What this check is
NGO Partner Review Checklist is a structured public-source and file-evidence review used when building a reusable partner review file. It looks for signals related to evidence fields, source logs, reviewer accountability, risk owner, decision rationale, and monitoring controls. The purpose is not to build a rumor list or to make an instant pass/fail decision; the purpose is to help a reviewer record what was checked, what was found, how reliable the source appears to be, and what decision or control followed.
A high-quality page should teach the reader a defensible workflow: define the exact entity, search the right names and jurisdictions, compare public records with internal documents, record source dates, preserve evidence, and escalate only when the signal is relevant and match confidence is reasonable. This approach is especially important for NGOs and civil society organizations because names, acronyms, language variants, fiscal sponsorship, coalitions, and informal operating histories can make shallow searches misleading.
In a due diligence file, this check should produce a short evidence trail: entity identifiers, people reviewed, jurisdictions searched, source links, search terms, screenshots or extracts where allowed, reviewer notes, partner explanations, unresolved questions, and any conditions placed on approval. A clean search should still be documented, because future reviewers need to know what was searched and when.
When to run it
- for every new partner review, including familiar or donor-recommended partners
- before renewals, amendments, or changes in scope, geography, activity, funding, or beneficiary contact
- when multiple teams must contribute to one common file
- when donors, auditors, or board members may review the file later
Run the check early enough that findings can still affect selection, award structure, budget controls, reporting duties, monitoring plans, or the decision not to proceed. It should also be refreshed when time has passed, risk context has changed, a new country or donor is added, key people change, or the partner will take on a role that is more sensitive than originally planned.
What to look for
- entity identifiers: names, aliases, registration, tax number, address, countries, website, and contacts
- people identifiers: board, trustees, senior management, project leads, finance/procurement leads, and signatories
- source log: source, URL, date/time, search terms, result, screenshot/PDF reference, reviewer, and match confidence
- decision record: risk rating, rationale, approver, conditions, residual risk, monitoring plan, and review date
- Name-variant accuracy: legal name, acronym, translated name, local-script name, former names, trading names, coalition names, and names used by fiscal sponsors or affiliates.
- Match confidence: whether the public record relates to the same entity or person, using identifiers such as address, registration number, officer name, website, tax number, geography, and date.
- Risk status: whether a signal is current, resolved, disputed, corrected, historical, jurisdiction-limited, or linked to a different entity with a similar name.
- Decision relevance: whether the signal affects the specific role, budget, geography, beneficiaries, goods, data, or authority the organization would give to the partner.
Public sources to review
Start with official and primary sources when available. Supplement with credible media, donor pages, court/regulator pages, annual reports, and partner-provided documents. Record access dates, source limitations, search settings, and false-positive logic.
Search terms to use
"[legal name]" "[country]"
"[legal name]" NGO registration OR charity register OR company register
"[legal name]" audit OR investigation OR complaint OR allegation
"[legal name]" fraud OR corruption OR bribery OR "misuse of funds"
"[legal name]" sanctions OR debarred OR suspended OR excluded
"[director name]" "[organization name]"
"[former name]" OR "[local-language name]"
"[organization name]" "annual report" OR "financial statements" OR "Form 990"
"[organization name]" "annual report" "board"
"[organization name]" "policy" "safeguarding" OR "PSEA"
"[organization name]" "donor" "audit" OR "evaluation"
"[registration number]" "[country]"
What reviewers often miss
- boxes marked complete without evidence references
- recording 'searched Google' without the exact query, date, language, or result
- capturing entity risk but not key people, branches, signatories, or downstream actors
- entering a risk rating without rationale or controls
- Not documenting why a near-match was ruled out, especially for common names, transliterations, and older articles.
- Relying on a single search engine, a single spelling, or a partner-provided document without checking an official source where one exists.
- Treating a clean public-source review as a permanent clearance rather than a dated snapshot that may need renewal.
- Failing to connect the finding to the actual decision: proceed, proceed with controls, pause, reject, report, or investigate.
Expert section: Checklist fields that make a partner file defensible
The expert issue for this page is checklist fields that make a partner file defensible. This is where the reviewer should move beyond generic web searching and show practical judgment: what matters for this specific relationship, which facts are material, which facts are noise, and which controls would actually reduce risk.
- A strong checklist is an audit trail. Each conclusion should point to evidence: registry extract, sanctions screenshot, donor report, public filing, article, partner response, or decision memo.
- Separate 'not found' from 'not applicable.' PSEA may be not applicable to a back-office vendor but essential for an implementing partner; Form 990 may not apply outside the United States.
- Include match confidence. A same-name sanctions or media result is not a confirmed issue unless identifiers match.
- Every signal should have an owner, deadline, escalation path, partner question, proposed condition, and final decision status.
A strong expert note connects each observation to a file decision. For example, a missing filing may lead to a request for updated registration evidence; a related-party link may lead to recusal; a safeguarding signal may require escalation to the safeguarding lead; a donor audit finding may require repayment status and corrective-action evidence; and a sanctions or debarment match may require immediate legal or donor review.
- Minimum evidence fields: entity or person searched; exact search term; source; access date; match identifiers; reviewer conclusion; partner response; escalation route; decision; and next review date.
- Materiality test: does the signal affect funds, authority, beneficiaries, data, goods, field access, public trust, donor obligations, or legal eligibility?
- Control design: convert findings into specific conditions such as dual authorization, restricted budget lines, enhanced reporting, site verification, training, data-access limits, or approval gates.
- Uncertainty handling: write down what is unknown, why it could not be confirmed from public sources, and what evidence would resolve it.
What to do when a signal appears
- Classify the signal against the page scope: evidence fields, source logs, reviewer accountability, risk owner, decision rationale, and monitoring controls. If it is outside scope, document why it was not material.
- Confirm match quality before escalation. Compare names, dates, addresses, registration numbers, people, websites, operating countries, and role descriptions.
- Preserve evidence in the file. Save the source title, URL, access date, screenshot or extract where permitted, search term, and reviewer note.
- Ask the partner for a targeted explanation and supporting documents, not a broad denial. Give the partner a chance to correct identity mistakes or provide closure evidence.
- Escalate according to severity. Sanctions, debarment, safeguarding, credible fraud, criminal, donor-reportable, or legal-status signals should move to the responsible compliance, legal, safeguarding, procurement, grants, or donor lead.
- Decide the operating response: clear, clear with explanation, proceed with conditions, pause, reject, report, or investigate.
- Set a monitoring trigger. Examples include leadership change, new country, new budget, new donor, new subpartner, new adverse media, open audit, or expired registration.
Realistic review scenarios
- A same-name sanctions hit is cleared after country, address, and date of birth do not match; the false-positive logic is recorded.
- A website names a new finance director not in partner documents; the checklist creates a follow-up item.
- A government registry is offline; the reviewer records the attempt and sets a follow-up date instead of marking complete.
For publication, scenarios should read like practical training examples rather than dramatic allegations. They should show how a reviewer identifies a signal, checks match confidence, asks a narrow follow-up question, and records the decision. This helps readers understand that due diligence is a documented decision process, not a search for reasons to reject every partner.
File-ready wording
Clean review wording: On [date], [reviewer] completed ngo partner review checklist for [legal entity name] using the entity name, acronym, former names, local-language names, key people, and relevant jurisdictions. No confirmed material public-source signal was identified from the sources reviewed. This conclusion is limited to the sources, search terms, dates, and jurisdictions recorded in the file.
Signal identified wording: On [date], the review identified a public-source signal relating to [describe signal]. Match confidence was assessed as [low/medium/high] because [identifiers]. The partner was asked to provide [specific document or explanation]. The matter was escalated to [team/person] because it may affect [funds/beneficiaries/legal eligibility/donor obligations/public trust].
Proceed-with-conditions wording: Approval may proceed only if [condition] is completed before [milestone], [control] is added to the agreement or monitoring plan, and [owner] confirms closure. The file should be refreshed by [date/event] or earlier if a new signal appears.
Unable-to-confirm wording: Public sources did not allow the reviewer to confirm [fact]. The file should state the limitation, list the sources checked, request partner documentation if needed, and avoid implying that absence of public evidence proves absence of risk.
What this does not replace
- Legal advice, sanctions counsel, tax advice, charity-law advice, employment advice, or donor-specific eligibility determinations.
- A financial audit, forensic investigation, site visit, beneficiary interview process, safeguarding investigation, or security assessment.
- Mandatory donor vetting, government screening, anti-terrorism certification, conflict-of-interest disclosure, procurement approval, or internal risk committee review.
- Partner capacity assessment, reference checks, program-quality review, environmental and social review, data-protection impact assessment, or ongoing monitoring.
- A final conclusion that an allegation is true or false. Public-source review documents signals and match confidence; adjudication requires the proper authority and process.
Follow-up questions
- Does the checklist identify the exact entity reviewed?
- Does every conclusion include a source, URL, date, term, and reviewer?
- Are false positives documented with match logic?
- Are open items assigned to an owner and due date?
- Does the risk rating connect to award conditions?
- Can an auditor understand the decision without interviewing the reviewer?