You fund twenty, fifty, sometimes a hundred partner organisations. Each one passed your due diligence at intake. And yet it is often at the final report — or worse, during your upstream donor's audit — that you discover a partner had been struggling for months: missing supporting documents, unjustified advances, a procurement procedure bypassed because it was never understood. Between the initial assessment and the finding, your visibility on partner risk rested on quarterly PDF reports, re-keyed into a tracking spreadsheet, with a three-month lag. The risk did not erupt: it matured outside your field of vision.
This article looks at partner risk management from the seat of the one who funds: how to map the real exposure of your portfolio, right-size supervision without smothering the organisations you support, and move from a logic of risk transfer to one of risk sharing — the shift promoted by the Grand Bargain and now being structured by initiatives such as the Dutch Relief Alliance's 2026 risk-sharing approach. We will also see how a platform like Abvius turns the supervision of a partner portfolio into a continuous flow rather than a periodic collection of documents.
Partner Risk: Managing Your Portfolio Exposure
Reading time: ~12 min
- Partner risk: what are we actually talking about?
- Risk transfer, the blind spot of the contractual cascade
- Mapping your portfolio exposure
- From reinforced control to risk sharing
- Equipping supervision: what a shared platform changes
- Five steps to proportionate partner risk management
- Mini FAQ
- Summary
Partner risk: what are we actually talking about?
Partner risk covers all the events that may occur within an organisation you fund and affect your objectives: the proper use of funds, the achievement of results, your compliance towards your own upstream donor, and your reputation. The risk-sharing framework that emerged from the Grand Bargain work distinguishes several families of risk, worth restating at your portfolio scale:
- Fiduciary risk: funds used for purposes other than agreed, ineligible expenditure, insufficient justification, fraud.
- Compliance risk: breaches of upstream donor rules (procurement, screening, visibility, eligibility) that mechanically travel back up the cascade to you.
- Operational risk: implementation delays, budget under-spending, unreliable monitoring data.
- Accountability risk: inability to consolidate heterogeneous reports within the deadlines of your own reporting.
- Reputational and safeguarding risk: a PSEAH incident, a sanction, a controversy affecting a partner, whose shockwave reaches the funder.
Two important clarifications. First, partner risk is not an intrinsic property of the partner: it is the product of a situation — operating context, complexity of the rules applied, fit between requirements and the management resources the organisation actually has. Second, it is not the same thing as due diligence: the intake assessment is a photograph; partner risk management is a film that plays for the entire duration of the agreement. It is precisely between two assessments that most audit findings take root. If you are looking for the assessed organisation's point of view, we covered it on the NGO side in our guide to partner due diligence and to risk mapping — this article deliberately takes the other seat: yours.
Risk transfer, the blind spot of the contractual cascade
In a contractual cascade — upstream donor, fund manager or lead agency, implementing partners, sometimes sub-partners — each level tends to replicate downstream the obligations it accepted upstream, adding its own requirements on top. The result has long been documented by the aid localisation literature: obligations travel down the cascade, but the means to meet them rarely travel with them. This is what the sector calls risk transfer, as opposed to risk sharing.
Why risk transfer does not protect the funder
Intuitively, contracting risk downstream seems to protect the funder: if the partner fails, the recovery clause applies. In practice, that protection is largely illusory. A partner unable to apply a rule it neither understood nor had the means to implement will produce ineligible expenditure — clause or no clause. Recovering funds from an organisation with limited reserves is slow, uncertain and corrosive for the partnership, and it does not make the audit finding at your upstream donor disappear. The risk was not transferred: it was hidden, and it comes back to you with interest.
The localisation anti-bias: the partner is not the problem
This calls out a frequent appraisal bias: equating "small local organisation" with "high risk" and mechanically excluding such organisations from funding schemes. That is doubly wrong. First, fiduciary incidents are not the preserve of small structures — audits of large international organisations regularly remind us of that. Second, a weakness in management tooling is a fundable, fixable gap, not a permanent trait: that is the whole point of capacity strengthening, which we detailed in our article on strengthening CSO financial capacity. Systematically screening out local actors on risk grounds confuses gross risk with net risk after mitigation — and drifts away from the localisation commitments most donors have signed, at a time when the share of direct funding to local and national actors remains far below the Grand Bargain's 25% target.
Mapping your portfolio exposure
Partner risk management starts with a simple question few fund managers can answer quickly: where is your exposure concentrated? Portfolio exposure cannot be read from the average of due diligence scores. It is read at the intersection of three dimensions, for each agreement:
- The volume at stake: contracted amount, disbursed amount not yet justified (your actual exposure to date), pace of upcoming disbursements.
- The probability of an incident: derived from the capacity assessment (HACT micro-assessment, pillar assessment or your own grid — see our guide to assessing a CSO's financial management capacity), updated with implementation signals: late reports, budget variances, finance team turnover.
- The context: intervention area, currency, complexity of the upstream donor rules applied to the agreement, depth of the cascade below the partner.
Classify to right-size supervision
This intersection lets you classify the portfolio's agreements by risk level, and above all derive differentiated supervision from it — the spirit of the United Nations HACT approach, transposable to any fund manager (we described this framework from the partner's side in our HACT guide):
| Risk level | Typical profile | Proportionate supervision arrangements |
|---|---|---|
| Low | Confirmed capacity, clean justification track record, stable context | Standard reporting, light desk review, spaced-out spot checks |
| Moderate | Adequate capacity but sharply increasing volume, or first grant of this type | Tighter disbursement tranches, sample-based document review, quarterly check-in |
| High | Gaps identified at assessment, volatile context, deep downstream cascade | Short advances justified before renewal, close accompaniment, monitored strengthening plan |
| Critical | Confirmed incident or converging signals (missing reports, old unjustified advances) | Disbursements suspended, targeted verification, remediation plan before resumption |
Two symmetrical pitfalls threaten the exercise. The first: a static map, frozen at contracting time, never refreshed with implementation data. The second: uniform supervision that applies the regime of the most fragile partner to the whole portfolio — costly for you, discouraging for high-performing partners, and contrary to the proportionality principle upstream donors themselves recommend.
From reinforced control to risk sharing
Faced with a partner risk judged high, the classic reflex is to add control: more frequent reports, supporting documents demanded from the first euro, multiplied prior approvals. That response has a cost — for you as for the partner — and well-known diminishing returns: beyond a certain threshold, additional control no longer reduces risk; it consumes the partner's management capacity that should have gone into implementing the project. The Grand Bargain's Risk Sharing Framework (2023) and the risk-sharing approach published by the Dutch Relief Alliance for 2026 propose a shift: analyse risk together, make each party's risk appetite explicit, and decide who is best placed to carry and treat each risk — rather than letting it slide silently towards the weakest link in the cascade.
Reinforced control or equipped partner: two answers to the same risk
| Dimension | "Reinforced control" logic | "Equipped partner" logic |
|---|---|---|
| Posture | Verify after the fact, sanction the deviation | Prevent the deviation upstream, correct continuously |
| Eligibility rules | Annexed to the agreement, applied from memory by the partner | Built into the partner's management tool, blocking before the expense |
| Detecting a problem | At the next report, with a 1-to-3-month lag | As it happens, from implementation data |
| Supervision cost | Grows with every partner added to the portfolio | Largely pooled, grows slowly with the portfolio |
| Effect on the partner | Heavier reporting burden, capacity absorbed by compliance | Durably strengthened capacity, reusable beyond the agreement |
Risk sharing is not a weakening of control: it is a reallocation. The funder keeps supervision, the audit trail and the disbursement decision; the partner receives the means — configured rules, tools, accompaniment — to apply the requirements rather than endure them. Net risk falls for both.
Equipping supervision: what a shared platform changes
Nearly all the difficulties described above share one root: data travels down the cascade as documents — PDF reports, spreadsheets in heterogeneous formats — that your teams collect, re-key and consolidate. That mechanism imposes the time lag that makes risk invisible, and turns every new partner into an additional supervision cost. This is the lock a platform shared between funder and partners removes, and it is how we designed Abvius.
A real-time portfolio view, while each partner works in its own space
Concretely, each funded CSO or partner works in its own Abvius space: its budget, its expenses entered with their supporting documents, its progress. On your side, the funder monitoring dashboard consolidates that portfolio in real time: burn rate per agreement, outstanding advances and the age of their justification, reporting delays, alerts on the signals that should trigger a review. Risk mapping stops being an annual exercise on dead data: it refreshes with implementation. We detailed this mechanism in our article on the grant portfolio monitoring dashboard.
Equipping partners, not just the funder
The other half of the arrangement is the one that makes risk sharing tangible: Abvius equips the organisations you fund, not only your teams. Your upstream donor's eligibility rules are configured once and apply across the whole cascade: a partner cannot book an out-of-scope expense without the deviation being flagged at entry time — not six months later at audit. Reporting consolidates without re-keying, in your format. The audit trail runs down to the level of each partner — a growing upstream-donor requirement on cascading funds, as we showed in our article on CSO support facilities and cascading sub-grants. And because control and strengthening stop being two separate activities — the tool that secures the expense is also the one that structures the partner's management — your supervision cost falls structurally as the portfolio gets equipped.
Five steps to proportionate partner risk management
Here is an implementation path, designed for a fund manager or partnerships team starting from spreadsheet-based tracking:
- 1. Establish the portfolio's actual exposure. For each agreement: disbursed amount not yet justified, date of the last report received, date of the last capacity assessment. This simple inventory usually reveals unsuspected concentrations of exposure.
- 2. Classify agreements, not partners. Cross volume, probability and context to assign a risk level per agreement, and document the criteria — your appraisal officers must be able to apply the same grid.
- 3. Formally differentiate supervision regimes. For each level, define disbursement arrangements, reporting frequency and the depth of document verification. Make the lighter regime attainable: that incentive is what gives the system meaning.
- 4. Turn every finding into a strengthening action. A detected gap should feed the partner's accompaniment plan — dedicated strengthening budget, tooling, close support — not just a formal reminder letter.
- 5. Equip the flow, not the snapshot. Replace the periodic collection of documents with a shared platform where implementation data flows up continuously. That is the condition for steps 1 to 4 to stay current without mobilising an entire team.
Mini FAQ
What is the difference between due diligence and partner risk management?
Due diligence is a point-in-time assessment, at intake or renewal. Partner risk management is the continuous process that follows: updating the risk level from implementation data, proportionate supervision, acting on signals. The former without the latter is like judging a film by its first frame.
Can I demand the same level of control from a small local partner as from an international NGO?
You can demand the same level of assurance — funds used as agreed, expenses justified, audit trail — but not through the same means. Proportionality applies to the arrangements: shorter tranches, closer accompaniment, tooling provided. Demanding the compliance apparatus of an international organisation from day one amounts to mechanically excluding local actors, against your own localisation commitments.
Isn't a recovery clause in the agreement enough to cover the risk?
No. The clause organises the legal consequences of an incident; it reduces neither its probability nor its impact on your compliance towards the upstream donor. Recovery from an organisation with limited reserves is slow and uncertain, and the audit finding remains. Prevention — rules applied before the expense, continuous visibility — protects better than sanction.
Does risk sharing increase my exposure as a funder?
Quite the opposite. Risk transfer gives an apparent contractual protection while letting the real risk mature out of sight. Risk sharing makes explicit who carries what, equips the link best placed to treat each risk, and restores your continuous visibility. Your legal exposure is better framed and your actual exposure decreases.
Summary
Partner risk management is neither about piling up controls nor about screening out organisations judged fragile: it is about knowing your portfolio's actual exposure continuously, right-sizing supervision, and equipping your partners so that upstream donor requirements are applicable — and applied — at every level of the cascade. That is the shift from risk transfer to risk sharing, and it is as much a matter of tooling as of posture. To go further, see our guide to assessing a CSO's financial management capacity, our article on the grant portfolio monitoring dashboard and our analysis of direct funding of local NGOs. And if you would like to see how Abvius equips the supervision of a partner portfolio — consolidated dashboard on the funder side, equipped spaces on the partner side — contact our team.