The European Banking Authority's (EBA) March 2023 Guidelines on de-risking require you to move beyond blanket-rejecting Non-Profit Organisations (NPOs). You must document a risk-sensitive assessment for every NPO customer. If you can't show how you differentiate category risk from individual customer risk, your next supervisory review will highlight that gap.
This template provides a structured approach to NPO Customer Due Diligence, aligning with the EBA's amended Guidelines on customer due diligence and risk factors. It helps your team avoid defaulting to rejection while maintaining compliance.
Purpose of the Template
Use this template when:
- Onboarding a new NPO customer
- Conducting periodic reviews of existing NPO relationships
- Reassessing an NPO flagged for heightened monitoring
- Documenting your decision to accept, reject, or terminate an NPO relationship
The EBA identified that NPO de-risking often stems from jurisdiction concerns and the complexity of Customer Due Diligence (CDD). This template addresses both by breaking the assessment into clear, answerable questions that your team can handle without specialized NPO expertise.
Prerequisites
Before starting, ensure you have:
- NPO registration documents (charity registration number, articles of incorporation, or equivalent)
- Governance structure documentation (board composition, trustee list, organizational chart)
- Financial statements for the most recent fiscal year
- Program descriptions covering activities, geographic areas, and beneficiary populations
- Funding sources breakdown (government grants, private donations, corporate sponsorships)
- Beneficial Owner Identification completed per your standard CDD procedures
- Access to sanctions screening results for directors, trustees, and beneficial owners
If the NPO operates in or sends funds to jurisdictions on the Grey List or Black List, you'll also need details on their correspondent banking relationships and any third-party payment processors they use.
The Template
Section 1: NPO Profile Overview
| Field | Information Required |
|---|---|
| Legal name | |
| Registration number | |
| Jurisdiction of registration | |
| Mission statement | |
| Year established | |
| Annual revenue (most recent year) | |
| Number of employees/volunteers |
Section 2: Governance Assessment
Answer each question. Mark "Unable to Determine" if the NPO cannot provide sufficient information.
Board and oversight structure:
- Who comprises the board of directors or trustees? [List names, roles, and any relevant professional backgrounds]
- How often does the board meet, and are minutes documented?
- Does the NPO have independent financial oversight (audit committee, external auditor)?
- Are there policies governing conflicts of interest for board members?
Decision-making authority:
- Who authorizes expenditures above €10,000 (or your institutional threshold)?
- What approval process exists for new programs or geographic expansion?
- How does the NPO document major strategic decisions?
Section 3: Financing and Fund Flows
Sources of funds:
- What percentage of funding comes from government grants?
- What percentage comes from individual donations?
- What percentage comes from corporate or foundation grants?
- Does the NPO receive funding from outside your jurisdiction? If yes, list source countries.
Use of funds:
- What are the NPO's three largest program expenditure categories?
- Does the NPO make cash disbursements to beneficiaries? If yes, describe controls.
- Does the NPO transfer funds to partner organizations? If yes, list partner names and jurisdictions.
Section 4: Activities and Operations
Geographic footprint:
- In which countries or regions does the NPO operate programs?
- For each jurisdiction, is it on the Grey List or Black List? [Yes/No for each]
- Does the NPO operate in active conflict zones?
Program delivery:
- Describe the NPO's primary activities (e.g., emergency relief, education, healthcare).
- Who are the intended beneficiaries? (Be specific: refugees, children, displaced persons, etc.)
- How does the NPO verify that funds reach intended beneficiaries?
Partnerships:
- Does the NPO work with local implementing partners? If yes, how are partners vetted?
- Does the NPO share resources or coordinate with other NPOs?
Section 5: Risk Factor Analysis
For each risk factor, assess whether it applies and rate the individual customer's exposure.
| Risk Factor | Present? | Individual Customer Rating (Low/Medium/High) | Mitigation Applied |
|---|---|---|---|
| Operations in high-risk jurisdictions | |||
| Cash-intensive program delivery | |||
| Opaque governance structure | |||
| Difficulty obtaining CDD information | |||
| Funding from high-risk jurisdictions | |||
| Partnership with unvetted local entities | |||
| Rapid geographic expansion | |||
| Inconsistent financial reporting |
Section 6: Decision and Documentation
Relationship decision:
- Approve relationship with standard monitoring
- Approve relationship with enhanced monitoring
- Approve with limited access (specify product/transaction limits):
- Reject relationship
- Terminate existing relationship
Rationale: [Provide specific reasons tied to the risk factors above. If rejecting or terminating, explain why risk mitigation options were insufficient.]
Mitigation measures applied:
- Increased transaction monitoring sensitivity
- Quarterly (instead of annual) periodic review
- Enhanced verification of beneficiary payments
- Restricted transaction types (specify):
- Geographic transaction limits (specify):
- Other (describe):
Approver:
Name: ________________
Title: ________________
Date: ________________
Customizing the Template
Adjust thresholds to your risk appetite. The €10,000 expenditure threshold in Section 2 should match your institution's standards. If you serve primarily small NPOs, lower it. If you're a corporate bank serving international relief organizations, you might raise it to €50,000.
Tailor geographic risk questions to your footprint. If you don't serve customers operating in conflict zones, remove that question. If you're in a jurisdiction with specific NPO registration requirements, like the UK's Charity Commission, add a field for that registration number.
Expand the risk factor table based on your experience. If you've identified additional red flags specific to your customer base, such as NPOs that frequently change bank accounts or those with unusually high administrative expense ratios, add rows to Section 5.
Define "limited access" products in advance. Before using the limited access option, document what it means: perhaps a basic current account with no international wire capability, or a transaction limit of €5,000 per month. The EBA Guidelines require you to specify these options before you need them.
Validation Steps
After completing the template:
Cross-reference sanctions screening. Confirm that every individual named in Sections 2 and 4 has been screened and cleared. If you identified a match requiring further investigation, document it in Section 6.
Check your decision logic. If you marked three or more risk factors as "High" but approved the relationship with standard monitoring, your rationale must explain why those risks don't warrant enhanced measures. Supervisors will scrutinize inconsistencies.
Verify jurisdiction classifications. Don't rely on memory for FATF lists. Check the current Grey List and Black List at the time of assessment, and cite the list date in your documentation.
Confirm you differentiated category from individual risk. The EBA Guidelines explicitly require this. Your Section 5 analysis should show how this specific NPO's risk profile differs from the general NPO category. If you can't articulate that difference, you haven't completed a risk-sensitive assessment.
Retain the completed template. Your competent authority can request this documentation. Store it with the customer's CDD file, and flag it for retrieval during supervisory examinations.
The EBA's Guidelines take effect three months after publication in all EU official languages. If you're still using a binary accept/reject approach to NPO customers, you're already behind the compliance curve.



