Internal Financial Controls for Irish Charities: The Practical Implementation Guide
The Charities Regulator's Internal Financial Controls Guidelines tell you what controls Irish charities need. The Charities Governance Code then asks you to prove you have them. This guide shows you how to actually put both in place — before Charities SORP becomes mandatory in 2026.
“Charity trustees are responsible for ensuring that their charity has adequate internal financial controls in place. Sound controls protect the charity's assets and public trust in the sector.”
— Charities Regulator, Internal Financial Controls Guidelines for Charities
Free IFC Self-Assessment
36 questions, 8 minutes. Scored against the Regulator's five IFC areas and the Governance Code overlay so you know exactly where to focus.
Ireland has more than 11,000 registered charities, managing roughly €18 billion of activity between them. The Charities Regulator's Internal Financial Controls Guidelines for Charities is the single document trustees, finance leads, and statutory auditors reach for when something looks wrong. It sits under the trustees' statutory duties in the Charities Act 2009 — and alongside the separate Charities Governance Code, which trustees must declare against every year.
This guide is a practical companion to the Regulator's version. It walks through what the IFC Guidelines actually require, how the Governance Code overlay changes day-to-day finance work, what auditors look for in each area, and the four control gaps that most commonly appear in audit findings and Regulator concerns. At the end, there's a free 36-question self-assessment your team can run in under ten minutes.
Who this is for: charity finance directors, treasurers, finance managers, and trustees with financial oversight responsibility in Irish charities. Useful for statutory auditors and independent examiners too.
What are the IFC Guidelines?
The Internal Financial Controls Guidelines for Charities is the Charities Regulator's official guidance on the financial controls trustees should put in place to protect the charity's assets, prevent fraud and error, and run accountably. It is practical and short — designed to be usable by trustees and treasurers without a finance background.
The current edition was issued by the Regulator in 2017 and remains the active standard. Read alongside it: the Charities (Amendment) Act 2024, which updated audit and reporting thresholds, and the move to Charities SORP for accounting periods commencing on or after 1 January 2026.
The Guidelines apply to all charities registered with the Charities Regulator — not just the large ones. The expectations scale with the charity's size and complexity, but the underlying principles apply equally to a €200k community group and a €15m national organisation.
Legally required
Keeping proper financial controls — the statutory duty comes from the Charities Act 2009 and trustees' general duties of care and prudence.
Recommended good practice
Most of the specific control activities in the Guidelines — expected by auditors and the Regulator, but not set out line-by-line in the Act itself.
The official guidance is at charitiesregulator.ie — Internal Financial Controls Guidelines for Charities. Keep it open while you read this guide.
Why this matters more in 2026
Four pressures have made internal financial controls more important for Irish charities — and harder to run on goodwill and spreadsheets.
Charities SORP becomes mandatory
For accounting periods commencing on or after 1 January 2026, Charities SORP becomes the reporting standard for many Irish charities. SORP requires far more detailed disclosure of restricted funds, related parties, trustee remuneration, and risk — and those disclosures only work if the underlying controls have been capturing the data all year.
New audit thresholds under the 2024 Act
The Charities (Amendment) Act 2024 set new reporting tiers: charities above €250,000 in income or expenditure must prepare a simplified income and expenditure account; those above €500,000 require a full statutory audit. Verify the current thresholds against the Regulator's published guidance — sub-thresholds can change.
62% of concerns relate to control failures
In the Charities Regulator's 2024 Annual Report, 42% of concerns received about Irish charities related to governance failures (often excessive individual control by a CEO or chair), and a further 20% related to financial controls and transparency. Together, almost two-thirds of all concerns to the Regulator are about controls and oversight.
Cyber-crime and supplier-detail fraud
The single most common attack against Irish charity finance teams is an emailed “supplier” request to change bank details — a spoofed address, a plausible invoice, and an urgent tone. Verifying bank-detail changes by a separate channel (a phone call to a number held on file, never a reply email) has moved from optional to baseline.
The five core areas of the Regulator's Guidelines
The Guidelines are structured around five areas of financial activity. For each: what the Regulator expects, a worked example, and the gap most Irish charities have.
1. Income
All income — donations, public grants, philanthropic funding, trading, investments, CHY-relief gifts — must be recorded promptly, banked intact, and tied to the underlying activity. Restricted grant income must be identified and tagged at the point of receipt, not retro-fitted at year-end.
Example: A €40,000 restricted grant from Pobal arrives on a Tuesday. By the end of the week the receipt is posted, coded to the right restricted fund in the chart of accounts, and the grant agreement saved with the donor record.
Common gap: Restricted grants posted as unrestricted, then re-classified during the audit prep. A control failure even if the numbers eventually reconcile.
2. Expenditure and procurement
The area auditors pay most attention to — because it is where most charity money flows out and most charity fraud occurs. The Regulator expects authorisation before commitment, separation of the person who orders from the person who pays, supplier vetting, and an audit trail for every transaction above a defined threshold.
Example: A purchase over the delegation limit is authorised in writing before the order is placed — not retrospectively when the invoice arrives. The authorisation is visible to the person processing the payment, and stored somewhere an auditor can find it twelve months later.
Common gap: Approvals scattered across Outlook threads. The trail exists but is unfindable. Systems that enforce dual authorisation at the point of order — like ProcurementExpress — remove the risk of single-person sign-off without requiring manual policing.
3. Banking and cash
Two authorised signatories on every payment above a defined threshold. Multi-factor authentication on every online banking user. Monthly reconciliations performed by someone other than the person who processes payments. Petty cash held under lock and reconciled monthly.
Example: The bank mandate is reviewed and re-signed at the AGM each year, and immediately whenever a signatory changes role. Online-banking access is removed within one working day of a leaver's last day.
Common gap: Bank mandates and online-banking users that haven't been reviewed since the charity was set up. Former staff still on the mandate.
4. Assets and investments
A fixed-asset register that reconciles to the accounts. A written investment policy that sets the trustees' risk appetite. Restricted reserves ring-fenced and reported separately at every finance review. Disposals and asset gifts approved in writing before they happen.
Example: A laptop bought from a restricted programme grant is added to the asset register, tagged to that fund, and its disposal three years later requires the same trustee approval that any other charity asset would.
Common gap: Asset register out of date and no investment policy — or one that hasn't been reopened since the chair was different.
5. Monitoring and trustee oversight
Trustees see management accounts at least quarterly. A finance or audit sub-committee meets at least three times a year and minutes its meetings. A risk register exists and is reviewed annually. Control breaches and near-misses are reported promptly — not bundled into the year-end update.
Example: A one-page board finance pack — income, expenditure, balance sheet, variance to budget, restricted-fund position — issued monthly even when nothing has changed.
Common gap: Trustees told the numbers only at the AGM. Nine months of drift before anyone with a fiduciary duty actually sees a balance sheet.
The Charities Governance Code overlay
The Charities Governance Code is the second layer Irish charities carry that UK charities do not. The Code sets six principles of good governance, with standards charities are expected to comply or explain against in their annual report. It is published by the Charities Regulator and reaffirmed across the sector since 2020.
For finance teams, four specific touchpoints inside the Code shape day-to-day work — and these are the ones auditors and Regulator concerns most often flag.
Compliance Record Form
The artefact that evidences compliance with the Code, standard by standard. It maps each Code standard to the documentary evidence inside the charity. Trustees tabled at the meeting that approves the annual report. Keep it current — it is the single most important governance artefact for Irish charities.
Annual declaration of compliance
A formal statement in the annual report — comply or explain — for every Code standard relevant to the charity. The declaration draws directly on the Compliance Record Form.
Conflicts-of-interest register
Reviewed at the start of every trustee meeting. Conflicts minuted and managed — not just noted. Particularly important on any procurement decision involving a connected supplier.
Financial section of the annual report
Must meet the Regulator's content expectations and, from accounting periods commencing 1 January 2026, the Charities SORP requirements for many larger charities. The financial narrative — not just the numbers — is the part trustees carry personal responsibility for.
The Code is published at charitiesregulator.ie — Charities Governance Code.
The four controls every Irish charity gets wrong
From the patterns that show up in Regulator concerns, statutory audit reports, and our own work with Irish charity finance teams, these are the four IFC controls that fail most often.
1. Single-signatory bank payments
What the Guidelines say: Payments above a defined threshold should require two authorised signatories.
Why charities miss it: The online-banking threshold was set when the charity was smaller, and never refreshed. A second signatory was “temporarily” bypassed when one of them was unavailable, and the workaround stuck.
What good looks like: Dual authorisation enforced by the system — not by a colleague remembering to check. Where headcount genuinely is too thin, a trustee reviewer countersigns above a defined threshold.
2. Undocumented scheme of delegation
What the Guidelines say: Authority limits should be written, board-approved, and known to the people who use them.
Why charities miss it: Limits get agreed in a budget meeting, recorded loosely, and drift over time as roles change.
What good looks like: A one-page scheme of delegation, reviewed and signed off by trustees annually, visible to every approver. Approval workflows that automatically apply delegation limits remove the remembering-them part.
3. Restricted-fund tracking in spreadsheets
What the Guidelines say: Restricted income should be identified and tagged at receipt, with restricted reserves ring-fenced in the accounts.
Why charities miss it: Accounting systems aren't configured to ring-fence funds, so the finance team runs a parallel spreadsheet — which drifts from the accounting system the moment something unexpected happens.
What good looks like: Fund codes set up in the accounting system on day one of the grant, every transaction tagged at posting, monthly fund-by-fund report to the finance lead.
4. Informal expense reimbursement
What the Guidelines say: A written expense policy, line-manager approval before payment, receipts on every claim above a defined threshold, and trustee approval for senior staff (especially the CEO).
Why charities miss it: Small teams treat expenses as a peer-trust matter rather than a control. The CEO submits to their own line manager — i.e., themselves — or to a co-signing colleague who never declines.
What good looks like: A two-page expense policy, line-manager approval routed through a system rather than email, and CEO expenses sent to a designated charity trustee for sign-off with a clear record of what was reviewed.
Your IFC implementation roadmap
A realistic ninety-day path for an Irish charity finance team that already has a day job. Adjust to your size and starting point.
Self-assessment and gap analysis
Run the IFC self-assessment with the finance lead, the CEO, and at least one charity trustee. Score each section. Identify the three weakest areas.
Policy review and trustee sign-off
Update or write the financial controls policy and scheme of delegation. Refresh the Compliance Record Form. Get the board to formally approve, and minute the decision.
System and process changes
Move single-person approvals to dual authorisation. Formalise supplier onboarding and bank-detail verification. Move the audit trail off email and spreadsheets onto something exportable.
Annual review and declaration
Re-run the self-assessment annually. Refresh the Compliance Record Form. Complete the Governance Code declaration in the annual report. Update whenever the Regulator publishes new guidance.
How does your charity score against the IFC Guidelines?
Thirty-six questions across the Regulator's five IFC areas and the Charities Governance Code overlay. Scored out of 108 with a per-section breakdown so you know exactly where to focus first. Designed to be done in eight minutes.
Procurement-weighted · Built for Irish charities · GDPR compliant
IFC and Governance Code FAQ
Who must comply with the IFC Guidelines?
All charities registered with the Charities Regulator are expected to operate sound internal financial controls under the Charities Act 2009. The Guidelines describe what good looks like for charities of every size — expectations scale with income, complexity, and risk profile, but the underlying principles apply to a €200k community charity and a €15m national one alike.
How is this different from UK CC8?
The principles overlap heavily, but the documents, regulator, and surrounding legal framework are different. Ireland has the Charities Regulator (not the Charity Commission), the Charities Act 2009 (not the Charities Act 2011), and — uniquely — a separate Charities Governance Code that trustees must declare against every year. Audit thresholds are set in euros. Charities SORP becomes mandatory in Ireland for accounting periods commencing on or after 1 January 2026. Always work from the Irish documents, not their UK equivalents.
When does Charities SORP apply in Ireland?
Charities SORP is being adopted in Ireland for accounting periods commencing on or after 1 January 2026, with tiered reporting expectations that scale with income. The Charities (Amendment) Act 2024 set €250k as the threshold above which a simplified income and expenditure account is required, and €500k as the threshold above which a full statutory audit is required. Verify current thresholds against the Regulator's published guidance before relying on them.
What is the Compliance Record Form?
The Compliance Record Form is the artefact that evidences a charity's compliance — or explained non-compliance — with the Charities Governance Code. It maps each Code standard to documented evidence inside the charity, and trustees use it to support the annual declaration of compliance in the annual report. The Regulator publishes a template you can start from.
Do small charities below €10k need to do this?
Yes — though proportionate to the scale of the operation. The Charities (Amendment) Act 2024 introduced an exemption from audit or examination for the very smallest charities (broadly, under €10k of income or expenditure where additional micro-charity conditions are met), but trustees of every registered charity remain responsible for sound internal financial controls under the Charities Act 2009. The self-assessment is still useful at small scale — it just won't take very long to fill in.
Further reading
Internal Financial Controls Guidelines (official)
The Charities Regulator's full guidance on internal financial controls for Irish charities. Read alongside this guide.
Read on charitiesregulator.ieCharities Governance Code
The Regulator's governance framework. Trustees must declare comply-or-explain against it in the annual report.
Read on charitiesregulator.ieCluster guides (coming soon)
- The Charities Governance Code financial-control standards, explained
- Charities SORP for Ireland: what's changing for accounting periods from 2026
- Dual authorisation of charity payments — what the Regulator expects
- Segregation of duties in a small Irish charity
- The Compliance Record Form: a practical guide
- Charity expenditure controls under the Charities (Amendment) Act 2024
- Preparing for your annual report — an IFC-aligned checklist
Automate the controls the Regulator checks
ProcurementExpress enforces dual authorisation at the point of order, applies delegation limits automatically, ring-fences restricted funds, and keeps a complete audit trail that exports to your auditor in one click — the controls Irish charities most often miss, solved by default.
