Transcription
Hi, I'm Jerry Sparks, president of AG Financial Insurance, a certified insurance risk manager and insurance agent for over 30 years. And what a subject. We have Rich Hammer here with us, a CPA and a renowned attorney.
So, when we're looking at what we're going to be talking about here, keeping church fraud in check today, I mean, the people you would look for is an attorney, an accountant, and an insurance agent. And we've thrown in a risk manager to boot. So, this is right up our alley. And we're going to get right into it. If you have questions, be sure to email them to us and we'll try to answer your questions as we go along.
But why church leaders should take the risk of embezzlement seriously? Let me give you a little research of why church leaders should do this. The Gordon Conwell Theological Seminary did some research through its center for the study of global Christianity. Here's what they found: It is projected that ecclesiastical crime is projected to be $37 billion worldwide, or nearly 6% of the total giving of churches. In contrast, only $32 billion is spent on missions work to introduce Christianity to more people. So, if the way I look at this is that there's more money going out the door from crime than what there is going out to missions. So, if we can just stop all of this crime, we can double the amount we do for missions, and we can do the Lord's work twice as fast. Twice as fast. What do you think? And a lot less people in prison. There you go.
What is also interesting, according to this report, is much of the fraud goes unreported. 95% of fraud within churches goes undetected or unreported to the insurance companies and/or to the local authorities. So let's get right into it.
You mean crimes, financial crimes that are known to church leaders, but they do not report it to the authorities?
Absolutely. And of course, conversely, most cases of embezzlement are never disclosed to the church leadership, because people obviously go to such great lengths to conceal their crime. It is very difficult to figure it out. I know in my own case, I did a survey on this for several years ago, and right at 15% of churches knew that they'd had a case of financial misappropriation or embezzlement during the previous five years. Who knows what the actual—those were known cases, Jerry, in terms of actual cases, it had to be many times that number.
Yeah, it is amazing when you look at the internet and see how many things are happening from a church crime standpoint. It seems like when the economy is bad, crime goes up, no matter whether it's in the church or elsewhere. So, let's look at some of the reasons, or actually why don't you define embezzlement, and then let's go into why church leaders or pastors should take this seriously.
Well, in terms of a definition, it varies somewhat from state to state, but the general idea in all states is that embezzlement, and by the way, it goes by different names as well. It's not called embezzlement in every state, refers to the conversion of funds or assets that are lawfully in your possession. So, the idea is, in the case of money or church funds, you have possession of those funds, which is not wrongful in of itself—you count the offering, you deposit the offering, etc.—but then you convert those funds to your own personal use or purposes. That's what is the common definition of embezzlement. Many people are confused by this, Jerry, in the sense that I see this happen all the time: when somebody is apprehended, church leaders will confront the person, "Well, I'll pay it back, or I didn't mean to steal it. You know, I just meant to borrow it because I had a financial issue and I was going to give it back." And church leaders say, "Oh, okay." Does that mean that embezzlement has not occurred? And the answer is no. The crime is complete when money is converted to the personal use of the embezzler. It doesn't matter; of course, that person's going to say, "I intended to give it back." I would say the vast majority of church embezzlers have some vague desire to pay that money back at some point in the future. That does not sanitize it. That does not eliminate the legal implications here, the criminal implications. The crime is complete when the conversion occurs.
Let's, you know, actually that brings up a good point. Why do people actually steal from the church? And number one is probably because they do not have the internal controls put together. So, there's a perceived opportunity where they can get by with it pretty easily. Number two, they may have pressure, financial pressure or some other reason that they need the money. And third is they rationalize it. "Well, I deserve this," or, "the pastor, yeah, they don't pay me enough. They haven't paid me enough for the last 15 years. I've got access to church accounts. We only need my signature for withdrawals for writing checks. I'm going to start paying myself what I deserve." I mean, how many times have I seen that situation? And so that gets into your point of rationalization—that I didn't do anything wrong. I just was balancing the books here. I was paying myself what I deserve. That does not—that does not—that's not a defense to embezzlement. Believe me.
And one other thing I'll mention, Jerry, in addition to those three factors you identified, some studies have shown that it is not the need or desire for money that is the primary driver behind church embezzlement or any embezzlement, but rather it's the continual exposure to funds in a completely unsupervised, unregulated environment. So, the fact that Bob has been counting your church offerings for the last 30 years back in that locked room, the fact that Bob has access to the money in an unsupervised environment—that becomes, in many cases, a powerful driver that results in embezzlement, more so, some studies indicate, than actually a need on Bob's part for that money.
You know, there it's funny when we started talking about doing this, and this is right up our alleys with you being an attorney and a CPA and myself being an insurance agent. I Googled how many church crimes have happened, you know, just how many church crimes, and it is amazing the number of church crimes. But let's go through some of the specific—Yeah. financial crimes. But let's look at some of the specific cases that are out there so we can give some examples because churches may say, "Gosh, we we don't really need to do much. Sally's been counting the money for 30 years. You know, we've never had a problem. We've never had a problem. So why, you know, how does this actually happen?" Give us some case studies. Let's go through.
Well, it's like cancer. Some forms of cancer that basically have no symptoms until you're months from death. And I think that's the way financial crimes in a church are. There are no symptoms. Nobody knows it's happening. Everybody thinks everything's fine. Sally's doing fine. Bob's doing fine back there counting the offerings. That's the way we've always done it. And it's only when the situation becomes terminal and near death that the crime is unveiled and the church is confronted with what to do. But let me give you some examples. I've dealt with so many of these, and I've read countless cases where people in the church, whether it's an accountant, bookkeeper, usher, pastor, member of the pastoral staff, whoever it might be, office secretary, cases of embezzlement, church business administrator. Let me just give a few. And I know you got some too, Jerry.
For example, here's one: An usher collected offerings each week in the church's balcony. And as he brought the offering plates downstairs, he just pocketed the cash. Or the same two people counted church offerings every week for years. There was no rotation. Or how about this: a pastor had sole signatory authority over the church's checking accounts and therefore he ultimately used the church checking account to pay personal expenses and to augment his own salary. Again, rationalizing this, "I'm only doing what is right and fair and proper." Or how about this: a church bookkeeper embezzled several thousand dollars by issuing checks to a fictitious company and then later withdrew those funds for personal use. Or a church business administrator embezzled over $350,000 from his church. He wrote unauthorized checks to himself from the church's accounts and used the church's credit card on over 300 occasions to purchase personal items. The problem in these cases is there just was not proper accountability with respect to church expenditures. By the way, in this case, this business administrator was sentenced to 32 years in prison as a result of his embezzling $350,000. And the court, in giving the sentence, observed that this person had embezzled a substantial amount from a prior church, but that church chose not to initiate criminal charges, believing this person had learned his lesson, and that facilitated the second case of embezzlement. And so I think that's something that is important for church leaders to factor in. Yes, there's a place for mercy, but that doesn't necessarily mean you—the person—an embezzler is not held accountable for his or her actions. It's a serious crime, and for you to treat it lightly and leniently may expose future churches to problems as well.
I remember a case, Jerry, in I think it was Louisiana, where a 55-year-old female bookkeeper in a church embezzled $3,000. I can't believe this, and she was sentenced to eight years at hard labor. Now, think of that poor grandma out on the rock pile. I've thought about this many times. That poor woman. Did she realize what the consequences were going to be? What a terrible case. I shouldn't mention some of these.
Or how about this one? How about this case: a church's chief financial officer, treasurer, embezzled $850,000 in church funds, mostly by increasing the church's line of credit, and then he proceeded to distribute funds to himself. The interesting thing in that case is he was able to do this because he had access to the digital versions of the signatures of four of the officers of the church. Do you have digital signatures? Do you have signature stamps that you use in your church? Those things are toxic. They're nuclear risks unless they are fully safeguarded and are not accessible by individuals that could fabricate and falsify and forge signatures on financial documents. This individual was sentenced to eight years in prison and was ordered to pay restitution of the full $850,000 back. So, so there are some cases I've dealt with recently.
Yeah, actually, by looking, I found one: $80,000 taken over the last six to seven years by a bookkeeper; $27,000—she was a treasurer in the church over a five-year period; $300,000 stolen from the treasure over a seven-year period; eight years—a woman with the Roman Catholic diocese embezzled over a million dollars; Pastor White, a pastor and his wife gambled away $430,000 from a Houston church; we actually had a large theft which was very public where people stole money out of a safe from a large mega church, $600,000; one of the world's largest mega churches had their pastor convicted of embezzling more than $12 million. So, I mean, when we look at these cases, most of the time it involves somebody that is trusted with the money and actually Fraud Talk has chronicled 21 major church embezzlements.
Can I interrupt J and just make a comment about that, about these cases that you and I have both mentioned? Is look at the value of some of these cases—millions and millions of dollars. You know, churches are doing an increasingly better and better job of providing a safe environment for children, protecting them from pedophiles and from CA incidents of child molestation. Many churches are doing a good job over the years; you have instituted very effective safeguards and protocols to protect children on your premises. And yet it's—and those cases, a single case of child molestation can be a substantial loss to the church in terms of the financial damages that you may be assessed that may exceed your insurance coverage limits. And some insurance policies and companies even say we don't even cover that type of risk because it's an intentional wrong. We've talked about that before. But the interesting thing to me, Jerry, is when you look at these $1 million, $8 million, $12 million, $18 million cases of embezzlement, there is a risk that many churches face today in this country that exceeds in potential value a child molestation case. And what are we doing about it? Have we applied the same scrutiny? Have we applied the same desire and energy to, in terms of risk management, to ensure that this risk is minimized?
I remember what you said at the beginning—that churches lose—the amount of money embezzled from churches exceeds the amount given to missions. I mean, think about that. And so the point is, what are we doing in our congregations to be sure that we are aware of this risk that we take steps to prevent it? And the good news is there are steps that can be taken. Let me just look at a little thing and then we'll go through the internal controls that churches should place. But of the 21 major church embezzlement cases that Fraud Talk looked at, 19 out of the 21 cases, or 90%—over 90%—it involved an alleged perpetrator who was the bookkeeper, finance person, or was the person in the fiduciary position. So 90% of them are the people that are your money people. One of the things that you brought up: four out of the 21 cases, or 19%, involve the alleged perpetrator that had a history of prior fraud. So, background checks, criminal records checks, getting references from former churches, and then the average duration that the embezzlement took place, or the church fraud took place, seven years. It took over a seven-year time period for people to actually find it.
So, what can a church do? What controls can they put in place to prevent these from happening?
Well, we can never—we're not talking about prevention. We're talking about risk management. This is called—our program is called Risk Management Live. It's not Risk Elimination Live. There are very few risks that we can eliminate. Well, in fact, there are some that we can, but we're not willing to do it. For example, you can not just manage and reduce, but you can eliminate the risk of child molestation in your church by just having a huge banner above your main entrance: No minors allowed. That's risk elimination, but we're not willing to go there. So, we're talking about risk. And the same is true for your local public school. You know, the national report given to Congress as a part of the No Child Left Behind legislation, they have to do a report to Congress on sex abuse cases in schools. It is unbelievable: 10% of elementary and secondary age school children in public schools claim to have been victims of sexual inappropriate conduct. 10%. I mean, that is a substantial number. It's much more than we see in churches.
One of the first things that I see that a church should probably do is have an independent auditor to perform a compilation review or do an audit of the books of the church. They can look at the internal controls. You're a CPA. Wouldn't you ask every church to do this so that they might be able to catch something?
Well, I think it's important for church leaders to understand there are different things that a CPA firm can do. They can do a full-fledged audit, or they can do limited engagements, what are called limited engagements, and those include compilations where they compile your financial statements and reviews of your financial statements. Those limited engagements, however, fall short of a full audit in a number of respects. Number one, they don't provide the assurance of accountability to the level of a full audit, which basically certifies that your financial statements are prepared in accordance with generally accepted accounting principles. You don't get that with reviews or compilations. So, it provides a greater sense of financial accountability, which so many church leaders are desiring to have today. The problems we're talking about here happen when there's no financial accountability. But the second thing about a financial full audit, and I think this is a—to me it may be the greatest benefit—is you will receive what's called a management letter from the CPA firm, which is a letter to the management of your church that indicates deficiencies in internal control. What are things that they've observed in your financial management that can contribute to misappropriation or financial crimes? So that that is so valuable. It gives you a road map for steps that you can take to minimize the risk of the very things we're talking about here. So I think that's worth it. Yes, it's expensive. But keep in mind, the second and subsequent years generally the price goes down because the CPA firm is familiar with your procedures and they don't have that startup cost that can elevate the cost of the first-year audit. But it's a question of how much you're willing to spend for accountability compared to some of the other expenses that you have. And maybe it's something you won't do every year. But I do strongly recommend an audit as opposed to a limited engagement, be that a review or a compilation. You know, one of the things that a church might look at is doing an audit every three years or every five years and then doing maybe a review, especially for our smaller churches. There are so many churches that have under 200 people, and they may not be able to pay for a full—a full audit because those are quite expensive, but at least get the framework on your internal controls set up where then they may be able to look at a review. Even if you do just one, you're right, to help set up—get the management letter that will help you set up a system, an architecture for internal controls that maybe you don't need to repeat this every year, and maybe in the off years you have a limited engagement such as a review or compilation, and if those indicate a problem then you can move into a full audit. Some smaller churches also appoint an audit committee. If you have financially astute people in the congregation, maybe CPAs, bankers, that can form an informal audit committee, and that can be helpful. That can be a substitute; it doesn't have the advantages of a full audit, but again, they can be sentinels looking for potential problems, and if they're encountered they can they can go to the church and request or suggest that a full audit be—
All right, let's get right into the internal controls that we believe are necessary to help hopefully prevent or catch church embezzlement from happening.
Well, let's talk about some common examples of poor internal control that can contribute to embezzlement. And the flip side is you do the opposite, and that's going to be an example of good internal control. So, for example, some of this is so basic, but it's so often omitted and ignored. Having one person count the church offerings—that violates one of the most basic and fundamental principles of internal control, and that's division of responsibilities. The more you spread responsibilities over more people, the more people that are assuming responsibilities, the less likely embezzlement is because there has to be collusion among more than one person. And that's often going to be difficult, especially in a church setting. And one of the things, too, is I say not only have two—two cash counters, but two unrelated cash counters, and then actually we will make available to anybody that needs it. There's an offering counting—counting—counting sheet that they can use that we'll make available on our website that you can use, and actually you can have each person—each counter sign off on the other person's counting, so you have a checks and balance there on everybody doing it, and a CPA will be glad to review this kind of documentation and provide others to assist you in maintaining that crucial system of internal control.
Now let me give you an example. You say, "Well, how in the world can a church have one person counting the offering? That just—most of us understand that is outrageous. How is it possible that so many churches in fact do this?" And I'll tell you the answer: It's because Bob has been doing this for the last 30 years. And we don't want to hurt Bob's feelings and say, "Bob, we think we need another person back there counting the offering with you." They're afraid. Church leadership are afraid. They're going to offend people; they're going to hurt people's feelings. Bob may leave the church. You're suggesting that I am not trustworthy. Hey, let's apply Ronald Reagan's theory of negotiating with the Soviets, and that is trust but verify. Who is—who would not welcome greater accountability and the fact that you know you need to be aware of this—that every time Bob's on vacation or maybe he's out for an extended period of time with an illness, and bang, cash offerings spike. Well, what does that tell you? You know, maybe Bob's not as trustworthy as we thought. But the point is, you want an atmosphere of accountability. You do not have one person counting the church offering.
Here's number two: There's not regular turnover or rotation among persons who count the offerings. You want a pool of people; you identify that you randomly select two, three, however large your church is to do the counting. You don't want the same people back there counting offerings all the time. Number three: One person collects the offerings. Well, how does that happen? Well, I've seen that happen. In fact, I dealt with a case several years ago of a fairly large case of embezzlement. And the way it had happened was the person that collected the offering in the balcony of the church, as he came down the stairway totally unobserved, he just pocketed all the cash, the loose cash laying in the offering plate. And over the course of a year, that amounted to several thousands of dollars. And it was a long time, as you say, Jerry, seven years is the average. It was a long time before that person was apprehended. Or number four: Offerings—offering counts are submitted to the person who deposits the offering. Again, a breakdown in the fundamental requirement that there be a division of responsibility. Or number five: Offering counts and bank deposit slips are not regularly reconciled. Number six: Only one signature is needed to write a check. How many of these cases of embezzlement that we've reviewed today were based on one signature?
One of the things that I was not only requiring two signatures on checks, and I—I put a predetermined amount. I know you'd rather have two signatures all the time, but so you do some day-to-day operations, but make sure that—
So what you're saying is maybe two signatures above a specified level, correct, of $50, $100?
Churches vary on this depending on a number of factors, right? And I'm okay with that. The other thing I would add is make sure that the signature documentation or the signature card that you have with the bank shows that restriction so that they are following that restriction. So, not only do you have that in your financial policy, you actually let the bank know that this is happening so that they don't cash any of those checks over that predetermined amount.
Yes. Good. Good.
Or how about this: Members who contribute coins and currency other than checks do not use offering envelopes. So what does that mean? You got loose $20 bills in the offering plate or bag, and it just becomes a temptation for some people because it's so accessible, and especially if you're allowed to carry that offering plate to maybe a counting room, and there's a period of time where you're not subject to the—the sight or the supervision—the oversight of somebody else. Number eight: Contribution receipts are not issued to members, or members receive them, but they're not encouraged to report discrepancies to the church board. And that can be a problem that can contribute to embezzlement if members are not given receipts indicating how much they've given because people can use—
That information to extract funds from the church.
Uh, number nine, offerings are not deposited immediately. And I would actually also say they need to be stamped "for deposit only" as soon as they get into the room. So if anything does happen to them, people are going to have a harder time cashing those checks. So make sure you stamp "for deposit only" on those checks as immediately as possible. That is a very excellent point.
Uh, number 10, uh, monthly bank statements are not reviewed by someone having no responsibility for handling cash. Again, division of responsibilities.
And the final one I'm going to mention is uh number 11, reimbursing employees for travel expenses or purchases of church equipment or supplies without requiring adequate substantiation. In other words, whether you think you've got an accountable plan or not, you don't because you're not requiring adequate substantiation of business expenses. Uh, you're just reimbursing people without ensuring that those expenditures were being used for legitimate church purposes that were approved by the church. And and so that can also be a problem. And this gets into the credit card issue as well.
Yeah. Actually, um, we'll just talk about credit cards real quick. Um, you should have a credit card use policy and approval for payment of purchases. The number one reason, or the what they found—one of these outfits found out—was that credit card crime was the number one way that people actually steal money, which amazed me.
Um, one of the other things too that I came up with, or a couple here: Counting should be done behind locked doors. Um, a lot of times, don't count it in an open area, and I like the idea—we've actually had churches do this—have a camera overlooking the counting area. Let the people know that they're in there, but let there be a, you know, a camera in that area, like in a bank lobby.
Absolutely. Um, the other thing is when you place um the money that you get from the offering, place it in a locked bank bag immediately. And if you can't take it to the bank right then and there, put it in a safe. But night depository uh is recommended because actually we've seen churches actually get money stolen out of the churches before they come in and count it on Monday if they're having it on a Sunday service.
Well, Jerry, I, as we expected, this this issue is so uh broad and expansive and important that there are a number of issues we haven't addressed yet today, and we decided in advance that rather than uh race through this topic because of its significance, uh we decided that uh we probably would have to uh resume this discussion in next month's risk management live.
Yeah. And actually we are out of time. So, um, we're going to look at the the other internal controls that you should have placed. Um, what actions are normally taken uh against a perpetrator. And we haven't even got to the idea of does insurance cover this and what does insurance cover. So, join us next week. I know there were some questions, too. We'll get to those questions um next week and or we'll try to put them on our website, or next month, I should say. Thank you. But, uh, we enjoyed the time together and and wow, what a subject. And a lot of information is here. We're going to try to get the rest of this information to you next month. God bless.
Thanks, Rich.