🤝CharityInsurance.co.nz
← Back to Blog
Risk ManagementThe CharityInsurance Crew8 min read15 August 2026

Fraud in the Charitable Sector: The Cover Most Miss

Charities Services has published its own account of what it finds when it investigates the sector, and it makes for sobering reading. Its investigations have uncovered examples of significant fraud resulting in the loss of hundreds of thousands of dollars to the charitable sector — money donated, granted, or raised for charitable purposes that never reached the people it was intended for.

The uncomfortable part is that these are the cases that were found. Fraud in small organisations is frequently discovered by accident: a treasurer goes on leave and someone else opens the bank statements, an auditor asks a question nobody had asked before, a supplier calls about an invoice that does not match anything in the ledger. The cases that surface are unlikely to be the whole picture.

Why Community Organisations Are Exposed

The conditions that make charities vulnerable are the same conditions that make them work. Small teams operate on trust because trust is cheaper than process. One volunteer or part-time staff member often holds the finance function entirely — raising invoices, approving payments, reconciling the bank account, and preparing the reports the board reviews. Segregation of duties, the single most effective control against internal fraud, is difficult to achieve when there are three people in the office and one of them is the person you are trying to segregate.

Longevity compounds it. The treasurer who has served the club faithfully for fifteen years is the person nobody questions, and is also the person with the longest uninterrupted access to the accounts. Boards rotate; the finance volunteer often does not.

Cash-handling activities add another layer. Raffles, door sales, sausage sizzles, collection buckets, op shop tills, and event gate takings all generate cash that exists in no system until someone records it. The gap between money received and money banked is where a meaningful share of sector losses occur, and it is close to invisible after the fact.

The External Threat Has Changed Shape

Internal fraud is only half the problem. CERT NZ has received more than 10,000 cyber security reports in a year covering phishing, scams, unauthorised access to email and bank accounts, denial of service attempts, ransomware, and compromised websites. Charities appear in that data both as targets and as brands being impersonated.

Fake charity scams follow disasters with grim reliability. After major events in New Zealand, CERT NZ has warned about emails circulating with links to fake banking logins or fraudulent accounts set up to intercept donations intended for legitimate appeals. The damage to the genuine charity is real even though no money left its own accounts: donors who gave to a fake page believe they gave to you, and the reputational cleanup falls on the organisation whose name was used.

Invoice redirection is the variant that hits charities hardest financially. An attacker gains access to an email account — often through a reused password on a volunteer’s personal address — watches the correspondence, and sends a plausible request to change bank account details on a genuine invoice or a supplier payment. The payment is authorised by someone acting in good faith on what looks like an ordinary email. Because the organisation authorised the transfer itself, recovery from the bank is difficult and often impossible.

What Crime and Fidelity Cover Actually Does

Crime cover, also written as fidelity guarantee, responds to the direct financial loss an organisation suffers from dishonest acts. In a well-structured policy for a not-for-profit, that typically extends to theft of money, securities, or property by employees, volunteers, or committee members; forgery and alteration of cheques or payment instructions; loss of funds through fraudulent electronic transfer; and, in broader wordings, social engineering losses where a staff member was deceived into making a payment.

Good policies also fund the work that follows the loss. Investigation and forensic accounting costs are frequently the larger number in a small organisation’s claim, because establishing what happened over several years of transactions is expensive and the organisation cannot begin recovery, reporting, or insurance claims without it.

Two limitations matter. Cover generally responds to the direct loss of funds, not to consequential effects such as lost grant income or the cost of rebuilding donor confidence. And insurers expect a baseline of controls; a policy is not a substitute for dual authorisation on payments, and an application that overstates the controls in place creates a disclosure problem at claim time.

Crime Cover Is Not Cyber Cover, and Neither Is D&O

This is where most organisations discover a gap. A cyber policy responds to a breach of systems and data — forensic response, notification obligations under the Privacy Act 2020, restoration of systems, and often extortion. It is not primarily designed to reimburse money stolen from a bank account. A trustee liability policy responds to claims against individuals arising from governance decisions; it does not restore funds taken by an employee.

An invoice redirection fraud can sit at the intersection of all three: an email account was compromised, a payment was authorised, and the board may face questions about oversight. Whether any of your policies responds — and which one — depends on how the wordings interact. That question is worth asking your broker explicitly rather than assuming the package covers it.

The Controls Worth Having Regardless

Insurers price crime cover partly on controls, so the same steps that reduce risk also reduce premium. Dual authorisation on every payment above a modest threshold, with no exceptions for the chief executive or the treasurer, is the single most valuable control. Bank account changes for any supplier should be verified by a phone call to a number already on file, never to a number supplied in the email requesting the change. Someone other than the person who prepares the accounts should review bank statements each month. Two people should count and sign for cash at every event. Access to banking systems should be reviewed whenever anyone leaves a role.

None of these require a finance team. They require a board willing to say that trust in individuals and process discipline are separate things, and that having controls is not an accusation against anyone.

The Cost Comparison

Crime and fidelity cover is typically among the least expensive lines in a not-for-profit insurance package, particularly when written as part of a combined management liability policy rather than purchased standalone. Set that against the scale of losses Charities Services has documented in its investigations, and the case is straightforward. For most small and mid-sized organisations, a single modest fraud would exceed several decades of premium.

If your organisation handles cash, holds grant funds, or processes supplier payments without a formal dual-authorisation rule, this is a conversation worth having before your next renewal. To review your crime and fidelity exposure, get a quote from one of our specialist charity insurance brokers.

About the Author

The CharityInsurance Crew — the CharityInsurance crew are your friendly insurance geeks on a mission to make specialist cover simple and accessible for every NZ charity, sports club, and community organisation.

Ready to Get Protected?

Get tailored insurance options from licensed NZ brokers who specialise in charities and not-for-profits.

No obligation. Brokers we personally know and trust.