An NGO partner due diligence checklist helps an organisation decide whether a proposed grantee, subrecipient, consortium member or implementing partner can manage funds and deliver safely. It creates a consistent evidence trail before an agreement is signed or money is transferred.
The process should be proportionate. A small community organisation receiving a modest award should not face the same documentation burden as a large international subrecipient. However, every assessment should cover legal identity, governance, delivery capacity, financial controls, safeguarding, integrity and the risks created by the specific project.
Copyable NGO partner due diligence checklist
| Assessment area | Questions to answer | Suggested evidence | Rating |
|---|---|---|---|
| Legal identity | Does the organisation legally exist and have authority to operate? | Registration certificate, constitution, tax record and verified address | Low/Medium/High |
| Governance | Is there effective oversight and separation of responsibilities? | Board list, organogram, meeting records and conflict declarations | Low/Medium/High |
| Delivery capacity | Can the partner deliver the proposed scope, geography and budget? | Past-performance records, staffing plan, references and workplan | Low/Medium/High |
| Financial management | Can funds be received, recorded, controlled and reported accurately? | Accounts, audit reports, finance manual, budget controls and bank verification | Low/Medium/High |
| Procurement and assets | Are purchases competitive and assets protected? | Procurement policy, sample files, asset register and approval limits | Low/Medium/High |
| Safeguarding and PSEA | Can the partner prevent, report and respond to harm? | Policies, reporting channels, focal person, training and case procedures | Low/Medium/High |
| Fraud and integrity | Are conflicts, fraud, corruption and prohibited conduct controlled? | Code of conduct, declarations, whistleblowing channel and investigation procedure | Low/Medium/High |
| Data protection | Can personal and sensitive information be handled securely? | Data policy, access controls, consent process and incident procedure | Low/Medium/High |
| Downstream partners | Will the organisation pass responsibilities to another party? | Subaward procedures, approval process and monitoring plan | Low/Medium/High |
| Security and access | Can activities be delivered without exposing people to unmanaged risk? | Security plan, access analysis, incident records and duty-of-care measures | Low/Medium/High |
Step 1: Define the relationship and risk
Start with the proposed work, not a generic questionnaire. Record the partner’s role, funding amount, countries and locations, duration, target population, access to personal data, safeguarding exposure, procurement responsibility, cash use and authority to appoint further partners.
Use these facts to decide the depth of review. Higher-risk arrangements may require independent verification, interviews, sample testing, site visits or enhanced approval. Record why the selected assessment level is proportionate.
Step 2: Verify legal identity and governance
Confirm the organisation’s full legal name, registration number, registered address, operating authority and tax status through reliable records where available. Check that names and numbers agree across the certificate, bank account, proposal and contracts.
Review the governing body, senior management, ownership or control structure and conflicts of interest. Identify who can commit the organisation legally and who will approve expenditure. A board list alone does not demonstrate active oversight; request recent evidence that governance bodies meet and review organisational performance.
Step 3: Assess delivery capacity
Compare the proposed project with the partner’s actual experience, staffing and systems. Examine whether it has delivered work of similar size, complexity, sector and geography. Contact references using independently verified details rather than relying only on contacts supplied in a proposal.
Identify roles that are vacant, shared across projects or dependent on one individual. Where gaps are manageable, convert them into a capacity-strengthening plan with actions, owners, deadlines and monitoring evidence.
Step 4: Review financial controls
Assess budgeting, accounting, bank controls, segregation of duties, cash management, payroll, advances, supporting documents, financial reporting and audit arrangements. Reconcile the latest financial statements to other information about the organisation’s income and scale.
Do not treat an audit report as automatic assurance. Read the management letter, qualifications and repeat findings. Confirm whether corrective actions were completed. Where controls are weak, consider smaller tranches, expenditure verification, prior approvals or direct procurement rather than simply accepting the risk.
Step 5: Test safeguarding and PSEA capacity
Check whether safeguarding policies operate in practice. Staff and volunteers should understand expected conduct, reporting channels and protection against retaliation. The organisation should have safe procedures for receiving concerns, managing confidentiality, referring survivors and reporting serious incidents.
The updated FCDO safeguarding due diligence guidance assesses leadership, recruitment, codes of conduct, complaints mechanisms, risk management and response. Apply requirements proportionately while keeping minimum protection standards non-negotiable.
Step 6: Check fraud, conflicts and prohibited parties
Ask about prior fraud, corruption, investigations, litigation, donor sanctions and material reputational issues. Screen the correct legal entity and relevant key people against the sanctions, exclusion and debarment sources required by the donor and applicable law.
Document potential matches carefully. Similar names are not proof. Verify identifiers such as registration number, address, date of birth, nationality or ownership before escalating a result.
Recent UK government guidance on fraud control in international aid emphasises regular partner due diligence, fraud-risk assessment, effective audit processes and clear fraud clauses in agreements.
Step 7: Rate findings and decide controls
Rate inherent risk before controls and residual risk after proposed mitigation. Avoid averaging away a critical finding: a serious safeguarding gap or unverifiable legal identity should not become “medium” because other sections scored well.
Use a documented decision such as:
- Approve: risks are acceptable with routine monitoring.
- Approve with conditions: specific controls must be completed before or during the award.
- Defer: evidence is incomplete and no funding should be transferred yet.
- Decline: risks cannot be reduced to an acceptable level.
Step 8: Turn due diligence into an action plan
For every condition, record the action, responsible person, deadline, verification evidence and consequence of non-completion. Reflect important controls in the agreement, budget, payment schedule and monitoring plan.
Examples include dual approval for payments, monthly bank reconciliation, procurement thresholds, mandatory safeguarding induction, prior approval for downstream partners, quarterly asset checks or a deadline for closing audit findings.
Step 9: Refresh the assessment
Due diligence is not a one-time file. Review it when the agreement is renewed, the budget or scope increases, the partner enters a new country, senior leadership changes, serious incidents occur or monitoring reveals a control failure. Set a routine review date even when no trigger occurs.
Minimum due diligence record
Keep the completed assessment, documents reviewed, verification sources, interview notes, risk ratings, approval decision, conditions, conflicts declarations and follow-up evidence in a restricted partner file. Record dates and reviewers so another staff member can understand what was checked and why the decision was reasonable.
Strengthen grants and partnership management
Partner assessment works best when it is connected to programme design, financial management, safeguarding and monitoring. ATI’s Grants Management Training Workshop helps NGO teams build practical systems for partner selection, compliance, reporting, risk management and award closeout.
Important note
This checklist is a practical starting point, not legal advice or a replacement for donor-specific procedures. Organisations should adapt it to applicable laws, grant conditions, sanctions rules, safeguarding requirements and their own risk appetite.