Thirty active grant agreements, four countries, two portfolio officers — and the same question at every steering committee: what do you actually know about what is happening inside your partner organisations between two reports? The micro-assessment is eighteen months old, verifications are decided as opportunities arise, and too often it is the final report — or an audit commissioned by your own upstream donor — that reveals a partner had been accumulating difficulties for a year. Control exists in your facility, but it is ad hoc, reactive, and rarely proportionate to the real risk in your portfolio.
This article is written for you — programme manager, delegated fund manager, partnership officer. It shows how to move from the partner spot check decided case by case to a genuine assurance plan: proportionate, scheduled, documented, inspired by proven frameworks such as the United Nations HACT and transposable to any CSO support facility. We will also look at how a shared platform like Abvius changes the mechanics of these verifications — for you and for the organisations you fund.
Partner spot checks: from ad hoc control to an assurance plan
Reading time: ~11 min
- Spot check, micro-assessment, audit: what are we talking about?
- Why case-by-case control does not protect your portfolio
- Building a risk-based assurance plan
- From findings to strengthening: using the results
- Equipping the assurance plan: collected documents or shared data
- What Abvius brings to funders and their partners
- Five steps to set up your assurance plan
- Mini FAQ
Spot check, micro-assessment, audit: what are we talking about?
The vocabulary largely comes from the Harmonized Approach to Cash Transfers (HACT) used by United Nations agencies, but the logic applies to any funder transferring funds to implementing partners: bilateral donor, foundation, local authority, operator or lead NGO in a consortium. We have described this framework from the seat of the NGO on the receiving end; here we deliberately take the other seat — yours.
Three families of exercises complement each other, and are often confused:
- The micro-assessment (or due diligence, or capacity assessment) takes place before or at the start of the relationship: it analyses the partner''s management arrangements and produces a risk rating — low, moderate, significant or high. We devoted a dedicated guide with an assessment grid to it.
- The spot check is a targeted verification during the agreement: on a sample of reported expenditure, you verify that supporting documents exist, that costs are eligible, correctly allocated and consistent with the reports. It does not produce an audit opinion: it is an assurance exercise — lighter, and feasible by your own teams or a mandated firm.
- The audit (scheduled or special) remains the most formal exercise, conducted by an independent auditor under professional standards, generally at year-end or at the close of the agreement.
The partner spot check in the assurance chain
The partner spot check is the middle link in the chain: more frequent than an audit, more factual than a programmatic visit, it is the tool that lets you detect early — and at reasonable cost — a gap between what is reported and what is documented. Provided it belongs to a plan, not to a series of improvised decisions.
Why case-by-case control does not protect your portfolio
Most facilities already carry out verifications. The problem is not the absence of control: it is its improvisation. Four perverse effects come up systematically.
- Convenience sampling. You check the partners who are easy to reach, who speak your language, who are close to the capital — not those who concentrate the risk. The portfolio''s real exposure remains unknown.
- Late detection. Without an assurance calendar, the first in-depth verification happens at final report stage, when expenditure is committed and corrective options are exhausted. Findings become ineligible costs instead of becoming action plans.
- Duplicated controls. Each funder verifies the same partner separately, with its own formats. The partner spends weeks answering redundant requests — time taken from implementation, which you end up paying for.
- No consolidated trail. When your own upstream donor audits the facility, you must reconstruct who was checked, when, with what findings and what follow-up. If the answer lives in the mailboxes of three portfolio officers, the exercise turns into archaeology.
One point deserves to be named: the reflex of over-controlling small local organisations because they are small is an appraisal error, not prudence. Size is not a risk rating. A local CSO with simple but respected procedures can present less risk than an international organisation that outsources its management. Saturating a local partner''s team with redundant verifications does not reduce risk: it consumes the very capacity you are trying to strengthen, and it runs against the aid localisation commitments made under the Grand Bargain. Proportionality must follow documented risk — never assumption.
Building a risk-based assurance plan
An assurance plan is a simple document: for each partner in the portfolio, it sets in advance the nature, frequency and trigger of the year''s assurance activities — spot checks, programmatic visits, audits. Two variables calibrate it: the risk rating from the micro-assessment, and the volume of funds transferred.
Calibrating the frequency of partner spot checks
The frequencies below, inspired by HACT practice and by the CSO support facilities we observe, are a reasonable starting point — to be adjusted to your materiality thresholds:
| Risk rating | Spot checks / year | Programmatic visit | Audit |
|---|---|---|---|
| Low | 1 if transfer volume is significant, otherwise on trigger | 1 / year | Based on cumulative agreement threshold |
| Moderate | 1 / year | 1 / year | Based on cumulative threshold |
| Significant | 2 / year | 2 / year | Annual audit recommended |
| High | 2 or more / year, larger samples | 2 / year minimum | Annual audit + adapted disbursement modalities |
For high-risk partners, the answer is not necessarily exclusion: adapted modalities — reduced advances, tranche disbursements conditional on reporting, reimbursement against documentation while strengthening takes effect — keep the relationship alive while containing exposure. That is the heart of reasoned partner risk management at portfolio level.
Set triggers, not just a calendar
A good assurance plan combines the scheduled and the conditional. Define in advance the events that trigger an off-calendar spot check: repeated reporting delays, turnover of the partner''s finance lead, a significant gap between budget consumption and activity progress, an alert received through a complaints mechanism, or a finding left open for more than six months. A trigger written in calm times avoids two symmetrical pitfalls: the improvised punitive inspection, and inaction for lack of a contractual basis.
From findings to strengthening: using the results
A spot check that produces a report filed in a shared folder has achieved nothing. The value of the exercise comes afterwards: in the findings register and in the strengthening loop.
Each finding should be logged with a category (missing document, ineligible expenditure, misallocation, procedural weakness, suspected fraud — which follows a separate channel), a severity, an action plan agreed with the partner, an owner and a deadline. At portfolio level, aggregating this register is a steering instrument: it reveals recurring weaknesses, feeds the annual review of risk ratings and documents your diligence towards your upstream donor.
Above all, distinguish what the finding reveals. A recurring missing document at a partner that keeps its accounts on spreadsheets is not a fraud signal: it is a tooling deficit — and a tooling deficit can be funded. A capacity-strengthening budget line, closer accompaniment, provision of tools: the options are known, and we detailed them in our article on strengthening CSO financial capacity beyond training. An assurance plan reaches maturity when control and strengthening stop being two separate activities: each finding feeds the support plan, and each support action shows up in falling findings.
Equipping the assurance plan: collected documents or shared data
How you access partner information determines the cost — and the reliability — of each verification. Two models stand opposed:
| Dimension | Spot check on collected documents | Spot check on a shared platform |
|---|---|---|
| Preparation | 2–3 weeks of email exchanges to obtain the ledger and documents | Sample drawn upstream on actual entries, documents already attached |
| Sampling basis | What the partner sent | The full population of recorded expenditure |
| Burden on the partner | Several days of mobilisation per exercise, for each funder | The work is done as they go; verification adds almost nothing |
| Findings follow-up | The portfolio officer''s personal spreadsheet | Shared, time-stamped register that stands up in audit |
| Portfolio view | Manual consolidation, quickly outdated | Real-time consolidation across all agreements |
The first model turns control into a costly, dreaded event; the second turns it into a reading of already-structured data. The difference is not the rigour of the teams but the infrastructure — the whole point of the portfolio dashboard we described elsewhere.
What Abvius brings to funders and their partners
Abvius is a management platform built for NGOs, CSOs and their funders, covering finance, operations and MEAL. On the subject at hand, two capabilities concretely change the mechanics of the assurance plan.
The donor monitoring dashboard. Each funded CSO or partner works in its own space — budget, expenditure with supporting documents attached, activity progress — while you have a real-time consolidated view of the portfolio. For a spot check, this means the sample is drawn on actual entries before you even contact the partner, supporting documents are already linked to expenditure, and findings are logged in a shared register with action plans and deadlines. The audit trail goes down to each partner: when your upstream donor reviews you, the history of verifications and their follow-up is available without reconstruction.
Strengthening the capacity of supported organisations. Abvius equips the partners, not only the funder. Your upstream donor''s eligibility rules are configured once and applied across the whole contractual cascade; reporting consolidates without re-entry; and a partner who records expenditure as it happens, with built-in controls, structurally makes fewer errors — which shows, spot check after spot check, in falling findings. Control and strengthening stop being two separate activities, and the facility''s supervision cost falls structurally. Learn more at abvius.org.
Five steps to set up your assurance plan
- Map the portfolio. For each partner, cross the risk rating (an up-to-date micro-assessment or due diligence — redo it if older than two or three years) with the volume of funds transferred over the year.
- Write the assurance policy. Frequencies per risk level, materiality thresholds, off-calendar triggers, a separate channel for suspected fraud. Annex it to the agreements: a contractually scheduled spot check is experienced as a normal modality, not as a mark of distrust.
- Plan the year and pool efforts. Schedule exercises away from partners'' reporting peaks, and reach out to the partner''s other funders: one shared spot check — or one whose results circulate — is worth two redundant exercises.
- Standardise the outputs. A single spot check report format, one findings register for the facility, stable categories: that is what makes portfolio-level aggregation possible.
- Close the loop to strengthening. Annual review: recurring findings → a funded support plan; documented progress → an upgraded risk rating and lighter controls. Lightening deserves to be as visible as tightening: it is what makes the system an incentive.
Mini FAQ
What is the difference between a spot check and an audit?
The spot check is a targeted assurance exercise, on a sample, without a formal opinion, feasible by your teams or a mandated firm. The audit is conducted by an independent auditor under professional standards and produces an opinion. The former detects early at low cost; the latter certifies. A sound assurance plan articulates both.
Who can perform a partner spot check?
Your own teams (ideally someone other than the project officer who works with the partner day to day, to preserve independence), a mandated local firm, or a team pooled between funders. What matters is a consistent method and traceable results.
Should the partner be notified before a spot check?
Yes, as a rule: the objective is assurance and improvement, not catching someone in the act, and an announced exercise with a reasonable preparation list is more productive. Reserve unannounced verifications for substantiated alerts — and provide for that possibility in the agreement.
How should the assurance plan be funded?
Build supervision costs into the facility budget at appraisal stage — a legitimate expense, generally accepted by upstream donors. Pooling between funders and shared tooling reduce the weight: the marginal cost of a spot check on structured data is a fraction of a document-collection exercise.
Summary
Partner spot checks protect your portfolio only when they stop being improvised decisions and become the centrepiece of an assurance plan: proportionate to documented risk rather than to organisational size, triggered by written criteria, and captured in a findings register that feeds capacity strengthening and the review of risk ratings. To go further, see our CSO financial management capacity assessment grid, our guide to grant portfolio monitoring and our article on partner risk management — and if you would like to see how Abvius equips your assurance plan end to end, contact us.