Partner Due Diligence: How to Select Reliable Partners and Protect Your Organisation from Risk

‏16 اغسطس 2026 SHIREEN MIQDAD
Partner Due Diligence: How to Select Reliable Partners and Protect Your Organisation from Risk
sharing

Introduction

Non-profit organisations increasingly rely on partnerships to implement programmes, reach communities, exchange expertise, and expand their impact. A partner may be a local charity, an international organisation, a government entity, a company, an academic institution, or an organisation responsible for implementing part of a project or managing resources on behalf of another organisation.

However, partnerships do not transfer capabilities alone; they may also transfer risk.

A partner may have excellent field experience but weak financial management. Another may have strong operational capacity but inadequate governance, data protection, or complaints-management systems. In other cases, more serious concerns may arise relating to integrity, legal status, or conflicts of interest.

For this reason, it is not enough for an organisation to ask:

Do we know this partner, and does it have a good reputation?

It should also ask:

What risks are associated with this specific partnership, and do we have sufficient information and evidence to make a responsible decision?

This is where Partner Due Diligence becomes essential: a systematic process for verifying a prospective partner, understanding its capabilities and associated risks, and determining whether the organisation should enter into a relationship with it—and under what conditions and controls.

Due diligence is not an expression of distrust. It is a practice of governance, risk management, and protection of the organisation, its beneficiaries, and its resources.

Nor does due diligence end when the partnership agreement is signed. Information, risks, and circumstances may change throughout the partnership lifecycle.

This article develops the original Partner Due Diligence framework, including legal, financial, institutional, compliance, and reputational assessment; verification tools; risk classification; monitoring; governance; and donor requirements, while introducing a more risk-based approach to partnership decision-making.


First: What Is Partner Due Diligence?

Partner Due Diligence is a structured process of collecting, verifying, and analysing information to assess a partner's eligibility, capabilities, and associated risks before assigning responsibilities or resources to it, followed by continued monitoring of those risks throughout the relationship.

The process helps answer questions such as:

  • Does the partner have a valid legal status?
  • Who is authorised to represent it and make decisions on its behalf?
  • Does it have the institutional and operational capacity to fulfil its obligations?
  • Does it have appropriate financial and internal control systems?
  • Are there significant governance, integrity, or compliance concerns?
  • Are there potential conflicts of interest that should be disclosed?
  • Are its policies and practices aligned with project and donor requirements?
  • What risks are associated with the partnership?
  • Can those risks be mitigated, or do they exceed acceptable levels?

The objective, therefore, is not to collect as many documents as possible, but to obtain sufficient evidence to support a decision proportionate to the level of risk.


Second: Due Diligence Should Be Risk-Based

It is neither practical nor appropriate to apply the same level of scrutiny to every partner.

A partner participating in a limited event without managing funds does not present the same level of risk as a partner receiving a substantial grant, handling sensitive beneficiary data, or implementing field activities in a high-risk environment.

The guiding principle should therefore be:

The higher the level of risk, the greater the level of verification, controls, and monitoring required.

Factors that may determine the scope of due diligence include:

  • Value of funds or assets managed by the partner.
  • Nature of activities.
  • Access to beneficiaries.
  • Work involving children or people at greater risk.
  • Access to personal or sensitive data.
  • Geographic and security environment.
  • Use of sub-partners or third parties.
  • Duration of the partnership.
  • Previous experience with the partner.
  • Applicable legal and donor requirements.

The process can therefore be structured as:

Partnership Context → Initial Risk Screening → Proportionate Due Diligence → Risk Rating → Decision → Controls → Monitoring → Reassessment


Third: When Should Due Diligence Begin?

Due diligence should begin before creating a commitment that may be difficult to reverse.

Situations that may require due diligence include:

  • Before signing a partnership agreement.
  • Before transferring grants or resources to another entity.
  • Before assigning part of project implementation to a partner.
  • When entering a consortium or alliance.
  • When selecting a long-term strategic partner.
  • When there is a significant increase in funding or responsibilities.
  • When new information emerges that may change the risk level.
  • When there is a material change in the partner's legal, management, or operational circumstances.

This does not necessarily mean repeating the entire process every time. The scope of reassessment should be proportionate to the change and the resulting risks.


Fourth: Begin With Initial Screening Before Full Assessment

Before requesting dozens of documents, an organisation can conduct an Initial Screening to determine the appropriate scope of due diligence and identify issues that may require deeper verification.

Depending on the nature of the partner and applicable requirements, this may include:

Identity and Legal Status Verification

  • Legal name.
  • Registration and licensing.
  • Address and institutional information.
  • Authorised signatories.
  • Board members or key officials where relevant.

For certain types of entities, it may also be necessary to understand Beneficial Ownership / Control, depending on the applicable legal and operational context.

Conflicts of Interest

The organisation should determine whether financial, personal, or management relationships exist between the prospective partner and individuals involved in its selection that could affect the independence of the decision.

Integrity and Compliance Screening

Depending on applicable law, context, and donor requirements, relevant screening may include sanctions or other applicable legal restrictions, as well as indicators of fraud, corruption, or serious misconduct.

The purpose of screening is not to reach an immediate judgement, but to determine:

Is there anything that requires deeper investigation before proceeding?


Fifth: What Should Be Assessed?

The assessment should be as comprehensive as the risks of the relationship require and should not be limited to legal status or financial information.

1. Legal Assessment

This may include:

  • Legal registration.
  • Required licences.
  • Authority to represent and sign on behalf of the organisation.
  • Relevant regulatory obligations.
  • Restrictions that may affect implementation of the agreement.

2. Financial Assessment

This examines the partner's ability to manage funds appropriately, including:

  • Accounting systems.
  • Segregation of duties.
  • Financial approvals.
  • Bank account management.
  • Financial reporting.
  • Audits.
  • Procurement.
  • Cash and asset management.
  • Resolution of previous financial findings.

3. Governance and Institutional Capacity

This may include:

  • Organisational structure.
  • Board or governing body.
  • Delegation of authority.
  • Human Resources.
  • Previous experience.
  • Management capacity.
  • Institutional policies and procedures.

4. Operational Capacity

The central question is:

Can the partner actually deliver what we are asking it to deliver?

This may include:

  • Technical expertise.
  • Availability of personnel.
  • Logistics capacity.
  • Geographic access.
  • Supplier management.
  • Monitoring and reporting capacity.
  • Experience with similar projects.

5. Integrity and Compliance

Depending on the nature of the relationship, the assessment may examine appropriate policies and practices relating to:

  • Fraud and corruption prevention.
  • Conflicts of interest.
  • Data protection.
  • Safeguarding.
  • Complaints and reporting mechanisms.
  • Procurement.
  • Professional conduct.

6. Reputation and Track Record

The organisation may review:

  • Previous experience.
  • Professional references.
  • Previous partnerships.
  • Available audit or assessment findings.
  • Reliable information concerning significant misconduct or relevant disputes.

Reputation alone, whether positive or negative, should not determine the decision. Significant information should be verified through appropriate sources.


Sixth: Collecting Documents Does Not Mean You Have Conducted Due Diligence

One of the most common mistakes is turning the process into:

Checklist → Documents Received → Approved

Having a financial policy does not prove that financial practices are sound.

Having a Safeguarding Policy does not prove that employees understand how to implement it.

Depending on the level of risk, organisations should therefore combine tools such as:

Checklists

To promote consistency and ensure that important areas are not overlooked.

Institutional Questionnaires

To understand the partner's systems and capabilities.

Document Review

To examine policies, reports, records, and supporting evidence.

Interviews

To understand how systems operate in practice and clarify inconsistencies.

References

To verify previous experience where appropriate.

Site Visits

These may be particularly valuable where the partnership is higher risk or where operational capacity cannot be adequately verified through documentation alone.

The principle is:

Do not ask only whether a policy exists. Ask whether it works—and what evidence demonstrates that it does.


Seventh: Red Flags — When Should You Stop and Ask More Questions?

During an assessment, Red Flags may emerge. These do not automatically mean that a partner should be rejected, but they require verification and escalation before a decision is made.

Examples may include:

  • Material inconsistencies between information and supporting documents.
  • Refusal to provide essential documents without reasonable explanation.
  • Lack of clarity regarding persons authorised to act on behalf of the entity.
  • Bank information that does not reasonably correspond with the partner's identity.
  • Significant unexplained changes in management or control.
  • Severe weaknesses in segregation of financial duties.
  • Material audit findings that remain unresolved.
  • Undisclosed conflicts of interest.
  • Reliable information concerning serious misconduct.
  • Unreasonable difficulty verifying activities or experience claimed by the partner.

A Red Flag should not be ignored because of time pressure.

The appropriate logic is:

Stop → Verify → Escalate → Decide

This may lead to requests for additional information or Enhanced Due Diligence before a final decision is made.


Eighth: Do Not Confuse a Capacity Gap With an Integrity Issue

This distinction is particularly important when assessing partners.

A local charity may have a committed team and excellent field experience but an underdeveloped procurement system.

This is a Capacity Gap, which may often be addressed through:

  • Training.
  • Technical assistance.
  • Additional controls.
  • More frequent reviews.
  • An institutional improvement plan.

However, if an organisation identifies deliberate falsification, concealment of a material conflict of interest, or manipulation of documents, this is not an ordinary capacity gap.

It is an Integrity Issue requiring a different level of assessment, escalation, and decision-making.

This distinction matters because due diligence should not penalise smaller partners simply because their systems are less mature, while at the same time it should not treat integrity concerns as issues that can simply be resolved through training.


Ninth: From Assessment to Risk Rating

Once verification and analysis have been completed, findings should be translated into a form that supports decision-making.

A classification such as the following may be used:

Low Risk

Systems and capabilities appear appropriate, with no significant findings, and normal monitoring arrangements may be sufficient.

Medium Risk

Weaknesses exist but can be managed through additional controls, improvement plans, or more intensive monitoring.

High Risk

Significant risks exist that require treatment, additional verification, or higher-level management approval before proceeding.

Risk classification should not be based on personal impressions.

The organisation should be able to answer:

Why was the partner assigned this rating?

What evidence supports it?

What are the key risks?

Which risks can be mitigated?

Which risks cannot be accepted?


Tenth: High Risk Does Not Always Mean a “Bad Partner”

Particularly in humanitarian work, a partner may receive a high Risk Rating because of its operating context, rather than because of misconduct.

The partner may operate in:

  • A conflict-affected area.
  • An environment with limited banking infrastructure.
  • An area with weak infrastructure.
  • A complex regulatory environment.
  • A hard-to-reach location.

These circumstances may make the partnership inherently higher risk even when the partner itself operates professionally.

Organisations should therefore distinguish, where possible, between:

Partner Risk and Context Risk.

The question becomes:

Can we responsibly manage this level of risk?

rather than simply:

Is this a good or bad partner?


Eleventh: The Decision Is Not Always “Approve or Reject”

Partner Due Diligence may result in several outcomes:

Approve

Proceed with the partnership under standard controls.

Approve with Conditions

Proceed subject to specific requirements or corrective actions.

Enhanced Due Diligence

Conduct deeper verification before reaching a final decision.

Decline / Suspend

Do not proceed, or suspend the relationship, where risks are unacceptable or sufficient information is unavailable to support a responsible decision.

This provides a more accurate and flexible model than a simple:

Pass / Fail.


Twelfth: Conditional Approval — Turn Weaknesses Into an Action Plan

Where risks can be managed, the partnership may be linked to a Mitigation / Capacity Improvement Plan.

For example, if the assessment identifies weaknesses in procurement, conditions may include:

  • Adoption of an agreed procurement procedure before expenditure begins.
  • Training for relevant staff.
  • Additional approval for purchases above a specified threshold.
  • Periodic sample reviews.
  • Reassessment of the procurement system after an agreed period.

Each finding can be documented as:

Risk / Gap → Required Action → Responsible Party → Deadline → Evidence Required → Follow-up Status

Due diligence then becomes not only a partner-selection tool but also a mechanism for risk management and partnership capacity strengthening.

However, this approach is appropriate for weaknesses that can reasonably be addressed. It should not be used to bypass serious integrity concerns or unacceptable violations.


Thirteenth: Who Assesses and Who Approves?

Governance is important within the Due Diligence process itself.

The organisation should clearly define:

  • Who collects the information?
  • Who verifies it?
  • Who determines the Risk Rating?
  • Who has authority to approve the partner?
  • Who approves exceptions?
  • When must the decision be escalated to senior management or the Board?

Individuals involved in partner selection should also disclose relevant Conflicts of Interest.

If an employee has a direct relationship with a prospective partner, this does not necessarily mean that the partner must be excluded. However, the relationship should be disclosed and the conflict managed in a way that preserves the independence of the decision.

As risk increases, the required level of review and approval authority should also increase.


Fourteenth: The Partnership Agreement Is Part of Risk Management

Due Diligence findings should not remain confined to the assessment file.

Significant risks and controls should, where appropriate, be reflected in the partnership agreement.

The agreement may address matters such as:

  • Roles and responsibilities.
  • Reporting requirements.
  • Use of funds.
  • Procurement.
  • Record retention.
  • Access to documentation for review purposes.
  • Compliance requirements.
  • Data protection.
  • Safeguarding.
  • Reporting incidents or misconduct.
  • Use of sub-partners.
  • Audit and review rights.
  • Corrective actions.
  • Suspension or termination in cases of material breach.

The process then becomes:

Due Diligence Finding → Risk Control → Contractual Requirement → Monitoring

rather than leaving assessment findings disconnected from management of the relationship.


Fifteenth: Due Diligence Does Not End at Signing

This is one of the most important principles.

A partner may be suitable at the beginning of the relationship, but its circumstances may change.

Depending on the risk level, ongoing monitoring may include:

  • Reviewing reports.
  • Monitoring contractual obligations.
  • Monitoring financial and operational performance.
  • Following up on improvement plans.
  • Monitoring significant incidents and complaints.
  • Confirming continued compliance.
  • Reviewing material organisational changes.
  • Periodic reassessment where required.

Monitoring frequency can also be Risk-Based.

A low-risk partner does not necessarily require the same level of oversight as a higher-risk partner.


Sixteenth: When Should Due Diligence Be Repeated Before the Scheduled Review?

In addition to periodic reviews, organisations should use Trigger-Based Reassessment.

This means that certain events automatically prompt reconsideration of the partner even if the next scheduled review has not yet arrived.

Examples include:

  • A significant change in management or control.
  • A change in legal status.
  • A substantial increase in funding.
  • A material expansion of project scope.
  • A significant financial irregularity.
  • A serious complaint or incident.
  • New information relating to integrity or compliance.
  • Significant audit findings.
  • Assignment of a substantial part of implementation to a new sub-partner.

The principle is:

If the risks change, the partner assessment should not remain static.


Seventeenth: Protecting Data During Due Diligence

During the assessment, an organisation may collect legal and financial documents, information about Board members and management, contact information, identification documents, and information related to verification and compliance.

Due Diligence itself should therefore not become a source of data risk.

Organisations should consider principles such as:

  • Collecting only necessary information.
  • Defining the purpose for collecting it.
  • Restricting access to files.
  • Secure storage.
  • Defined retention periods.
  • Controlled information sharing.
  • Compliance with applicable legal requirements.

A useful principle is:

Do not collect a sensitive document simply because the Due Diligence template has a field for it; collect what is genuinely required to make the decision and fulfil applicable obligations.


Eighteenth: Common Weaknesses in Partner Due Diligence Systems

Common weaknesses include:

  • Relying on personal relationships or reputation.
  • Using the same assessment model for every partner.
  • Collecting documents without verifying implementation.
  • Failing to document the basis for a Risk Rating.
  • Ignoring Red Flags because of time pressure.
  • Confusing Capacity Gaps with Integrity Issues.
  • Failing to manage conflicts of interest.
  • Failing to reflect findings in the partnership agreement.
  • Failing to follow up on Mitigation Actions.
  • Conducting Due Diligence only once.
  • Failing to reassess after significant changes.
  • Collecting sensitive data without adequate controls.

An organisation may have an excellent Due Diligence template but still have a weak system if the findings do not influence decisions, contractual conditions, or monitoring.


Nineteenth: How Does Due Diligence Relate to Governance and Risk Management?

Due Diligence is not separate from the organisation's wider management systems.

It is a practical application of governance because it defines:

Who Assesses? → Who Reviews? → Who Approves? → Who Has Authority to Accept Risk?

It is part of risk management because it enables the organisation to identify third-party risks before they become organisational problems.

It is also part of compliance because it supports verification of legal, contractual, and donor requirements.

Its findings should, where appropriate, influence:

Partner Selection → Risk Register → Contract → Monitoring Plan → Audit → Management Reporting → Future Partnership Decisions

Where partner risks are significant to the organisation, they may also need to appear in the institutional Risk Register.


Twentieth: What Does a Donor Want to See?

A donor does not only want to hear:

We have a Partner Due Diligence Policy.

The donor needs evidence that the system actually works.

The evidence trail may include:

Policy → Screening → Assessment → Supporting Evidence → Risk Rating → Approval → Mitigation Plan → Agreement Conditions → Monitoring → Reassessment

One useful readiness test is for a donor to ask:

Show us a partner you classified as Medium or High Risk.

Then:

Why did the partner receive that rating?

What evidence supported the assessment?

What risks were identified?

Who approved the partnership?

What conditions or controls were imposed?

Were they implemented?

How did you verify implementation?

Did the risk level change afterwards?

If the organisation can provide documented answers, this demonstrates greater institutional maturity than having numerous policies and templates that are not actively used.


Twenty-First: How Do You Know Whether Your Partner Due Diligence System Is Mature?

An organisation can assess whether it has:

✓ A clear Partner Due Diligence policy and procedure.

✓ A Risk-Based Approach.

✓ Appropriate Initial Screening.

✓ Clear assessment criteria.

✓ Verification of legal status, financial and operational capacity, governance, and compliance according to the level of risk.

✓ A mechanism for identifying and responding to Red Flags.

✓ Conflict-of-interest disclosure and management.

✓ A clear distinction between Capacity Gaps and Integrity Issues.

✓ A documented Risk Rating.

✓ Defined approval-authority levels.

✓ Conditional Approval where risks can reasonably be mitigated.

✓ Integration of assessment findings into contracts and monitoring plans.

✓ Follow-up of Mitigation Actions.

✓ Trigger-Based Reassessment.

✓ Appropriate protection of information collected during the process.

✓ Sufficient evidence explaining how and why decisions were made.

However, the most important test is not the number of templates.

It is:

Can the organisation demonstrate that Due Diligence findings changed a decision, contractual condition, or level of monitoring?

If the answer is yes, the system has become an active part of institutional management.


Before Moving to the Next Article...

A charity can begin practically by:

✓ Classifying its different partnership types according to risk.

✓ Reviewing its current Partner Due Diligence Policy.

✓ Creating a simple Initial Screening process.

✓ Defining documentation requirements according to risk instead of requesting the same documents from every partner.

✓ Establishing clear criteria for Low / Medium / High Risk.

✓ Defining Red Flags and their escalation process.

✓ Determining who assesses, who reviews, and who approves.

✓ Adding a Conflict of Interest Declaration to the partner-selection process.

✓ Creating a Mitigation Plan for partners approved with conditions.

✓ Linking Due Diligence findings to partnership agreements.

✓ Setting Monitoring Frequency according to risk.

✓ Establishing clear Triggers for reassessment.

✓ Reviewing how Due Diligence files are stored and accessed.


Quick Self-Assessment

Ask yourself:

□ Do we subject every partner to the same level of review, or do we use a Risk-Based Approach?

□ Do we verify important information, or merely receive documents?

□ Do we know who has authority to represent the partner and sign on its behalf?

□ Do we have a clear mechanism for identifying and addressing Red Flags?

□ Do we distinguish between capacity weaknesses and integrity concerns?

□ Can we explain why a partner was classified as Low, Medium, or High Risk?

□ Can we use Conditional Approval rather than only approve or reject?

□ Does every mitigation action have an owner, deadline, and required evidence?

□ Are Due Diligence findings reflected in the partnership agreement?

□ Does the intensity of monitoring change according to the level of risk?

□ Do we have defined events that trigger reassessment?

□ Do we manage conflicts of interest within the partner-selection process?

□ Do we protect sensitive information collected during Due Diligence?

□ Can we demonstrate a real case where Due Diligence changed a partnership decision?

If the answer is “No” to several of these questions, the organisation may be collecting partner documents, but it has not yet built an integrated Partner Due Diligence system.


Conclusion

Partner Due Diligence is not a search for the “perfect partner,” nor is it a process designed to prove that a partner is free from all risk.

It is a process that helps an organisation understand the partner, the context, and the associated risks well enough to make a responsible decision.

The process begins by defining the nature of the relationship, conducting appropriate screening, verifying evidence, assessing capacity, integrity and compliance, assigning a risk rating, and making a decision proportionate to that risk.

In some cases, the decision will be approval.

In others, it may involve:

Conditional Approval, stronger controls, partner capacity strengthening, Enhanced Due Diligence, or a decision not to proceed with the relationship.

Most importantly, the decision-making process does not end when the agreement is signed.

Partnerships change, and their risks change with them. Monitoring and reassessment should therefore continue throughout the relationship.

A mature organisation does not merely ask:

Have we completed Due Diligence for this partner?

It asks:

What did we discover? How did it affect our decision? What controls did we establish? And are the risks still within the limits we are prepared to accept?

At that point, Partner Due Diligence moves beyond being a document-collection checklist and becomes a genuine tool for governance, risk management, and building more reliable and sustainable partnerships.