Operational Risk ControlsCEF OperationsChurch Extension FundInternal ControlsRisk Management

Operational Risk Controls for CEFs and Faith-Based Funds

By 16 min read
Operational Risk Controls for CEFs and Faith-Based Funds

A construction draw is ready to fund. The loan servicing clerk opens the familiar vendor template, updates the project details, and sends the payment instruction forward. A stale routing number directs $187,000 to a closed account. Nobody sees the failed delivery until the ACH return has already become difficult to recover, and the wire recall window has expired.

That scenario feels uncomfortably plausible at a Church Extension Fund. The organization may have capable staff, a committed board, and a long-standing spreadsheet process, yet still lack a control that stops one person from preparing, approving, releasing, and reconciling the same transaction. Operational risk controls are how a mission-driven fund protects investor money, loan proceeds, member data, and the credibility it has built with churches.

The practical challenge is right-sizing bank-grade discipline for a CEF managing $10M to $500M or more in assets. Basel and Federal Reserve frameworks provide useful principles, but a smaller institution needs controls that fit its staffing model, transaction volume, systems, and state securities obligations. The framework below focuses on what works in daily CEF operations, where excessive manual review can be almost as harmful as too little review.

When a Quiet Control Gap Becomes a Capital Loss

The near-miss often starts with an ordinary handoff. A loan officer approves a construction draw, a servicing clerk copies information into a payment template, and a treasury employee assumes the account details were already validated. Each person performs a familiar task, but nobody owns the complete control chain from project verification through settlement and reconciliation.

If the stale routing number sends $187,000 to a closed account, the first failure isn't necessarily fraud. It may be a template that was never retired, a bank detail changed without independent verification, or a spreadsheet field that allowed an old value to survive. The loss becomes more serious when the return isn't reviewed the same day and the CEF can't quickly establish who approved the instruction, what source document supported it, or when the receiving bank rejected it.

A mid-sized fund can feel a loss of that size immediately. It can consume a material share of annual earnings, delay a church project, create pressure around investor liquidity, and invite difficult questions from auditors or state securities examiners. The reputational consequence can reach farther than the accounting entry, especially when investors believe their funds are supporting ministry rather than financing avoidable administrative failures.

Practical rule: A control isn't complete until someone can prove who performed it, what evidence they reviewed, and what happened when an exception appeared.

The Basel Committee's 2002 Loss Data Collection Exercise compiled more than 47,000 individual operational loss events from 89 banks. That dataset helped move operational risk from a qualitative concern into a measurable discipline, supporting later approaches to incident tracking, internal controls, and capital allocation (Basel operational risk loss data collection). A CEF doesn't need a global bank's infrastructure to apply the underlying lesson. It does need deliberately designed controls instead of inherited tribal knowledge.

The rest of the framework separates controls into preventive, detective, and corrective layers, then applies them to notes, ACH, construction draws, escrow, reporting, and audit evidence.

What Operational Risk Controls Really Mean for a CEF

Operational risk controls are the policies, procedures, and system-enforced rules a CEF uses to keep transactions accurate, authorized, traceable, and recoverable. They cover the full operating chain, from investor onboarding and note issuance to loan servicing, cash management, general ledger posting, and regulatory reporting.

A useful control environment has three layers:

  • Preventive controls stop a problem before execution. A second authorized employee approves an investor note issuance or construction draw before funds leave the account.
  • Detective controls identify a problem after it occurs. Finance reconciles the loan subsidiary ledger to the core system and bank activity, then investigates differences.
  • Corrective controls contain the damage and prevent recurrence. After an NSF construction draw, the CEF corrects the accounting, documents the loss, reviews the root cause, and changes the process or system rule that allowed it.

The distinction matters because no single review catches every failure. A preventive approval may confirm the amount but miss a duplicate posting. A reconciliation may detect the duplicate but not restore a delayed project. A corrective review may improve the process without recovering the original funds.

Basel guidance says banks should identify and assess operational risk across material products, activities, processes, and systems, then maintain policies and procedures that control or mitigate those risks. Its examples include observing risk thresholds, protecting access to assets and records, and ensuring employees have suitable expertise and training (Basel Committee operational risk guidance). Those principles translate directly to a CEF, even when the organization has a small accounting team.

A diagram illustrating operational risk controls in a CEF, including policies, system rules, and segregation of duties.

The practical test is simple: can the CEF show how a high-risk transaction is prevented, how exceptions are detected, and how failures are corrected? If the answer depends on one employee remembering a spreadsheet convention, the control isn't durable. Written procedures, restricted permissions, independent review, and reliable evidence turn an informal habit into an operational control.

The Core Controls Every CEF Should Be Running

CEF operations expose several points where a small mistake can become a financial or regulatory problem. The controls below address the most consequential failure modes without requiring a large risk department.

Separate authority across the transaction lifecycle

No individual should be able to initiate, authorize, execute, and review the same transaction. Strong internal-control guidance for financial institutions recommends separation between operational risk management, business lines, and support functions, because conflicting duties can conceal errors, losses, or inappropriate actions (supervisory guidance on control independence).

For a CEF, that means separating note issuance, disbursement, and reconciliation. The employee who prepares an investor note shouldn't release its proceeds, and the person reconciling the investor subledger shouldn't be the person who posted the transaction. Where staffing makes complete separation difficult, dual control and documented independent review provide a practical alternative. A financial-institution internal-controls guide specifically recommends that no single person initiate, authorize, execute, and review the same transaction, with a second-person approval where full segregation isn't feasible (internal controls for financial institutions).

Use maker-checker approval where exposure changes

A maker-checker workflow requires one employee to prepare a transaction and another authorized employee to approve it. Apply it to construction draws, investor redemptions, bank-detail changes, journal entries affecting restricted funds, and transactions above board-approved thresholds.

The control should be enforced by the system where possible. An email saying “approved” is weaker than an approval record tied to the exact amount, recipient, source documents, timestamp, and user identity.

Reconcile subledgers to the general ledger and bank

Daily cash reconciliation catches settlement failures while they can still be investigated. Month-end reconciliation should tie investor notes, loan servicing, escrow balances, and bank cash to the general ledger, with an independent reviewer signing off on outstanding items.

The reconciliation must include aging. A list of unresolved differences without an owner or due date becomes a recurring report rather than a control.

Restrict access and review it regularly

Role-based access should follow least privilege. A loan officer may view portfolio data and submit a draw, while treasury approves payment instructions and accounting posts the related entry. User access reviews should occur quarterly, with prompt removal for terminated employees and documented investigation of incompatible permissions.

Encryption protects investor personally identifiable information and ACH data both at rest and in transit, but encryption doesn't replace access governance. A properly encrypted file can still be exposed to a user who shouldn't have access.

Treat recovery as a tested control

Disaster recovery documentation has value only when staff rehearse it. Define recovery time and recovery point objectives, then test restoration of the servicing environment, investor records, payment files, and reconciliation data. A ransomware event that wipes a servicing server is an operational failure, but an untested backup can turn it into an extended service interruption.

Control Risk Addressed What It Catches CEF Example
Segregation of duties Unauthorized or concealed activity One person controlling a transaction end to end Note issuance separated from disbursement and reconciliation
Maker-checker approval Incorrect or fraudulent release Unsupported amount, recipient, or source document Second approval before a large construction draw
Independent reconciliation Posting and settlement errors Duplicate entries, missing returns, stale items Bank cash tied to the loan and investor subledgers
Role-based access Excessive privilege Unauthorized data changes or access Treasury rights excluded from loan-rate maintenance
Encryption Data disclosure Exposure of investor and ACH information Protected files and transmissions
Tested recovery Availability and data-loss risk Failed restoration after outage or ransomware Servicing records restored within documented objectives

The EBA's supervisory material shows why these controls remain economically material. EU and EEA banks reported about 3 million operational loss events in 2023, while materialised losses from new operational risk events reached EUR 17.5 billion. Those losses equaled 1.1% of CET1 capital, compared with 0.9% in 2022 (European Banking Authority operational risk and resilience data). The scale differs, but the control logic applies to CEFs.

For a broader implementation perspective, the Doczen operational control solution offers a useful way to think about documenting control objectives, owners, evidence, and testing. CEF leaders can also use this internal controls framework as a practical reference when organizing policies around their own processes.

Designing and Prioritizing Controls Without Overbuilding

A CEF doesn't need a control for every conceivable error. It needs a clear connection between material exposure, responsible ownership, and evidence that the control worked.

Start with a risk-and-control matrix. Keep the first version limited to processes tied directly to cash, investor notes, ACH, loan proceeds, member data, and financial reporting.

Five steps for a workable matrix

  1. Inventory the process. Map who prepares, approves, posts, settles, and reviews each transaction.
  2. Score inherent risk. Assess likelihood and dollar impact before controls are applied. Include regulatory and mission impact, not only accounting loss.
  3. Map existing controls. Record the actual procedure, system restriction, reviewer, frequency, and evidence. Don't list a policy that staff don't follow.
  4. Calculate residual risk. Document what remains after the current control operates. A strong approval may reduce release risk while leaving reconciliation risk untouched.
  5. Rank remediation. Prioritize the gap that reduces the most exposure for each hour of staff effort.

Prevention generally deserves priority over detection, and detection over correction. Blocking an invalid bank account before release is less costly than chasing a returned payment, explaining a delay to a church, and reconstructing the evidence afterward.

Overbuilding creates its own problems. Multiple manual approvals can delay a time-sensitive ACH return. A second maker-checker layer adds little when the transaction is already subject to effective dual control. Disaster recovery binders that nobody rehearses create comfort without resilience.

Process Inherent Risk Existing Control Residual Risk Priority
Investor note issuance Unauthorized or inaccurate note Preparer review and approval Unsupported changes may pass High
Construction draw Funds released without current project support Loan officer review Independent inspection may be missing High
ACH returns Returned item not acted on promptly Daily bank review Ownership may be unclear High
Investor data access Excessive employee permissions Role-based access Former access may remain Medium or high
Month-end close Subledger and GL mismatch Reconciliation spreadsheet Evidence may be incomplete Medium

Use a simple queue rule when scoring becomes subjective: any gap that could cause a misstatement over $25,000 or a regulator finding moves ahead of lower-impact work. The threshold isn't a substitute for judgment, but it prevents a small team from spending weeks polishing low-risk documentation while a material cash control remains manual and fragile.

Operational Risk Controls in Real CEF Processes

The value of a framework appears in the handoffs where money, data, and accountability meet. Four CEF workflows deserve specific control design rather than generic policy language.

Investor note issuance

Rate-setting, note generation, and disbursement should be separate activities. The system or authorized rate owner establishes the approved terms. A second employee verifies the investor record, amount, rate, maturity, source documents, and payment instructions before the note is issued. The disbursement role shouldn't be able to alter the approved terms.

Scanned source documents should remain attached to the transaction. Without that evidence, staff may need to search email, shared drives, and paper files to prove why a note was issued or adjusted. That becomes especially difficult when an investor asks about interest, redemption, or year-end reporting.

ACH origination and returns

ACH controls need an owner who watches the bank file and returned items every business day. Nacha timing makes this operationally urgent. Unauthorized or improper corporate ACH debits must be returned no later than the opening of business on the second banking day following settlement, according to a bank treasury-management guide explaining the applicable return process (ACH return timing guidance).

The originator and approver should be different people, and a return should trigger same-day review, member contact where appropriate, accounting correction, and escalation when the pattern suggests a broader problem. The control owner must know whether the item is a bank error, a member dispute, invalid account data, or an unauthorized debit.

A flowchart detailing operational risk control steps for four distinct processes: Investor Note Issuance, Loan Disbursement, Member Data Access, and Financial Reconciliation.

Construction draw funding

A loan officer's recommendation shouldn't be the final control. An inspector or designated project reviewer verifies the work and supporting documentation. A loan committee or independent approver confirms that the draw fits the approved loan terms, and finance reconciles the requested amount to the project budget before releasing funds.

The exposure may be a single draw of thousands or hundreds of thousands of dollars, but the precise amount isn't the only concern. A premature release can leave a church with an unfinished project, create a covenant issue, and force staff to explain why the CEF funded work that wasn't independently verified.

The maker-checker approval process provides a useful operating model for separating preparation from authorization. For a CEF reviewing its technology and vendor safeguards, guidance on secure IT for your business can also help frame questions about access, endpoint protection, recovery, and third-party accountability.

Escrow and 1099-INT reporting

Escrow balances need monthly bank reconciliation with independent review. Year-end interest allocation should originate from the core ledger, not a manually edited spreadsheet, and every post-close adjustment should have an immutable log showing the reason, approver, and accounting impact.

For investor note and deposit-interest reporting, Form 1099-INT generally applies when a payer has paid $10 or more in reportable interest during the calendar year, including interest reported in Boxes 1, 3, or 8 (IRS draft Publication 1099 guidance). The control question isn't only whether the form was produced. It's whether the CEF can trace the reported interest back to the ledger and explain any correction.

Monitoring, KPIs, and Board Reporting That Actually Helps

A board dashboard should show whether controls are working before a loss appears. Lagging indicators, such as audit findings, regulatory comments, and recorded loss events, tell directors what already happened. Leading indicators show whether exposure is building.

A small CEF can sustain a focused set of measures:

  • Reconciliation timeliness: Track days since the last unreconciled item and the age of the oldest open difference.
  • Approval evidence: Measure whether required maker-checker approvals contain complete evidence.
  • ACH returns: Watch volume and direction, then investigate unusual movement rather than treating every return as the same.
  • Access governance: Report overdue user access reviews and segregation-of-duties exceptions.
  • Resilience testing: Record the last recovery exercise, the systems included, and unresolved findings.
  • Remediation: Show outstanding high-risk actions, owner, due date, and status.

A professional infographic titled Monitoring KPIs for Operational Risk, detailing leading and lagging indicators and board reporting focus.

A one-page report works better than a catalogue of every exception. Use a traffic-light view, but accompany it with a short narrative explaining movement. “Red” without context doesn't tell the board whether staff are discovering old issues, whether a vendor failed, or whether the threshold changed.

Board question: Which control weakness could delay an investor redemption, interrupt a church project, or misstate a member's tax reporting?

That question connects operational metrics to mission risk. A delayed redemption affects a person who may have entrusted retirement savings to the fund. A construction draw error affects a congregation waiting for a usable building. Those consequences help directors engage with controls as stewardship, not merely compliance administration.

Cloud platforms can surface reconciliation status, approval evidence, access exceptions, and remediation activity continuously. The technology doesn't replace judgment, but it can remove the quarterly manual roll-up that obscures what happened between board meetings.

Audit, Exams, and Cloud-Native Evidence

Auditors and state securities reviewers usually want to understand whether controls exist, operate consistently, and produce reliable evidence. For a CEF, that evidence commonly includes bank and subledger reconciliations, transaction approval trails, vendor due diligence, user-access reviews, policy exceptions, incident records, and documentation supporting investor and loan activity.

Legacy operations often assemble this material through email chains, shared drives, screenshots, and spreadsheet tabs. Staff may know that an approval happened, but proving the exact version of the transaction and the identity of the reviewer can take days. A changed file may not preserve the original value, and an exception may sit in an inbox without a clear owner.

Cloud-native evidence changes the work pattern. An immutable event log can capture each maker-checker decision, access change, reconciliation sign-off, and post-close adjustment. Timestamped evidence packets let finance staff answer the auditor's question directly instead of reconstructing the history from multiple systems.

Evidence Request Legacy Process Cloud-Native Process
Reconciliation support Spreadsheet, email approval, manual aging System record, reviewer sign-off, exception history
Transaction authorization Scanned form or email chain User identity, timestamp, amount, decision, source documents
Access review Exported user list and meeting notes Role report, review status, changes, approval record
Vendor due diligence Shared-drive documents Central profile, review dates, evidence, exceptions
Policy exceptions Separate log maintained manually Exception record linked to affected transaction and remediation
Disaster recovery testing Narrative memo and screenshots Test scope, restoration evidence, findings, owner, due date

A current controls matrix should identify every control owner, frequency, population, evidence source, exception process, and testing method. Update it when a system, vendor, product, or staffing model changes. During a multi-state exam cycle, that discipline prevents one state-specific request from exposing an undocumented process used everywhere else.

Control testing should assess both design and operating effectiveness. The practical difference is significant: a policy may require independent reconciliation, while the test determines whether the reconciliation occurred, whether the reviewer was independent, and whether unresolved items were escalated. This guide to control testing provides a useful structure for defining those tests and retaining evidence.

A unified platform can shorten preparation by keeping loans, notes, general ledger activity, cash operations, reporting, permissions, and audit history connected. CEFCore is one example of a purpose-built cloud platform that brings those functions together with role-based access, maker-checker approvals, reconciliation support, encryption, and immutable audit trails. The objective isn't to eliminate every manual judgment. It's to make the important judgments visible, repeatable, and defensible.


If your CEF is still reconciling loans, investor notes, cash, and reporting across disconnected spreadsheets, map the highest-risk handoffs before the next audit cycle. Visit CEFCore to review how a unified platform can support maker-checker approvals, role-based access, reconciliation, reporting, and cloud-native evidence in daily fund operations.

CEF

CEF Core Editorial Team

Written and reviewed by CEF Core's treasury, fund-accounting, and compliance team — the people who build the financial management platform purpose-built for Church Extension Funds. Learn more about CEF Core.