Bank Risk Reviews: Your NGO Response File Explained
An NGO can discover that its bank sees it as “high risk” in a very ordinary way. A donor transfer is delayed. A payment to a field partner is held. The relationship manager asks again for the source of funds, the identity of a donor, the purpose of a programme or the people behind a counterparty. Sometimes the questions arrive one at a time until the organisation feels it is being asked to prove its legitimacy from the beginning.
The
instinctive response is usually to send more documents. That can make the
problem worse. A registration certificate, grant agreement, annual report,
audit and invoice may all be genuine, but the bank still has to work out how
they fit together. The better response is a response file: an organised record
that tells one coherent story about who the NGO is, who controls it, where the
money came from, why it is moving, who will receive it and what controls
protect it. The point is not to overwhelm the bank. It is to make the risk
understandable.
“High
risk” and “wrongdoing” are not the same thing. A higher-risk classification
normally means closer customer due diligence and monitoring; it is not, by
itself, proof of money laundering or terrorist financing. The Financial Action
Task Force, or FATF, has repeatedly stressed that risk should be identified and
managed rather than avoided by treating whole categories of customers alike.
Its 2023 revision of Recommendation 8 and accompanying Best Practices Paper
emphasise focused, proportionate and risk-based measures for non-profit
organisations. FATF strengthened the same direction in 2025 by giving greater
weight to proportionality and simplified measures in lower-risk situations.
Start
with the bank’s actual question
Before
preparing a large bundle, the NGO should identify what the bank is trying to
verify. A delayed transaction may concern an outdated signatory mandate, a
donor whose name does not match the remitter, a new counterparty, a higher-risk
jurisdiction, a sanctions alert, an unusual increase in transaction value or a
simple gap in the bank’s customer records. Those are different problems and
need different evidence.
The
NGO should ask the relationship manager or compliance team, in writing, for the
category of information still required, the transaction or account reference,
the deadline and the channel for submission. If the bank cannot disclose the
full reason, the NGO can still ask which customer due diligence information
remains incomplete and whether the matter can be escalated for compliance
review. A bank may be legally unable to disclose certain suspicion-reporting
details, so silence about the precise trigger should not automatically be
treated as bad faith.
The
response file should begin with a short cover note identifying the account, the
payment under review, the donor or funding source, the programme, the amount,
the proposed recipient, the relevant dates and the NGO contact person. That
page becomes the map to the evidence.
Prove
the organisation before explaining the transaction
The
first part of the file should establish legal identity and control. It should
contain the current registration or incorporation document, the governing
constitution or equivalent instrument, evidence of current regulatory or tax
status where relevant, and a current list of directors, trustees or board
members. It should also show executive officers and authorised bank
signatories, together with the authority under which they act.
This
matters where an NGO has changed leadership, amended its constitution, renewed
registration or changed signatories. A bank should not have to reconstruct the
organisation’s current position from old minutes and several email chains. The
file should show which document is current and when any important change took
effect.
Some
bank forms use the language of “beneficial ownership” even where an NGO has no
shareholders. The organisation should not invent an owner to satisfy the form.
It should explain its legal structure and identify the natural persons who
exercise control or senior management functions to the extent required by
applicable law and the bank’s due diligence process. The goal is transparency
about control, not forcing a non-profit into a company ownership model that
does not fit it.
Show
the source of funds as a traceable chain
“Source
of funds” is often answered too vaguely. Writing “donor funding” or attaching
only a grant agreement may not explain the transfer under review. A stronger
file shows the chain from funding commitment to the money that reached the
account.
For
an institutional grant, that chain may be demonstrated by the signed grant
agreement or award letter, the donor’s legal identity, the approved budget, the
payment schedule, the remittance advice and the bank entry showing receipt. If
a payment agent sent the funds, the file should explain that relationship. If
the amount changed because of an amendment or supplementary award, the
amendment should be included rather than leaving the bank to guess.
This
approach reflects the Central Bank of Kenya’s 2025 Guidance on Customer Due
Diligence. The guidance expects financial institutions to understand the
purpose of a relationship, expected transactions, the persons with whom the
customer will transact and, where necessary, the source of funds. It also
requires ongoing due diligence and enhanced measures where higher risk is
identified. For an NGO, the practical lesson is that the bank is checking
whether the transaction makes sense when compared with what it knows about the
organisation.
Public
fundraising, cash donations and multiple small transfers need a different
explanation. The NGO should document the fundraising method, approval,
collection controls, deposits and reconciliation. Anonymous cash should not be
treated as harmless merely because it was donated for a good cause. At the same
time, the response should remain proportionate to the actual risk and the
domestic rules that apply.
Make
the programme explain the payment
A
bank may understand the donor and still question the outgoing transaction. The
response file should connect the payment to a real programme. The project
agreement, workplan or approved budget should show what the NGO is doing, where
it is doing it, why the payment is needed and why the selected recipient is
involved.
For
a payment to a partner, supplier, consultant or grantee, the file should
normally contain the counterparty’s legal name, registration details where
applicable, the contract or memorandum, the invoice or payment request, bank
details and the NGO’s due diligence record. Where sanctions or
terrorist-financing risk is relevant, the organisation should retain evidence
of the screening it actually performed. A dated record from the original
approval process is stronger than a screenshot created only after the bank asks
questions.
Cross-border
payments should explain why the money is crossing a border, why that route was
chosen and whether the recipient operates in the programme location. Kenya’s
2025 Terrorism Financing National Risk Assessment Guidance, for example,
identified vulnerabilities where NPOs operate close to terrorist activity, rely
on unverified funding or partners, or lack adequate financial controls. The
same guidance recorded an absence of direct evidence of terrorist-financing
abuse of NPOs in Kenya. That combination shows why individual facts matter.
Beneficiary
information needs particular care. FATF’s 2023 Best Practices Paper warns
against automatically imposing customer due diligence requirements on the
individual recipients of NPO assistance. For humanitarian and protection work,
unnecessary disclosure can also create privacy and safety risks. An NGO should
be ready to explain beneficiary categories, selection methods, distribution
controls and monitoring without casually handing over sensitive personal data
that is unnecessary for the bank’s stated purpose. Where specific names are
legally required, the organisation should use a secure channel and document the
basis for disclosure.
Controls
are more persuasive when they can be seen working
Policies
matter, but a bank reviewing a difficult transaction will usually learn more
from evidence that the controls were actually used. If the NGO has a
procurement policy, the file should show the procurement record for the
payment. If payments require two approvals, both should be visible. If partner
due diligence is required, there should be a completed assessment rather than
an unsigned template. Audit reports, anti-fraud procedures, sanctions controls,
staff training, whistleblowing arrangements and a documented risk assessment
can then support the picture rather than substitute for it.
FATF
groups useful NPO governance safeguards around organisational integrity,
partner and donor relationships, financial transparency and accountability, and
programme planning and monitoring. Its Best Practices Paper also says financial
institutions should consider an NPO’s own due diligence, governance and
risk-mitigation measures when assessing the customer. This gives the NGO a
practical opportunity to show not simply that it is registered, but that its
controls reduce the specific risk under review.
A
transaction note can save weeks of correspondence
For
transfers that are unusually large, cross-border, urgent or connected to a new
partner, the NGO should consider preparing a one-page transaction note before
the bank asks. The note can identify the funding source, programme, amount,
recipient, purpose, supporting contract, payment route, relevant risk factors,
controls applied and approving officers. It should also explain any feature
that may look unusual without context.
Compliance
teams often see transaction data before they see the programme story. A payment
may look inconsistent because the bank’s records say the NGO usually receives
quarterly grants and pays domestic suppliers, while the new transaction is a
large transfer to a new country. The transaction note explains the change
before the data has to speak for itself.
The
file should preserve the correspondence trail as well. Each request, response,
document supplied, date and responsible person should be logged. Repeated
questions are easier to address when the NGO can show that the same information
was already provided on a particular date.
What
FATF does, and does not, say about de-risking
FATF’s
current position matters because “FATF requirements” are sometimes used as a
shorthand explanation for broad restrictions. The 2023 Best Practices Paper
states that financial institutions should not view all NPOs as high risk and
should base measures on a documented assessment of the particular customer and
context. Where residual risk exists, the institution should first consider
whether safeguards can reduce it sufficiently for legitimate activity to
continue. FATF identifies blanket high-risk categorisation and wholesale
termination of NPO relationships as inconsistent with a proper risk-based
approach.
That
does not mean an NGO has an automatic right to every account or transfer. FATF
also recognises that a financial institution may decline or terminate a
relationship on a case-by-case basis where the terrorist-financing risk cannot
be mitigated. Domestic banking law, sanctions rules, contractual terms and the
bank’s lawful risk appetite still matter. The useful distinction is therefore
between a justified individual decision and a category-wide assumption that
“NGO” itself proves unacceptable risk.
National
assessments reinforce that distinction. Rwanda’s 2024 national money-laundering
and terrorist-financing risk assessment rated the NPO sector overall as low
risk for terrorist-financing abuse while identifying differences between types
of organisations and vulnerabilities such as cash fundraising and anonymous
sources. Uganda has also undertaken a dedicated 2023 terrorism-financing risk
assessment for its NPO sector, and its Financial Intelligence Authority
continues to frame compliance around the risk-based approach. These examples do
not make one country’s rules applicable in another, but they show why local
evidence should matter more than stereotypes.
If
closure is threatened, move from documents to escalation
An
NGO facing possible account closure should respond before the notice period is
nearly over. It should ask for a senior compliance review, provide the
organised response file and ask whether a narrower control would address the
concern. Depending on the issue, that could mean advance notice of certain
transfers, use of specified payment routes, additional documents for a
particular country, transaction limits or enhanced partner due diligence.
If
the bank maintains its decision, the NGO should preserve the notice, reasons
that were provided, correspondence and evidence supplied. It should use the
bank’s formal complaints or appeal process and then consider the relevant
national supervisory, ombudsman or legal route where one exists. Those avenues
differ across East African jurisdictions. Donors should also be informed early
where closure may interrupt grant conditions or programme delivery.
The
NGO should not respond by concealing the concern from another bank, splitting
transfers to avoid scrutiny or inventing documents that appear more convenient.
Those steps can turn a manageable risk question into a much more serious
compliance problem. The aim is to make the organisation easier to understand,
not harder to trace.
The
best response file is not the largest
A
good bank response file is a form of institutional memory. It brings together
legal status, governance, donors, programmes, counterparties, transaction
explanations and internal controls in a way that another person can follow
without knowing the organisation already. It also makes repeated bank questions
easier to answer because the NGO is not rebuilding its identity from scratch
each time.
The
deeper point is that de-risking is not solved only by arguing that NGOs do good
work. Banks have legal duties to understand customers and transactions. NGOs
are in a stronger position when they can show, calmly and with evidence, why a
transaction is legitimate and how its risks are controlled. FATF’s risk-based
approach leaves room for that conversation. It does not require every NGO to be
treated as harmless, but it also does not support treating every NGO as
suspect.
The
practical test is simple. If a bank reviewer opened the file today, could that
person identify the organisation, understand the money, follow the programme,
verify the counterparty and see the controls without sending five more emails?
If the answer is yes, the response file is doing its job.
Source note. This article is based on the
Financial Action Task Force Recommendations as revised through 2025, FATF’s
2023 Best Practices Paper on Combating the Terrorist Financing Abuse of
Non-Profit Organisations and its current materials on non-profit organisations
and de-risking; the Central Bank of Kenya’s Guidance on Customer Due Diligence,
effective 1 September 2025; Kenya’s Terrorism Financing National Risk
Assessment Guidance, February 2025; Rwanda’s National Money Laundering and
Terrorist Financing Risk Assessment 2024; and Uganda’s 2023 Terrorism Financing
Risk Assessment for the Non-Profit Organisations Sector and current Financial
Intelligence Authority materials. The national materials are used as East
African examples and should not be read as if one country’s rules automatically
apply in another. This article is general legal information and not legal
advice on a particular bank decision.
Suggested citation:
Ronald Serwanga, “Bank Risk Reviews: Your NGO Response File Explained” East Africa Legal Insight (4 September 2026).