Proportionate partner due diligence checklist
How to Use This Checklist
A grants, finance or program officer runs this before signing with a funded partner, consortium member or implementing partner. The question is whether the partner can manage funds and deliver safely. Begin as soon as you decide to team up with a partner, and repeat the exercise at later milestones or whenever circumstances shift.
One source says every assessment should cover legal identity, governance, delivery capacity, financial controls, safeguarding, integrity and the risks of the specific project. How deep you go depends on the size and risk of the award, so match the form to the award instead of sending the same one to everyone. Check the partner's own claims against independent sources, and watch for relevant facts it omits.
Set the Depth of Review First
Standard checks were designed with large international agencies and their big staffs in mind, so they can be overbuilt for small local groups. Demanding extensive management systems can shut out partners you want. A community organization may not be formally registered or may lack some written policies, and a template blind to that can cost it funding, so it should not carry the documentation load of a large international partner. One practitioner guide suggests a streamlined questionnaire for a small local association receiving less than 50,000 euros. The point of scoring is to fit the level of control to the real risk, not to shut out fragile partners.
- Define the partner's role and the award.
- Choose an assessment level and record why it is proportionate.
- Flag higher-risk features that call for independent verification, interviews, sample testing, site visits or enhanced approval.
Legal Identity and Governance
You are checking the partner's legal identity and how it is governed. Source registration documents yourself instead of relying on copies the partner hands you.
- Names and numbers agree across the registration certificate, bank account, proposal and contracts.
- Recent evidence shows that governance bodies meet and review performance.
- You have not treated a board list as proof of oversight. A list of names shows who is on the board, not whether anyone is watching.
Delivery Capacity and References
- Staff and skills match the proposed work.
- Roles that are vacant, shared across projects or dependent on one person are identified.
- References were contacted using independently verified details, not only the contacts in the proposal.
- Manageable gaps are turned into a capacity-strengthening plan with actions, owners, deadlines and monitoring evidence.
Financial Controls
The review looks at whether the partner can track and report money accurately.
- Budgeting, accounting and financial reporting are in place.
- Bank controls, segregation of duties and cash management work in practice.
- Payroll, advances, supporting documents and audit arrangements are covered.
- Any audit report was read for the management letter, qualifications and repeat findings. A report on file is not assurance.
Where controls are weak, do not simply accept the risk. Options include smaller tranches, expenditure verification, prior approvals, or buying directly instead of transferring funds.
Safeguarding (Protection From Sexual Exploitation and Abuse)
Apply requirements in proportion to the partner's size, but minimum protection standards stay in place for everyone.
- Procedures exist for receiving concerns and managing confidentiality.
- People affected by harm (survivors) can be referred, and serious incidents are reported.
- Gaps are written into a capacity-strengthening plan with a firm end date. One humanitarian agency's guidance expects full safeguarding capacity within six months of starting the plan, or nine months in an exceptional case.
Integrity, Conflicts and Screening
- You asked about prior fraud, corruption, investigations, litigation, sanctions and material reputational issues.
- Local court rolls were checked for past or pending lawsuits, whether brought against the organization or by it.
- The correct legal entity and relevant key people were screened against the sanctions, exclusion and debarment sources the funder and applicable law require.
- Any name that is only similar was tested against identifiers before escalation. Similar names do not prove a match.
Data, Security and Downstream Partners
- A data policy, access controls, consent process and incident procedure exist.
- The partner's security capacity is understood. If it is thin, your own staff could be exposed to more risk than is acceptable.
- If the partner passes funds on, you have seen its subaward procedures, approval process and monitoring plan.
Rate, Decide and Set Conditions
Rate the risk on a scale you set yourself, then keep one rule in mind. A serious safeguarding gap or a legal identity you cannot verify should never be averaged into a medium rating because other sections scored well.
Choose one decision:
- Approve.
- Approve with conditions.
- Defer because evidence is incomplete (no funds transferred yet).
- Decline because risks cannot be reduced to an acceptable level.
For every condition, write down:
- The action.
- The responsible person.
- The deadline.
- The verification evidence.
- The consequence of non-completion.
Record and Refresh
Keep the file restricted.
- The file holds the assessment, documents reviewed, verification sources, interview notes, risk ratings, decision, conditions, conflict declarations and follow-up evidence.
- Each screening record shows the entity or person searched, exact search term, source, access date, match identifiers, reviewer conclusion, partner response, escalation route, decision and next review date.
- A routine review date is set even if no trigger occurs.
- The events that trigger a refresh are written down: the agreement is renewed, budget or scope grows, the partner enters a new country, senior leadership changes, a serious incident occurs, or monitoring reveals a control failure.
- Sanctions, exclusions, debarments, registry status, leadership and recent public allegations are rechecked, since they change frequently. A clean public-source review is only a dated snapshot.