Nonprofits move value through relationships that do not fit a single customer-and-supplier model. Funds may enter from an individual donor or institutional funder, pass through a grant-making body or implementing partner, pay local suppliers and ultimately support a programme or beneficiary population. Trustees, directors, representatives, banks and other payment parties can become relevant at different points.
The control objective is not to produce the longest possible screening list. It is to identify which supplied parties matter, why they are in scope, when the check can inform a decision, who investigates a candidate and what evidence is retained.
FATF revised Recommendation 8 in 2023 to reinforce focused, proportionate and risk-based measures for the subset of nonprofit organisations exposed to terrorist-financing abuse. That is a guardrail against treating every nonprofit, donor or aid recipient identically.1
This guide describes screening operations, not legal advice or a complete charity AML/CFT programme.
Map the nonprofit value flow before choosing whom to screen
Start with the organisation's actual operating model:
- 1Donor or funder
A person, company, foundation, government body or other funding source enters the relationship.
- 2Charity or NGO
The organisation accepts funds, appoints accountable people and applies its programme and risk controls.
- 3Grantee or partner
A grant applicant, local partner or delivery organisation receives authority or value.
- 4Supplier or payment chain
Contractors, agents, payees, banks and other transaction parties support delivery.
- 5Programme delivery
Activities reach intended populations under the organisation's operational and safeguarding controls.
- 6Change and review
New parties, source updates or relationship changes send defined records back for assessment.
This map prevents several common category errors. A payment beneficiary is not automatically a programme beneficiary. A donor is not necessarily a customer. A local implementing partner may require a different review from a routine office supplier. A trustee's governance role differs from the ownership role of a shareholder in a commercial company.
Use the customer-versus-counterparty screening guide for the generic classification method. Keep this guide focused on the nonprofit roles and decisions.
Build the control around parties, events and decisions
There is no universal instruction to screen every row below. The matrix is a design tool: include a population only where the applicable framework, programme, risk assessment and approved policy justify it.
| Operational event | Potential supplied parties | Screening question | Decision outside the screening result |
|---|---|---|---|
| Donor or funder acceptance | Individual or entity; supplied owners/controllers where relevant | Is there a relevant sanctions candidate? Does the approved policy require separate PEP or adverse-media review? | Accept, seek information, escalate or restrict the funding relationship |
| Grant application or approval | Applicant or grantee; trustees, directors, representatives and supplied owners/controllers | Does the supplied party or relationship produce a candidate requiring investigation? | Grant eligibility, approval, conditions, escalation or rejection |
| Implementing-partner onboarding | Local partner, authorised representatives and supplied related parties | Is there relevant restricted-party exposure or unresolved identity similarity? | Contracting and programme decision |
| Trustee, director or key-role appointment | Proposed person | Does the role holder match a configured sanctions, PEP or other relevant source? | Appointment, governance or enhanced-review decision |
| Supplier or logistics engagement | Supplier, contractor, agent, logistics provider and relevant supplied owners | Does the procurement relationship create sanctions exposure? | Procurement, contracting or delivery decision |
| Programme-beneficiary registration | Beneficiary only where lawful, justified and proportionate | Does an approved control require this population to be screened with the available data? | Whether screening is appropriate and any humanitarian or programme response |
| Grant, aid or operating disbursement | Payee, payment beneficiary, supplied transaction parties and supported identifiers | Does the payment event return a relevant sanctions or watchlist candidate? | Release, hold, licence or exception analysis, escalation or other action |
| Relevant party or source change | Previously approved monitored party | Has new information created a candidate or invalidated the earlier disposition? | Reopen, retain or change the previous decision |
| Possible humanitarian exception or licence | Confirmed relevant party or activity | Which screening evidence and facts must be handed to legal or compliance review? | Whether an exception or licence applies and whether activity may proceed |
For each population, document:
- why the role is relevant;
- which names, identifiers and relationship evidence are available;
- which source categories and matching configuration apply;
- what event triggers the check;
- which decision can still be paused;
- who investigates a candidate;
- who owns the legal, grant, payment or programme outcome; and
- what evidence must be retained.
Put screening at meaningful nonprofit events
Screening is most useful where reliable party data exists and the organisation can still respond. Depending on the approved control, that may be before accepting a material donor, approving a grant, onboarding an implementing partner, appointing a trustee, committing to a supplier or releasing a payment.
Different populations need different delivery routes. A grants platform can call a real-time screening API when an applicant or authorised representative is submitted. A charity can use CSV batch screening for a supplied trustee, partner or grantee portfolio. An analyst can use the portal for an ad hoc investigation. Defined records can enter ongoing monitoring when the organisation's policy requires later source or identity changes to return for review.
The trigger remains an organisational and legal-control decision. Technology can execute the approved check; it does not decide that every donation, beneficiary or programme event must be screened.
Keep sanctions, PEP and adverse-media questions separate
A sanctions candidate can introduce asset-freeze, ownership/control, reporting, licensing or other regime-specific questions. PEP status identifies political exposure and informs the applicable risk-based process; it is not an accusation or an automatic rejection reason. Adverse media may add investigative context but does not prove wrongdoing or establish a legal restriction.
These checks may run in one operational workflow, but reviewers should still see the source category and make the downstream decision under the correct policy. The AML name-screening guide explains the generic sanctions-and-PEP review sequence.
PEP screening does not verify a donor's source of funds or source of wealth. Where further evidence is required, the organisation must obtain and assess it through its own due-diligence process.
Handle trustees, related parties and ownership without overclaiming
Nonprofit legal forms differ. Some organisations have trustees or members rather than shareholders; a corporate donor, grantee, supplier or implementing partner may have owners and controllers. Preserve the supplied relationship and role instead of forcing every person into a commercial UBO model.
Where ownership or related-party information is relevant, connect the supplied directors, trustees, representatives, owners or controllers to the organisation being reviewed. Checklynx can screen that supplied context, but it does not universally discover or verify every ownership relationship. Use the UBO and related-party screening guide for the ownership handoff.
Treat humanitarian exceptions and licences as a legal branch
A candidate match is not the final answer to whether humanitarian activity can proceed. United Nations Security Council Resolution 2664 created a humanitarian exemption to specified UN asset-freeze measures for defined actors and activities. Its scope is specific. Resolution 2761 (2024) later affirmed the exemption's continuing application to the ISIL (Da'esh) and Al-Qaida regime.23
The UK OFSI charity and NGO guidance separately addresses due diligence, licensing and humanitarian provisions, and states that the guidance is not legal advice.4 An organisation must identify the applicable regime and current legal route rather than infer an exception from a software result.
The operational requirement for screening software is therefore to preserve the relevant party, source record, identifiers, relationship context and review history so legal or compliance teams can assess the actual facts.
Match international names without multiplying review work
Charities and NGOs may operate across languages and scripts. Test original-script names, transliterations, aliases, changed name order, common names and secondary identifiers. Weak matching can miss relevant candidates; overly broad matching can overwhelm a small compliance team.
Checklynx Smart Matching groups source records that likely refer to the same real-world person or entity into a consolidated profile. This can reduce repeated record-by-record review while keeping the supporting sources and relationships visible. Customer-specific false-positive context can remain attached while the relevant identity and source facts stay unchanged; a meaningful change can return the candidate for review.
Explore Smart Matching and profile clustering for the matching layer.
Investigate candidates and retain reconstructable evidence
A nonprofit screening case should allow another authorised reviewer to reconstruct:
- the programme, grant, donation, appointment, procurement matter or payment event;
- the supplied party and its role;
- the original names, identifiers and relationship information;
- the policy and source categories applied;
- the candidate profiles and matching explanation;
- the source evidence and timestamp available at review;
- the reviewer, notes, attachments, escalation and rationale;
- the outcome and any condition attached to it; and
- the later change that reopened the case, where applicable.
AI-assisted result assessment can organise source-grounded result context and highlight confirming, conflicting or missing evidence for an authorised reviewer. Governed agents can call permitted Checklynx capabilities through MCP-ready agentic AML workflows. Neither route transfers policy ownership, permissions, humanitarian or legal analysis, reviewer accountability or the final decision to the model or agent.
What Checklynx can—and cannot—do for nonprofit teams
Checklynx can screen supplied donors, funders, grant applicants, grantees, trustees, directors, representatives, implementing partners, suppliers, payment parties, programme beneficiaries where appropriately configured, and supplied owners or controllers. Teams can use portal, API, CSV batch and ongoing monitoring workflows, then connect candidates to case management, reviewer decisions and audit evidence.
Checklynx does not authenticate identity documents or biometrics, discover every beneficial owner, verify source of funds or wealth, prove that aid reached an intended beneficiary, perform behavioural transaction monitoring, detect diversion, assess programme effectiveness, determine whether an exception or licence applies, or make the final legal, grant, appointment, procurement, payment or programme decision.
Use Checklynx sanctions screening after the organisation has defined its populations, events, configurations, reviewers and decision owners.
Market terminology and legal perimeter differ
In the UK, OFSI publishes dedicated financial-sanctions guidance for charities and NGOs. Since 28 January 2026, the UK Sanctions List has been the sole UK government source for UK sanctions designations.45
Germany's Ministry of Finance describes earlier and continuing sector-risk work concerning terrorist-financing abuse of nonprofit organisations. That risk analysis should not be converted into one universal screening obligation for every German association or foundation.6
Spain's Treasury uses Organizaciones Sin Fines de Lucro and repeats FATF's focused, proportionate, risk-based approach. The relevant legal form and activity still determine the applicable duties.7
The UAE Ministry of Community Empowerment oversees a dedicated nonprofit-sector framework and operates approval processes for establishing nonprofit organisations and receiving donations. Requirements depend on the entity, activity, licence and competent authority; rules addressed to financial institutions or DNFBPs should not automatically be applied to every charity.89
Operational checklist
- Identify the legal entity, programme and jurisdictions involved.
- Map how funding enters, moves through and leaves the organisation.
- Distinguish donors, grant applicants, grantees, implementing partners, suppliers, payment parties and programme beneficiaries.
- Record why each selected population is in scope and exclude populations without a justified basis.
- Define sanctions, PEP, wanted-list and adverse-media configurations separately.
- Decide which events use portal, API, CSV batch or ongoing monitoring.
- Preserve a stable matter, grant, programme, partner or transaction identifier with each request.
- Record the party's role, supplied relationships and available secondary identifiers.
- Define who investigates a candidate and who owns the consequential decision.
- Create a separate escalation path for ownership/control, humanitarian-exception and licensing questions.
- Test original scripts, transliterations, common names, entities and supplied related parties.
- Test a known false positive without a change and again after a relevant identity or source change.
- Reconstruct one completed decision from the original input through review, escalation, outcome and later reassessment.
- Keep identity verification, source-of-funds, diversion, programme and legal records in their appropriate systems.
- Recheck source dates and jurisdiction-specific language before relying on the implementation.
Frequently asked questions
Must every charity screen every donor and beneficiary?
No universal global rule requires every nonprofit to screen every donor or programme beneficiary identically. The organisation should determine its populations and controls from the applicable framework, activities, risk assessment, programme and available data. FATF Recommendation 8 calls for focused and proportionate measures rather than indiscriminate treatment of the whole NPO sector.1
Who might a charity or NGO screen?
Depending on the applicable framework and approved policy, supplied parties may include donors, funders, grant applicants, grantees, trustees, directors, representatives, implementing partners, suppliers, payment parties and, only where justified, programme beneficiaries.
Is a donor PEP result the same as a sanctions match?
No. PEP status identifies political exposure for the applicable risk-based process. A sanctions result identifies possible similarity with a configured sanctions record. Neither result alone determines whether a donation should be accepted.
Can sanctions screening establish that aid was diverted?
No. Screening can identify a candidate connected to a supplied person, organisation or payment party. It does not prove that funds or goods were diverted or that a programme failed.
Does a sanctions match mean humanitarian activity must stop?
Not automatically. The relevant regime, party, activity, exception, licence and facts require legal or compliance analysis. Screening should preserve the evidence needed for that decision rather than make it autonomously.
Can a grants or donation platform integrate screening through an API?
Yes. It can submit supplied party information at an approved acceptance, application, onboarding, appointment or disbursement event and route candidates for review. The organisation remains responsible for defining the population, trigger, intervention and final decision.
Is transaction screening the same as transaction monitoring?
No. Transaction screening checks supplied parties or supported identifiers connected to an event. Behavioural transaction monitoring analyses activity patterns over time. Checklynx provides the former, not behavioural transaction monitoring.
Official sources
Footnotes
-
Financial Action Task Force, FATF strengthens standards on the nonprofit sector to protect legitimate NPO activity, describing the November 2023 revisions to Recommendation 8 and the focused, proportionate and risk-based approach, accessed 14 September 2026. ↩ ↩2
-
United Nations Security Council, Resolution 2664 (2022), establishing a humanitarian exemption to specified UN asset-freeze measures for defined actors and activities, accessed 14 September 2026. ↩
-
United Nations Security Council, Resolution 2664 (2022): current implementation status, confirming the subsequent continuation under Resolution 2761 (2024), accessed 14 September 2026. ↩
-
UK Office of Financial Sanctions Implementation, Financial sanctions guidance for charities and non-governmental organisations, updated 28 January 2026, accessed 14 September 2026. ↩ ↩2
-
UK Government, The UK Sanctions List, current source for UK sanctions designations following closure of the former OFSI Consolidated List on 28 January 2026, accessed 14 September 2026. ↩
-
German Federal Ministry of Finance, Sector-specific risk analysis and the update of Germany's national risk analysis, 20 August 2026, describing prior NPO terrorist-financing risk analysis and continuing national work, accessed 14 September 2026. ↩
-
Spanish Treasury, Sectoral risk analysis of nonprofit organisations, describing focused and proportionate NPO terrorist-financing risk measures, accessed 14 September 2026. ↩
-
UAE Ministry of Community Empowerment, Non-Profit Organizations Sector, describing the Ministry's licensing, regulatory and oversight framework for nonprofit organisations, accessed 14 September 2026. ↩
-
UAE Ministry of Community Empowerment, Request to Issue a No-Objection Certificate to Receive Donations, describing approval for registered nonprofit organisations to receive donations from inside or outside the UAE, accessed 14 September 2026. ↩