NGO Management

Strengthening Governance and Internal Controls in NGOs

Strong governance and effective internal controls help NGOs protect resources, comply with donor and regulatory requirements, prevent fraud, safeguard beneficiaries, and demonstrate accountability. This guide explains how NGOs can build practical systems that support both compliance and program delivery.

Strengthening Governance and Internal Controls in NGOs
Strengthening Governance and Internal Controls in NGOs

Dr. Abenet Yohannes, Ph.D. · 2026 · 20 min read

Introduction

Non-governmental organizations operate in an environment where trust is fundamental.

Donors provide resources with specific expectations. Governments require compliance with applicable laws and regulations. Communities expect programs to respond to their needs. Employees require fair and transparent systems. Governing bodies must ensure that organizational resources are used responsibly.

A failure in governance or internal control can therefore have consequences far beyond a financial loss. It can result in:

  • Loss of donor confidence
  • Suspension or termination of funding
  • Fraud and misuse of resources
  • Regulatory penalties
  • Weak program quality
  • Safeguarding failures
  • Reputational damage
  • Audit findings
  • Employee dissatisfaction
  • Loss of community trust

Strong governance establishes direction, oversight, accountability, and ethical leadership. Internal controls translate these expectations into the policies, procedures, approvals, checks, systems, and monitoring activities used in everyday operations. The two must work together. Good governance without effective controls may remain only a policy statement. Strong procedures without effective governance may be ignored, overridden, or inconsistently applied.

What Is NGO Governance?

Governance refers to the structures and processes through which an NGO is directed, overseen, and held accountable. It determines:

  • Who has authority
  • Who makes strategic decisions
  • Who oversees management
  • How organizational performance is monitored
  • How risks are governed
  • How conflicts of interest are managed
  • How financial accountability is maintained
  • How ethical standards are enforced
  • How stakeholders are represented and protected

Depending on the organization, governance may be exercised through a board, governing council, trustees, general assembly, or similar structure. The governing body should provide strategic oversight without taking over the day-to-day responsibilities of management.

Governance versus management

Governance and management are closely connected but have different responsibilities.

GovernanceManagement
Defines strategic directionImplements strategy
Approves major policiesDevelops and applies procedures
Oversees organizational performanceManages daily operations
Reviews major risksManages operational risks
Holds senior management accountableHolds employees accountable
Approves major budgetsManages approved budgets
Provides independent oversightProduces management information
Protects mission and organizational integrityDelivers programs and services

Problems arise when these responsibilities are unclear. A board that becomes excessively involved in routine operational decisions may weaken management accountability. A board that is too passive may fail to identify serious financial, compliance, safeguarding, or strategic problems.

What Are Internal Controls?

Internal controls are the processes designed and implemented by the governing body, management, and employees to provide reasonable assurance that organizational objectives will be achieved. They help an NGO:

  • Protect financial and physical assets
  • Maintain reliable records
  • Produce accurate financial and program reports
  • Prevent and detect fraud and error
  • Comply with donor agreements
  • Comply with applicable laws and regulations
  • Manage operational risks
  • Protect employees and beneficiaries
  • Improve efficiency
  • Achieve program objectives

Internal control is not simply the responsibility of the finance department. Procurement, HR, programs, logistics, safeguarding, IT, management, risk and compliance, and governing bodies all have internal-control responsibilities.

The Five Foundations of an Effective Internal-Control System

An effective NGO internal-control framework can be organized around five interconnected components.

1. Control environment

The control environment establishes the organization's culture of integrity, accountability, and compliance. It includes:

  • Ethical leadership
  • Active governing-body oversight
  • Clear organizational structures
  • Codes of conduct
  • Appropriate delegation of authority
  • Competent employees
  • Job descriptions
  • Performance management
  • Conflict-of-interest requirements
  • Consistent disciplinary procedures
  • Management accountability

The attitude of leadership is particularly important. If senior managers regularly bypass procurement procedures, approve unsupported expenses, ignore conflicts of interest, or fail to address audit findings, employees may conclude that policies are optional. The behaviour of leadership shapes the control culture.

2. Risk assessment

NGOs should identify the risks that may prevent them from achieving their organizational and project objectives. Risk areas may include:

  • Financial management
  • Fraud and corruption
  • Procurement
  • Human resources
  • Payroll
  • Inventory
  • Fixed assets
  • Partner management
  • Donor compliance
  • Safeguarding and PSEA
  • Data protection
  • Cybersecurity
  • Program quality
  • Security
  • Reputation
  • Regulatory compliance
  • Business continuity

Each significant risk should be assessed based on likelihood and impact. Management should then determine existing controls, remaining risk, required additional actions, the risk owner, a target completion date, and the monitoring frequency.

Risk registers should be living management tools, not documents prepared only for audits or donor assessments.

3. Control activities

Control activities are the specific procedures used to reduce identified risks. Examples include:

  • Segregation of duties
  • Approval limits
  • Budget controls
  • Procurement thresholds
  • Bank reconciliations
  • Inventory counts
  • Supplier due diligence
  • Payroll verification
  • Access controls
  • Management reviews
  • Physical verification
  • Contract monitoring
  • Partner assessments

Controls may be preventive, detective, or corrective. The strongest systems combine all three.

4. Information and communication

Employees need timely and accurate information to perform their responsibilities. NGOs should clearly communicate policies, donor requirements, approval limits, program responsibilities, codes of conduct, safeguarding requirements, changes in regulations, risk-management responsibilities, reporting deadlines, and escalation procedures.

Information must also move upward. Management and governing bodies need reliable information about:

  • Financial performance
  • Program progress
  • Audit findings
  • Major risks
  • Fraud allegations
  • Safeguarding incidents
  • Compliance breaches
  • Donor concerns
  • Stakeholder feedback

5. Monitoring

Controls must be monitored to determine whether they are functioning effectively. Monitoring may include:

  • Supervisory review
  • Management self-assessment
  • Compliance checks
  • Internal audit
  • External audit
  • Donor spot checks
  • Physical verification
  • Financial reviews
  • Field monitoring
  • Partner monitoring
  • Investigation follow-up

Weaknesses should result in corrective action. Repeated findings indicate that the organization is identifying problems without adequately resolving them.

Strengthening Financial Controls

Financial management is one of the highest-risk areas for most NGOs. Essential controls include:

  • Approved finance policies
  • Clear chart of accounts
  • Project-specific accounting codes
  • Approved budgets
  • Budget-holder accountability
  • Defined authorization limits
  • Proper supporting documents
  • Separation of payment preparation, approval, payment, and recording
  • Dual authorization for bank transactions
  • Monthly bank reconciliations
  • Independent review of reconciliations
  • Petty-cash limits
  • Periodic cash counts
  • Monthly financial reporting
  • Budget-versus-actual analysis

Every financial transaction should be traceable from authorization through payment and accounting.

Strengthening Procurement Controls

Procurement is particularly vulnerable to fraud, conflicts of interest, overpricing, collusion, and inappropriate supplier selection. A strong procurement system should include:

  • Approved procurement plans
  • Procurement thresholds
  • Appropriate competition
  • Clear specifications
  • Supplier due diligence
  • Conflict-of-interest declarations
  • Independent evaluation
  • Documented bid analysis
  • Approval of procurement decisions
  • Purchase orders or contracts
  • Verification of goods and services received
  • Supplier-performance monitoring
  • Segregation between procurement, receiving, and payment

Procurement files should clearly demonstrate how and why the supplier was selected.

Strengthening Payroll, HR, Inventory and Asset Controls

Payroll can represent a significant proportion of an NGO's expenditure. Controls should include:

  • Approved organizational structures
  • Authorized positions
  • Complete personnel files
  • Signed employment contracts
  • Verified employee identities
  • Approved salary structures
  • Independent review of payroll changes
  • Approved timesheets where applicable
  • Proper leave records
  • Reconciliation of payroll with bank payments
  • Timely removal of separated employees
  • Periodic verification of employees

HR and payroll responsibilities should be appropriately separated.

NGOs frequently manage vehicles, equipment, relief items, educational materials, medical supplies, and other project assets. Controls should include:

  • Asset registers
  • Inventory registers
  • Asset tagging
  • Goods-received documentation
  • Store-requisition documentation
  • Restricted warehouse access
  • Periodic physical counts
  • Reconciliation of physical quantities with records
  • Investigation of differences
  • Transfer documentation
  • Disposal procedures
  • Vehicle logbooks
  • Fuel monitoring
  • Maintenance schedules

Asset responsibility should be clearly assigned.

Donor Compliance as an Internal-Control Responsibility

NGOs frequently implement projects funded by multiple donors, each with different contractual requirements. Controls should help ensure compliance with:

  • Approved budgets
  • Eligible-cost requirements
  • Procurement procedures
  • Staffing structures
  • Reporting deadlines
  • Visibility requirements
  • Asset rules
  • Subgrant provisions
  • Currency requirements
  • Documentation standards
  • Cost-allocation rules
  • Approval requirements

A donor-compliance checklist should be prepared when a new agreement is signed. Program, finance, procurement, HR, logistics, partnerships, and management teams should understand the conditions that affect their responsibilities. Donor compliance should not be left to the finance department at the time of reporting.

Partner and Subgrant Controls

When an NGO transfers funds or implementation responsibilities to another organization, it also assumes additional risks. Before engaging a partner, the NGO should conduct proportionate due diligence covering legal status, governance, financial systems, internal controls, procurement, HR, safeguarding, fraud prevention, previous experience, sanctions and prohibited-party screening where required, reputation, and technical capacity.

After the agreement is signed, monitoring may include:

  • Financial reports
  • Supporting-document reviews
  • Program reports
  • Field visits
  • Spot checks
  • Procurement reviews
  • Asset verification
  • Capacity-development support
  • Audit or assurance activities

Due diligence should inform the level of monitoring rather than simply determine whether a partner passes or fails.

Safeguarding, Whistleblowing and IT Controls

NGO governance must extend beyond financial accountability. Organizations also have responsibilities to protect beneficiaries, communities, employees, and other stakeholders from abuse, exploitation, harassment, and other harm. Controls may include:

  • Safeguarding policies
  • Codes of conduct
  • Recruitment screening
  • Reference checks
  • Employee induction
  • Regular training
  • Community awareness
  • Safe reporting mechanisms
  • Survivor-centered response procedures
  • Confidential case handling
  • Partner safeguarding requirements
  • Management oversight

Safeguarding should be integrated into organizational risk management and governance.

Employees and stakeholders should have safe ways to report fraud, corruption, safeguarding concerns, harassment, conflicts of interest, procurement misconduct, financial misuse, retaliation, and other ethical violations. Effective mechanisms should be accessible, confidential, trusted, available through more than one channel, appropriate for different stakeholders, and protected against retaliation.

Reports should be logged securely, assessed consistently, assigned appropriately, and followed through to closure. The organization should also communicate the existence of reporting mechanisms to employees, partners, communities, and beneficiaries.

NGOs increasingly depend on digital financial, HR, project, procurement, and document-management systems. Important controls include:

  • Individual user accounts
  • Role-based access
  • Multi-factor authentication where appropriate
  • Strong password standards
  • Regular access-right reviews
  • Removal of access when employees leave
  • Data backups
  • Disaster-recovery procedures
  • Audit trails
  • Change-management controls
  • Cybersecurity awareness
  • Protection of confidential data

System permissions should follow job responsibilities. An employee should not receive system access simply because access is convenient.

Segregation of Duties

No single employee should control every stage of a financial or operational transaction. Where possible, responsibilities should be separated between initiation, approval, custody, recording, reconciliation, and review.

For example, the same person should not independently request a purchase, select the supplier, receive the goods, approve the invoice, make the payment, and record the transaction.

What about small NGOs?

Small NGOs may have limited employees and may not be able to achieve complete segregation. Compensating controls can include:

  • Executive review
  • Board oversight
  • Dual approvals
  • Independent bank-statement review
  • Frequent inventory counts
  • Automated approval limits
  • External financial review
  • Periodic compliance checks

The limitation should be recognized and actively managed.

Governance Responsibilities for Internal Control

Governing body

  • Approve strategy
  • Approve major policies
  • Review organizational risks
  • Review financial performance
  • Oversee executive management
  • Review significant audit findings
  • Monitor serious fraud and safeguarding matters
  • Ensure corrective actions are implemented

Executive management

  • Establish the organizational control environment
  • Implement board-approved policies
  • Allocate sufficient resources
  • Assign responsibilities
  • Review risks
  • Monitor performance
  • Enforce accountability
  • Address control failures

Department managers

  • Identify process risks
  • Implement controls
  • Maintain documentation
  • Supervise employees
  • Report weaknesses
  • Complete corrective actions

Employees

  • Follow policies
  • Protect organizational resources
  • Maintain accurate records
  • Declare conflicts of interest
  • Report concerns
  • Participate in required training

Internal audit

Internal audit should independently evaluate governance, risk management, and internal controls. It should report significant findings to the appropriate level of oversight and monitor management's corrective actions. Internal audit should not assume responsibility for designing and operating controls that it will later evaluate.

A Practical NGO Risk-Control Matrix

Risk area and example riskKey control
Finance — unauthorized expenditureBudget-holder and delegated approval
Banking — unauthorized paymentDual bank authorization
Procurement — supplier favoritismCompetition and conflict-of-interest declaration
Payroll — ghost employeesHR and payroll verification
Inventory — theft or lossPhysical counts and inventory reconciliation
Donor compliance — ineligible expenditureDonor-compliance checklist and expenditure review
Subgrants — partner misuse of fundsDue diligence, monitoring, and financial review
Safeguarding — abuse goes unreportedAccessible and confidential reporting mechanism
IT — unauthorized system accessRole-based access and periodic review
Reporting — inaccurate donor reportProgram-finance reconciliation and management review

Warning Signs of Weak Governance and Controls

Leadership should pay attention when:

  • The same audit findings repeatedly appear
  • Bank reconciliations are delayed
  • Supporting documents are frequently missing
  • Policies are regularly waived
  • Procurement repeatedly uses the same suppliers without adequate justification
  • Conflict-of-interest declarations are absent
  • Financial reports are significantly delayed
  • Employees share system passwords
  • Staff cannot explain approval requirements
  • Inventory differences remain unresolved
  • Complaints receive no documented response
  • High-risk partners receive limited monitoring
  • Management frequently overrides established procedures
  • Governing bodies receive insufficient information

These indicators do not automatically prove misconduct, but they justify further review.

A 90-Day Governance and Internal-Control Improvement Plan

Days 1–30: Assess

  • Review governance arrangements
  • Confirm board and management responsibilities
  • Review major policies
  • Conduct an organizational risk assessment
  • Map high-risk processes
  • Review audit and donor findings
  • Identify overdue corrective actions
  • Review delegations and approval limits
  • Identify critical control gaps

Days 31–60: Strengthen

  • Update priority policies and procedures
  • Develop risk-control matrices
  • Strengthen segregation of duties
  • Clarify approval limits
  • Improve procurement documentation
  • Review payroll controls
  • Verify user-access rights
  • Strengthen partner due diligence
  • Review safeguarding and reporting mechanisms
  • Train employees

Days 61–90: Test and monitor

  • Test high-risk transactions
  • Review bank reconciliations
  • Verify payroll
  • Conduct inventory counts
  • Test procurement files
  • Review donor compliance
  • Conduct selected partner spot checks
  • Track corrective actions
  • Report results to management and the governing body
  • Establish a regular control-review schedule

NGO Governance and Internal-Control Checklist

A strong NGO should be able to answer yes to most of these questions:

  • Does the governing body actively oversee the organization?
  • Are governance and management responsibilities clearly separated?
  • Are major policies formally approved and regularly reviewed?
  • Is there a current organizational risk register?
  • Are authorization limits clearly defined?
  • Are important duties appropriately segregated?
  • Are bank accounts reconciled regularly?
  • Are procurement decisions properly documented?
  • Are conflicts of interest declared?
  • Are payroll changes independently reviewed?
  • Are inventory and assets periodically verified?
  • Are donor requirements communicated to relevant departments?
  • Are partners subjected to risk-based due diligence and monitoring?
  • Are safeguarding requirements integrated into operations?
  • Are confidential reporting mechanisms available?
  • Are system-access rights reviewed?
  • Are audit findings assigned, monitored, and closed?
  • Does senior management regularly review internal-control performance?

Key Takeaways and Conclusion

Strong NGO governance and internal controls require:

  • Active governing-body oversight
  • Ethical leadership
  • Clear accountability
  • Risk-based controls
  • Strong financial management
  • Transparent procurement
  • Proper segregation of duties
  • Donor-compliance systems
  • Partner due diligence
  • Safeguarding mechanisms
  • Accessible reporting channels
  • Secure information systems
  • Independent assurance
  • Timely corrective action

Governance and internal control should not be viewed as administrative burdens that compete with program delivery. They make effective program delivery possible.

Strong governance ensures that an NGO remains focused on its mission, manages risks responsibly, protects the people it serves, and remains accountable to stakeholders. Effective internal controls translate these expectations into daily practice.

An NGO that understands its risks, clearly assigns responsibilities, protects its resources, monitors compliance, listens to stakeholders, and responds quickly to weaknesses is better positioned to maintain donor confidence and achieve sustainable impact.

Trust is one of an NGO's most valuable assets. Strong governance and internal controls help protect it.

Need Support with Strategic Planning?

Dr. Abenet Yohannes provides strategic planning, organizational assessment, financial management, risk and compliance, research, project advisory, and capacity-development services — including planning facilitation, situational analysis, strategic objectives, performance indicators, implementation plans, budgets, risk registers, and monitoring dashboards.

← Back to all insights

Turn your strategy into measurable results

A short consultation can clarify priorities, indicators, and the accountability structure your plan needs.

Talk to Us