Partner due diligence is no longer paperwork
For NGOs, partner due diligence used to be treated as a formality: a checklist, a registration certificate, a quick internet search, and a signed declaration. That is no longer enough. International programs move funds across borders, humanitarian operations may touch sanctioned jurisdictions, donors require evidence, banks ask questions, and local partners may carry legal, financial, safeguarding, sanctions, fraud, operational, and reputational exposure.
The hard question is not whether NGOs should do due diligence. They must. The hard question is how to conduct due diligence that is serious enough for donors, auditors, boards, banks, and regulators without creating an impossible burden for legitimate civil society partners.
The right standard is serious, proportionate, evidence-based, and repeatable. A good file should show what was checked, what was found, what was not confirmed, how match confidence was assessed, what the partner said, who reviewed the issue, and what control or decision followed.
What NGO partner due diligence means
Partner due diligence is the structured process an NGO uses to understand who it is working with, whether the partner is legitimate, whether the relationship creates risk, and what controls are needed before work begins.
A partner may be a local implementing organization, subrecipient, subgrantee, fiscal sponsor, community-based organization, vendor, consultant, hospital, school, shelter, clinic, local distributor, field coordinator, payment agent, research collaborator, coalition member, advocacy partner, logistics provider, donor, or funder.
Due diligence should answer five practical questions:
- Who are they?
- Are they legitimate and legally able to do the work?
- Are they safe to work with from a sanctions, fraud, safeguarding, and reputational perspective?
- Can they deliver and account for funds, goods, services, data, or activities properly?
- What monitoring is needed after approval?
The point is not to collect documents for their own sake. The point is to know enough to make a responsible, documented decision before money, data, beneficiaries, goods, or reputation move.
Why it matters more in 2026
NGOs often operate where need is greatest, but those same settings can involve heightened risk: conflict zones, fragile states, sanctioned countries, cash-heavy programs, weak public registries, politically exposed organizations, urgent humanitarian delivery, cross-border transfers, donor flow-down requirements, and programs involving children, refugees, survivors, patients, or other vulnerable groups.
Standard vendor onboarding is not enough for that environment. A serious NGO due diligence program protects beneficiaries, donor funds, staff, volunteers, legal standing, bank access, public trust, board oversight, and the partner organization itself.
It also protects legitimate humanitarian and development work from being frozen by fear. A strong process gives teams confidence to work with local partners responsibly rather than avoiding partnership altogether.
The IntegrityFile principle
Do not ask every partner for everything. Ask every partner for the right evidence based on risk.
A low-risk local supplier should not face the same due diligence burden as a subrecipient operating in a high-risk jurisdiction with access to cash, beneficiaries, and sensitive data. A risk-based process should sort partners into tiers and then match evidence, controls, approval level, and monitoring intensity to the tier.
The 4-tier NGO partner risk model
| Tier | Typical examples | Typical checks |
|---|---|---|
| Tier 1: Low risk | Small local vendor, one-time trainer, low-value service provider, no beneficiary access, no funds handled on behalf of the NGO, no sensitive data. | Identity or business verification, basic conflict-of-interest declaration, sanctions screening, scope confirmation, simple contract or purchase order. |
| Tier 2: Moderate risk | Local service provider with beneficiary contact, small implementation partner, vendor handling limited personal data, recurring consultant, partner receiving modest funding. | Registration documents, key personnel list, sanctions and adverse-media screening, references or track record, safeguarding confirmation if relevant, basic financial controls review, data protection questions, compliance clauses. |
| Tier 3: High risk | Subrecipient receiving funds, partner serving vulnerable beneficiaries, field partner in fragile or conflict-affected context, partner handling cash, aid distribution, or procurement. | Full organizational profile, governance documents, leadership mapping, bank account verification, anti-fraud and anti-corruption controls, safeguarding and incident handling, sanctions screening of entity and key people, adverse media review, donor restrictions review, monitoring plan. |
| Tier 4: Critical risk | Work in sanctioned or conflict zones, large subaward, cash transfer program, politically sensitive work, partner with previous allegations, government or politically exposed links, multiple intermediaries. | Enhanced due diligence, legal or sanctions review, senior approval, documented risk acceptance, independent references, layered monitoring, payment controls, beneficiary verification controls, incident escalation plan, periodic rescreening, exit plan. |
The 12 checks every NGO should consider
Not every check applies to every partner. A serious file should still show that each category was considered and either completed, scoped down, or excluded for a documented reason.
- Legal existence and registration. Confirm legal name, registration number, country of registration, legal form, registered address, operating address, date established, license or registration certificate, authority to operate, nonprofit status, and tax status where relevant. For informal grassroots groups, alternative evidence may include community references, prior donor records, local authority letters, umbrella network confirmation, site visit notes, bank confirmation, or a signed representative declaration.
- Mission and activity alignment. Check whether the partner's mission, experience, sector, population, legal purpose, and proposed role align. A newly formed education charity suddenly receiving a large health-sector subaward in a high-risk geography deserves more scrutiny.
- Governance and leadership. Identify directors, trustees, board members, senior managers, founders, beneficial owners where relevant, authorized signatories, project leads, politically exposed persons, family links, and conflicts of interest. The file should show who controls or influences the partner.
- Sanctions screening. Screen the legal name, aliases, directors or trustees, key officers, signatories, bank account holder, major subcontractors where relevant, and high-risk intermediaries. Record lists checked, dates, name variants, false-positive logic, and rescreening triggers.
- Terrorist financing and diversion risk. Consider conflict-affected areas, aid distribution through intermediaries, cash or voucher programs, pressure from armed groups, weak beneficiary verification, politically controlled local organizations, opaque procurement, high-value goods, cross-border transfers, and limited end-use monitoring.
- Financial management capacity. Review bank account ownership, segregation of duties, authorization controls, procurement procedures, accounting system, receipt retention, audit history, prior donor experience, budget management, cash handling, currency conversion, and financial reporting ability.
- Anti-fraud, anti-bribery, and corruption risk. Check anti-fraud rules, procurement controls, conflicts of interest, related-party transactions, cash use, payments to individuals, government involvement, facilitation payment exposure, and previous fraud allegations.
- Safeguarding and protection. For work involving children, vulnerable adults, refugees, patients, survivors, or marginalized populations, review safeguarding policy, child protection, PSEA, code of conduct, recruitment screening, incident reporting, survivor-centered response, training records, referral pathways, and confidentiality.
- Data protection and confidentiality. Identify what data the partner will access, why they need it, where it will be stored, who can access it, retention period, onward sharing, consent requirements, cross-border transfers, deletion duties, breach notification, and secure transfer method.
- Program delivery capability. Assess relevant experience, staffing, local presence, beneficiary access, language ability, technical expertise, equipment, logistics, prior performance, monitoring ability, timeline realism, and dependency on subcontractors.
- Reputation and adverse media. Search the partner name, leaders, aliases, local-language variations, fraud allegations, corruption allegations, abuse allegations, sanctions references, political violence references, and donor suspension references. Document both findings and no findings.
- Monitoring and end-use verification. Set the monitoring plan before approval. Consider milestone reports, receipts, beneficiary verification, site visits, photo evidence where appropriate, inventory checks, bank reconciliation, expenditure testing, procurement review, incident reports, partner meetings, periodic rescreening, and closeout records.
A serious NGO due diligence workflow
| Step | What happens | File output |
|---|---|---|
| 1. Intake | Collect legal name, country, registration status, proposed role, project value, location, funding source, beneficiary contact, data access, funds handled, subcontractors, urgency, and prior relationship. | Preliminary risk tier. |
| 2. Risk triage | Assess geography, activity, value, beneficiary vulnerability, sanctions exposure, cash exposure, data sensitivity, delivery complexity, donor restrictions, and partner maturity. | Tier 1, 2, 3, or 4 with rationale. |
| 3. Evidence request | Request only the documents needed for the tier. A low-risk vendor may need identity evidence and a sanctions check; a high-risk subrecipient may need governance records, bank evidence, financial controls, safeguarding, anti-fraud, references, and a monitoring plan. | Evidence pack. |
| 4. Screening | Run sanctions screening, adverse media screening, conflict-of-interest checks, donor exclusion checks, and politically exposed person review where relevant. | Screening log with dates, terms, sources, and false-positive notes. |
| 5. Review and scoring | Review legal status, governance, sanctions, financial controls, safeguarding, data protection, delivery capacity, reputation, and monitoring feasibility. | Risk summary and recommendation. |
| 6. Decision | Approve, approve with conditions, request more information, escalate, reject, or defer until controls are implemented. | Decision record, approver, date, conditions. |
| 7. Contract controls | Add clauses for permitted use of funds, anti-diversion, sanctions compliance, anti-bribery, safeguarding, data protection, audit rights, reporting, subcontracting, incident notification, termination, retention, and repayment. | Controls mapped to risk. |
| 8. Monitoring and rescreening | Set reporting frequency, payment gates, site visit requirements, rescreening schedule, and triggers such as new personnel, scope change, adverse media, renewal, or major payments. | Monitoring calendar and refresh triggers. |
| 9. Closeout | Document deliverables, funds reconciled, unused funds returned, incidents closed, data deleted or returned, assets accounted for, final risk notes, and future eligibility. | Closeout record. |
Checklist for the file
Red flags that require escalation
- sanctions match or unresolved possible match
- refusal to identify leadership, signatories, or bank account holder
- bank account in an unrelated person's name
- inconsistent registration information, address, directors, or operating country
- politically exposed ownership, control, or undisclosed family links
- credible allegations of fraud, abuse, diversion, exploitation, or corruption
- pressure to bypass normal process or extreme urgency without a program reason
- cash request with weak justification or no ability to track funds
- unexplained subcontractors, intermediaries, or pass-through arrangements
- no safeguarding controls for vulnerable beneficiaries
- prior donor termination, suspension, repayment demand, or unresolved audit finding
- conflict of interest with NGO staff, board, procurement panel, or donor contact
- unverifiable existence or mismatch between mission and proposed project
- unwillingness to sign basic compliance, audit, safeguarding, data, or sanctions clauses
A red flag does not always mean reject. It means pause, investigate, document, and decide deliberately.
Public sources to review
Start with official and primary sources when available. Supplement with credible media, donor pages, court or regulator pages, annual reports, and partner-provided documents. Record access dates, source limitations, search settings, and false-positive logic.
Search terms to use
"[legal name]" "[country]"
"[legal name]" NGO registration OR charity register OR company register
"[legal name]" audit OR investigation OR complaint OR allegation
"[legal name]" fraud OR corruption OR bribery OR "misuse of funds"
"[legal name]" sanctions OR debarred OR suspended OR excluded
"[director name]" "[organization name]"
"[former name]" OR "[local-language name]"
"[organization name]" "annual report" OR "financial statements" OR "Form 990"
"[organization name]" "board" OR "trustees" OR "directors"
"[organization name]" "Form 990" OR "annual report" OR "audited financial statements"
"[organization name]" "former name" OR "formerly known as"
"[director name]" "[organization name]" sanctions OR debarred OR fraud
What reviewers often miss
- searching only the English trade name and missing the legal name, acronym, local script, transliteration, or former name
- confirming that an entity exists but not proving it is the same entity in the proposal
- treating old donor logos as proof of current donor confidence
- recording a clean sanctions search without source date, settings, name variants, or false-positive logic
- Not documenting why a near-match was ruled out, especially for common names, transliterations, and older articles.
- Relying on a single search engine, a single spelling, or a partner-provided document without checking an official source where one exists.
- Treating a clean public-source review as a permanent clearance rather than a dated snapshot that may need renewal.
- Failing to connect the finding to the actual decision: proceed, proceed with controls, pause, reject, report, or investigate.
Sanctions and donor-funded programs
Sanctions screening is now a core NGO control. Screen the partner legal name, known aliases, directors, trustees, key officers, authorized signatories, bank account holder, major subcontractors where relevant, and high-risk local intermediaries. Depending on jurisdiction and donor requirements, relevant lists may include the UN Security Council Consolidated List, OFAC sanctions lists, EU sanctions resources, UK sanctions lists, and national lists required by the donor or operating country.
A serious sanctions check is not only an exact-name match. It also requires aliases, transliterations, local-language names, false-positive resolution, date and source documentation, screenshots or logs where appropriate, and periodic rescreening for longer relationships.
Some donor-funded awards have specific partner vetting rules. Before onboarding a partner, check the grant agreement, donor rules, flow-down clauses, sanctions clauses, anti-terrorism certifications, subaward approval requirements, procurement restrictions, data-sharing rules, branding restrictions, and audit rights.
What a board-ready file should contain
- partner profile and relationship purpose
- risk tier and rationale
- documents collected and documents missing
- sanctions screening record
- adverse media and reputation notes
- financial capacity review
- safeguarding and PSEA review where relevant
- data protection review where relevant
- delivery capacity assessment
- red flags, partner explanations, and mitigations
- approval decision, approver, date, and conditions
- contract controls and monitoring plan
- review date and closeout record
This is the difference between "we checked them" and "we can prove we made a responsible decision."
What to do when a signal appears
- Classify the signal against the file scope: legal identity, governance, reputation, key people, eligibility, sanctions, debarment, safeguarding, donor history, diversion risk, or financial control.
- Confirm match quality before escalation. Compare names, dates, addresses, registration numbers, people, websites, operating countries, and role descriptions.
- Preserve evidence in the file. Save the source title, URL, access date, screenshot or extract where permitted, search term, and reviewer note.
- Ask the partner for a targeted explanation and supporting documents, not a broad denial. Give the partner a chance to correct identity mistakes or provide closure evidence.
- Escalate according to severity. Sanctions, debarment, safeguarding, credible fraud, criminal, donor-reportable, or legal-status signals should move to the responsible compliance, legal, safeguarding, procurement, grants, or donor lead.
- Decide the operating response: clear, clear with explanation, proceed with conditions, pause, reject, report, or investigate.
- Set a monitoring trigger. Examples include leadership change, new country, new budget, new donor, new subpartner, new adverse media, open audit, or expired registration.
Common mistakes NGOs make
A practical example
Imagine an NGO wants to work with a local organization to distribute food vouchers in a conflict-affected region. The partner is locally known and trusted, but has limited formal documentation.
A weak process says: "They are recommended by someone we know. Approved."
A serious process confirms legal status or alternative legitimacy evidence, identifies leaders and signatories, screens the entity and key people against relevant sanctions lists, reviews distribution and beneficiary controls, assesses cash and voucher diversion risk, checks safeguarding and complaint mechanisms, uses milestone-based payments, requires distribution records, monitors sample beneficiaries, rescreens before major payments, and documents approval and risk acceptance.
That process does not block the work. It protects the work.
Due diligence maturity model
| Level | What it looks like |
|---|---|
| Level 1: Informal | Ad hoc checks, no risk tiers, no screening log, no monitoring plan. |
| Level 2: Basic | Standard form, basic documents, sanctions check, approval email. |
| Level 3: Structured | Risk tiers, evidence requirements by tier, documented screening, contract controls, monitoring calendar. |
| Level 4: Integrated | Donor rules mapped, automated reminders, rescreening, incident tracking, management reporting. |
| Level 5: Assurance-ready | Complete due diligence files, audit trail, risk acceptance records, continuous monitoring, portfolio-level risk dashboard. |
IntegrityFile is built for organizations moving from informal or basic checks toward structured, integrated, assurance-ready partner files.
Realistic review scenarios
- A proposal lists a project director who is not named in public records; the reviewer asks for delegated authority before signature.
- The NGO uses an acronym online but a long legal name in the registry; the reviewer searches both and documents an old article under the acronym.
- A donor page shows a previous grant from six years ago; the file treats it as history, not proof of current eligibility.
- A partner has no formal safeguarding policy but will work with children; the reviewer requires code of conduct, training, referral pathway, incident reporting clauses, and supervision before project start.
- A possible sanctions match appears for a common personal name; the reviewer compares date of birth, location, role, aliases, address, and source identifiers before escalating as unresolved or clearing as a false positive.
- A partner has a prior donor suspension that appears resolved; the reviewer asks for closure evidence, corrective action, repayment status, and monitoring conditions.
For publication, scenarios should read like practical training examples rather than dramatic allegations. They should show how a reviewer identifies a signal, checks match confidence, asks a narrow follow-up question, and records the decision. This helps readers understand that due diligence is a documented decision process, not a search for reasons to reject every partner.
File-ready wording
Clean review wording: On [date], [reviewer] completed partner due diligence for [legal entity name] using the entity name, acronym, former names, local-language names, key people, and relevant jurisdictions. No confirmed material public-source signal was identified from the sources reviewed. This conclusion is limited to the sources, search terms, dates, and jurisdictions recorded in the file.
Signal identified wording: On [date], the review identified a public-source signal relating to [describe signal]. Match confidence was assessed as [low/medium/high] because [identifiers]. The partner was asked to provide [specific document or explanation]. The matter was escalated to [team/person] because it may affect [funds/beneficiaries/legal eligibility/donor obligations/public trust].
Proceed-with-conditions wording: Approval may proceed only if [condition] is completed before [milestone], [control] is added to the agreement or monitoring plan, and [owner] confirms closure. The file should be refreshed by [date/event] or earlier if a new signal appears.
Unable-to-confirm wording: Public sources did not allow the reviewer to confirm [fact]. The file should state the limitation, list the sources checked, request partner documentation if needed, and avoid implying that absence of public evidence proves absence of risk.
What this does not replace
- Legal advice, sanctions counsel, tax advice, charity-law advice, employment advice, or donor-specific eligibility determinations.
- A financial audit, forensic investigation, site visit, beneficiary interview process, safeguarding investigation, or security assessment.
- Mandatory donor vetting, government screening, anti-terrorism certification, conflict-of-interest disclosure, procurement approval, or internal risk committee review.
- Partner capacity assessment, reference checks, program-quality review, environmental and social review, data-protection impact assessment, or ongoing monitoring.
- A final conclusion that an allegation is true or false. Public-source review documents signals and match confidence; adjudication requires the proper authority and process.
Follow-up questions
- What is the exact legal name, local-language name, acronym, and former names?
- Who can sign and who will control funds, reports, data, goods, and beneficiary contact?
- Do public records match the partner's governance documents?
- Have past donor findings, investigations, repayments, suspensions, or safeguarding matters been disclosed?
- Which jurisdictions and name variants were searched?
- What conditions or monitoring are needed before approval?
Quick FAQ
What is partner due diligence for NGOs?
It is the process of checking a partner's identity, legitimacy, governance, sanctions status, financial controls, safeguarding practices, reputation, and delivery capacity before working together.
Do NGOs need to screen partners for sanctions?
In many cases, yes. NGOs should screen partners against relevant sanctions lists based on jurisdiction, donor obligations, geography, program risk, and the partner's role.
Is partner due diligence required for every NGO partner?
Some level of due diligence should apply to every partner, but depth should be risk-based. A low-risk vendor does not need the same review as a high-risk subrecipient.
How often should NGOs repeat due diligence?
Repeat due diligence at renewal, when scope changes, when key personnel change, when new risks arise, before major payments in high-risk projects, and periodically for long-term partners.
What is enhanced due diligence for NGOs?
Enhanced due diligence is a deeper review used for high-risk partners, high-risk geographies, large funding amounts, sanctions-sensitive work, cash programs, vulnerable beneficiaries, or serious allegations.