Donor due diligence can quickly become one of the most revealing tests of your organization’s internal systems. Requests may cover governance, finance, safeguarding, HR, procurement, insurance, board records, program evidence, and legal status. A structured response process helps your NGO or CBO avoid sending outdated files, contradictory information, or documents that do not actually answer the donor’s question.
Triage the request before collecting files
Your organization should first separate mandatory items from optional or contextual questions. Identify requests that contain sensitive information, need board or external approval, or depend on third parties such as auditors, banks, or regulators. This prevents simple and complex tasks from being treated as if they require the same response time.
Use one due-diligence tracker
| Request type | Typical owner | Evidence to review | Risk if weak |
|---|---|---|---|
| Governance | Executive/board secretary | Board list, minutes, constitution | Donor questions active oversight |
| Finance | Finance lead | Audits, policies, bank controls | Award size may be reduced or blocked |
| Safeguarding | Safeguarding/compliance lead | Policy, reporting procedures, training | High reputational and donor risk |
| Program evidence | Program/MEL lead | Results, evaluations, source data | Track record is difficult to verify |
Check freshness, approval status, and consistency
Before sending any file, confirm that it is current, approved, and relevant to the donor’s request. An expired certificate or unsigned policy can create more concern than a transparent note explaining that an update is underway. Your team should also compare names, dates, staff numbers, board members, and financial figures across documents so one attachment does not contradict another.
Detailed example: when the correct answer is not to disguise the gap
Imagine an NGO being considered for a USD 450,000 institutional grant. The donor requests audited accounts, proof of insurance, signed board minutes, and a safeguarding policy. The organization has a current audit and safeguarding policy, but its insurance expired two months ago and the latest board minutes are still unsigned.
The correct response is not to rename old files or backdate records. The tracker should show what is available, what limitation exists, what action is underway, and when a verified document can be provided. Leadership may also ask the donor whether a temporary explanation or renewal confirmation is acceptable. Transparency protects the organization’s integrity and gives the donor a clearer view of the real risk.
Due-diligence response checklist
- Every donor request is listed in one tracker.
- Each item has one accountable owner.
- The latest approved version is confirmed.
- Missing evidence is disclosed internally rather than fabricated.
- Sensitive data is shared only when necessary and appropriately protected.
- File names and numbering match the donor’s request.
- The final package receives a consistency and authorization review.
- A copy of exactly what was sent is preserved.
What institutional donors are likely to infer
Due diligence is often about more than the documents themselves. Donors may infer whether your organization controls its records, understands its own systems, responds transparently, and can close gaps without improvising. A calm, well-organized response can therefore strengthen donor confidence even when one or two items still need remediation.
What to do next
Use the Grant Evidence Inventory to prepare key evidence before a due-diligence request arrives, then use the Funding Readiness Self-Check to turn recurring gaps into management actions. For practical funding intelligence, subscribe to Africads Grant News.
Frequently asked questions
What documents do donors commonly request during due diligence?
Requests vary, but they may include registration, governance records, audits, bank controls, procurement and safeguarding policies, HR information, insurance, program evidence, and partner records. Your organization should use the donor’s actual checklist rather than assume every process is the same.
What should an NGO do if a required document is missing?
Do not fabricate, backdate, or disguise the gap. Explain internally what is missing, assess whether an interim document or remediation is acceptable, and ask the donor for clarification where necessary.
How should sensitive information be handled?
Share only what is necessary through a verified donor channel and apply your organization’s data-protection and access rules. Sensitive staff, beneficiary, banking, and governance information should not circulate informally simply because the request is urgent.
Who should coordinate the due diligence response?
One coordinator should manage the tracker and submission package, while the relevant functional owners verify their own evidence. This creates consistency without making the grants team responsible for certifying finance, HR, safeguarding, or governance records it does not own.
How can due diligence improve future readiness?
Record recurring requests and gaps after each process. If the same policy, audit, board record, or evidence problem appears repeatedly, leadership should treat it as an organizational systems issue rather than a one-off application task.
Conclusion
A strong due diligence response is accurate, controlled, and transparent. Your organization should centralize the request, verify every file, protect sensitive data, disclose real gaps honestly, and use recurring donor questions to strengthen readiness long before the next review.

