Benevolence Without Exposing the Pastor
Hospital bills, school fees, funeral costs, rent for a family in crisis — benevolence is the most pastorally sensitive money a church handles and usually the least controlled, because control feels like suspicion.
A church that helps people in crisis will, sooner or later, face one of two failures. Either the money is handed out with so little record that nobody can say who received what — leaving the pastor personally exposed the moment anyone asks — or the process becomes so procedural that a family in genuine distress waits eleven days for a decision. Both failures come from the same mistake: treating benevolence as either purely pastoral or purely financial, when it is unavoidably both.
The resolution is not a compromise between the two. It is a design where the pastoral judgement and the financial control operate on different parts of the same transaction. The pastoral side decides who and how much, quickly, on information that is often confidential. The financial side records that a decision was made, by whom, on what date, and where the money went — and it does that without needing to know the medical details. Once you separate those, you can be both fast and accountable, which most churches assume is a trade-off.
The three-role rule, and why it protects the pastor most
Almost every benevolence problem in a church traces to one person performing all three functions: identifying the need, deciding the amount, and handing over the money. This is rarely dishonesty. It is usually a pastor responding compassionately at speed with cash that happened to be available. But it produces a situation where the only account of what happened is the account of the person who did it — and that is a terrible position to leave a faithful minister in, because it can only be defended by trust rather than by evidence.
Splitting the roles costs almost nothing and changes the character of the whole activity. Someone recommends — a pastor, an elder, a small-group leader who knows the family. Someone else approves against a policy and a budget, usually a welfare committee or a designated elder for smaller amounts. Someone else again disburses and records it, in finance. Nobody in that chain has to know more than their part requires, and the record that emerges belongs to the church rather than to an individual.
-
Write the policy before the next request arrives
What the fund exists for, what it does not cover, the maximum a single approver may authorise, the amount above which the committee must sit, and how often the same household may receive support. Deciding these under pressure, with a distressed family present, produces inconsistency that will later be read as favouritism. One page, adopted by the board.
-
Separate the confidential file from the financial record
The pastoral notes — the diagnosis, the family circumstances, the sensitive detail — belong in a confidential pastoral file with tightly restricted access. The financial record needs the recipient, the amount, the date, the approver and a purpose category like "medical" or "education". It does not need the diagnosis, and putting it there creates a data-protection exposure with no control benefit.
-
Pay the provider, not the person, wherever you can
Paying the hospital, the school or the landlord directly is better on every dimension: the money reaches the intended purpose, the evidence is a third-party invoice rather than an acknowledgement, and the recipient is spared the indignity of being seen to receive cash. Reserve cash for genuine emergencies and food support, and set a low ceiling on it.
-
Record it as a payment run, not as petty cash
A batch of welfare payments prepared as a run, approved as a batch, and then posted, gives you a document with an approver and a date rather than a series of cash movements with a note attached. It also means the same discipline applies to the fifth payment of the month as to the first, which is where informal processes decay.
-
Report totals to the board and details to nobody
The board needs the total disbursed, the number of households helped, the split by purpose, and whether the fund is within budget. It does not need names, and a board paper listing recipients by name is a pastoral breach dressed as transparency. If a board member wants assurance on individual cases, the internal auditor or an independent elder reviews the file and reports that the policy was followed.
-
Review the pattern annually, not the cases
Look for the things a case-by-case view hides: households receiving support repeatedly over years, which is a signal that benevolence has become a substitute for a different kind of help; the concentration of approvals in one person; and whether the fund is being spent at all, because an underspent welfare fund is its own kind of failure.
What a payment run gives you, and what it costs
Our system has no welfare or benevolence module, and there is a mechanism that fits the shape of the work reasonably well: a payout run against a project. It is worth walking through exactly what that gives you and where it is uncomfortable, because the discomfort is real and you should know about it before you build a process on it.
A batch with a reference
A payout run created against a project, with its own generated reference number, a currency and a total that recalculates as lines change. This is the document the approver approves.
Draft, approved, posted
Three states with real gates. Only a draft can be edited, only an approved run can be posted, and a posted run cannot be posted twice. The approver and the approval time are stamped on the record.
A line per recipient
Each line carries an amount, an optional note, and a payee. Lines can be added and removed while the run is a draft, and the total follows.
Payment to a named non-employee
A line can name a payee as free text rather than pointing at an employee or a registered vendor — which is what makes paying an individual possible at all. The word the system uses for that payee is "contractor", and there is no way to relabel it.
Posting into the payments register
Posting creates a pending money-out transaction that accrues to payable and settles when the payment is confirmed, either through mobile money where details exist or by recording it as paid manually. So the disbursement lands in the same consolidated register as every other payment the church makes.
Attribution to a fund
The run belongs to a project, so a standing "Welfare Fund" project collects every payment and reports the total against a budget figure. This is the closest thing to fund accounting available and it is a convention, not an enforcement.
A benevolence application or case record
Nothing captures the request, the recommending pastor, the circumstances, the supporting documents or the decision rationale. The case file lives outside the system entirely.
A recipient entity
There is no member record, so a recipient is a name typed on a line. Nothing links this month's payment to the same household's payment last year, and repeat-support patterns are invisible without a register you keep yourself.
A restricted-fund lock
Nothing prevents an unrelated cost being charged to the welfare project, and nothing prevents welfare being paid when the fund is exhausted. The budget figure is displayed, never enforced.
Money coming in
No offering, designated gift or contribution record exists, so what the welfare fund has received is not something this system holds. The balance is always a combination of two records.
Two of those deserve emphasis because they will affect your decision. The first is the label. A benevolence recipient recorded as a "contractor" is accurate about the mechanism and wrong about the relationship, and in a document a board or an auditor might read, that wording is at best confusing and at worst hurtful if it is ever seen by the family. Put the real nature of the payment in the note field on every line, consistently, and be aware you are borrowing a mechanism rather than using a designed feature.
The second is a genuine trap. A payout run has two routes: a direct payment, or a route through payroll. The payroll route exists for paying employees for project work, and it creates the amount as a taxable earning on their payslip. If a member of staff receives benevolence support and somebody routes that payment through payroll for convenience, it will be treated as taxable employment income. Whether that is the correct treatment for a genuine hardship payment is a question for your accountant and for the Kenya Revenue Authority, and the system will not ask it — it applies the taxable flag automatically. Use the direct route for benevolence, and take advice before paying hardship support to an employee in any form.
Score your current practice honestly. The criteria weighted High are the ones that protect people rather than money — and they are the ones churches most often fail.
Three different people recommend, approve and disburse
Make them prove it: Take the last five benevolence payments and name the three people for each. If any name appears twice on the same payment, the control is absent.
A written policy existed before the request
Make them prove it: Ask for the policy and check its adoption date against the date of the last unusual payment.
Confidential detail is separated from the financial record
Make them prove it: Look at the financial record for a medical case. Can you see the diagnosis?
Providers are paid directly where possible
Make them prove it: What proportion of last year's benevolence went to a hospital, school or landlord rather than as cash?
The fund has a budget and the board sees totals
Make them prove it: Ask for the total disbursed last year and the budget it sat against.
Repeat support is visible
Make them prove it: Ask which households received support more than twice in three years.
Somebody independent reviews the files
Make them prove it: When did anyone other than the approver last read the case files against the policy?
A closing word on the data-protection dimension, because benevolence records are among the most sensitive information a church holds. Health information, financial distress and family circumstances attract the strictest handling obligations under Kenyan data-protection law, and the practical implications are unglamorous: restrict access to the pastoral file to the smallest possible number of named people, with the same care our member giving records guide applies to contribution data, do not circulate case detail on messaging groups, do not put diagnoses in a finance system, and decide how long you keep these records rather than keeping them forever by default. Confirm the current requirements with the Office of the Data Protection Commissioner or your own counsel rather than relying on a summary here — but treat the principle as settled: this is the category of information where a breach does real harm to a real family.
What AWRA OpsHub does today
- Payout runs with a real approval lifecycle — draft, approved, posted — where only a draft can be edited, only an approved run can be posted, a posted run cannot be posted again, and the approver and approval time are stamped on the record.
- A line per recipient with an amount and a note, and the ability to name a payee as free text so an individual who is neither an employee nor a registered vendor can be paid.
- Posting into the consolidated payments register, creating a pending money-out transaction that settles when the payment is confirmed — so welfare disbursements sit in the same register as every other payment.
- A standing project as the fund container, collecting every payment against a budget figure with what remains, which is the closest available thing to a designated fund.
- Named users on every action and full audit logging, so who approved what and when is a matter of record rather than recollection.
- Document storage with access logging, which is where supporting invoices from a hospital or school can live attributably.
What it does not do
- No benevolence, welfare or assistance module. No application, no case record, no recommending pastor, no decision rationale, no supporting-document workflow. The entire pastoral half of the process is outside the system.
- No member or recipient entity. A recipient is a name typed on a line, so nothing connects a household's support this year to last year, and repeat-support patterns are invisible unless you keep your own register.
- The payee is labelled "contractor". The free-text payee field belongs to a contractor mechanism and cannot be relabelled. It is accurate about the plumbing and wrong about the relationship.
- No fund accounting and no restricted-fund lock. Nothing prevents an unrelated cost hitting the welfare project, and nothing blocks a payment when the fund is exhausted — the budget is displayed, not enforced.
- No income side. Offerings, designated gifts and contributions to a welfare fund are not captured anywhere, so the fund balance always spans two systems.
- No confidentiality partition inside the record. Permissions are role-based across modules; there is no special protection making a particular payout line more restricted than the rest of the register. Sensitive detail must stay out of it rather than be protected within it.
- The payroll route applies tax automatically. An amount routed through payroll becomes a taxable earning on a payslip with no assessment of whether that treatment is right. Use the direct route and take advice before paying hardship support to staff.
Read this as a division of labour rather than a gap to be closed. The pastoral process — the request, the judgement, the confidential file, the decision — belongs in a small controlled record outside any operations system, and probably should. What we add is that the money leaves through a document with three states, a named approver, a timestamp and a place in the payments register, attributed to a fund with a budget. That is a real improvement on cash and a note, and it is not a benevolence system.
Our take
Split the three roles this month, before you think about software at all — because a pastor who recommends, approves and disburses is carrying a risk that no record-keeping can retire, and the only person that arrangement fails to protect is them. Then pay providers directly wherever you can, keep the diagnosis out of the finance record entirely, and run the disbursements as approved batches against a standing welfare project so the total is a number rather than a reconstruction. Use the direct payment route, not payroll, and take advice before paying hardship support to an employee.
Let the money leave through a document
Approved payment runs with draft, approve and post states, a named approver on the record, a standing fund project with a budget, and everything landing in the consolidated payments register. The case file and the giving side are not built.
Explore church finance & operationsFrequently asked questions
Is it really wrong for the pastor to hand out cash in a genuine emergency?
It is not wrong, and it should be rare and bounded. Emergencies exist and a process that cannot move at all on a Sunday evening will simply be bypassed, which is worse. The workable answer is a small emergency float with a stated ceiling per incident, drawn against and reported at the next committee sitting with a receipt or a written note of what was given and to whom. What causes harm is not the emergency payment — it is the emergency payment becoming the normal channel because it is faster.
How do we decide how much to give?
Against a written policy rather than against the strength of the case in front of you, because every case in front of you is compelling. Most churches set a ceiling a single approver may authorise, a higher band requiring two signatures, and a committee threshold above that, plus a limit on how often one household may be supported in a year. The policy is not there to be hard-hearted; it is there so that the family who asks in November is treated the same as the family who asked in March, and so the person declining a request has something other than their own judgement to stand on.
Should the congregation know how much the welfare fund disburses?
The total, yes — and it usually increases giving to it. Publishing the number of households helped and the split by purpose demonstrates the fund is working without identifying anyone. Names should never be published or read out, and a well-meaning testimony naming a recipient can cause real harm even with consent, because consent given in gratitude to a pastor is not freely given in any meaningful sense. Report the aggregate generously and the individual never.
What if the same family keeps coming back?
Then benevolence has become a substitute for something else, and continuing it unexamined helps nobody. Chronic need usually points to employment, health, debt, or family circumstances that a monthly payment maintains rather than resolves. The pattern is the finding, which is why the annual review looks at patterns rather than cases. Practically this means keeping your own register of recipients over time, because nothing here holds a recipient entity — the payment history exists, but it is a list of typed names rather than something you can group by household.
Can we pay school fees directly to the school?
Yes, and it is the best-controlled form of benevolence there is. The school invoices, the church pays the invoice, and the evidence is a third-party document tied to a named student and a term. Register the school as a vendor and the payment flows through the same governed channel as any other supplier payment, with the fund project as the attribution. This also handles the awkward case where a family's need is real and their financial management is not, without anybody having to say so.
Does benevolence support count as taxable income for the recipient?
This is a question for a tax adviser and for the Kenya Revenue Authority rather than for an article, and the answer can turn on the recipient's relationship to the church, the nature of the payment and whether anything is expected in return. What we can tell you is what our system does mechanically: a payment routed through payroll is flagged taxable automatically with no assessment, and a direct payment is not treated as income at all. Neither behaviour is tax advice, and the fact that a payment to an employee is convenient to run through payroll is not a reason to do it. Get the treatment confirmed before you set up a repeating arrangement.
How long should we keep benevolence records?
Long enough to satisfy audit and governance needs, and not indefinitely by default — which is what most churches do. The financial record has a natural retention period alongside your other accounting records. The confidential pastoral file is a different question, because it contains health and family information whose continued storage needs a reason. Set a retention period in the policy, apply it, and confirm the current legal position with the Office of the Data Protection Commissioner or your own counsel. A file kept for twenty years because nobody decided to delete it is a liability, not diligence.