Your address will show here +12 34 56 78

An NGO partner due diligence checklist helps an organisation decide whether a proposed grantee, subrecipient, consortium member or implementing partner can manage funds and deliver safely. It creates a consistent evidence trail before an agreement is signed or money is transferred.

The process should be proportionate. A small community organisation receiving a modest award should not face the same documentation burden as a large international subrecipient. However, every assessment should cover legal identity, governance, delivery capacity, financial controls, safeguarding, integrity and the risks created by the specific project.

Copyable NGO partner due diligence checklist

Assessment areaQuestions to answerSuggested evidenceRating
Legal identityDoes the organisation legally exist and have authority to operate?Registration certificate, constitution, tax record and verified addressLow/Medium/High
GovernanceIs there effective oversight and separation of responsibilities?Board list, organogram, meeting records and conflict declarationsLow/Medium/High
Delivery capacityCan the partner deliver the proposed scope, geography and budget?Past-performance records, staffing plan, references and workplanLow/Medium/High
Financial managementCan funds be received, recorded, controlled and reported accurately?Accounts, audit reports, finance manual, budget controls and bank verificationLow/Medium/High
Procurement and assetsAre purchases competitive and assets protected?Procurement policy, sample files, asset register and approval limitsLow/Medium/High
Safeguarding and PSEACan the partner prevent, report and respond to harm?Policies, reporting channels, focal person, training and case proceduresLow/Medium/High
Fraud and integrityAre conflicts, fraud, corruption and prohibited conduct controlled?Code of conduct, declarations, whistleblowing channel and investigation procedureLow/Medium/High
Data protectionCan personal and sensitive information be handled securely?Data policy, access controls, consent process and incident procedureLow/Medium/High
Downstream partnersWill the organisation pass responsibilities to another party?Subaward procedures, approval process and monitoring planLow/Medium/High
Security and accessCan activities be delivered without exposing people to unmanaged risk?Security plan, access analysis, incident records and duty-of-care measuresLow/Medium/High

Step 1: Define the relationship and risk

Start with the proposed work, not a generic questionnaire. Record the partner’s role, funding amount, countries and locations, duration, target population, access to personal data, safeguarding exposure, procurement responsibility, cash use and authority to appoint further partners.

Use these facts to decide the depth of review. Higher-risk arrangements may require independent verification, interviews, sample testing, site visits or enhanced approval. Record why the selected assessment level is proportionate.

Step 2: Verify legal identity and governance

Confirm the organisation’s full legal name, registration number, registered address, operating authority and tax status through reliable records where available. Check that names and numbers agree across the certificate, bank account, proposal and contracts.

Review the governing body, senior management, ownership or control structure and conflicts of interest. Identify who can commit the organisation legally and who will approve expenditure. A board list alone does not demonstrate active oversight; request recent evidence that governance bodies meet and review organisational performance.

Step 3: Assess delivery capacity

Compare the proposed project with the partner’s actual experience, staffing and systems. Examine whether it has delivered work of similar size, complexity, sector and geography. Contact references using independently verified details rather than relying only on contacts supplied in a proposal.

Identify roles that are vacant, shared across projects or dependent on one individual. Where gaps are manageable, convert them into a capacity-strengthening plan with actions, owners, deadlines and monitoring evidence.

Step 4: Review financial controls

Assess budgeting, accounting, bank controls, segregation of duties, cash management, payroll, advances, supporting documents, financial reporting and audit arrangements. Reconcile the latest financial statements to other information about the organisation’s income and scale.

Do not treat an audit report as automatic assurance. Read the management letter, qualifications and repeat findings. Confirm whether corrective actions were completed. Where controls are weak, consider smaller tranches, expenditure verification, prior approvals or direct procurement rather than simply accepting the risk.

Step 5: Test safeguarding and PSEA capacity

Check whether safeguarding policies operate in practice. Staff and volunteers should understand expected conduct, reporting channels and protection against retaliation. The organisation should have safe procedures for receiving concerns, managing confidentiality, referring survivors and reporting serious incidents.

The updated FCDO safeguarding due diligence guidance assesses leadership, recruitment, codes of conduct, complaints mechanisms, risk management and response. Apply requirements proportionately while keeping minimum protection standards non-negotiable.

Step 6: Check fraud, conflicts and prohibited parties

Ask about prior fraud, corruption, investigations, litigation, donor sanctions and material reputational issues. Screen the correct legal entity and relevant key people against the sanctions, exclusion and debarment sources required by the donor and applicable law.

Document potential matches carefully. Similar names are not proof. Verify identifiers such as registration number, address, date of birth, nationality or ownership before escalating a result.

Recent UK government guidance on fraud control in international aid emphasises regular partner due diligence, fraud-risk assessment, effective audit processes and clear fraud clauses in agreements.

Step 7: Rate findings and decide controls

Rate inherent risk before controls and residual risk after proposed mitigation. Avoid averaging away a critical finding: a serious safeguarding gap or unverifiable legal identity should not become “medium” because other sections scored well.

Use a documented decision such as:

  • Approve: risks are acceptable with routine monitoring.
  • Approve with conditions: specific controls must be completed before or during the award.
  • Defer: evidence is incomplete and no funding should be transferred yet.
  • Decline: risks cannot be reduced to an acceptable level.

Step 8: Turn due diligence into an action plan

For every condition, record the action, responsible person, deadline, verification evidence and consequence of non-completion. Reflect important controls in the agreement, budget, payment schedule and monitoring plan.

Examples include dual approval for payments, monthly bank reconciliation, procurement thresholds, mandatory safeguarding induction, prior approval for downstream partners, quarterly asset checks or a deadline for closing audit findings.

Step 9: Refresh the assessment

Due diligence is not a one-time file. Review it when the agreement is renewed, the budget or scope increases, the partner enters a new country, senior leadership changes, serious incidents occur or monitoring reveals a control failure. Set a routine review date even when no trigger occurs.

Minimum due diligence record

Keep the completed assessment, documents reviewed, verification sources, interview notes, risk ratings, approval decision, conditions, conflicts declarations and follow-up evidence in a restricted partner file. Record dates and reviewers so another staff member can understand what was checked and why the decision was reasonable.

Strengthen grants and partnership management

Partner assessment works best when it is connected to programme design, financial management, safeguarding and monitoring. ATI’s Grants Management Training Workshop helps NGO teams build practical systems for partner selection, compliance, reporting, risk management and award closeout.

Important note

This checklist is a practical starting point, not legal advice or a replacement for donor-specific procedures. Organisations should adapt it to applicable laws, grant conditions, sanctions rules, safeguarding requirements and their own risk appetite.

0

African organisations should prepare now for the anticipated 2026/2027 El Niño episode. The African Union’s latest continental climate outlook calls for anticipatory action across agriculture, water, health, energy, infrastructure and humanitarian response. This practical checklist helps NGOs and project teams convert climate warnings into operational decisions.

The African Union Commission, ACMAD and regional partners consolidated forecasts during the 21st African Continental Climate Outlook Forum. The resulting July–October 2026 outlook is intended to help decision-makers act before climate shocks become emergencies. The AU warns that the cost of climate inaction could exceed 5% of regional GDP in some areas.

What El Niño 2026/2027 could mean for African projects

El Niño does not create identical conditions everywhere. Impacts vary by country and season, so teams must use their national meteorological service and regional climate centre for location-specific forecasts. Likely operational risks include irregular rainfall, floods or drought, crop losses, water stress, disease outbreaks, disrupted transport and changing humanitarian needs.

10-step NGO preparedness checklist

1. Assign a climate-risk lead

Name one accountable person to monitor official forecasts, coordinate decisions and maintain a simple risk log.

2. Update the project risk register

Add climate hazards, exposed locations, vulnerable groups, triggers, probability, impact, mitigation actions and owners. Review risks monthly or whenever an official forecast changes.

3. Map critical programme locations

Identify offices, warehouses, health facilities, water points, schools, roads and communities exposed to flood, drought, heat or landslide risk.

4. Define early-action triggers

Triggers should be specific and measurable—for example, a forecast probability, river level, rainfall deficit, disease threshold or government alert. Link each trigger to an agreed action and budget.

5. Protect supply chains

Review supplier concentration, transport routes, lead times and buffer stock. Pre-qualify alternatives for essential medicines, water-treatment materials, food, fuel and communications equipment.

6. Review budgets and donor flexibility

Estimate the cost of preparedness actions and check whether grants permit budget revisions. Discuss contingency lines and no-cost changes with donors before a crisis.

7. Strengthen community communication

Use trusted local channels, accessible languages and two-way feedback. Avoid alarming messages; explain the forecast, uncertainty, recommended actions and official sources.

8. Safeguard data and operations

Back up programme data, test remote-working arrangements, update emergency contacts and identify alternative power and connectivity options.

9. Coordinate with authorities

Align plans with national disaster-management agencies, meteorological services, local government and humanitarian coordination structures.

10. Run a tabletop exercise

Test one realistic scenario with programme, finance, logistics, security and leadership teams. Record decisions, gaps and actions with deadlines.

Minimum early-action plan template

ElementWhat to record
HazardFlood, drought, heat, disease or other risk
TriggerOfficial threshold that activates action
ActionSpecific measure to take
OwnerNamed responsible person
DeadlineTime allowed after trigger
BudgetCost and funding source
EvidenceHow completion will be verified

How to use this resource

Copy the checklist into your team’s planning document, adapt it to official local forecasts, and review it with decision-makers. Combine it with an NGO risk register and a donor-ready budget. More practical tools are available in the Resources Hub and professional learning is available through the Africa Training Hub.

Frequently asked questions

Is El Niño certain to affect every African country?

No. Impacts differ by region and season. Use national and regional official forecasts for operational decisions.

What is anticipatory action?

It means acting on credible forecasts before a hazard causes severe harm—for example, pre-positioning supplies or protecting water systems when agreed triggers are reached.

Sources: African Union: Preparing Africa for El Niño 2026/2027; AU continental policy brief.

0

An NGO risk register is a living management tool that records threats and opportunities, assesses their significance, assigns ownership and tracks action. It helps project teams make risks visible before they become incidents or delivery failures.

Copyable NGO risk-register structure

IDRisk statementCategoryLikelihoodImpactRatingControls and actionsOwnerReview date
R01If [cause] occurs, then [event] may happen, resulting in [effect]Programme/finance/security/compliance1–51–5L × IExisting controls and additional actionsNamed roleDate

Write risks clearly

Use a cause–event–effect format. “Political instability” is a context description, not a complete risk. A stronger statement explains how instability could restrict field access and delay services for targeted communities.

Score likelihood and impact consistently

Define every score. Impact criteria should consider people, programme delivery, finance, safeguarding, reputation and compliance. Agree escalation thresholds so high and critical risks receive management attention.

Distinguish controls from actions

Controls already reduce risk, while actions are additional measures with deadlines. Record the residual rating expected after controls. Avoid vague responses such as “monitor closely” without an owner, frequency or decision threshold.

Cover the full NGO risk landscape

  • Context and conflict risks
  • Programme quality and delivery risks
  • Safeguarding and protection risks
  • Fraud, corruption and financial risks
  • Procurement and partner risks
  • Safety, security and duty-of-care risks
  • Data protection and information-security risks
  • Donor compliance and reputational risks

Review the register throughout the project cycle

Review risks during design, inception, partner assessment, procurement, programme reviews and close-out. Update the register after incidents, major context changes, or significant budget and scope revisions. Risk information should inform decisions rather than sit in a compliance file.

ATI’s Risk Management in Donor-Funded Projects Course covers assessment, mitigation planning, compliance, monitoring and contingency planning.

Sources: UNDP Portfolio and Project Risk Register Template and GISF Blank Risk Register Template.

0

A strong NGO project budget converts planned activities into transparent, realistic and compliant costs. It should help a donor understand what resources are needed while giving the project team a practical tool for implementation, cash-flow planning and financial monitoring.

Recommended NGO project budget structure

Budget lineUnitQuantityUnit costTotalAssumption or justification
PersonnelMonthTime allocation and role
Travel and transportTrip/day/kmRoute, frequency and policy rate
Training and eventsParticipant/dayVenue, materials and refreshments
Equipment and suppliesItemSpecification and procurement basis
Subgrants or partnersAgreementPartner scope and controls
Monitoring and evaluationActivityData collection and evaluation costs
Indirect costsPercentageApproved base and rate

Build the budget from activities

Start with the implementation workplan. For every activity, list the people, time, transport, materials, procurement and support required. Activity-based budgeting reduces missing costs and makes the relationship between the proposal and budget easier to defend.

Document every calculation

A reviewer should be able to reproduce the total. State quantities, unit costs, exchange rates, salary allocations and procurement assumptions. Separate formulas from narrative justification and maintain a version-controlled assumptions sheet.

Check donor compliance

Confirm eligible and ineligible costs, indirect-cost rules, procurement thresholds, currency requirements, tax treatment, cost-sharing commitments and budget ceilings. Donor rules override a generic template.

Plan for implementation risk

Stress-test major cost drivers such as fuel, exchange rates, inflation and travel. Do not hide contingencies inside unrelated lines. Where contingency costs are allowed, label and justify them transparently.

Use the budget after approval

Convert the approved budget into monthly forecasts and budget-versus-actual reports. Assign budget owners, review variances, document reallocations and start donor conversations before an overspend or underspend becomes difficult to correct.

ATI’s Diploma in Finance Management for NGOs covers budgeting, internal controls, grants management, cash-flow analysis and financial reporting.

Sources: USAID Resources for Partners and European Commission: Managing a Grant Project.

0