You are appraising a promising application: a CSO rooted in its territory, a relevant intervention, a coherent budget. One question decides everything else — can you transfer funds to this partner without exposing your scheme? Too often, that question is settled by instinct or reputation, then painfully caught up at the final report, once a disbursement has already gone out and an audit finding travels all the way up to your upstream donor. The partner micro-assessment exists precisely to break that chain: to diagnose a partner's control framework before you disburse, and to calibrate monitoring accordingly. Provided you treat it as a steering tool, not a box to tick.
This article takes the funder's seat — programme manager, delegated-funds manager, partnerships officer, application appraiser. It shows how to run a useful partner micro-assessment, how to translate its risk rating into a proportionate assurance plan and disbursement modality, and how to avoid the costliest bias of localization: confusing weak tooling with disqualification. At Abvius, we see this step not as a filter that excludes, but as the starting point of support that equips.
Partner micro-assessment: from risk rating to assurance plan
Reading time: ~14 min
- Why the partner micro-assessment decides everything else
- What a micro-assessment actually measures
- From risk rating to assurance plan: the missing translation
- The localization angle: a low score is not grounds for exclusion
- Abvius: equip the partner, not just control it
- Setting up a proportionate micro-assessment approach
- Mini-FAQ
- Summary
Why the partner micro-assessment decides everything else
In a CSO support facility or a delegated-funds scheme, the first payment to a partner is a point of no return. Once the funds are gone, your room for manoeuvre narrows: you can only observe, control after the fact and, in the worst case, recover. The partner micro-assessment moves the decision to the right moment — before disbursement — by producing a structured reading of a partner's ability to manage, trace and account for the funds you entrust to it.
The reference method is well known to UN agencies: the Harmonized Approach to Cash Transfers (HACT) provides for a micro-assessment that examines a partner's programmatic, financial and operational management framework and results in a risk rating — low, moderate, significant or high. That rating is not an end in itself: it drives the transfer modality and the level of assurance activities. Beyond the UN framework, the same logic runs through the practices of bilateral donors, foundations and lead NGOs that re-grant in cascade: assess first, calibrate next.
The problem is almost never the absence of a micro-assessment. It is how it is used. Too many schemes produce a solid micro-assessment report… that ends up filed away, never translated into a differentiated monitoring plan. The result: every partner is supervised the same way — often the heaviest way, out of caution — regardless of their actual risk profile. Strong partners are over-controlled, fragile partners are under-supported, and supervision costs explode without exposure falling. The value of a micro-assessment lies not in the diagnosis, but in the decision that flows from it.
Micro-assessment, due diligence, capacity assessment: what are we talking about?
These terms partly overlap and are often conflated. It helps to separate them. Due diligence answers a question of entering into a relationship: is this partner what it claims to be, does it exist legally, does it present an integrity, sanctions or conflict-of-interest risk? The micro-assessment goes further on one axis: the capacity of the internal control framework to secure financial flows. Financial management capacity assessment is the generic donor-side term for this exercise, of which the HACT micro-assessment is a formalized version. In practice, you run all three in sequence: integrity screening, capacity diagnosis, then monitoring calibration.
What a micro-assessment actually measures
A serious partner micro-assessment does not stop at asking for the statutes and the latest accounts. It examines, with supporting evidence and through interviews, how the partner actually runs its operations. The analysis can be grouped into five control areas.
- Accounting and financial reporting. Existence of accounts kept up to date, separation of financial years, ability to isolate a donor's funds analytically, production of usable financial reports. A partner who cannot distinguish your funds from others will not be able to account for them cleanly.
- Cash management and disbursements. Banking circuit, petty-cash handling, payment controls, regular reconciliations. This is where most misappropriation and error risks sit.
- Procurement and purchasing. Existence of thresholds, competitive tendering, traceability of purchasing decisions. A sensitive point as soon as the partner buys goods, rents premises or contracts suppliers with your funds.
- Internal control and segregation of duties. Who commits, who pays, who checks? In small organizations, one person often holds several roles — not a deal-breaker, but a trigger for compensating measures.
- Governance, human resources and systems. Stability of the finance team, existence of written procedures, management tools, dependence on a single key person. The resilience of the framework matters as much as its quality at a given moment.
The output of this examination is not a binary "reliable / unreliable" verdict. It is a map of strengths and weaknesses, from which you draw an overall risk rating and a list of specific findings. This dual output is essential: the rating drives monitoring, the findings drive support. A scheme that keeps only the score forgoes half the value produced. It is the same logic as following up on audit findings and corrective action plans, but applied upstream, before the first euro is paid.
From risk rating to assurance plan: the missing translation
This is the heart of the matter, and the most neglected step. A risk rating is only worth something if it translates into concrete decisions on two fronts: how you disburse and how you control. The principle is proportionality: the higher the residual risk, the more cautious the disbursement modality and the more intense the assurance activities. Conversely, a strong partner should not have to endure disproportionate monitoring that costs you dearly and wears them out for nothing.
On the disbursement side, HACT logic distinguishes several modalities: direct cash transfer (advances to the partner, who then accounts for them), direct payment (you pay suppliers on the partner's behalf) and reimbursement (the partner spends its own funds, you reimburse against evidence). The higher the risk, the more you favour short tranches, a low advance ceiling, or direct payment on sensitive items. On the assurance side, you modulate the mix of desk reviews, spot checks, programmatic monitoring visits and scheduled audits.
The table below illustrates a translation grid. It is not prescriptive — each scheme sets its own thresholds according to its framework and risk appetite — but it shows what "proportioning" means in practice.
| Risk rating | Preferred disbursement modality | Minimum assurance activities | Support measures |
|---|---|---|---|
| Low | Standard tranche advances, standard ceiling | Annual desk review, programmatic visit | None specific; capture of good practice |
| Moderate | Tranche advances, adjusted ceiling | Enhanced desk review, one spot check during implementation | Targeted support on one or two priority findings |
| Significant | Short tranches, low advance ceiling, direct payment on sensitive items | Frequent spot checks, enhanced visit, mid-term review | Formalized strengthening plan, regular check-ins |
| High | Direct payment or reimbursement against evidence, minimal advances | Scheduled audit, frequent spot checks, close supervision | Intensive support or transitional co-management of at-risk functions |
What this grid reveals: the rating is not a sanction, it is a setting. It serves as much to lighten the monitoring of strong partners — and thus reduce your supervision cost — as to tighten that of fragile ones. A scheme that applies the same regime to its whole portfolio misses the point: making visible, at a glance, which partner falls under which regime is precisely the job of a portfolio monitoring dashboard.
The localization angle: a low score is not grounds for exclusion
This is where your scheme's credibility on the localization agenda is decided. Grand Bargain commitments and the push to fund local actors more directly are not slogans: they require accepting that younger, smaller, less-equipped partners enter your portfolio. And these partners mechanically obtain higher risk ratings at micro-assessment. The temptation is then strong to turn the micro-assessment into an entry filter: insufficient score, application dropped.
That is an appraisal error, not a compliance requirement. A high rating signals a need for adapted measures — not an impossibility to fund. Compliance does not require funding only already perfectly equipped partners; it requires the risk level to be known, documented and covered by proportionate measures. Mechanically excluding small organizations means always funding the same large intermediaries, lengthening the contractual cascade and betraying the very localization objective your upstream donor asks you to serve.
The decisive distinction is this: a weakness in tooling is fundable — it is corrected with a system, a procedure, training, support. An integrity failure is not — it belongs to upstream due diligence screening and has nothing to do with the capacity rating. Conflating the two leads either to funding real risks in the name of localization, or to excluding legitimate partners in the name of compliance. The table below contrasts the two possible postures facing the same low score.
| Facing a low-scoring partner | "Filter" posture (exclusion) | "Equip" posture (support) |
|---|---|---|
| Appraisal decision | Application dropped or routed to an intermediary | Funding with a strengthening plan attached |
| Effect on localization | Reconcentration towards large actors | Widening of the pool of local actors |
| Risk treatment | Risk avoided, but programmatic value lost | Risk covered by modality and assurance |
| Effect over time | The partner stays fragile, with no chance to progress | Capacity builds, risk falls cycle after cycle |
This equipping posture aligns with what we develop elsewhere on strengthening CSO financial capacity beyond training and on localizing aid and funding local NGOs. It does, however, require a concrete way to provide support without multiplying your supervision workload — and that is where a shared tool changes the equation.
This article takes the funder's seat. For the symmetric reading, from the side of the organization that receives and applies the HACT framework, see our mirror article: HACT — the UN cash transfers framework for NGOs.
Abvius: equip the partner, not just control it
The operational difficulty of everything above comes down to one tension: the more fragile partners you fund in the name of localization, the more your supervision workload rises — unless you change the tooling. At Abvius, we start from a simple observation: as long as control and strengthening remain two separate activities, the cost of supervising a wider portfolio becomes unsustainable. Our approach is to bring them together in one environment, from the upstream donor down to the final partner.
A monitoring dashboard for the funder, a consolidated real-time view
The first lever is the monitoring dashboard for donors. Each funded CSO or partner works in its own space — its budget, its expenses with supporting documents, its progress — while you get a consolidated view of the whole portfolio, in real time. Concretely, the risk rating from the micro-assessment stops being a line in a spreadsheet: it becomes a visible, living monitoring regime, where you see at a glance which partner is on which modality, where disbursements stand, which findings remain open. It is the natural extension of the "score to assurance plan" translation described above.
Strengthening built into control, not alongside it
The second lever is strengthening the capacity of the partners you support. Abvius equips the partner, not just the funder. Your upstream donor's eligibility rules are configured once and apply to the entire contractual cascade: the partner entering an expense is guided by your rules at the moment they apply them, rather than controlled six months later. Reporting consolidates without re-keying — no more PDF report handed back to be re-typed into your own spreadsheet — and the audit trail reaches down to partner level, including the smallest ones.
The economic effect is structural: when the rule is applied at source and the data comes back structured, control and strengthening stop being two distinct activities. The partner progresses by using the tool; you supervise by reading data that is already reliable. Supervision cost falls instead of rising, precisely as you widen your portfolio to more local actors. This is what makes the equipping posture sustainable at the scale of an entire scheme. You can explore Abvius to see how this logic fits with your existing framework.
Setting up a proportionate micro-assessment approach
Here are five actionable steps, written from your scheme's point of view, to move from a "box-ticking" micro-assessment to a genuine portfolio-steering tool.
- 1. Clearly separate integrity and capacity. Treat due diligence screening (legal existence, sanctions, conflicts of interest, integrity) as a distinct entry condition, and reserve the micro-assessment for measuring management capacity. A partner can fail the first without contaminating the second — and vice versa.
- 2. Set your translation grid in advance. Decide, before assessing, which rating triggers which disbursement modality and which assurance activities. This grid, formalized and shared, removes arbitrariness from the decision and makes your scheme defensible before your own hierarchy and your upstream donor.
- 3. Turn every finding into an action, not a score. For each identified weakness, define a measure: expected correction, support offered, deadline, owner. The micro-assessment thus becomes the starting point of a strengthening plan, not a mere ranking.
- 4. Proportion, then reassess. The risk level is not fixed. Plan a periodic reassessment — at least at each agreement renewal — and lower the monitoring regime once the partner has progressed. This movement rewards effort and makes the relationship sustainable.
- 5. Equip the cascade, not just headquarters. Give the partner an environment where your rules apply at source and where their data comes back consolidated. Without this, every risk reduction stays theoretical: it is the shared tool that turns a strengthening plan into real progress and a controlled supervision cost.
Mini-FAQ
What is the difference between micro-assessment and due diligence?
Due diligence verifies who the partner is (existence, integrity, sanctions, conflicts of interest): it is an entry condition. The micro-assessment measures their capacity to manage and account for funds, and results in a risk rating that drives your monitoring. The first protects against fraud and illegality; the second calibrates the financial relationship. The two are complementary and do not substitute for each other.
Should a partner with a high risk score be dropped?
No, not on the score alone. A high score calls for a more cautious disbursement modality and enhanced assurance activities, together with a strengthening plan — not exclusion. The only real red line concerns integrity (detected by due diligence), not capacity, which is built over time. Excluding on capacity alone contradicts your localization commitments.
How often should a partner be reassessed?
At least at each agreement renewal, and earlier in the event of a significant change: a serious audit finding, a change in the finance team, a sharp rise in the volume entrusted. The point of regular reassessment is also to lower the monitoring regime once the partner has progressed, which lightens your supervision cost and rewards the effort made.
How do you micro-assess without excluding small CSOs?
By separating a tooling weakness, which is fundable and correctable, from an integrity failure, which is not. A small CSO will often get a higher score: cover that risk through modality and assurance, and support the capacity build with a shared tool. This is how the micro-assessment widens your pool of local partners instead of shrinking it.
Summary
A partner micro-assessment is worth not the report it produces, but the decisions it enables: a disbursement modality and an assurance plan proportionate to the real risk, and a strengthening plan that turns a weakness into a trajectory. Done well, it reconciles two requirements too often set against each other — the compliance expected by your upstream donor and the localization you must serve — because it treats a tooling weakness as fundable and reserves exclusion for integrity failures alone. Provided you can support without exploding your supervision cost: that is the whole point of tooling that applies your rules at source and brings back data already consolidated, from the upstream donor down to the last partner in the cascade.
To go further: assessing CSO financial management capacity — the donor's guide, partner due diligence, partner risk management across the portfolio, running a CSO support facility and cascading sub-grants and the cost of supervising a grant portfolio. To discuss your scheme, get in touch.