Audit-Ready NGOs: Preparing for Donor & Statutory Audits
Audit-ready is a system state, not a season — the evidence auditors actually request, the findings that repeat across the sector, and a 90-day preparation plan.
There are two kinds of NGOs in audit week: those retrieving documents and those reconstructing them. The difference is not diligence — both teams work hard. It is whether evidence was captured when transactions happened or assembled after the fact. Audit readiness is a property of your daily system, and it is decided months before the auditors arrive.
Know your audits
| Audit | Who requires it | What it examines |
|---|---|---|
| Statutory audit | NGO Coordination Board / Registrar, annually | Financial statements, statutory compliance, going concern |
| Donor / project audit | Individual grant agreements | That grant's spending vs budget, procurement, assets, deliverables |
| Systems / institutional audit | Large donors before or during funding | Your policies, controls, and whether you follow them |
| Statutory returns review | KRA, NSSF, SHIF | PAYE, withholding, levy filings vs payroll reality |
A donor audit is narrower but deeper than the statutory one: expect sampled transactions traced end-to-end — requisition to approval to quotes to PO to delivery to invoice to payment. One complete chain answers in minutes; one broken chain becomes a finding plus a deeper sample.
The findings that repeat across the sector
- Procurement procedures not followed — the perennial #1; see procurement challenges in NGOs.
- Unliquidated advances — field advances aging past policy deadlines with no follow-up trail.
- Unsupported expenditure — payments whose receipts, attendance sheets, or activity reports cannot be produced.
- Co-mingled funds — restricted money covering core costs; see restricted vs unrestricted funds.
- Asset register gaps — equipment that cannot be located or lacks grant attribution.
- Payroll vs statutory mismatches — PAYE/NSSF/SHIF filings that disagree with the payroll ledger.
The 90-day readiness plan
Days 1–30: find the gaps yourself
- Pull five random transactions per active grant and trace each end-to-end. Every missing document is a finding you just prevented.
- Age all open advances; chase everything past deadline.
- Reconcile the asset register against a physical spot check of one office.
Days 31–60: close them
- Collect missing support while memories are fresh — a signed memo explaining a gap now beats silence in audit week.
- Post shared-cost allocations consistently back through the year.
- Match statutory filings to payroll month by month; correct differences before KRA finds them.
Days 61–90: institutionalize
- Move the trace test into month-end routine — two transactions per grant, every month, forever.
- Decide deliberately how auditors will see evidence — scoped read-only access if your system can genuinely restrict them to one grant, and a prepared export if it cannot. Ours cannot: permissions are per module, not per grant, so we would hand over that grant's extract rather than a login.
- Brief staff: answer what is asked, retrieve rather than narrate, and never guess.
Management responses matter
A finding with a concrete management response and a completed corrective action reads as institutional strength. The same finding repeated two years running — previously reported, unresolved — is what erodes donor confidence fastest.
Every item in this plan gets cheaper when the paper trail assembles itself. That is the practical case for an ERP built for NGO governance — evidence captured at transaction time, retrievable at audit time. Here is exactly how much of that trail we assemble, and where you still hold the pen.
What AWRA OpsHub does today
- The procurement chain as linked records — requisition, RFQ, quotation, purchase order, goods check-in, invoice, payment. This is the end-to-end trace a donor auditor samples, and it is real.
- Three-way matching that compares ordered, received and billed quantities and prices, and reports each discrepancy rather than silently passing the invoice.
- An audit log of who changed what, down to the session.
- Role-based permissions per module, so a reviewer can be given read rights without edit rights.
- A document vault with classification, checksums, access logging and archive — so you can prove who opened a document, not just that it exists.
- An asset register with named custodians, movement history and last-verified dates.
- Versioned statutory payroll rules — PAYE, NSSF, SHIF and the Housing Levy, each carrying effective dates and each verified against a real employer payslip — which is what makes the payroll-versus-filing reconciliation in Days 31–60 possible at all.
- Documents attach to the transaction itself — shipped 2026-08-01. Expenses, purchase orders, requisitions, quotations and assets all take Document Vault files directly: checksummed on upload, classified, every download logged, and archived rather than deleted when removed. The receipt now lives on the record it evidences instead of in a naming convention.
More we can add to your workspace
- Auditor access scoped to one grant. Permissions are per module rather than per project today, which is why the Days 61–90 advice above changed: prepare an extract rather than promising a scoped login.
- The receipt link depends on the quotation path. Matching traces the order through its quotation to the check-in; a purchase order raised outside that flow has no receipt to match against, and that is where a broken chain will actually come from.
- Evidence as a condition of approval. "Produce the receipt for this payment" is now a link on the record rather than a filing convention — but only where somebody actually attached it, which is what making the attachment compulsory would settle.
- Advance ageing. The Days 1–30 instruction to age open advances needs the advances module below it, and a report on top.
- A statutory return submission. PAYE, NSSF and SHIF are computed and exported; somebody files them on the portal. The mismatch this post warns about is therefore a comparison you run, not one the system prevents.
- An audit-response or corrective-action tracker. Findings, management responses and follow-up live outside the system.
- Automatic retention enforcement per grant. Retention periods are a setting you review, not a per-donor clock that acts on its own.
The fair summary is that we are strong exactly where donor audits bite hardest — the procurement chain, the change log, custody of assets, and payroll arithmetic — and weak on the wrappers: advances, document-to-transaction linking, and the audit process itself. Read the second list as your preparation checklist rather than a disqualification, and note that two of its items changed the advice in this post rather than merely qualifying it. Retention obligations are covered in retention and deletion, and the trail itself in who changed what.
Anything above that you need, we can build for you
Everything listed above as something we can add describes what ships in the standard product today — it is a starting point, not a limit on what AWRA OpsHub can do for your organisation. Kenya's eTIMS integration and its maintained payroll engine are both in the product because clients needed them and commissioned them; neither appeared by itself, and the same door is open for whatever you just read about. One qualification so this is worth what it claims: a small number of things on this blog we deliberately leave to a specialist rather than build — a statutory ledger we will not sign our name to, a rule that would decide a tax question for you, a clinical or member-funds record that belongs in a regulated system — and where that is true the post says so in those words. Everything else is a scope, a timeline and a price.
The operational work, which is what most commissions actually are
An extra approval stage in a chain that does not match the standard one, a custom field set on employees or assets that only your sector needs, an expiry that has to block an order rather than send an email, a report your board asks for in a shape nothing produces, or a scanner or weighbridge feeding the goods-in door. These are the commissions we are asked for most often and the smallest ones we quote — and unlike a revenue-authority pipeline, none of them waits on a regulator.
The module-shaped additions, which are the ones readers ask for most often
A price list with real discount authority, a customer-facing quotation that expires, a bill of materials or recipe costing, a staff advance that is issued, acquitted and chased, a member or unit ledger, a matching rule that holds a payment. Each of these is a build rather than a setting, and each has been quoted before — a bigger piece of work than a custom field, with a written spec and a date instead of a roadmap slide.
The report, document or pack nothing currently produces
The board pack in the shape your board actually asks for, a donor or funder layout, an invoice or receipt template carrying what your regulator or your customer expects, a dataset the report builder cannot reach yet. Usually the fastest thing on this list to deliver, because the data is already in the system.
Systems, rails and hardware you already run
The accounting package, CRM, online store, core banking or custom database you intend to keep — connected through our API so a fact is entered once and appears everywhere it is needed. Plus the physical edge: a scanner, a scale, a weighbridge or a till peripheral feeding the door it belongs to.
How it works: you describe the requirement, we return a written scope, timeline and cost, and once agreed it is built into your environment and maintained as part of the product. Nothing here waits on a regulator or a published specification, which is why operational builds are the ones we quote fastest. Tell us the requirement that would otherwise rule us out — that is a better first conversation than a demo.
Tell us what your operation needsBe the retrieve team, not the reconstruct team
Requisition to approval to quote to order to receipt to invoice to payment, held as linked records with three-way matching and a full change log — with the gaps named honestly so your 90-day plan targets the right work.
See AWRA for NGOsFrequently asked questions
How long should we retain financial records?
Kenyan law generally requires seven years for accounting records; donor agreements often specify five to ten years after grant closure. Apply the longest applicable period per grant, and store scans systematically — paper fades faster than retention periods.
Can auditors demand access to our accounting system?
Donor audit clauses typically grant access to records in whatever form they exist, including systems. Scoped read-only access is ideal where the system supports it — auditors see the trail themselves without touching live data. Check whether yours actually scopes: in ours, permissions are per module rather than per grant, so a read-only login would show an auditor more than their grant. Where that is true, a prepared per-grant extract plus a supervised screen-share is the cleaner answer, and no auditor objects to it.
What if we simply cannot find a supporting document?
Say so, in writing, with what you did to search and any secondary evidence (bank records, delivery confirmation, activity photos). A documented gap with a corrective action reads far better than a suspiciously perfect file produced late.
Are small NGOs audited less strictly?
The sample is smaller; the standard is not. A KES 5 million grant gets the same end-to-end tracing as a KES 500 million one — smaller organizations just have fewer transactions to keep clean, which is an advantage if the system is right.