How to Pass a Donor Organizational Readiness Assessment: A Practical Guide to Building a Funding-Ready Organization

‏17 اغسطس 2026 SHIREEN MIQDAD
How to Pass a Donor Organizational Readiness Assessment: A Practical Guide to Building a Funding-Ready Organization
sharing

Introduction

Donors are increasingly careful to verify whether non-profit organizations can manage funding effectively and achieve intended results before entering into funding agreements. Funding decisions are no longer based solely on the quality of a project idea or the importance of the issue being addressed; they also depend on the organization’s administrative, financial, technical, governance, oversight, compliance, and risk-management readiness.

This has led to the growing use of Organizational Readiness Assessments and, in some cases, Organizational Capacity Assessments (OCA) as structured tools for determining whether an organization is prepared to manage grants and implement projects responsibly.

These assessments usually cover interconnected areas such as governance, financial management, Human Resources, procurement, programme management, MEAL, risk management, internal controls, compliance, safeguarding, data management, and operational and technical capacity.

A common mistake is to treat readiness as a documentation exercise, with organizations rushing to draft policies and assemble files only weeks before a donor visit.

A professional assessor looks beyond the document itself and examines a deeper chain:

Existence → Approval → Implementation → Evidence → Review & Improvement

In other words:

Does the system exist? → Is it formally approved? → Is it being implemented? → Is there evidence of implementation? → Is it reviewed and improved?

A funding-ready organization is therefore not the one with the greatest number of policies, but the one that can demonstrate that its systems actually function and produce verifiable decisions, records, and controls.

This article builds on the original institutional readiness framework, while retaining its focus on governance, finance, Human Resources, risk, compliance, documentation, and sustainability, and adding more practical tools for preparing for donor assessments and demonstrating implementation.


First: What Is an Organizational Readiness Assessment?

An Organizational Readiness Assessment is a structured process used by donors or organizations themselves to determine whether an organization has the capacity to manage resources, implement projects, achieve results, and comply with relevant administrative, financial, legal, and contractual requirements.

The assessment seeks to answer one central question:

Does the organization have the systems, capabilities, and controls required to manage this funding effectively and responsibly?

For this reason, the assessment does not only examine policies. It also considers:

  • How decisions are made.
  • How authorities are distributed.
  • Whether internal controls are effective.
  • How funds and assets are managed.
  • Whether staff are capable of performing their roles.
  • How programmes and results are managed.
  • How risks are identified and addressed.
  • Whether compliance requirements are understood and applied.
  • How beneficiaries and data are protected.
  • Whether the organization can identify problems and correct them.

It is also important not to treat the assessment purely as a Pass / Fail exercise.

An organization may be ready, ready with conditions, in need of specific capacity improvements before funding, or not yet ready for the scale or complexity of the proposed grant.


Second: Why Do Donors Conduct Readiness Assessments?

Donors are responsible for ensuring that funds are managed properly and that implementing partners can fulfil their obligations.

A readiness assessment helps donors:

  • Verify the organization’s ability to manage grants.
  • Assess governance, transparency, and accountability.
  • Evaluate financial and control systems.
  • Identify institutional weaknesses.
  • Assess risks before funding.
  • Determine any controls required for the grant.
  • Identify capacity-building needs.
  • Reduce the likelihood of fraud or mismanagement.
  • Improve the likelihood of successful implementation and results.

The assessment should therefore be understood as part of a Risk-Based Funding Decision.

The donor is effectively asking:

What risks would we assume by funding this organization, and can those risks be managed to an acceptable level?


Third: When Is an Organizational Readiness Assessment Required?

A readiness assessment may be conducted:

  • Before signing a funding agreement.
  • Before entering into a strategic partnership.
  • Before transferring grants to local partners.
  • When applying for large or multi-year grants.
  • When implementing programmes funded by international organizations.
  • When the scale of funding or responsibilities increases significantly.
  • During periodic donor reviews.
  • When major organizational changes or risks emerge.

Organizations can also conduct periodic Self-Assessments even when no funding opportunity is imminent.

This is a more mature approach because it turns readiness from a temporary response to donor requirements into part of normal institutional management.


Fourth: How Does an Assessor Think? From Policy to Evidence

This is one of the most important concepts in understanding readiness assessments.

Suppose the organization submits an excellent Procurement Policy.

That document answers only the first question:

Do you have a procurement policy?

The assessor may then select an actual procurement transaction and ask:

Who requested the purchase?

Who approved it?

How was the supplier selected?

Were the required quotations obtained?

Were the bids evaluated?

Was any Conflict of Interest identified?

Who received the goods or service?

Who authorized the payment?

How was the transaction recorded in the accounting system?

The evidence trail becomes:

Policy → Request → Quotations → Evaluation → Approval → Purchase → Receiving → Payment → Accounting Record

This is effectively an Evidence Trail.

The key principle is:

The policy tells the assessor how the organization is supposed to work; the sample shows how the organization actually works.


Fifth: Evidence Trail — How Do You Prove the System Works?

An organization should be able to trace a system from policy to implementation.

Example: Conflict of Interest

The evidence is not only:

Conflict of Interest Policy

It may also include:

Policy → Annual Declarations → Conflict Register → Disclosure → Recusal → Meeting Minutes

Example: Human Resources

HR Policy → Recruitment Request → Selection → Approval → Contract → Induction → Personnel File → Performance Review

Example: Risk Management

Risk Management Policy → Risk Register → Risk Owner → Mitigation Action → Review → Escalation → Management Decision

Example: Complaints

Complaints Policy → Complaint Received → Classification → Assignment → Investigation/Response → Closure → Learning

with appropriate confidentiality and access controls.

The ability to trace processes from beginning to end is one of the strongest indicators of institutional maturity.


Sixth: What Are the Main Areas Donors Assess?

Assessment models vary across donors, but most focus on several core domains.

1. Governance and Leadership

The assessment may review:

  • The Board and the effectiveness of its role.
  • The relationship between the Board and executive management.
  • Roles and authorities.
  • Decision-making.
  • Conflicts of interest.
  • Accountability.
  • Strategic planning.
  • Board minutes and follow-up of decisions.

The question is not merely:

Do you have a Board?

but:

Can you demonstrate that the Board performs a real oversight and strategic role?


2. Financial Management and Internal Controls

This may include:

  • Accounting systems.
  • Budgeting.
  • Grant management.
  • Segregation of duties.
  • Financial approvals.
  • Bank account management.
  • Reconciliations.
  • Financial reporting.
  • External audit.
  • Resolution of audit findings.
  • Cash management.

Donors are particularly interested in whether the organization can trace the use of grant funds and produce accurate, timely financial reports.


3. Procurement, Supplier Management, and Asset Management

Procurement is a significant area in grant management because it brings together money, decision-making, suppliers, and potential conflicts of interest.

The assessment may review:

Procurement Planning → Vendor Selection → Competition → Conflict of Interest → Evaluation → Approval → Receiving → Payment → Record Keeping

Asset management may include:

  • Asset Register.
  • Asset identification and tagging.
  • Custodial responsibility.
  • Physical inventory.
  • Transfers.
  • Maintenance.
  • Disposal according to approved procedures.

4. Human Resources

This may cover:

  • Organizational structure.
  • Job descriptions.
  • Recruitment and selection.
  • Contracts.
  • Personnel files.
  • Induction.
  • Training.
  • Performance management.
  • Codes of conduct.
  • Volunteer management.
  • Appropriate segregation of responsibilities.

An HR Manual is not sufficient if actual recruitment practices do not follow it.


5. Programme and Project Management

The assessment may consider the organization’s ability to:

  • Design projects.
  • Plan implementation.
  • Prepare budgets.
  • Implement activities.
  • Manage schedules.
  • Manage risks.
  • Monitor outputs and outcomes.
  • Prepare reports.
  • Manage changes.
  • Close projects and document lessons learned.

6. Monitoring, Evaluation, Accountability and Learning – MEAL

The donor may review whether the organization can:

  • Define indicators.
  • Collect data.
  • Assure data quality.
  • Measure progress.
  • Analyse results.
  • Manage feedback.
  • Learn from implementation.
  • Use findings in decision-making.
  • Produce evidence-based reports.

7. Risk Management and Compliance

This may include:

  • Risk Management Framework.
  • Risk Register.
  • Risk Owners.
  • Mitigation measures.
  • Escalation processes.
  • Fraud and corruption prevention.
  • Conflict of Interest.
  • Reporting of misconduct.
  • Compliance with legal and contractual obligations.

A more mature organization does not simply say:

We have a Risk Register.

It can show:

A real risk that was identified, how it was assessed, who owned it, what actions were taken, and what management decision followed.


8. Safeguarding and PSEA

For organizations working directly with communities, children, or people at increased risk, this area may be critical.

Having a Safeguarding Policy alone is not enough.

The donor may examine a chain such as:

Policy → Code of Conduct → Recruitment Controls → Induction → Training → Reporting Mechanism → Response Responsibilities → Case Management Controls

Depending on the donor and programme, PSEA – Protection from Sexual Exploitation and Abuse requirements may also apply.


9. Complaints and Accountability to Affected People

The assessment may examine:

  • Complaints channels.
  • Accessibility.
  • Confidentiality.
  • Classification and referral mechanisms.
  • Response times.
  • Closure documentation.
  • Trend analysis.
  • Use of complaints to improve programmes.

10. Data Protection and Cybersecurity

This is increasingly important where organizations handle beneficiary, staff, or donor data.

The question is not only:

Do you have a Data Protection Policy?

but:

What Data Do We Collect? → Why? → Who Can Access It? → Where Is It Stored? → How Is It Protected? → How Long Is It Retained? → What Happens If an Incident Occurs?

The assessment may also cover account and access management, backups, incident response, and system continuity.


11. Health, Safety and Security – HSS

Depending on the organization’s activities, the assessment may include:

  • Risk assessments.
  • Site safety.
  • Emergency preparedness.
  • Incident management.
  • Staff and volunteer safety.
  • Travel and field-work risks.
  • Training and responsibilities.

12. Operational Capacity and Business Continuity

The donor may examine:

  • Technical infrastructure.
  • Document management.
  • Knowledge management.
  • Business continuity plans.
  • Backups.
  • Key suppliers.
  • The ability to continue operations when key people are unavailable.

This raises an important risk:

Single Point of Failure

If only one person understands a key financial process, holds all passwords or files, or knows how to prepare a donor report, the problem is not the individual—it is the design of the organizational system.

The key question is:

Does institutional knowledge belong to the organization, or does it live in one person’s memory?


Seventh: Start With a Self-Assessment, Not With Document Collection

When preparing for an assessment, do not begin by asking:

What documents will the donor ask for?

Start with:

How mature are our systems?

An organization can develop a simple internal Readiness Scorecard.

For example:

0 – Not Available
The requirement or system does not exist.

1 – Documented
It exists in written form.

2 – Implemented
It is implemented at a basic level.

3 – Consistently Implemented
There is consistent evidence of implementation.

4 – Monitored & Improved
Its effectiveness is measured, reviewed, and improved.

The organization may then assess areas such as:

Governance | Finance | Procurement | HR | Programmes | MEAL | Risk | Compliance | Safeguarding | Data Protection | Cybersecurity | HSS

This is an internal readiness tool and does not imply that every donor uses the same scoring system.


Eighth: Do Not Treat All Gaps Equally

A Self-Assessment will reveal gaps.

But not all gaps carry the same significance.

An outdated form requiring redesign is not equivalent to a failure to segregate the person who creates a payment from the person who approves it.

The organization can therefore create a Readiness Improvement Plan:

Finding → Risk Level → Required Action → Owner → Deadline → Evidence Required → Status

Priorities may be classified as:

Critical → High → Medium → Low

The organization should first address gaps that may:

  • Expose beneficiaries to harm.
  • Expose funds to misuse.
  • Cause legal or contractual breaches.
  • Prevent effective grant management.
  • Materially affect reporting accuracy.
  • Threaten project continuity.

Ninth: Review Policies — But Do Not Write Policies You Do Not Apply

The organization should ensure it has policies appropriate to its activities, potentially including:

  • Governance.
  • Finance.
  • HR.
  • Procurement.
  • Risk Management.
  • Anti-Fraud & Anti-Corruption.
  • Conflict of Interest.
  • Safeguarding.
  • Complaints.
  • Data Protection.
  • Cybersecurity.
  • HSS.
  • Whistleblowing or misconduct reporting where appropriate.

However, writing dozens of policies immediately before an assessment can create an even bigger problem:

A policy may claim that the organization follows a process it does not actually follow.

A policy should therefore be:

Appropriate → Approved → Communicated → Implemented → Evidenced → Reviewed


Tenth: Create a Donor Readiness Room

Instead of searching for documents whenever a funding opportunity appears, the organization can maintain an organized readiness repository.

It may include:

Legal

Registration documents, bylaws, licences.

Governance

Board decisions, minutes, policies, Conflict of Interest Register.

Finance

Financial statements, audits, budgets, policies, sample transactions.

HR

Policies, structure, job descriptions, sample files.

Procurement & Assets

Policies, vendor information, procurement samples, Asset Register.

Programmes & MEAL

Project plans, reports, indicators, monitoring tools.

Risk & Compliance

Risk Register, treatment plans, compliance records.

Safeguarding & Complaints

Policies, training records, reporting mechanisms, and appropriate evidence.

Data & Cybersecurity

Policies, access controls, backup and incident-response arrangements.

HSS

Relevant assessments, plans, and records.

The system should ideally identify:

Document Owner → Version → Approval Date → Review Date → Access Level

The objective is not to create an attractive folder for the donor, but to maintain an organized institutional source of evidence.


Eleventh: Conduct a Mock Donor Assessment

This is one of the strongest preparation methods.

Before the assessor arrives, conduct a simulation as though the donor assessment were already taking place.

Do not allow each department to select its best file.

Choose random samples such as:

  • A procurement transaction.
  • An employee file.
  • A financial payment.
  • A completed project.
  • A complaint.
  • An Incident or Near Miss, where relevant.
  • A Board decision.
  • A Risk Register entry.
  • A project report.
  • An asset record.

Then trace each case from beginning to end.

For example:

Select a random procurement transaction from six months ago and prove that the Procurement Policy was applied.

If the organization cannot build a complete Evidence Trail, it has identified a real gap before the donor does.


Twelfth: Prepare People, Not Only Documents

The assessment may include interviews with:

  • Board members.
  • The Chief Executive.
  • Finance staff.
  • Human Resources.
  • Programme managers.
  • MEAL staff.
  • Procurement staff.
  • Safeguarding or Compliance staff.
  • Other employees.

People should not be trained to give memorized answers.

Instead, they should understand:

  • Their role.
  • Their authority.
  • The policies related to their work.
  • Where relevant evidence is located.
  • How escalation works.
  • What to do when there is an exception or violation.

If a policy says one thing and staff describe a completely different practice, that will be significant to the assessor.


Thirteenth: What Happens During the Assessment?

A donor may use several assessment techniques together.

Document Review

To review policies, systems, and records.

Interviews

To understand roles and actual implementation.

Sampling

To test real transactions and cases.

Site Visits

To verify the operating environment and actual practice.

System Demonstration

The organization may be asked to show how it generates a report, records a transaction, or retrieves a record.

Cross-Checking

This is particularly important.

The assessor may compare:

What the policy says → What the employee says → What the record shows → What the financial or operational system confirms

The best preparation strategy is therefore not to anticipate every possible question.

It is:

To ensure that the system itself is consistent and can be demonstrated.


Fourteenth: Questions That Reveal Real Readiness

An organization can test itself through more demanding questions.

Instead of:

Do we have a Procurement Policy?

Ask:

Show me the most recent procurement above the competitive threshold and explain how the supplier was selected.

Instead of:

Do we have a Conflict of Interest Policy?

Ask:

Show me a case where someone disclosed a conflict and explain how it was managed.

Instead of:

Do we have a Complaints Mechanism?

Ask:

Show me a closed complaint and demonstrate how it was handled while protecting the complainant’s data.

Instead of:

Do we have Risk Management?

Ask:

Show me a high risk that was escalated and the management decision taken in response.

Instead of:

Is the Board effective?

Ask:

Show me an oversight decision taken by the Board and how its implementation was followed up.

Instead of:

Do we have a Training Programme?

Ask:

Show me how you identified a training need and how you later assessed whether the training made a difference.

These questions move readiness from Claims to Evidence.


Fifteenth: What If the Assessment Identifies Gaps?

A Finding does not automatically mean the organization has failed.

Possible outcomes may include:

Ready

The organization can manage the proposed funding under the specified requirements.

Ready with Conditions

Funding can proceed subject to specific conditions or controls.

Capacity Improvement Required

The organization needs to address defined gaps before or during funding.

Not Ready for This Funding Level

The organization may be sound overall, but its current capacity may not match the scale or complexity of the proposed funding.

This distinction matters.

The objective is not to prove that the organization is Perfect, but that it:

Understands Its Risks → Identifies Gaps → Addresses Them → Monitors Them → Can Demonstrate Improvement


Sixteenth: Build a Readiness Remediation Plan

Assessment findings should not disappear into an archived report.

Each important Finding should become an action.

For example:

Finding: Weak segregation of payment responsibilities.

Risk: High.

Required Action: Modify the workflow so the same person cannot both create and approve a payment.

Owner: Finance Manager.

Deadline: Defined date.

Evidence Required: Updated Procedure + System Permissions + Sample Transaction.

Status: Open / In Progress / Closed.

Closure should be verified rather than accepted simply because the responsible person says:

It has been fixed.

The appropriate sequence is:

Finding → Corrective Action → Owner → Deadline → Evidence → Verification → Closure


Seventeenth: Common Weaknesses That Reduce Readiness Scores

Common weaknesses include:

  • Drafting policies only after receiving notice of the assessment.
  • Policies that are outdated or not formally approved.
  • Lack of Evidence of Implementation.
  • Actual practice differing from written procedures.
  • Weak documentation of decisions.
  • Lack of segregation of duties.
  • Weak Conflict of Interest management.
  • Failure to close previous audit findings.
  • Lack of clear Risk Owners.
  • Weak training records.
  • Failure to follow up Corrective Actions.
  • Dependence on one employee who holds all institutional knowledge.
  • Difficulty retrieving documents and records quickly.
  • Preparing perfect files specifically for the assessment while random operational samples remain weak.

The last point is especially important:

Do not measure your readiness by your best file. Measure it through a random sample of everyday work.


Eighteenth: Indicators of a Funding-Ready Organization

Real readiness is reflected when the organization can demonstrate that:

  • Governance functions in practice.
  • Authorities are clearly defined.
  • Financial processes are traceable.
  • Procurement is controlled.
  • Assets are documented.
  • Staff understand their responsibilities.
  • Programmes operate according to clear plans.
  • Results are measured.
  • Risks are identified and monitored.
  • Complaints are handled appropriately.
  • Safeguarding is embedded in practice.
  • Data is protected.
  • Incidents and violations are escalated.
  • Audit findings lead to action.
  • Important decisions are documented.
  • Institutional knowledge does not depend on one person.
  • The organization can produce accurate reports on time.

The most important indicator, however, is:

Consistency between what the organization says it does, what its systems require, and what the actual evidence shows.


Nineteenth: From Passing the Assessment to Continuous Readiness

One of the biggest mistakes is to make the donor assessment day the final objective.

If systems stop being updated after the assessment ends, gaps will quickly reappear.

Readiness should therefore become a continuous cycle:

Assess → Identify Gaps → Prioritise → Improve → Implement → Monitor → Evidence → Reassess

This can be supported through:

  • Periodic Self-Assessments.
  • Policy reviews.
  • Updating the Donor Readiness Room.
  • Monitoring improvement plans.
  • Analysing audit findings.
  • Reviewing the Risk Register.
  • Training staff.
  • Reviewing system access.
  • Conducting periodic Mock Assessments.
  • Monitoring relevant changes in donor requirements.

Twentieth: Institutional Readiness as a Competitive Advantage and Sustainability Investment

A funding-ready organization benefits far beyond a donor assessment.

The same systems help it:

  • Use resources more efficiently.
  • Reduce errors.
  • Improve decisions.
  • Identify risks earlier.
  • Protect beneficiaries and staff.
  • Improve programme quality.
  • Produce stronger reports.
  • Manage growth.
  • Transfer knowledge between staff.
  • Build stronger partnerships.
  • Respond to funding opportunities more quickly.

Readiness therefore moves from:

A requirement for obtaining a grant

to:

An institutional capability that helps the organization manage its mission better.


Before Moving to the Next Article: Test Your Organization

Ask your team to:

✓ Produce the most recent major procurement transaction and prove its complete approval trail.

✓ Select a random expenditure from a previous grant and trace it to the accounting entry.

✓ Show the latest Board minutes and identify which decisions were followed up.

✓ Open the Risk Register, select a high risk, and explain what happened next.

✓ Select a random employee file and verify recruitment, induction, and performance-management steps.

✓ Present a completed project and connect its plan with its indicators, reports, and results.

✓ Show a previous audit Finding and prove that it was closed.

✓ Demonstrate the complaints mechanism and how complaint closure is documented.

✓ Explain who can access beneficiary data and why.

✓ Select an asset funded by a project and identify its current location, custodian, and Asset Register record.

✓ Ask more than one employee about an important process and compare their answers with the approved policy.

✓ Assume a key employee is absent for one month and test whether critical operations can continue.

If the organization can pass these tests with clear evidence, it is much closer to genuine readiness than an organization that merely possesses a large collection of policies.


Quick Self-Assessment

Ask yourself:

□ Are our policies approved and up to date?

□ Can we demonstrate implementation through actual samples?

□ Do we have an Evidence Trail for key processes?

□ Is segregation of duties clear?

□ Can we demonstrate that the Board performs its role?

□ Are financial and audit findings closed?

□ Does our Risk Register actually function?

□ Is Safeguarding implemented rather than merely documented?

□ Do we know where beneficiary data is stored and who can access it?

□ Are procurement and assets traceable?

□ Can we retrieve documents quickly?

□ Do staff understand the policies related to their roles?

□ Can critical processes continue when a key person is absent?

□ Do we maintain a Readiness Improvement Plan?

□ Are gaps prioritised according to risk?

□ Can we prove closure of Corrective Actions?

□ Do we conduct Mock Assessments before significant donor reviews?

If the answer is “No” to several of these questions, this does not necessarily mean the organization is ineligible for funding. It does, however, identify the areas from which its readiness-improvement plan should begin.


Conclusion

Preparing for an Organizational Readiness Assessment does not begin when an email arrives from a donor, nor is it achieved by creating a collection of policies shortly before the assessment.

True readiness is demonstrated through a coherent chain:

Policy → Responsibility → Implementation → Record → Evidence → Review → Improvement

A mature organization is not afraid of random sampling because it does not rely on files prepared specifically for an assessment. It relies on systems that function consistently.

The organization should therefore ask itself not only:

Do we have the documents the donor is likely to request?

but:

If the assessor selects any random process, project, decision, or transaction, can we demonstrate how it was handled, who approved it, what controls were applied, and what record proves it?

When an organization can answer this consistently, it has moved beyond preparing for a donor assessment to a much higher level: continuous institutional readiness.

That readiness does more than increase funding opportunities. It strengthens governance, protects resources and beneficiaries, improves decision-making, and provides a stronger foundation for growth, sustainability, and impact.