Security Intelligence

Case Study: Partner Vetting That Survives an Audit

Proportionate due diligence on local partners, three tiers, documented reasoning, and a decision the organisation could defend two years later.

By Mowlid Ali 07 Sep 2026 6 min Security Intelligence
Source

Originally reported by INGO ADVISORY. INGO ADVISORY analysis is attributable to our intelligence desk; the underlying reporting remains the property of the publisher.

Read the original publication View all 5 citations
Author
Mowlid Ali
Source
INGO ADVISORY
Publication date
07 Sep 2026
Location
Client locations withheld
Country
South Sudan
Category
Security Intelligence
Threat level
SUBSTANTIAL — An attack is likely.
Analytic confidence
High
Verification status
Verified
Listen · 2 minReady to play · about 2 min

Anonymised practitioner case study. The organisation, precise locations and dates are withheld to protect the client and its staff. Internal metrics are not published, and none has been invented in their place.

The client

An organisation delivering the majority of its programme through national partner organisations, under donor conditions requiring documented counterparty checks.

The problem

Vetting existed but was inconsistent: thorough for large contracts, cursory for small ones, and largely undocumented in both cases. When a partner relationship was later questioned, the organisation could not reconstruct why it had been approved.

The method: proportionate tiering

  • Tier 1 (low value, low exposure): registration confirmation, sanctions and adverse-media screening, two references, signed declarations. Recorded on one page.
  • Tier 2 (material value or access-sensitive area): Tier 1 plus governance and ownership mapping, financial systems review, site visit and staff interviews.
  • Tier 3 (high value, high exposure, or an adverse finding at Tier 2): Tier 2 plus local network enquiry, political and community affiliation review, and a written risk memorandum with an accountable approver.
  • A standing rule that any adverse finding escalates the tier rather than being resolved informally.
  • Continuous monitoring: annual re-screening, plus re-screening on any change of leadership, ownership or operating area.

The part that mattered most

Every decision recorded what was checked, what was found, what was judged rather than verified, who approved it and when it must be reviewed. The reasoning, not just the outcome, was written down.

What changed

Small partnerships stopped being waved through, large ones stopped being delayed by disproportionate checks, and the organisation could answer audit questions from the file instead of from memory. No partner was excluded on the basis of unverified allegation alone.

Transferable lessons

  • Tier by exposure, not only by contract value.
  • Record reasoning, not just conclusions.
  • Escalate on adverse findings automatically.
  • Vetting is a monitoring cycle, not a gate you pass once.
Africa Risk Brief

Get the weekly Africa Risk Brief

Analysis like this — on security intelligence and Africa's highest-risk operating environments — delivered every Monday. Free.

No spam. Unsubscribe anytime. We never share your email.