Free policy template · CC BY 4.0

Financial Controls Policy

Dual authorisation, banking, and who can commit the association's money.

Version
1.0
Last reviewed
2026-08-10
Review
Annually, at the AGM
Licence
CC BY 4.0

Almost every P&C fraud story starts the same way: one trusted person, one login, and nobody looking. Not because committees are careless, but because "we all know each other" feels like a control and isn't one. This policy puts two people on every transaction — which protects the money, and protects the treasurer from ever having to prove their innocence.

It's written for an incorporated Australian P&C, P&F or PTA holding funds in its own name. If your association banks online, the single most valuable clause here is 4.3: a genuine two-to-authorise setting, where the second approver logs in with their own credentials. A shared login that two people happen to know is not dual authorisation, and it's the setup most committees mistakenly believe they already have.

Choosing a bank? Ask about this first

Whether an institution offers real maker–checker approval for community and not-for-profit accounts matters far more than the interest rate. Ask prospective banks directly: can one signatory initiate a payment and a second, separately, approve it with their own login? Can administrative changes — adding or editing a payee — also require two people? If the answer is no, the account can't support this policy.

How to adopt it

  1. Fill in the blanks. Everything in [square brackets] is yours to set. Type straight into them below and your answers come through in the Word or PDF download — then read what to change before you put it to a vote.
  2. Circulate it with the agenda so members can read it before the meeting. A policy sprung on the room gets deferred.
  3. Move it, second it, record it. Adopting a policy is an ordinary motion. Use this wording:

That the Association adopt the Financial Controls Policy (version 1.0) as circulated, effective immediately.

Record the version number in the minutes. When you revise the policy later, that number is what tells you — and your auditor — which text was in force when a decision was made.

The policy

Financial Controls Policy

1. Purpose

This policy sets out how [association name] ("the Association") holds and moves its money. Its aims are to protect the Association's funds, to protect the volunteers who handle them from suspicion and from temptation alike, and to make sure every payment can be explained to a member, an auditor or a grant body long after the people involved have moved on.

2. Scope

This policy applies to all funds held by the Association, including fundraising proceeds, grants, membership fees, canteen and uniform shop takings, event cash and any interest earned. It binds all office-bearers, committee members, sub-committee members and volunteers who handle money on the Association's behalf.

3. Core principles

  1. No one acts alone. Every movement of the Association's money requires two people: one to initiate it and a second, independent person to approve it.
  2. Duties are separated. The person who prepares a payment is not the person who approves it, and — so far as a volunteer committee allows — neither is the person who reconciles the account.
  3. Every payment traces to a decision. Any payment must be covered by an approved budget, a resolution of the committee, or a delegated authority under clause 5 of this policy.
  4. The record is contemporaneous. Decisions are recorded in the minutes when they are made, not reconstructed afterwards.

4. Bank accounts and signatories

  1. All Association funds are held in accounts in the Association's own name with an Authorised Deposit-taking Institution (ADI). No Association money is ever held in a personal account, a personal payment app, or a fundraising platform's wallet beyond the time needed to transfer it.
  2. The Association maintains at least [three] and no more than [four] authorised signatories, normally the President, Treasurer, Secretary and [Vice-President]. Holding more than two means a payment is not blocked by one person's holiday.
  3. Every account is configured to require two approvers. Where the Association banks online, this means a genuine two-to-authorise setting: one signatory initiates and a second signatory approves using their own credentials on their own device. A shared login operated by one person is not dual authorisation and must not be used.
  4. Two people who are related, who live together, or who are in a close personal or business relationship must not be the two authorisers on the same transaction.
  5. Signatories are reviewed and updated within [14 days] of every Annual General Meeting, and whenever an office-bearer resigns. Removing a departing signatory's access is the responsibility of the [President].
  6. Where the Association's bank supports it, administrative changes — adding a payee, changing a payee's account details, changing user permissions — also require two administrators.

5. Spending limits and delegated authority

  1. Expenditure is authorised as follows. All amounts are GST-inclusive and apply to the total cost of an item or project, which must not be split to fall under a limit:
    • Up to [$1,500] — may be approved by the President or Treasurer within an approved budget line, and reported at the next general meeting.
    • Up to [$10,000] — may be approved by the executive committee between general meetings, and reported at the next general meeting.
    • Above [$10,000] — requires a resolution of a general meeting of the Association.
  2. Regardless of the limit, every payment still requires two authorisers under clause 4. A delegated authority permits the decision; it never removes the second pair of eyes.
  3. Purchases above [$5,000] require at least [two] written quotes, which are tabled with the recommendation.
  4. Any expenditure involving a member's own business, employer or family member is subject to the Association's Conflict of Interest Policy and must go to a general meeting regardless of amount.

6. Receiving money

  1. Cash taken at an event is counted by two people before it leaves the event, who both sign a count sheet recording the amount and the event.
  2. Cash is banked within [three business days]. It is not held at a private residence for longer than necessary and is never used to pay expenses directly.
  3. Electronic payment is preferred wherever practical. Payments are made to the Association's account, never to an individual's account for later transfer.
  4. Receipts are issued on request, and always for donations and for any payment over [$50].

7. Reconciliation and reporting

  1. The Treasurer reconciles every account monthly against bank statements.
  2. A written financial report — income, expenditure, account balances and any matters of concern — is tabled at every general meeting and recorded with the minutes.
  3. Bank statements are obtained independently by the [President] at least [twice a year] and compared with the Treasurer's reports. This is not a statement of distrust; it is what allows the Treasurer to demonstrate that the accounts are sound.
  4. The Association's accounts are examined or audited annually as required by its constitution and by [applicable state legislation], and the outcome is presented to the Annual General Meeting.

8. Records

  1. The Association keeps invoices, receipts, quotes, count sheets, bank statements and reconciliations for at least [seven years].
  2. Financial records are held in the Association's own systems, not in a personal email account or on a personal device, so that they survive a change of office-bearers.
  3. The outgoing Treasurer hands over all records, access and passwords within [14 days] of the AGM, and the handover is recorded in the minutes of the following meeting.

9. Suspected fraud or error

  1. Any person who suspects an error, an unauthorised transaction or fraud reports it immediately to the President and Secretary. If the concern involves the President, it is reported to the Secretary and [the Vice-President].
  2. The executive committee suspends the relevant access, secures the records, and reports to the next general meeting. External reporting obligations — to the bank, to insurers, to [the relevant state regulator] and to police — are considered immediately and are not delayed for the sake of avoiding embarrassment.

10. Review

This policy is reviewed [annually, at the first meeting after the AGM], and whenever the Association changes banks or changes the way it takes payments.

What to change before you adopt it

This template is deliberately conservative. Read these before it goes to a vote — a policy your committee can't actually follow is worse than none.

  • The spending limits in clause 5. The [$1,500] / [$10,000] brackets suit a mid-sized primary school P&C with a healthy fundraising year. A small association should come down substantially; one running a canteen or a major capital project may go higher. Set them where your committee would genuinely be uncomfortable spending more without asking the room.
  • The number of signatories. Three is the practical minimum — two means a single holiday stops all payments. More than four gets hard to keep current.
  • Your constitution wins. Many P&C constitutions and state P&C federation rules already prescribe signatories, audit requirements and meeting approval thresholds. Where this template and your constitution differ, your constitution governs — amend the template, not the other way round.
  • Audit vs. examination. Clause 7.4 says "examined or audited" because the requirement varies by state and by turnover. Check what your incorporating legislation and your state body actually require before you commit the Association to a full audit you have to pay for.
  • Cash timeframes. Three business days assumes a branch or a smart ATM within reach. Rural committees may need longer — say so explicitly rather than adopting a rule you'll break every fete.
  • Who checks the Treasurer. Clause 7.3 is the clause people want to soften because it feels rude. Don't. Frame it in the meeting as protection for the Treasurer, which is exactly what it is.
Not legal advice

These templates are general information for Australian school parent bodies. Your constitution, your state's education department, your state P&C or P&F body, your incorporating legislation and your insurer may all impose requirements that override anything here. Where a policy touches money, children or personal information, have someone qualified look at it before you rely on it.

Use it, change it, share it

Licensed CC BY 4.0. You may copy, adapt and redistribute this policy — including for your own association's use — as long as you credit the source. A line reading "Adapted from the Bilby Bunch open policy library (bilbybunch.com/policies)" in your policy footer is plenty.

Why two approvers matters more than anything else here

Dual authorisation is the control that does the most work for the least effort. It doesn't require anyone to be suspicious, it doesn't need a finance background, and it fails safe: if one person is compromised, phished or simply mistaken, nothing moves. Every other control in this policy — reconciliations, reports, quotes — detects a problem after the fact. This one prevents it.

It also defends against the fraud most likely to actually hit a P&C, which isn't an office-bearer stealing. It's invoice redirection: a convincing email, apparently from a real supplier, asking you to update their bank details before the next payment. Two people, and a phone call to a number you already had, stops it.

Related