The Drupal Association exists to support and grow the Drupal project and community. Part of meeting that mission is performing our work in an open and transparent way. We have put a lot of energy and effort in the last few months into increasing our transparency, adding blog post summaries to our already public board meetings, asking you for input as we develop our programs, and admitting when we make mistakes. There is certainly more we can do to share how we do our work here at the Association, and we will continue to look for and act on those opportunities.
Today, we're excited to share one of those opportunitiies. Earlier this year we undertook our first ever financial audit. We don't currently have a legal or financial obligation for an audit, but wanted to undertake the work to share audited financials with the community and learn from the auditors as well. A good audit is a great chance to discuss how you can improve your operations, and we were thrilled with the opportunity to do just that. in this post, I want to share the process and the outcomes of our audit.
What IS a financial audit anyway?
Most of us think of an audit as a bad thing - something the government does when our tax filings don't seem right. That's definitely one kind of audit. Here at the Drupal Association, and for many other organizations, an audit is an annual opportunity to independently verify your financial statements and ensure that your financial operations are as strong as they can be. Audits can be conducted internally, but because of our size and our desire for transparency, we contracted with an external CPA firm, McDonald Jacobs, to conduct our first audit.
What did our audit cover?
The Drupal Association's fiscal year aligns with the calendar year. Our audit covered financials and practices in fiscal year 2012, Jan 1, 2012 through December 31, 2012. This was an interesting time for the Association as we finished the process of moving financial operations from VZW, the predeessor to the Drupal Association, and because we saw tremendous growth in staff and programs. For this period, the auditors looked at things like:
- Proper recording of income and expense: The first job of the auditor is to ensure that our financial statements are an accurate representation of the business weve conducted. Did we record transactions on the right date, to the right account, and the right class? In other words, if we said a 2012 DrupalCon netted a certain amount of revenue in a certain time period, is it true?
- Financial controls: Preventing fraud is an important part of the audit. Though everyone on the Drupal Association team is fantastic to work with, it's important to put the kinds of controls in place that can prevent common types of fraud, such as forged checks and payroll changes. Auditors look to see that there are two sets of eyes on transactions, and that documentation is provided to verify expenses and check requests. for example.
- Policies and procedures: Sarbanes-Oxley and other laws and regulation require that we have certain policies in place at our organization, including a whistleblower policy, for example. Our auditors looked at our policies to ensure they were in place and, in some cases, had been reviewed by the board and staff.
What are the documents the auditor provided?
The complete auditor's report includes four documents:
- Audit Communication Letter: This outlines the role of the auditor to the board, and any problems encountered during the audit.
- Management Letter: This document addresses any internal controls issues.
- Communications of Significant Deficiencies: This letter shares areas of materials concern - where the amount of the transactions in question are significant.
- Financial Statements: The numbers!
What did our auditors find?
In short - our house is in order! Thanks to the hard work of Kris Klinkhammer, our Operations Manager, we got a very clean bill of health from the auditor. That is not to say that everything was perfect. Working with the auditors, we did make a number of significant changes to the 2012 financials presentation:
- Currency conversion errors: At the beginning of 2012, we moved accounting systems, from Quickbooks to Xero. The main impetus for the move was to account for multiple currencies. Managing those currency conversions was not easy, and our audit turned up errors that we were able to correct. Now that we are firmly ensconced in Xero, we should not face the same errors again.
- Recognizing conference revenue appropriately: When you buy a ticket to a DrupalCon, we are liable to you until we are able to deliver the service you purchased - the Con. So, if you buy a ticket, and we cancel the Con, we owe you the ticket price. Because of that, we are not allowed to recognize Con revenue (from ticket sales, sponsorships, etc.) until the conference is actually held. In 2012, we recognized the revenue as we received it, not when the Con was held. Although we had already corrected this accounting practice in 2013, we had to move the revenue we received in 2011 for 2012 Cons to 2012.
- Capitalizing Drupal.org expenses: Just like a building, a bulldozer, or a copy machine, Drupal.org is an asset. According to the Financial Accounting Standards Board (and yes, one of the thrilling parts of my job is knowing that this exists!), if we make an investment in this asset, like, say a major software upgrade, we can capitalize that expense over a standard period of time (we're using three years). This allows us to absorb the expense over the lifetime of its usefulness. We made th decision to capitalize D7 upgrade expenses in this way.
You will see these items reflected in the letter entitled "Communication of Significant Deficiencies." It's true - these were all significant in terms of dollars. However, the auditors and those of us on staff, as well as the board that reviewed these financials, are confident that the issues have been addressed.
- Credit card receipts: If any of you have ever worked at a small organization that grows quickly, you know how easily process, or lack thereof can run amuck. Our auditor found several instrances where credit card transactions were lacking the proper documentation - namely a receipt. In response, we've instituted a new reporting system for credit card purchases at the Drupal Association. From now on, staff must document each purchase with a receipt and have a supervisor approve the report.
- Disaster Recovery Plan: If we learned anything at the Drupal Association in the month of June, it's that ANYTHING can happen. So yeah, we're going to get a Disaster Recovery Plan in place this year.
These findings are reflected in the "Management Letter" also attached to this post.
So what did 2012 look like?
In short, it looked like a successful year! There are a few things that I would like to point out about the Financial Statements:
- We've had a financial goal over the last couple of years to build and maintain a reseve of 6 months operating expenses. This will allow us the freedom to make strategic investments in programs and services for the community knowing that we can afford the risk. In 2012, we were able to contribute to this bottom line, netting over $500,000 for the year.
- One of the most important things financials can demonstrate is changes from year to year. Since this is our first set of audited financials, we can't campare to previous years. Look for that in the future.
- The Statement of Functional Expenses shows what we spent our money on. In 2012, we did not track this in a very granular manner. All of program expenses, whether Cons or D7 Upgrades or Community Cultivation Grants, are tracked together under "Program." We began to break these out further in 2013 and are designing a 2014 budget and accounting proceeses that will provide even more transparency.
What else can we tell you?
Still awake? Audits aren't always the most exciting of topics, but we want to make sure we can answer any questions you have! Let us know what you're thinking in the comments.
Comments
Superb! Keep up the good work.
---
Tom Geller * tomgeller.com * Oberlin, Ohio
See my lynda.com videos about Drupal
on things.
Transparancy and Accountability of the Actions taken by it's members.
Hopefully the same effort can be done to Companies that uses Drupal for theirs site.
img.imageResizerActiveClass{cursor:nw-resize !important;outline:1px dashed black !important;} img.imageResizerChangedClass{z-index:300 !important;max-width:none !important;max-height:none !important;} img.imageResizerBoxClass{margin:auto; z-index:99999 !important; position:fixed; top:0; left:0; right:0; bottom:0; border:1px solid white; outline:1px solid black;}