Bank Risk Reviews: Your NGO Response File Explained

An NGO can discover that its bank sees it as “high risk” in a very ordinary way. A donor transfer is delayed. A payment to a field partner is held. The relationship manager asks again for the source of funds, the identity of a donor, the purpose of a programme or the people behind a counterparty. Sometimes the questions arrive one at a time until the organisation feels it is being asked to prove its legitimacy from the beginning.

The instinctive response is usually to send more documents. That can make the problem worse. A registration certificate, grant agreement, annual report, audit and invoice may all be genuine, but the bank still has to work out how they fit together. The better response is a response file: an organised record that tells one coherent story about who the NGO is, who controls it, where the money came from, why it is moving, who will receive it and what controls protect it. The point is not to overwhelm the bank. It is to make the risk understandable.

“High risk” and “wrongdoing” are not the same thing. A higher-risk classification normally means closer customer due diligence and monitoring; it is not, by itself, proof of money laundering or terrorist financing. The Financial Action Task Force, or FATF, has repeatedly stressed that risk should be identified and managed rather than avoided by treating whole categories of customers alike. Its 2023 revision of Recommendation 8 and accompanying Best Practices Paper emphasise focused, proportionate and risk-based measures for non-profit organisations. FATF strengthened the same direction in 2025 by giving greater weight to proportionality and simplified measures in lower-risk situations.

Start with the bank’s actual question

Before preparing a large bundle, the NGO should identify what the bank is trying to verify. A delayed transaction may concern an outdated signatory mandate, a donor whose name does not match the remitter, a new counterparty, a higher-risk jurisdiction, a sanctions alert, an unusual increase in transaction value or a simple gap in the bank’s customer records. Those are different problems and need different evidence.

The NGO should ask the relationship manager or compliance team, in writing, for the category of information still required, the transaction or account reference, the deadline and the channel for submission. If the bank cannot disclose the full reason, the NGO can still ask which customer due diligence information remains incomplete and whether the matter can be escalated for compliance review. A bank may be legally unable to disclose certain suspicion-reporting details, so silence about the precise trigger should not automatically be treated as bad faith.

The response file should begin with a short cover note identifying the account, the payment under review, the donor or funding source, the programme, the amount, the proposed recipient, the relevant dates and the NGO contact person. That page becomes the map to the evidence.

Prove the organisation before explaining the transaction

The first part of the file should establish legal identity and control. It should contain the current registration or incorporation document, the governing constitution or equivalent instrument, evidence of current regulatory or tax status where relevant, and a current list of directors, trustees or board members. It should also show executive officers and authorised bank signatories, together with the authority under which they act.

This matters where an NGO has changed leadership, amended its constitution, renewed registration or changed signatories. A bank should not have to reconstruct the organisation’s current position from old minutes and several email chains. The file should show which document is current and when any important change took effect.

Some bank forms use the language of “beneficial ownership” even where an NGO has no shareholders. The organisation should not invent an owner to satisfy the form. It should explain its legal structure and identify the natural persons who exercise control or senior management functions to the extent required by applicable law and the bank’s due diligence process. The goal is transparency about control, not forcing a non-profit into a company ownership model that does not fit it.

Show the source of funds as a traceable chain

“Source of funds” is often answered too vaguely. Writing “donor funding” or attaching only a grant agreement may not explain the transfer under review. A stronger file shows the chain from funding commitment to the money that reached the account.

For an institutional grant, that chain may be demonstrated by the signed grant agreement or award letter, the donor’s legal identity, the approved budget, the payment schedule, the remittance advice and the bank entry showing receipt. If a payment agent sent the funds, the file should explain that relationship. If the amount changed because of an amendment or supplementary award, the amendment should be included rather than leaving the bank to guess.

This approach reflects the Central Bank of Kenya’s 2025 Guidance on Customer Due Diligence. The guidance expects financial institutions to understand the purpose of a relationship, expected transactions, the persons with whom the customer will transact and, where necessary, the source of funds. It also requires ongoing due diligence and enhanced measures where higher risk is identified. For an NGO, the practical lesson is that the bank is checking whether the transaction makes sense when compared with what it knows about the organisation.

Public fundraising, cash donations and multiple small transfers need a different explanation. The NGO should document the fundraising method, approval, collection controls, deposits and reconciliation. Anonymous cash should not be treated as harmless merely because it was donated for a good cause. At the same time, the response should remain proportionate to the actual risk and the domestic rules that apply.

Make the programme explain the payment

A bank may understand the donor and still question the outgoing transaction. The response file should connect the payment to a real programme. The project agreement, workplan or approved budget should show what the NGO is doing, where it is doing it, why the payment is needed and why the selected recipient is involved.

For a payment to a partner, supplier, consultant or grantee, the file should normally contain the counterparty’s legal name, registration details where applicable, the contract or memorandum, the invoice or payment request, bank details and the NGO’s due diligence record. Where sanctions or terrorist-financing risk is relevant, the organisation should retain evidence of the screening it actually performed. A dated record from the original approval process is stronger than a screenshot created only after the bank asks questions.

Cross-border payments should explain why the money is crossing a border, why that route was chosen and whether the recipient operates in the programme location. Kenya’s 2025 Terrorism Financing National Risk Assessment Guidance, for example, identified vulnerabilities where NPOs operate close to terrorist activity, rely on unverified funding or partners, or lack adequate financial controls. The same guidance recorded an absence of direct evidence of terrorist-financing abuse of NPOs in Kenya. That combination shows why individual facts matter.

Beneficiary information needs particular care. FATF’s 2023 Best Practices Paper warns against automatically imposing customer due diligence requirements on the individual recipients of NPO assistance. For humanitarian and protection work, unnecessary disclosure can also create privacy and safety risks. An NGO should be ready to explain beneficiary categories, selection methods, distribution controls and monitoring without casually handing over sensitive personal data that is unnecessary for the bank’s stated purpose. Where specific names are legally required, the organisation should use a secure channel and document the basis for disclosure.

Controls are more persuasive when they can be seen working

Policies matter, but a bank reviewing a difficult transaction will usually learn more from evidence that the controls were actually used. If the NGO has a procurement policy, the file should show the procurement record for the payment. If payments require two approvals, both should be visible. If partner due diligence is required, there should be a completed assessment rather than an unsigned template. Audit reports, anti-fraud procedures, sanctions controls, staff training, whistleblowing arrangements and a documented risk assessment can then support the picture rather than substitute for it.

FATF groups useful NPO governance safeguards around organisational integrity, partner and donor relationships, financial transparency and accountability, and programme planning and monitoring. Its Best Practices Paper also says financial institutions should consider an NPO’s own due diligence, governance and risk-mitigation measures when assessing the customer. This gives the NGO a practical opportunity to show not simply that it is registered, but that its controls reduce the specific risk under review.

A transaction note can save weeks of correspondence

For transfers that are unusually large, cross-border, urgent or connected to a new partner, the NGO should consider preparing a one-page transaction note before the bank asks. The note can identify the funding source, programme, amount, recipient, purpose, supporting contract, payment route, relevant risk factors, controls applied and approving officers. It should also explain any feature that may look unusual without context.

Compliance teams often see transaction data before they see the programme story. A payment may look inconsistent because the bank’s records say the NGO usually receives quarterly grants and pays domestic suppliers, while the new transaction is a large transfer to a new country. The transaction note explains the change before the data has to speak for itself.

The file should preserve the correspondence trail as well. Each request, response, document supplied, date and responsible person should be logged. Repeated questions are easier to address when the NGO can show that the same information was already provided on a particular date.

What FATF does, and does not, say about de-risking

FATF’s current position matters because “FATF requirements” are sometimes used as a shorthand explanation for broad restrictions. The 2023 Best Practices Paper states that financial institutions should not view all NPOs as high risk and should base measures on a documented assessment of the particular customer and context. Where residual risk exists, the institution should first consider whether safeguards can reduce it sufficiently for legitimate activity to continue. FATF identifies blanket high-risk categorisation and wholesale termination of NPO relationships as inconsistent with a proper risk-based approach.

That does not mean an NGO has an automatic right to every account or transfer. FATF also recognises that a financial institution may decline or terminate a relationship on a case-by-case basis where the terrorist-financing risk cannot be mitigated. Domestic banking law, sanctions rules, contractual terms and the bank’s lawful risk appetite still matter. The useful distinction is therefore between a justified individual decision and a category-wide assumption that “NGO” itself proves unacceptable risk.

National assessments reinforce that distinction. Rwanda’s 2024 national money-laundering and terrorist-financing risk assessment rated the NPO sector overall as low risk for terrorist-financing abuse while identifying differences between types of organisations and vulnerabilities such as cash fundraising and anonymous sources. Uganda has also undertaken a dedicated 2023 terrorism-financing risk assessment for its NPO sector, and its Financial Intelligence Authority continues to frame compliance around the risk-based approach. These examples do not make one country’s rules applicable in another, but they show why local evidence should matter more than stereotypes.

If closure is threatened, move from documents to escalation

An NGO facing possible account closure should respond before the notice period is nearly over. It should ask for a senior compliance review, provide the organised response file and ask whether a narrower control would address the concern. Depending on the issue, that could mean advance notice of certain transfers, use of specified payment routes, additional documents for a particular country, transaction limits or enhanced partner due diligence.

If the bank maintains its decision, the NGO should preserve the notice, reasons that were provided, correspondence and evidence supplied. It should use the bank’s formal complaints or appeal process and then consider the relevant national supervisory, ombudsman or legal route where one exists. Those avenues differ across East African jurisdictions. Donors should also be informed early where closure may interrupt grant conditions or programme delivery.

The NGO should not respond by concealing the concern from another bank, splitting transfers to avoid scrutiny or inventing documents that appear more convenient. Those steps can turn a manageable risk question into a much more serious compliance problem. The aim is to make the organisation easier to understand, not harder to trace.

The best response file is not the largest

A good bank response file is a form of institutional memory. It brings together legal status, governance, donors, programmes, counterparties, transaction explanations and internal controls in a way that another person can follow without knowing the organisation already. It also makes repeated bank questions easier to answer because the NGO is not rebuilding its identity from scratch each time.

The deeper point is that de-risking is not solved only by arguing that NGOs do good work. Banks have legal duties to understand customers and transactions. NGOs are in a stronger position when they can show, calmly and with evidence, why a transaction is legitimate and how its risks are controlled. FATF’s risk-based approach leaves room for that conversation. It does not require every NGO to be treated as harmless, but it also does not support treating every NGO as suspect.

The practical test is simple. If a bank reviewer opened the file today, could that person identify the organisation, understand the money, follow the programme, verify the counterparty and see the controls without sending five more emails? If the answer is yes, the response file is doing its job.

Source note. This article is based on the Financial Action Task Force Recommendations as revised through 2025, FATF’s 2023 Best Practices Paper on Combating the Terrorist Financing Abuse of Non-Profit Organisations and its current materials on non-profit organisations and de-risking; the Central Bank of Kenya’s Guidance on Customer Due Diligence, effective 1 September 2025; Kenya’s Terrorism Financing National Risk Assessment Guidance, February 2025; Rwanda’s National Money Laundering and Terrorist Financing Risk Assessment 2024; and Uganda’s 2023 Terrorism Financing Risk Assessment for the Non-Profit Organisations Sector and current Financial Intelligence Authority materials. The national materials are used as East African examples and should not be read as if one country’s rules automatically apply in another. This article is general legal information and not legal advice on a particular bank decision.

Suggested citation: 

Ronald Serwanga, “Bank Risk Reviews: Your NGO Response File Explained” East Africa Legal Insight (4 September 2026).