational context.

Continue with University access

This lesson is part of a $149 course. Purchase the course or sign in with an active membership to keep reading.

See purchase options