Blog · Nonprofit policies & compliance
The financial policies every nonprofit board should adopt
June 27, 2026 · By Benjamin Reinke
A nonprofit’s financial policies are the written rules its board adopts to govern how money and records are handled — the core set being a conflict-of-interest policy, an accountable reimbursement plan, a document-retention policy, a gift-acceptance policy, and a whistleblower policy, all sitting under an internal-controls policy as the umbrella. A board adopts them for three reasons: they’re what good governance looks like, they make the organization audit-ready, and several of them protect its tax-exempt status — the IRS asks about a few of them by name when it grants 501(c)(3) status. A church is a 501(c)(3), so the same policies apply to a congregation as to any other nonprofit; the names on the board may differ, the rules don’t.
This page is the hub. Each policy below gets a quick explanation of what it does and why it matters, with a link to its own deep-dive guide where one exists. If you’re earlier than that — still forming the organization or the board — start with how to start a nonprofit and the nonprofit board of directors overview, since the board is the body that adopts everything here.
Why a nonprofit board adopts written financial policies
A nonprofit board adopts written financial policies because money that no one wrote rules for is money no one can be held to. Three pressures push every board the same direction:
- Good governance. Policies turn “we trust our treasurer” into a system that works no matter who the treasurer is. They set the defaults so decisions aren’t improvised under pressure or made differently each time.
- Audit-readiness. A church audit — or any nonprofit review — goes faster and cleaner when the auditor can read the rules the organization set for itself and check the books against them. No policy means the auditor is grading against a standard that doesn’t exist.
- Protecting tax-exempt status. This is the part boards underestimate. When the IRS reviews a 501(c)(3) application, it asks directly whether the organization has adopted certain governance policies. They’re not legally mandatory, but a “no” invites scrutiny, and the wrong setup can put the exemption at risk through private benefit or insider dealing.
That third pressure is concrete. On the IRS Form 1023 application for recognition of exemption, the governance section asks whether the organization has a conflict-of-interest policy, and the IRS’s own materials walk applicants through document-retention and whistleblower expectations as well. Adopting these isn’t box-checking — it’s the evidence that the board governs at arm’s length instead of for its insiders. IRS Publication 557, the guide to tax-exempt status, lays out the same governance and recordkeeping ground.
The core nonprofit financial policies at a glance
A nonprofit’s core policy set is short — five written policies plus the controls umbrella. The table names each one, what it actually does, and whether the IRS asks about it when granting exemption.
| Policy | What it does | Does the IRS ask? |
|---|---|---|
| Conflict-of-interest policy | Insiders disclose any personal stake and recuse from the vote | Yes — Form 1023 asks directly |
| Document retention & destruction | Sets how long records are kept and when they’re destroyed | Yes — covered in Form 1023 governance |
| Whistleblower policy | Lets staff report misconduct without retaliation | Yes — covered in Form 1023 governance |
| Accountable reimbursement plan | Reimburses expenses tax-free under IRS rules | Indirectly — governs payroll/tax treatment |
| Gift-acceptance policy | Defines which gifts the organization will and won’t take | No — but expected for any org taking non-cash gifts |
| Internal financial controls | The umbrella: who can spend, sign, and reconcile | Not by name — but it’s what oversight rests on |
The rest of this page takes each one in turn. Each is its own guide; this hub explains what the policy is for and how it fits with the others.
The conflict-of-interest policy is the one the IRS most wants to see
A conflict-of-interest policy is the rule that requires an insider — a board member, officer, or key employee — to disclose any personal stake in a transaction and step out of the decision. It’s the policy the IRS most wants to see, and the only one Form 1023 asks about by name in plain terms. The reason is the duty of loyalty: a director owes the organization, not their own wallet, and this policy is how that duty gets enforced in practice.
A real conflict-of-interest policy does three things. It defines what counts as a conflict (a director’s business bidding on a contract, a relative on payroll, a vote that sets the director’s own pay). It requires disclosure up front, in writing, before the decision. And it requires recusal — the conflicted person leaves the room and the vote, and the minutes record that they did. Without recusal, even a fair deal looks like self-dealing, and self-dealing is exactly the private-benefit problem that can cost a nonprofit its exemption. The conflict-of-interest policy has its own guide; the short version is that disclosure plus recusal, documented in the minutes, is the whole point.
The accountable reimbursement plan reimburses staff and clergy tax-free
An accountable reimbursement plan is the written policy that lets a nonprofit pay back an employee’s or clergy member’s business expenses without that money becoming taxable wages. Under IRS rules, a reimbursement is tax-free only if it meets three tests: the expense had a business connection, the employee substantiated it with receipts and details within a reasonable time, and the employee returned any excess advance. Miss those and the reimbursement is taxable income — reportable on the W-2, subject to withholding.
The contrast is sharp and it’s where money gets lost. A church that hands its pastor a flat $400-a-month “car allowance” with no receipts is running a non-accountable plan, and that $400 is taxable wages. The same church reimbursing actual, documented mileage under a written accountable plan pays the same money tax-free. The policy is what makes the difference legal. For churches especially, this interacts with clergy pay and housing, so it’s worth getting right; the accountable reimbursement plan has its own guide for the full mechanics.
The document-retention and destruction policy sets how long records are kept
A document-retention and destruction policy is the written schedule for how long a nonprofit keeps each kind of record and when it’s allowed to destroy them. Form 1023’s governance section asks whether the organization has one, and the reason is partly defensive: a retention policy is also a destruction policy, and being able to show you destroy records on a routine schedule — not selectively when trouble appears — matters if the organization is ever investigated.
The schedule varies by record type. Some categories — articles of incorporation, bylaws, the IRS determination letter, board minutes — are kept permanently. Tax returns and supporting financial records are typically held for at least seven years. Routine correspondence and drafts can go much sooner. The policy’s job is to write those periods down so retention is a system, not a guess, and so no one is improvising “should we keep this?” years later. The document-retention policy has its own guide with a record-by-record schedule.
The gift-acceptance policy defines which gifts the organization will and won’t take
A gift-acceptance policy is the written rule for which gifts a nonprofit will accept, which it will refuse, and on what terms. The instinct is to take everything, but some gifts cost more than they give: real estate with environmental liability, a restricted gift with strings the organization can’t honor, donated stock in a private company it can’t sell, or a gift whose conditions pull the mission off course. A gift-acceptance policy lets the board say no without it being personal — the policy already decided.
A workable policy names the gift types the organization accepts without question (cash, publicly traded securities, standard checks), the types it accepts only after review (real property, non-cash assets, gifts with donor restrictions), and the ones it won’t take at all. It also sets who has authority to accept a complex gift and when a gift must come to the full board. This keeps the organization from being quietly steered by a large donor’s conditions, and it protects staff from having to make awkward judgment calls alone. The gift-acceptance policy has its own guide for drafting the acceptance tiers.
The whistleblower policy lets someone report misconduct without retaliation
A whistleblower policy is the written protection that lets an employee, volunteer, or board member report suspected financial misconduct without fear of being fired, demoted, or punished for it. Form 1023’s governance section asks whether the organization has one, and the logic is simple: most nonprofit fraud is caught not by an audit but by a tip, and people only give tips when reporting is safe. A policy that names a way to report — and forbids retaliation against the reporter — is what makes the safe channel real.
A whistleblower policy needs three parts. It tells people how to report (and to whom — usually someone other than the person they might be reporting, like the board chair or an audit committee). It promises confidentiality as far as is practical. And it prohibits retaliation, with consequences for anyone who retaliates. The federal law behind the non-retaliation piece traces to Sarbanes-Oxley, which made retaliation against whistleblowers a crime even for nonprofits — one of the few corporate-fraud rules that reaches the sector. The whistleblower policy has its own guide; the core is a safe, named channel that bypasses anyone who might be implicated.
Internal financial controls are the umbrella the other policies sit under
Internal financial controls are the broader set of rules — sometimes written up as a single financial-management or financial-controls policy — that govern who can spend money, who signs, who records, and who reconciles. This is the umbrella the five policies above sit under. Where a conflict-of-interest policy handles insiders and a whistleblower policy handles reporting, the controls policy handles the everyday mechanics: separation of duties, spending authority, check-signing limits, and bank reconciliation.
The single rule at the heart of it is separation of duties — no one person should control a transaction from start to finish. The person who records income shouldn’t be the one who reconciles the bank; the person who approves an invoice shouldn’t be the one who cuts the check. One trusted individual controlling money end to end is the most common setup behind nonprofit embezzlement, and the controls policy exists to make sure that setup never exists. This is also where day-to-day nonprofit bookkeeping connects to governance: clean books are what let the board verify the controls are actually holding. One more policy belongs alongside these for any organization holding reserves or an endowment: a nonprofit investment policy that sets how that money is invested and how much can be spent each year.
How church boards adopt the same financial policies
A church board adopts the same financial policies as any other nonprofit, because a church that incorporates is a 501(c)(3) — the same legal animal, with congregation-specific names. The vestry, session, elders, or board of trustees plays the role the law calls the board of directors, and that body adopts the conflict-of-interest, reimbursement, retention, gift-acceptance, and whistleblower policies exactly as a secular nonprofit would.
Churches get a few breaks: they’re automatically tax-exempt without filing for it, and they don’t file a Form 990. But the policy work is identical, and in some ways it matters more — a church handles loose cash offerings, clergy compensation, and benevolence funds, all of which are easy to mishandle without written rules. The board’s job, whatever it’s called, is the same one described in a nonprofit board’s responsibilities: set the rules, then verify they’re followed. Adopting this policy set is how the board does the first half.
FAQ
What financial policies should a nonprofit have? At a minimum, a nonprofit should have a conflict-of-interest policy, an accountable reimbursement plan, a document-retention and destruction policy, a gift-acceptance policy, and a whistleblower policy — all under an internal-controls (financial-management) policy that sets who can spend, sign, record, and reconcile. The IRS asks about conflict of interest, document retention, and whistleblower protection on the Form 1023 exemption application, so those three carry the most weight.
Which financial policy does the IRS care about most? The conflict-of-interest policy. It’s the one Form 1023 asks about most directly, because it’s how the board’s duty of loyalty gets enforced — insiders disclose any personal stake and recuse from the vote. A nonprofit without one signals to the IRS that insiders may be benefiting from the organization, which is the private-benefit problem that can put tax-exempt status at risk.
Are nonprofit financial policies legally required? Most are not strictly required by law — the IRS doesn’t mandate them — but several are effectively expected. The Form 1023 application asks whether a nonprofit has a conflict-of-interest, document-retention, and whistleblower policy, and answering “no” invites scrutiny. The non-retaliation part of a whistleblower policy is backed by federal law (Sarbanes-Oxley), which does apply to nonprofits. In practice, a board adopts the full set as a matter of good governance and audit-readiness.
Do churches need the same financial policies as nonprofits? Yes. An incorporated church is a 501(c)(3), so the same core policies apply — conflict of interest, reimbursement, retention, gift acceptance, and whistleblower. The body that adopts them may be called a vestry, session, or board of trustees instead of a board of directors, but the legal role and the policies are the same. Churches do get exemptions other nonprofits don’t, like not filing a Form 990, but those don’t change the policy work.
Vestrybooks gives a nonprofit or church board view-only access to live, reconciled books, so the financial controls these policies describe are something the board can actually verify instead of take on faith. See how it works.
This is general information, not legal or tax advice — confirm your organization’s situation with a qualified professional.
This article is general information for church treasurers, not professional tax or legal advice. For your church's situation, consult a qualified accountant or attorney.
Nonprofit accounting, minus the headache.
Vestrybooks does fund accounting, donor tracking, and board-ready reports for churches and faith-based nonprofits.
A real free plan · no credit card · your data stays yours