Financial Controls Policy
Dual authorisation, banking, and who can commit the association's money.
- Version
- 1.0
- Last reviewed
- 2026-08-10
- Review
- Annually, at the AGM
- Licence
- CC BY 4.0
Almost every P&C fraud story starts the same way: one trusted person, one login, and nobody looking. Not because committees are careless, but because "we all know each other" feels like a control and isn't one. This policy puts two people on every transaction — which protects the money, and protects the treasurer from ever having to prove their innocence.
It's written for an incorporated Australian P&C, P&F or PTA holding funds in its own name. If your association banks online, the single most valuable clause here is 4.3: a genuine two-to-authorise setting, where the second approver logs in with their own credentials. A shared login that two people happen to know is not dual authorisation, and it's the setup most committees mistakenly believe they already have.
Whether an institution offers real maker–checker approval for community and not-for-profit accounts matters far more than the interest rate. Ask prospective banks directly: can one signatory initiate a payment and a second, separately, approve it with their own login? Can administrative changes — adding or editing a payee — also require two people? If the answer is no, the account can't support this policy.
How to adopt it
- Fill in the blanks. Everything in [square brackets] is yours to set. Type straight into them below and your answers come through in the Word or PDF download — then read what to change before you put it to a vote.
- Circulate it with the agenda so members can read it before the meeting. A policy sprung on the room gets deferred.
- Move it, second it, record it. Adopting a policy is an ordinary motion. Use this wording:
That the Association adopt the Financial Controls Policy (version 1.0) as circulated, effective immediately.
Record the version number in the minutes. When you revise the policy later, that number is what tells you — and your auditor — which text was in force when a decision was made.
What to change before you adopt it
This template is deliberately conservative. Read these before it goes to a vote — a policy your committee can't actually follow is worse than none.
- The spending limits in clause 5. The [$1,500] / [$10,000] brackets suit a mid-sized primary school P&C with a healthy fundraising year. A small association should come down substantially; one running a canteen or a major capital project may go higher. Set them where your committee would genuinely be uncomfortable spending more without asking the room.
- The number of signatories. Three is the practical minimum — two means a single holiday stops all payments. More than four gets hard to keep current.
- Your constitution wins. Many P&C constitutions and state P&C federation rules already prescribe signatories, audit requirements and meeting approval thresholds. Where this template and your constitution differ, your constitution governs — amend the template, not the other way round.
- Audit vs. examination. Clause 7.4 says "examined or audited" because the requirement varies by state and by turnover. Check what your incorporating legislation and your state body actually require before you commit the Association to a full audit you have to pay for.
- Cash timeframes. Three business days assumes a branch or a smart ATM within reach. Rural committees may need longer — say so explicitly rather than adopting a rule you'll break every fete.
- Who checks the Treasurer. Clause 7.3 is the clause people want to soften because it feels rude. Don't. Frame it in the meeting as protection for the Treasurer, which is exactly what it is.
These templates are general information for Australian school parent bodies. Your constitution, your state's education department, your state P&C or P&F body, your incorporating legislation and your insurer may all impose requirements that override anything here. Where a policy touches money, children or personal information, have someone qualified look at it before you rely on it.
Licensed CC BY 4.0. You may copy, adapt and redistribute this policy — including for your own association's use — as long as you credit the source. A line reading "Adapted from the Bilby Bunch open policy library (bilbybunch.com/policies)" in your policy footer is plenty.
Why two approvers matters more than anything else here
Dual authorisation is the control that does the most work for the least effort. It doesn't require anyone to be suspicious, it doesn't need a finance background, and it fails safe: if one person is compromised, phished or simply mistaken, nothing moves. Every other control in this policy — reconciliations, reports, quotes — detects a problem after the fact. This one prevents it.
It also defends against the fraud most likely to actually hit a P&C, which isn't an office-bearer stealing. It's invoice redirection: a convincing email, apparently from a real supplier, asking you to update their bank details before the next payment. Two people, and a phone call to a number you already had, stops it.
Related
- Reserves and Investment Policy — what to do with money you're not spending yet.
- Reimbursement and Expenses Policy — the everyday end of the same problem.
- Conflict of Interest Policy — referenced at clause 5.4.
- Email for your P&C — why the treasurer's mailbox shouldn't be shared.