NGO Management
Strengthening Governance and Internal Controls in NGOs
Strong governance and effective internal controls help NGOs protect resources, comply with donor and regulatory requirements, prevent fraud, safeguard beneficiaries, and demonstrate accountability. This guide explains how NGOs can build practical systems that support both compliance and program delivery.

Dr. Abenet Yohannes, Ph.D. · 2026 · 20 min read
Introduction
Non-governmental organizations operate in an environment where trust is fundamental.
Donors provide resources with specific expectations. Governments require compliance with applicable laws and regulations. Communities expect programs to respond to their needs. Employees require fair and transparent systems. Governing bodies must ensure that organizational resources are used responsibly.
A failure in governance or internal control can therefore have consequences far beyond a financial loss. It can result in:
- Loss of donor confidence
- Suspension or termination of funding
- Fraud and misuse of resources
- Regulatory penalties
- Weak program quality
- Safeguarding failures
- Reputational damage
- Audit findings
- Employee dissatisfaction
- Loss of community trust
Strong governance establishes direction, oversight, accountability, and ethical leadership. Internal controls translate these expectations into the policies, procedures, approvals, checks, systems, and monitoring activities used in everyday operations. The two must work together. Good governance without effective controls may remain only a policy statement. Strong procedures without effective governance may be ignored, overridden, or inconsistently applied.
What Is NGO Governance?
Governance refers to the structures and processes through which an NGO is directed, overseen, and held accountable. It determines:
- Who has authority
- Who makes strategic decisions
- Who oversees management
- How organizational performance is monitored
- How risks are governed
- How conflicts of interest are managed
- How financial accountability is maintained
- How ethical standards are enforced
- How stakeholders are represented and protected
Depending on the organization, governance may be exercised through a board, governing council, trustees, general assembly, or similar structure. The governing body should provide strategic oversight without taking over the day-to-day responsibilities of management.
Governance versus management
Governance and management are closely connected but have different responsibilities.
| Governance | Management |
|---|---|
| Defines strategic direction | Implements strategy |
| Approves major policies | Develops and applies procedures |
| Oversees organizational performance | Manages daily operations |
| Reviews major risks | Manages operational risks |
| Holds senior management accountable | Holds employees accountable |
| Approves major budgets | Manages approved budgets |
| Provides independent oversight | Produces management information |
| Protects mission and organizational integrity | Delivers programs and services |
Problems arise when these responsibilities are unclear. A board that becomes excessively involved in routine operational decisions may weaken management accountability. A board that is too passive may fail to identify serious financial, compliance, safeguarding, or strategic problems.
What Are Internal Controls?
Internal controls are the processes designed and implemented by the governing body, management, and employees to provide reasonable assurance that organizational objectives will be achieved. They help an NGO:
- Protect financial and physical assets
- Maintain reliable records
- Produce accurate financial and program reports
- Prevent and detect fraud and error
- Comply with donor agreements
- Comply with applicable laws and regulations
- Manage operational risks
- Protect employees and beneficiaries
- Improve efficiency
- Achieve program objectives
Internal control is not simply the responsibility of the finance department. Procurement, HR, programs, logistics, safeguarding, IT, management, risk and compliance, and governing bodies all have internal-control responsibilities.
The Five Foundations of an Effective Internal-Control System
An effective NGO internal-control framework can be organized around five interconnected components.
1. Control environment
The control environment establishes the organization's culture of integrity, accountability, and compliance. It includes:
- Ethical leadership
- Active governing-body oversight
- Clear organizational structures
- Codes of conduct
- Appropriate delegation of authority
- Competent employees
- Job descriptions
- Performance management
- Conflict-of-interest requirements
- Consistent disciplinary procedures
- Management accountability
The attitude of leadership is particularly important. If senior managers regularly bypass procurement procedures, approve unsupported expenses, ignore conflicts of interest, or fail to address audit findings, employees may conclude that policies are optional. The behaviour of leadership shapes the control culture.
2. Risk assessment
NGOs should identify the risks that may prevent them from achieving their organizational and project objectives. Risk areas may include:
- Financial management
- Fraud and corruption
- Procurement
- Human resources
- Payroll
- Inventory
- Fixed assets
- Partner management
- Donor compliance
- Safeguarding and PSEA
- Data protection
- Cybersecurity
- Program quality
- Security
- Reputation
- Regulatory compliance
- Business continuity
Each significant risk should be assessed based on likelihood and impact. Management should then determine existing controls, remaining risk, required additional actions, the risk owner, a target completion date, and the monitoring frequency.
Risk registers should be living management tools, not documents prepared only for audits or donor assessments.
3. Control activities
Control activities are the specific procedures used to reduce identified risks. Examples include:
- Segregation of duties
- Approval limits
- Budget controls
- Procurement thresholds
- Bank reconciliations
- Inventory counts
- Supplier due diligence
- Payroll verification
- Access controls
- Management reviews
- Physical verification
- Contract monitoring
- Partner assessments
Controls may be preventive, detective, or corrective. The strongest systems combine all three.
4. Information and communication
Employees need timely and accurate information to perform their responsibilities. NGOs should clearly communicate policies, donor requirements, approval limits, program responsibilities, codes of conduct, safeguarding requirements, changes in regulations, risk-management responsibilities, reporting deadlines, and escalation procedures.
Information must also move upward. Management and governing bodies need reliable information about:
- Financial performance
- Program progress
- Audit findings
- Major risks
- Fraud allegations
- Safeguarding incidents
- Compliance breaches
- Donor concerns
- Stakeholder feedback
5. Monitoring
Controls must be monitored to determine whether they are functioning effectively. Monitoring may include:
- Supervisory review
- Management self-assessment
- Compliance checks
- Internal audit
- External audit
- Donor spot checks
- Physical verification
- Financial reviews
- Field monitoring
- Partner monitoring
- Investigation follow-up
Weaknesses should result in corrective action. Repeated findings indicate that the organization is identifying problems without adequately resolving them.
Strengthening Financial Controls
Financial management is one of the highest-risk areas for most NGOs. Essential controls include:
- Approved finance policies
- Clear chart of accounts
- Project-specific accounting codes
- Approved budgets
- Budget-holder accountability
- Defined authorization limits
- Proper supporting documents
- Separation of payment preparation, approval, payment, and recording
- Dual authorization for bank transactions
- Monthly bank reconciliations
- Independent review of reconciliations
- Petty-cash limits
- Periodic cash counts
- Monthly financial reporting
- Budget-versus-actual analysis
Every financial transaction should be traceable from authorization through payment and accounting.
Strengthening Procurement Controls
Procurement is particularly vulnerable to fraud, conflicts of interest, overpricing, collusion, and inappropriate supplier selection. A strong procurement system should include:
- Approved procurement plans
- Procurement thresholds
- Appropriate competition
- Clear specifications
- Supplier due diligence
- Conflict-of-interest declarations
- Independent evaluation
- Documented bid analysis
- Approval of procurement decisions
- Purchase orders or contracts
- Verification of goods and services received
- Supplier-performance monitoring
- Segregation between procurement, receiving, and payment
Procurement files should clearly demonstrate how and why the supplier was selected.
Strengthening Payroll, HR, Inventory and Asset Controls
Payroll can represent a significant proportion of an NGO's expenditure. Controls should include:
- Approved organizational structures
- Authorized positions
- Complete personnel files
- Signed employment contracts
- Verified employee identities
- Approved salary structures
- Independent review of payroll changes
- Approved timesheets where applicable
- Proper leave records
- Reconciliation of payroll with bank payments
- Timely removal of separated employees
- Periodic verification of employees
HR and payroll responsibilities should be appropriately separated.
NGOs frequently manage vehicles, equipment, relief items, educational materials, medical supplies, and other project assets. Controls should include:
- Asset registers
- Inventory registers
- Asset tagging
- Goods-received documentation
- Store-requisition documentation
- Restricted warehouse access
- Periodic physical counts
- Reconciliation of physical quantities with records
- Investigation of differences
- Transfer documentation
- Disposal procedures
- Vehicle logbooks
- Fuel monitoring
- Maintenance schedules
Asset responsibility should be clearly assigned.
Donor Compliance as an Internal-Control Responsibility
NGOs frequently implement projects funded by multiple donors, each with different contractual requirements. Controls should help ensure compliance with:
- Approved budgets
- Eligible-cost requirements
- Procurement procedures
- Staffing structures
- Reporting deadlines
- Visibility requirements
- Asset rules
- Subgrant provisions
- Currency requirements
- Documentation standards
- Cost-allocation rules
- Approval requirements
A donor-compliance checklist should be prepared when a new agreement is signed. Program, finance, procurement, HR, logistics, partnerships, and management teams should understand the conditions that affect their responsibilities. Donor compliance should not be left to the finance department at the time of reporting.
Partner and Subgrant Controls
When an NGO transfers funds or implementation responsibilities to another organization, it also assumes additional risks. Before engaging a partner, the NGO should conduct proportionate due diligence covering legal status, governance, financial systems, internal controls, procurement, HR, safeguarding, fraud prevention, previous experience, sanctions and prohibited-party screening where required, reputation, and technical capacity.
After the agreement is signed, monitoring may include:
- Financial reports
- Supporting-document reviews
- Program reports
- Field visits
- Spot checks
- Procurement reviews
- Asset verification
- Capacity-development support
- Audit or assurance activities
Due diligence should inform the level of monitoring rather than simply determine whether a partner passes or fails.
Safeguarding, Whistleblowing and IT Controls
NGO governance must extend beyond financial accountability. Organizations also have responsibilities to protect beneficiaries, communities, employees, and other stakeholders from abuse, exploitation, harassment, and other harm. Controls may include:
- Safeguarding policies
- Codes of conduct
- Recruitment screening
- Reference checks
- Employee induction
- Regular training
- Community awareness
- Safe reporting mechanisms
- Survivor-centered response procedures
- Confidential case handling
- Partner safeguarding requirements
- Management oversight
Safeguarding should be integrated into organizational risk management and governance.
Employees and stakeholders should have safe ways to report fraud, corruption, safeguarding concerns, harassment, conflicts of interest, procurement misconduct, financial misuse, retaliation, and other ethical violations. Effective mechanisms should be accessible, confidential, trusted, available through more than one channel, appropriate for different stakeholders, and protected against retaliation.
Reports should be logged securely, assessed consistently, assigned appropriately, and followed through to closure. The organization should also communicate the existence of reporting mechanisms to employees, partners, communities, and beneficiaries.
NGOs increasingly depend on digital financial, HR, project, procurement, and document-management systems. Important controls include:
- Individual user accounts
- Role-based access
- Multi-factor authentication where appropriate
- Strong password standards
- Regular access-right reviews
- Removal of access when employees leave
- Data backups
- Disaster-recovery procedures
- Audit trails
- Change-management controls
- Cybersecurity awareness
- Protection of confidential data
System permissions should follow job responsibilities. An employee should not receive system access simply because access is convenient.
Segregation of Duties
No single employee should control every stage of a financial or operational transaction. Where possible, responsibilities should be separated between initiation, approval, custody, recording, reconciliation, and review.
For example, the same person should not independently request a purchase, select the supplier, receive the goods, approve the invoice, make the payment, and record the transaction.
What about small NGOs?
Small NGOs may have limited employees and may not be able to achieve complete segregation. Compensating controls can include:
- Executive review
- Board oversight
- Dual approvals
- Independent bank-statement review
- Frequent inventory counts
- Automated approval limits
- External financial review
- Periodic compliance checks
The limitation should be recognized and actively managed.
Governance Responsibilities for Internal Control
Governing body
- Approve strategy
- Approve major policies
- Review organizational risks
- Review financial performance
- Oversee executive management
- Review significant audit findings
- Monitor serious fraud and safeguarding matters
- Ensure corrective actions are implemented
Executive management
- Establish the organizational control environment
- Implement board-approved policies
- Allocate sufficient resources
- Assign responsibilities
- Review risks
- Monitor performance
- Enforce accountability
- Address control failures
Department managers
- Identify process risks
- Implement controls
- Maintain documentation
- Supervise employees
- Report weaknesses
- Complete corrective actions
Employees
- Follow policies
- Protect organizational resources
- Maintain accurate records
- Declare conflicts of interest
- Report concerns
- Participate in required training
Internal audit
Internal audit should independently evaluate governance, risk management, and internal controls. It should report significant findings to the appropriate level of oversight and monitor management's corrective actions. Internal audit should not assume responsibility for designing and operating controls that it will later evaluate.
A Practical NGO Risk-Control Matrix
| Risk area and example risk | Key control |
|---|---|
| Finance — unauthorized expenditure | Budget-holder and delegated approval |
| Banking — unauthorized payment | Dual bank authorization |
| Procurement — supplier favoritism | Competition and conflict-of-interest declaration |
| Payroll — ghost employees | HR and payroll verification |
| Inventory — theft or loss | Physical counts and inventory reconciliation |
| Donor compliance — ineligible expenditure | Donor-compliance checklist and expenditure review |
| Subgrants — partner misuse of funds | Due diligence, monitoring, and financial review |
| Safeguarding — abuse goes unreported | Accessible and confidential reporting mechanism |
| IT — unauthorized system access | Role-based access and periodic review |
| Reporting — inaccurate donor report | Program-finance reconciliation and management review |
Warning Signs of Weak Governance and Controls
Leadership should pay attention when:
- The same audit findings repeatedly appear
- Bank reconciliations are delayed
- Supporting documents are frequently missing
- Policies are regularly waived
- Procurement repeatedly uses the same suppliers without adequate justification
- Conflict-of-interest declarations are absent
- Financial reports are significantly delayed
- Employees share system passwords
- Staff cannot explain approval requirements
- Inventory differences remain unresolved
- Complaints receive no documented response
- High-risk partners receive limited monitoring
- Management frequently overrides established procedures
- Governing bodies receive insufficient information
These indicators do not automatically prove misconduct, but they justify further review.
A 90-Day Governance and Internal-Control Improvement Plan
Days 1–30: Assess
- Review governance arrangements
- Confirm board and management responsibilities
- Review major policies
- Conduct an organizational risk assessment
- Map high-risk processes
- Review audit and donor findings
- Identify overdue corrective actions
- Review delegations and approval limits
- Identify critical control gaps
Days 31–60: Strengthen
- Update priority policies and procedures
- Develop risk-control matrices
- Strengthen segregation of duties
- Clarify approval limits
- Improve procurement documentation
- Review payroll controls
- Verify user-access rights
- Strengthen partner due diligence
- Review safeguarding and reporting mechanisms
- Train employees
Days 61–90: Test and monitor
- Test high-risk transactions
- Review bank reconciliations
- Verify payroll
- Conduct inventory counts
- Test procurement files
- Review donor compliance
- Conduct selected partner spot checks
- Track corrective actions
- Report results to management and the governing body
- Establish a regular control-review schedule
NGO Governance and Internal-Control Checklist
A strong NGO should be able to answer yes to most of these questions:
- Does the governing body actively oversee the organization?
- Are governance and management responsibilities clearly separated?
- Are major policies formally approved and regularly reviewed?
- Is there a current organizational risk register?
- Are authorization limits clearly defined?
- Are important duties appropriately segregated?
- Are bank accounts reconciled regularly?
- Are procurement decisions properly documented?
- Are conflicts of interest declared?
- Are payroll changes independently reviewed?
- Are inventory and assets periodically verified?
- Are donor requirements communicated to relevant departments?
- Are partners subjected to risk-based due diligence and monitoring?
- Are safeguarding requirements integrated into operations?
- Are confidential reporting mechanisms available?
- Are system-access rights reviewed?
- Are audit findings assigned, monitored, and closed?
- Does senior management regularly review internal-control performance?
Key Takeaways and Conclusion
Strong NGO governance and internal controls require:
- Active governing-body oversight
- Ethical leadership
- Clear accountability
- Risk-based controls
- Strong financial management
- Transparent procurement
- Proper segregation of duties
- Donor-compliance systems
- Partner due diligence
- Safeguarding mechanisms
- Accessible reporting channels
- Secure information systems
- Independent assurance
- Timely corrective action
Governance and internal control should not be viewed as administrative burdens that compete with program delivery. They make effective program delivery possible.
Strong governance ensures that an NGO remains focused on its mission, manages risks responsibly, protects the people it serves, and remains accountable to stakeholders. Effective internal controls translate these expectations into daily practice.
An NGO that understands its risks, clearly assigns responsibilities, protects its resources, monitors compliance, listens to stakeholders, and responds quickly to weaknesses is better positioned to maintain donor confidence and achieve sustainable impact.
Trust is one of an NGO's most valuable assets. Strong governance and internal controls help protect it.
Need Support with Strategic Planning?
Dr. Abenet Yohannes provides strategic planning, organizational assessment, financial management, risk and compliance, research, project advisory, and capacity-development services — including planning facilitation, situational analysis, strategic objectives, performance indicators, implementation plans, budgets, risk registers, and monitoring dashboards.
Turn your strategy into measurable results
A short consultation can clarify priorities, indicators, and the accountability structure your plan needs.